Security Testing is not about running the tools alone

Security Testing is not about running the tools alone

If things were so easy that tools would do the brainy work, humans should have done something else. Now, tools are what a human makes and they are designed to do however they have been programmed. Well, I am not saying running tools for security testing for your web apps or mobile apps is not good; but I am emphasizing on the fact that "Only running tools will not help if there is no brain behind it". You can relate to following something blindly without knowing the minute pieces of it.

Now, you got the context I hope. I have seen many testers who want to learn security testing and have failed miserably in learning it. Why? Its hard to provide a reason which may convince the audience. Like hackers just can hack for whatsoever reason, testers couldn't learn security testing for whatsoever reasons.

Testers who have been doing functional testing for a while always ask me about, "What tools can I use to do this?" Argh! This is the question that used to piss me off. However, I am much calmer now and understand testers while I try to answer them in better way. I insist them to build the mind-set and skill-set in parallel. Yes, in parallel and not really mind-set first or skill-set last (vice-versa).

I have been into hacking since 16 when I was in my school. Now, no one spoke to me about hacking or taught me hacking, I was curious and I started to dig more deeper about it. I may give credit to my financial problem when I was 16, I mean I did not have money to pay for internet dial-up packages. So, I learned about dial-up hacking where I need not pay for the package and use someone else bandwidth. And here it was not about TOOL but my BRAIN which designed this idea. And later was the search for a tool which can aid this activity.

So, you see it is crucial to generate the tests first and these tests need to be designed by your brain and not just the tool.

Both mind-set and skill-set are important. Even if you leave one, it is incomplete. Period.

Sivaanand Murugesan

Principal Software Engineer | Golang | Terraform & Crossplane Provider Design & Development | Quant enthusiast | HFT Systems

10 年

Well thought!! Tools are created to solve the problems and loop hole which already find and occurs more frequently!! But problem are “n” in number and in more scenario it was new ...

回复
Neha Thakur

Consultant at TCS, Technology and Agile Enthusiast, Speaker @CAST, STC, Writer

10 年

Well said Santosh!!

回复
Aamir Zeshan

Director at Metro consultants

10 年

Well tailored!

回复
Chirag Daxini

Technical Project Manager

10 年

nice...

回复
Abhinav Sejpal

Taking away app and cloud security pain of engineering squad | DevSecOps Leader & Advisor

10 年

Absolutely Correct!!

要查看或添加评论,请登录

Santhosh Tuppad的更多文章

  • My QA Mentor’s Initial Days

    My QA Mentor’s Initial Days

    I made a choice to join QA Mentor as a Director of Security Testing Practice and it was a very smooth conversation…

    4 条评论
  • E4: Social Engineering - My Forte!

    E4: Social Engineering - My Forte!

    In simple terms, social engineering is hacking someone’s thoughts and making them act like how you want them to by…

  • E2: The internet and irc bug.

    E2: The internet and irc bug.

    The internet My high-school friends come to my home in Tumkur and they say this, “Let’s go to the internet café. And I…

    1 条评论
  • E1: The Beginning - Fear, Stealing and Lying.

    E1: The Beginning - Fear, Stealing and Lying.

    Like we don’t really understand the beginning of this universe, I did not understand how everything started in the…

  • DIY: Learn security testing — Quick TIPS!

    DIY: Learn security testing — Quick TIPS!

    Software is Code. You write code and it behaves based on how you write the code.

    3 条评论
  • How to decide if you need security testing for your software?

    How to decide if you need security testing for your software?

    Do you hate nightmares? If you do, then please continue reading it as you are possibly one of the target audience for…

  • We need more smart technical software testers

    We need more smart technical software testers

    Speaking about Software Testing craft, I have always been into technical side of testing and understanding the software…

    16 条评论
  • Are you really productive for 8 hours?

    Are you really productive for 8 hours?

    I have been working as a Software Tester for 6 years now and have had various experiences in various organizations…

    10 条评论
  • How (bad) bug reports can increase project cost?

    How (bad) bug reports can increase project cost?

    In my 6+ years of experience as a Software Tester, I have come across large number of bug reports which I have read for…

    8 条评论
  • Stop calling yourself a Test Lab if you are not experimenting

    Stop calling yourself a Test Lab if you are not experimenting

    Nowadays, it's very stylish and jazzy to call your start-up testing services as "Test Lab" as it looks cool to the…

    3 条评论

社区洞察

其他会员也浏览了