October 26, 2009

Testing Role-based Authorization Controls in Websites

By Varun Sharma

This paper describes a practical approach on how to test websites for flaws in role-based authorization controls. The first two sections discuss the importance of testing these controls and how testing is tied to the business that the Website supports. The rest of the paper outlines the general approach and some specific tools and techniques that can be used.