Change Language
Sun Sun Sun

You are here: Resources >> Test Your Security Policy

 

Test Your Security Policy
 
The tools below will let you test your security policy. The following tests focus on a specific security domain in the product’s security policy.
 
Intrusion Prevention Security Engine Testing
 
Test Denial of Service (DoS)
 
Description: Denial of Service is an attack that causes an application to stop responding so that the user has no choice but to close it. In some cases, this exploit can be leveraged into a remote code execution attack by using an exploitable buffer overflow. The link below is a harmless example that will cause Internet Explorer to close on an unprotected machine.
 
Guidelines: Click on the link below to test your Vulnerabilities and Exploits policy. If you receive the "Security Status: You are safe" message, your Vulnerability Protection engine is active. If you receive the message "Security Status: You are vulnerable", it means that your Vulnerability Protection engine is not setup properly. When clicking on "Run Demo", your browser will crash.
Click To Buy a Protector UTM Appliance!
Click To Buy a Portable Penetrator Wifi Pen Test!
Click To Buy a Penetrator Pen Testing Appliance!
Click To Buy a Web Security Scan!
Click For a Free Security Scan!
Click For a Free Newsletter!
 
 
Solution: To prevent this malicious code from entering your network, make sure to enable the Vulnerability Protection service.
 
Links: DoS_Test.html
 
Test Remote Code Execution (RCE)
 
Description: The Remote Code Execution attack allows an unauthorized party to remotely control your computer and steal confidential information. The attacker can also create or delete files and basically do anything with your system.
 
Guidelines: Click on the link below to test your Vulnerabilities and Exploits policy. If you receive the "Security Status: You are safe" message, your Vulnerability Protection engine is active. If you receive the message "Security Status: You are vulnerable", it means that your Vulnerability Protection engine is not setup properly.
 
Solution: To prevent this malicious code from entering your network, make sure to enable the Vulnerability Protection service.
 
Links: RCE_Test.html
 
Test Phishing
 
Description: Phishing is an attack designed to steal data from an unsuspecting user. This can be done by disguising a malicious website as a known and trusted one (e.g., a bank website or a webmail website) and tempting the user to enter his personal information via a fake login screen and so forth.
 
Guidelines: Click on the link below to test your Vulnerabilities and Exploits policy. If you receive the "Security Status: You are safe" message, your Vulnerability Protection engine is active. If you receive the message "Security Status: You are vulnerable", it means that your Vulnerability Protection engine is not setup properly.
 
Solution: To prevent this malicious code from entering your network, make sure to enable the Vulnerability Protection service.
 
Links: Phishing_Test.html
 
Behavior Profile Security Engine Testing
 
Test Code Obfuscation of Malicious Script (COMS)
 
Description: Code Obfuscation is a methodology used by malicious code writers to obfuscate their harmful code. It uses encryption and encoding in order to garble the original source code, therefore making it harder to analyze.
 
Guidelines: Click on the link below to test your Behavior profile policy. If you receive "Security Status: You are safe" message, your Behavior policy is active. If you receive the message "Security Status: You are vulnerable", it means that your Behavior profile engine is not set up properly.
 
Solution: To prevent this malicious code from entering your network, make sure to enable the [Block Malicious Scripts by Behavior] rule in your security policy.
 
Links: This demo is based on a known vulnerability in web browsers.
 
COMS_Test.html
Test JavaScript/VB Script
 
Description: JavaScript/VB Script are codes that can be embedded into a webpage to add functionality. This added functionality and flexibility results in exposure to some security risk.
 
Test Java Applet
 
Description: Java applets are programs designed to execute on another program (usually a web browser). Since java applets run without user intervention, the JVM (Java Virtual Machine) enforces some limitations upon it. These limitations include writing files to the local computer, reading files, program execution, registry manipulation, and so on.
 
However, there are some security vulnerabilities (See: CAN-2005-3906) that allow malicious applets to bypass these limitations. As such, any applet that tries to perform any of the restricted actions should be blocked regardless of the bypass technique, if there are any used.
 
Guidelines: Click on the link below to test your Intrusion Prevention. If you receive "Security Status: You are safe" message, your Intrusion Prevention is active. If you receive the message "Security Status: You are vulnerable", it means that your Intrusion Prevention engine is not setup properly.
 
Solution: To prevent this malicious code from entering your network, make sure to enable the Intrusion Prevention service.
 
Links: This demo is based on a vulnerability that is already patched. The below applet will try to create a file (AppletDemo.txt), on C:\secpoint. As described above, since this applet tries to perform potentially illegal and dangerous operations, it should be blocked (if your machine is patched, no file will be created).
 
Anti-Virus Security Engine Testing
 
Test Anti-Virus
 
Description: EICAR, the European Institute for Computer Anti-Virus Research, had developed a test file that an Anti-virus product “detects" as if it were a virus. This is not a real virus, and does not include any fragments of viral code. The file is a legitimate DOS program that shows the message, "EICAR-STANDARD- ANTI-VIRUS-TEST-FILE!"
 
Guidelines: Click on one of the links below to test your anti-virus policy. If the download dialog appears, your anti-virus policy is not active. If you see the Vital Security alert message, it means that your anti-virus policy is working properly.
 
Solution: To prevent this malicious code from entering your network, make sure to enable your anti-virus service.
 
Links: Eicar.zip, Eicar.jpg
 
URL Filtering Security Engine Testing
 
Test URL Filtering
 
Description: Perform the following test in order to validate weather the URL filtering engine works correctly
 
Guidelines: Click on the link below to test your URL Filtering policy. The URL below will lead to a site that is categorized as hacking site, and therefore should be blocked. If you receive the Vital Security alert message, your URL Filtering policy is active. If you get to the actual hacking site, it means that your URL Filtering policy was not setup correctly.
 
Solution: To prevent this malicious code from entering your network, make sure to enable the Web Content Filter.
 
Links: www.astalavista.box.sk
 
 
Click To Buy a Protector UTM Appliance!
Click To Buy a Portable Penetrator Wifi Pen Test!
Click To Buy a Penetrator Pen Testing Appliance!
Click To Buy a Web Security Scan!
Click For a Free Security Scan!
Click For a Free Newsletter!
 
 
Read more about our services and products here: About SecPoint, IT Security Products, and IT Security Jobs.

 

24 Hour Open Web Shop

Got a Question? - Call us!
EU: +45-70-235-245
US Toll Free: +1-888-704-7297
Sent us an Email!

Get a Free Vulnerability Scan

Get a Free SEO Blackhat Scan

  Email :
     
Related pages
 
Appliance VS Software
What is Cross Site Scripting(XSS)?
What is SQL Injection?
What is a Routing Table?
What is High Availability?
What is Grey Listing?
What is a Web Filter?
What is a Vulnerability?
What is a Proxy Server?
What is a Firewall?
What is a Cookie?
What is a Bayesian Filter?
Test Your Security Policy
Email & Spam Test Links
What is RoHS Weee?
What is Vulnerability Scanning?
What is Vulnerability Assessment?
What is Penetration Testing?
What is a Security Exploit?
What is Appliance Scanning?
What is Zero Day?
What is Unified Threat Management?
What is Intrusion Prevention?
What is a Content-Filter?
What is VoIP?
What is Virus?
What is Spyware?
What is Phishing?
What is P2P?
What is Instant Messaging?
What is Spam?
White Papers
Technology Papers
What is Wi-fi?
What is Wimax?
What is an open relay
What is vlan tagging?
Security Mailinglist Rss Feeds
What is a Man in the Middle Attack?
What is a Botnet?
Top 10 Ways to Protect Your Computer from Hackers
Top 10 Free IT Security Tools
Top 10 Website Security Myths
Top 10 Most Secure Operating Systems
Top 10 Worms
Top 10 Hackers
Top 10 Social Engineering Tactics
Top 10 Spyware
Top 10 Viruses
Top 10 Phishing Scams
SecPoint
Anti-Spyware Tips and Tricks
Anti-Spam Tips & Tricks
Anti-Virus Tips & Trick
How to get rid of malware
How to protect against client wireless hacking
Risks of Cyber Crime
How to choose a vulnerability scanning vendor?
Better Wi-Fi Range without Interference
SecPoint Free Security Scan
IT Security Gurus
Top 10 Myths in IT Security
Top 10 IT Security Tools
Top 10 IT Security Tips
Top 10 Hacker Attacks
Anti-Spam Appliance
Top 10 Spam Attacks
UTM Appliance
Penetration Testing
Application Security
Vulnerability Scanning
Vulnerability Assessment
Internet Filter
Spam Filters
Web Content Filter
WEP Crack
WiFi Security
Anti-Phishing Tips & Trick
PCI-DSS Compliance
Anti-Social Engineering Tips & Trick
Anti-Denial of Service Tips & Trick
Wifi Security Tips & Trick
Anti Hacking – Anti Cracking Tips & Tricks
Wireless Encryption Standards
CIDR Network Information
Virus Spam Bounce Ruleset
Anti-Cross Site Scripting (XSS) Tips and Tricks
Anti-SQL Injection Tips and Tricks
Wifi WEP Encryption Cracking Guide
Wifi WPA & WPA2 Encryption Cracking Guide
How to get rid of a trojan horse
What is Port Knocking?
SecPoint Training Videos
RC Release Candidate Software Firmware
What is SSL?
What is SOCKS?
What is SOCKS5?
Worldwide Security Events
Server Spam Filter
Spam Blocker
Anti-Spam Software
Vulnerability Scanning Appliance
What is a Grey Hat?
What is a White Hat?
What is a Black Hat?
Top 10 Cloud Computing Services
Cloud Security
WPA Key
Block Email Junk
Stop Spam
Anti-Virus
WEP Key
What is Encryption?
What is SSH?
Dell Worldwide Warranty Benefits
Aircrack
Anti-Spam Appliance Guide
Anti-Spam Firewall
BackTrack
Web Filter Appliance
Pen Test Appliance
Security Scanner
WEP WPA2 Crack
What is Blacklisting?
UTM Appliance Anti-Virus
What is FTP?
UTM Appliance WiFi Security
What is Greylisting?
Vulnerability Assessment Guide
What is SFTP?
Vulnerability Scanner
What is Telnet?
Wardriving
What is Whitelisting?
WPA2 Encryption
WiFi Audit
WiFi Pen Test Appliance
WiFi Client Cracking
WiFi Pen Test
WiFi Client Hacking
WiFi Hacking
WiFi Crack
WiFi Hack
WiFi Cracking
What is a vulnerability scanning appliance?
What is a web vulnerability scanner?
What is a web application firewall?
What is CISSP?
What is ISSAP?
What is ISSMP?
What is UTM?
Blind SQL Injection
What is “Dumpster Diving”?
How does SEO hacking occur?
What is search engine hacking?
What is Data Leak Prevention?
How essential is vulnerability management?
Global System for Mobile communication
What is UDP?
What is TCP?
What is GSM Encryption?
What is a Script Kiddie?
What is an Elite Hacker?
What is a Cracker?
What is Phrack?
What is Social Engineering?
What is a password?
What is Linux?
What is a Null Session?
What is Cyberwarfare?
What is Novell NetWare?
What is SHA Encryption?
What is MD5 Encryption?
What is RC4 Encryption?
What is Diffie-Hellman Encryption?
Malware
Logic Bomb
Cross-site Request Forgery
Red box
Black box
Blue box
What is War Dialing?
What is Denial-of Service Attack?
What is Penetration Test?
What is Tunneling Protocol?
What is a Spanning Tree Protocol Attack?
Man-in-the-middle Attack
Shoulder Surfing
What is ComboFix?
What is 2600?
What is SANS Top 20?
Hacker
Breaking Authentication Schemes
SQL Server - Stored Procedure Attacks
Logic Attack
Windows Operating System - Password Attacks
SharePoint – Multi-Tier Attacks
Internet Information Services (IIS) - Web Service Attacks
What is a 2.4 GHz Wi-Fi?
What is the 5.8 GHz Wi-Fi?
What are Server Misconfigurations and Predictable Pages?
What are the risks of the escalation of privileges in the active directory?
What is the mail service attack on Microsoft’s Exchange Server?
What are the attacks on the Macros and ActiveX?
What is a Password Replay Attack?
SEO check for no tags noarchive noindex nofollow
SEO check for small size font tag
SEO Check for css hiding of elements
SEO Check NOSCRIPT text for spamming
SEO Check for img alt title tags spamming
SEO check for long title tag spamming
SEO Check for short link tag spam
SEO Check cusor type to text spam
SEO Check page has count a tags
SEO Check a tags no follow
SEO Check links do not correspond to a tag
SEO Check long keyword description tags
SEO Same link with different content
SEO Check link from invisible img
SEO Check H tags H1..H6 spamming
SEO Too many keywords spam
SEO META REFRESH redirect spam
SEO Javascript popups spam
SEO 302 Redirect
SEO 200 codes to 404 errors not follow html standard
SEO Errors explanations
View More...
 
Privacy Statement | Link Policy | User Policy | IT Security Blog | IT Security Forum | SecPoint Pictures
Event Pictures | Exploit Archive | IT Security Web Shop | Vulnerability Library
IT Security Video | Sitemap
© Copyright 1999-2010: SecPoint®
SecPoint ApS - Lergravsvej 53 - 2300 Copenhagen S - Phone +45 70 235 245
Recent awards Compatible with Visit us on Facebook! Visit us on LinkedIn! Visit us on Myspace!
   
Facebook
Group!


Follow us on Twitter!
Anti-Spam Appliance - Anti-Spam Firewall - Unified Threat Management Appliance Anti-Virus - Web Filter Appliance - Anti Spam Appliance - Anti Spam Firewall - UTM Appliance Wifi Security - Wifi Pen Test - Wifi Crack - Wifi Hack - Wifi Audit - Wep Wpa2 Crack Vulnerability Scanner - Vulnerability Assessment - Security Scanner - Pen Test Appliance