Types of testing:
Pen testing: We do this twice a year on Umbraco cloud - We want a report of the pen-test.
Vulnerability testing: Identifying or evalutating the weakness of vulnerabilities. Here you would use software to run the test. EG if a person discovers a vulnerability in the CMS. Then we releas a patch for security upgrades
Security testing
Performance testing: To test how a system works in different conditions. Stress the systems with various stress conditions.
Load testing (DoS) :Simulate traffic to see if a site can handle the weight.
DDoSing: One single point of attack. Large number of computers that are used to send a big load of attack
Ethical hacking/ers
Whitehat hackers
-
What are they?
Security, pen and vulnerability testing are what we want on Umbraco cloud.
-
Which ones do we allow on a dedicated app service plan?
All test beside DDoS. Cloudflare will block the DDoS.
-
Which ones do we allow on a shared app service plan?
Pen, Security and vulnerability. So no perfomance testing.
-
What to do when a customer reaches out and asks if they can do an x test?
What kind of test?
- On shared: Pen, Security and vulnerability.
- On Dedicated: All beside DDoS
-
DDoS protection on UC
CloudFlare
-
What kind of test data are we interested in and why?
Security, pen and vulnerability testing. Customer needs to reach out to security@umbraco.dk with their results
-
What kind of testing do we do on UC?
Pen test twice a year
-
Payment
Customer does not have to pay for the dedicated while they test.
Let fishtank know.