Git Product home page Git Product logo

openmrs-security's Introduction

openmrs-security's People

Contributors

xding3 avatar genterist avatar adrianluan avatar zli36 avatar

Watchers

James Cloos avatar  avatar  avatar

openmrs-security's Issues

Final Review-1

Report order not correct
Include unnecessary files

[A1 - Injection] [ Drop Table ]: Lack of module (Search). Test case descriptions are not specific. Testing data might be something like [a'; Drop Table Patients;" ]. And for expected result, it should found out whether the table is deleted.

[A1 - Injection] [ Tautology ]: Lack of module (Login). Test case descriptions are not specific.

[A2 - BAC] [ Exposed Session IDs ]: Lack of module. Test case descriptions are not specific. URL opened for inspecting session ID could be specific?

[A2 - BAC] [ Session Time Outs ]:Lack of module. Test case descriptions are not specific. Have doubt on this test case. Firstly it's not about "time out". And when reopen the browser and , if the session still exist it should not mean "fail"

Fuzzing with ZAP - Tam

We used the jbrofuzz rulesets (introduced in the initial ZAP activity) to perform a fuzzing exercise on OpenMRS with the following vulnerability types: Injection, Buffer Overflow, XSS, and SQL Injection. We pick at least one ruleset for each type of vulnerability listed. The ruleset should be appropriate for the target field and backend. We include the chosen fuzzers for each vulnerability type along with the results, and what we believe the team would need to do to fix any vulnerabilities we find. If we don't find any vulnerabilities, we will provide our reasoning as to why that was the case, and describe how we would adjust the fuzzing rules we used.

Client-side bypassing - Tam

5 test cases in which we stop user input in OpenMRS with ZAP and change the input string to an attack.
We include the page URL, the input field, the initial user input, and the malicious input, and describe what "filler" information is used for the rest of the fields on the page (if necessar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.