Software Testing, Test Automation, Test Consulting, and Trainings...... Learn from experience
Thursday, May 27, 2010
Black box testing design techniques
For example, here in black box testing, if any input is passed into the system and if the result is what was expected, then the test is passed.
Following are the design techniques for black box tests:
1- Equivalence class partitioning
2- Boundary value analysis
3- decision tables
4- Orthogonal arrays.
Now we will cover one by one in detail.
1- Equivalence class partitioning:
This technique is based on mathematical set theory. When your input domain is too large
then you break down this domain into finite number of sub domains (or sets). Now when you test you software, every value in
these set will be treated as same value. So you can pick one value from each set and test you software. This way you are
able to test the large set of data with few number of test only.
So the motive behind using the techniques is clear and that is to reduce the number of test cases to save time and cost.
Example:
Suppose in a software there is a field which except numbers from 1-100. now the range 1-100 is called as partition which is
a valid partition. Other than this there are two more invalid partition and they are: <=0 and >=101 . Now we can choose one
value from each of these partitions.
Valid partition is (1,2,3...............98,99,100)
Invalid partition 1 is (0,-1,-2,-3......... so on)
Invalid partition2 is (101,102,103,......so on)
Further Equivalence partitioning is no stand alone method to determine test cases. It has to be supplemented by boundary
value analysis.
2- Boundary value analysis:
In this case, we use the term boundary conditions to identify the set of allowable or inputs,
for a particular function. Testing boundary conditions includes testing inputs that fall outside the boundaries.
The boundaries are the values on around of the beginning and end of the partitions.
Here in a valid partition the beginning value is 1 and end value is 100. so the testable values will be like 0,1,2 and 99,100,101.
so this is something the boundary values for X will be X-1, X and X+1.
3- decision tables:
This technique of decision tables can be used as a method to identify all possible inputs or combination of inputs
for a test case.
A decision table is typically divided into four quadrants, as shown below
----------------------------
=
Condition = Input values
=
----------------------------
=
Action = Output values
=
----------------------------
4- Orthogonal arrays:
This is also known as taguchi method.
Let me explain why this comes into picture. The equivalence class portioning and boundary value analysis allow u test only
single value at a time and after that decision table start to look at combination of variables. But here the combination
can becomes very large very quickly. Thus the question becomes: how do you limit the combination without compromising
the quality.
Now the orthogonal arrays technique addresses this problem. The use of this is to determine the number of experiments require
to find best solution to given design problem by testing many variables at once.
An orthogonal array is a subset of combination of values for variables such that for every pair of variables,
every pair of values occurs an equal number of times.As an example, consider a module of code that has
three decision statements where variables A, B, and C can be true (T) or false (F)
All possible combination of the three variables A, B, and C with two possible values, true and false,
can give you eight test variations.(The number of combination is the number of values raised to
the number of possible variables, or 23 = 8.)
TTT
TTF
TFT
TFF
FTT
FTF
FFT
FFF
The orthogonal array for this example offer you only following four cases.
TTF
TFT
FTT
FFF
for the rule applied here and detail pls visit
http://www2.research.att.com/~njas/oadir/oa.4.3.2.2.txt
Wednesday, October 21, 2009
Web 2.0 security testing oversight
This post is for them who want to take an overview on security testing of web 2.0 applications.
so lets start with the question 'Can automated tool be used for securing a website from hacking inexpensively and easily and what they are ?' so there are numbers of such tools available in market. many of them are free. one can search in internet. there are so many which are paid but parallel they provide their free version also.
But my concern over here is , we should not overestimated the value of such tools or scanner. The manual activities also important to find out the securities vulnerabilities. so just do not underestimate the manual effort given to your testing activities.
The firefox plugin or extension can help us to find this. Most developer use such extension. firebug is one of them. SQL injection is one of the best method to
lets now try to see the most vulnerabilities discovered. I would like to thanks Kevin Beaver, one of the best author I used to read the article. he also given the below fact which i am going to describe.
here re the few most affective Web vulnerabilities according to the order:
1- Cross site scripting (CSS also known as XSS)
2- Broken session management
3- Improper error handling
4- Unvalidated input
5- Injection flaws
6- Insecure config management
7- Broken access control
and many more.
so from this it is very clear that XSS is very common Web vulnerabilities. I have already posted one article on XSS. you can find this here
I have also manage to write white paper on web testing which may help you to understand the whole process of testing web application. That can be find on clicking here.
Thank you for using my blog. I will really appreciate if you write few comments and suggestion to improve it.
Monday, May 11, 2009
Manual database testing using stored procedures
To test such applications a tester should be smart enough in identifying the scenarios which covers the testing of every functionality.
Now one and major part of this testing is to test in back end. the data inserted from from end is properly gone to the correct place. we do it manually. for this we need to know:
1- Detail knowledge of application.
2- Good knowledge of database used(overview of database used, good in query, datamodel, reltionship used).
3- Sound skills to identify the scenarios which covers all the functionality.(some time we need to identify the case which really come into action in production only. for this testers some times need to change from code to execute such scenarios.)
so doing verification of data we generally use some query to fetch data from database. We have sets of statement here.
I would always prefer to make some stored procedure which realy help in excecuting the queruies.
I wil give an simple example here which may help you that how to used stored procedure while testing with database.
I am taking an example here which allow a user to to register with a application by sending a request in form of XML. after registerting this the request will give you a key and using that key you can see the result which the application provide.
The flow of the request will be like:
1- The set of user data inserted
2- A key provided to user as in response
3- User again send a request using this key
4-user information recieved in form of XML.
so here the testing will include
1- wheather user data inserted in proper place in database.
2- The information recieved by user is correct or not.
for this we can make some quesries to fetch the data(it can be manually checked but that will take much time and will not be compatible.)
here we can also make some strored procesure(hope you undersatand basic of stored procesure how to create , how to execute).
suppose I want the user data from user table corresponding to a user id. for this you can write a procesure in a way...
1- Open a new query prompt
2- Write..
create procedure userdetail
{
@user_id numeric(10)
}
as
select * from USER
where USER_ID= @user_id
3- Execute this query
4- Now you can see this procesure in you list.
5- now to execute this you can use
exec userdetail '2001'
or simple go to the listing of procesures and execute there by clicking the option in right click.
you will find a window whete to pass user_id.
this is a simple procedure i used here. in same way we can test by passing inputs .
Tuesday, April 7, 2009
Testing in Agile software Development
Continuing to my last article....
In era of the rapid software development where the changes take places randomly and requirement chances every hours, the role of testers is very tough and challenging.
The biggest challenges in agile software development is to handle the changes made rapidly. Software changes every hour. The new code is being pushed in test server every day or even every hour and hence the testing system becomes changing. To deal with such cases and to test this , we need a different kind of approach of testing with may be totally differ with a scripted testing. This need different set of skills and tactic. For this tester need to very flexible and very innovative. I found in some case company don't allow to adopt any approach other than the scripted one. But For this a agile tester should have a valid reason and tendency to make project manager/ seniors agree to adopt new approaches. I always have a reason to adopt my approach. Some time I need to make significant change in our testing approach and I do this because I do have confidence in my approach.
propose your plan to the team without hesitation after all our prime motive is same which is "to make s/w bug free". So if you have any idea in your mind and you believe this will work , don't wait and let your bosses know.
Agile testers need to be well versed in following area:
1- Active participation in scrum meeting to make decision on agile test plan. I pointed agile test plan here specially because the test plan we make here can be quite different as a normal. take decision on what will you do next, how will you do, and the reason of doing this means how it is meaning full and how it will how practically.
2- Experiencing the application in different ways to improve the understanding of risk, c to find such scenarios which might be missed during first planing. and expected behaviors. I always preffer to see my application in different ways: QA, Tester(Some how technical, data model, flow of application ), End users, and layman.
So these should be the common and beneficial practices in agile software development.
Some time we work in such project where there are many teams works together sitting in different places. There are many challenges in testing such projects. Few things(other that the expected skills from a tester) which I feel every tester should follow to accept the challenges in testing of such project.
1- Tester must be very active in participating in all meeting and conference calls with other teams and client. If this is not happening in your project, just ask for this.
2- Need to be very active and flexible to adopt the changes during development. Documentation can help to manage them. To identify the scenario at the spot.
3- Need to practice to make a TO DO LIST (I adopted this from of my manager and believe me it is working) . This practice really help you to remember the things to be implemented. once come back from meeting just review the TO DO LIST and update your documents.
4- Should be very straight forward. Don't say YES all the time. if you feel this is wrong, put your thought to the front of team. Realize that you are responsibility for over all quality of the application and process.
5- Do regular meeting with team working with, to find the gaps in requirement. As there are not fixed requirement and this keep changing so there might be the cases that you are not communicated some changes during development. some changes for most of them think no This is not beneficial to Tester. No I don't think so, every thing weather it is requirement change or changes in architecture or design, the tester should know about this. So This meeting will insure you that really you did not missed nay thing.
6- Practice to make scenario(a high level scenario which really does not have the steps to test) and document this in a different folder. Discuss these scenarios with your PM and other seniors persons and ask them to review. This will be a green signal to your cases that you have not missed any thing and are sufficient to cover the testing. Later you can extend these scenarios to a detailed test cases as per the time arability.
at the end , I say... The agile method don't use a typical QA process, but this does't meas that we produce a quality less product using agile method. In Agile, we need to do frequent communication among the whole team. Break down the testing in smaller part and that to be flexible. Allow end user to access application ASAP and in a very early phase which also let you know that whether application behaves accordingly or not. exploratory testing should be the part of this methodology. Over all , in net the quality of application is much high in agile software developemnet..
Thanks,
Vishal Sachan
Sr.QA, Tekriti Software
Wednesday, April 1, 2009
Exploratory testing in agile environments
I read many article and white papers and found that the term exploratory testing is used equivalent to ad hoc testing. I fed up. I am not agree with this. there Once a guy asked me that 'is exploratory testing and ad hoc testing is same?' My answer was very simple.
"It depends on you , if you think an ad hoc testing is a very rough and thought less testing then I would say that no, exploratory testing and ad hoc testing are not same ". Guys please make it clear, I am using exploratory testing here is not like this. Exploratory Testing is always done with the intent of understanding the functionality of the application
In Agile software project when a new tester join the project, I would suggest to do this testing . This will help him to perform testing and getting familiar with application. What bad in this? Unlike traditional test methods where there are certain process , exploratory testing is more of a real-time process. Tell me one thing...Is this practical possible to adopt a scripted testing in agile development. I hope most of you will say NO. so what? We can say it is better way for a tester to get familiar with application parallel to their testing activities, to follow the exploratory testing. It is also true most of the testers follow this at least once or later this approach in their project testing but the problem they never go with its definition and a proper way.
I have been working in a project which used the agile development method and I am working as a lead QA off shore for that project. I always asked my colleague to explore the application using exploratory testing.
To deal with the constant changes on an agile project, testers need to understand which risks are important to the project , team and should focus on what is going to be changed and to be done in project. We generally gone through the scrum meeting to discuss the work plan and work which is done last and what to be done in next.
In my project I separately do regular meeting to discuss my test scenarios with whole team to find the gaps and to make them clear.
Agile project have their own challenges to the testing team like- Unclear project scope, iteration, Minimal Documentation, early and frequent testing. all these demand diverse and special skills testing guys. So one of the skill 'exploratory testing' is important here. This will cover, exploration od application, touring the application through GUI, analyzing the product/application ect..
Any way, the article was intended to discuss on exploratory testing so I will take an another separate note to explore my experience on my process of doing the testing in agile software project.
So now lets discuss the merits and demerits of Exploratory Testing. I will cover this section pointing out questions and then the appropriate answers:
Why Exploratory Testing (I wil use ET now onward for this)? - ET is much more capable to find those bugs which can not be found in scripted testing approach this means ET extend our test coverage which we generally prepared using specification. here the question may be that why we miss such bugs in our scripted method. So as specification is intended to a specific s/w behavior so the change to miss some scenarios which may produce some untouched bugs which can be found in ET.
Is ET is simliar to Ahdoc testing? As I pointed this issue earlier in this post only, the answer can be YES or NO depends on the person and his understanding on this. One more thing i want to point here that adhoc testing can be done by any one . but for ET the person should be more skilled.
Monday, March 16, 2009
Multiple versions of IE on the same machine
Hi Folks,
Generally a tester need to test the application for cross browser to check the compatibility of the application if different browsers. Sometimes we need to test the application in IE for various version and for this we need multiple IE . When have a single system and then the the question is"how to test in different IEs".
We generally use "Multiple IE" but the problem here I faced that when we use IE6 and IE7 parallel, IE7 works fine. but In IE6 it seems that some features are missing and testing is not done properly. For this I was using separate system or remote access of the system where slandered alone IE6 is present. But that was also not feasible in most cases. So i was wondering for some permanent solution.
Recently I came to know about a tool for testing in IE. and that is IETester. This not only allow to access IE6 and IE7 but You can use it to test pages in IE5.5, IE6, IE7 and IE8 all on the same machine without messing around with your main installed version of IE. This feature I liked more and forced me to use this.
Later I acme across few users and found that there are also some restrictions using this. It seems that this is about 90% of IE......what ever personally i do not have much issue over here.
Now I am happy using this. Hope this help all of you as well.........
Thanks,
Vishal Sachan
Sr. QA, Tekriti Software
Wednesday, January 14, 2009
QA: back end testing
In fact Back end/database testing is a separate area of testing which it a kind of white box testing. But we can cover some of this in out QA/ testing. Now the question is , How and what? Is this possible to do this manually?
Yes, at least doing some thing is better than avoiding . In my projects I always prefer to do database testing. Testing the front end of a site, should not be considered only. We need to practice back end testing also. I manage to write some SQL queries and execute them manually. This is all depend on you depth knowledge of the application database. the relations among various tables. Write yoy test cases and implement them into queries.
will be pointing out some case here . Basic thing is that , to test back end we need to be strong in database. To test application we need to gain knowledge of the data model and the relation ship among the different tables. If you are new to this job you can take help from your team mates to get in touch with database.
There are some tools to test database. but in most case working in small project or middle organization, you are not facilitated with this. In such case we need to practice it manually. I will cover all this later here in this post only.
just have look here why we need to test database in more....
If your data server's slow then there is no chances that your front-end coding will improve things. The most common reason must be Poorly optimized table indexes. so in this case we need to test Index.
The list of things we generally cover in database testing:
1. Data integrity-The complete data belonging to each entity should be stored in the database. There should not be any missing data
2. Correctness of the data stored in the database- The data stored should be correct and stored in right place.
3. Data type testing
4. Data size testing- Generally we test Data size only at the front end, but it is essential to test it at back end separately
5. Database performance
6. Data security
7. In case of data migration check Correctness and completeness of data
8- If you are good in database also test for Stored procedure. in this we need to test Every Stored Procedure separately. which may cover:
-. The no. of arguments being passed
-. The data type of each of the arguments being passed
-. The order of the arguments being passed
-. The return value
-. The data type of the return value
9. Input Item verification- In this we verify the input items like text box, combination box, active X controls. generally ask you developer to test this during unit testing.
As in point 5 , it is pointed out that we need to test for performance. So what can we check in database. we measure the executing time to see the performance. Also check the indexing . The poor indexing may cause your application slowness. So always there should be a proper Indexing for better performance.
I am pointing out a simple example here that how can we verify the database entries manually.
Suppose We have a registration form . so in from end we only have a UI where there must be some input fields and a submit button. Most common test is to fill the form and verify weather that user is created or not. but we don't know what is going on in database. so taking this example we first gain full knowledge of our database. Which field is mapped with which table and what are the columns where data will be inserted.
once you are familiar with the data model , we can write some queries using various tables and columns joining.
Now First thing to do- check in front end(execute all test case)
and second- test back end same thing by executing the queries to insure that the data is inserted in right table and the data is correct.
This is not the end in fact, there is lots to do.
Please share your experience and come with the more ideas.
Wednesday, December 10, 2008
Finding MAX salary from a table
I know most often in interview there is a question "how to select max, second max or third max salary from table........ect"
I tried my hand on this and came with the final solution taking help from colleague and google devata.
really facing problems finally came with more experience and knowledge.
here I want to share some queries on select statement. Hope these will help specially for beginners
try to execute all the given scenarios , this will help you to understand better.....
1- Create a table first by using the following statement. This will create a table named 'employee' with two columns 'name' and 'salary'.
CREATE TABLE employee (name varchar(256) , salary int)
2- Insert some data in this table. for this use
INSERT INTO employee (name, salary)
VALUES ('vishal' , 32000)
insert more data to this table.for example ('amit', 20000), ('nitin', 25000), ('raju', 30000), ('david', 27000), ('marc', 18000)
3- Selecting max salary from table:
SELECT max(salary) FROM employee
4- Selecting second highest salary from table:
SELECT max(salary) FROM employee
WHERE salary < (SELECT MAX(salary) FROM employee)
5- Selecting third highest salary :
SELECT MAX(salary) FROM employee
WHERE salary < (SELECT MAX(salary) FROM employee
WHERE salary < (SELECT MAX(salary) FROM employee))
6- Selecting fourth highest salary:
SELECT MAX(salary) FROM employee
WHERE salary < (SELECT MAX(salary) FROM employee
WHERE salary < (SELECT MAX(salary) FROM employee
WHERE salary < (SELECT MAX(salary) FROM employee)))
and so on........................
But it seems to heavy and to complicated..............
here I am going to write a query for Nth highest salary....
SELECT salary FROM employee e1
WHERE (N=(SELECT count(distinct(e2.salary)) FROM employee e2 WHERE e2.salary >= e1.salary))
You can put 1, 2 ,3, 4......for first, second, third.......in place of N.
hope you will be happy now.........
Thursday, August 7, 2008
Checking security vulnerability -XSS
Some of the Risks associated with XSS are:
1- One can track your activities
2- One can stolen your session ID.
3- One can use your cookies
4- One can modify/change/delete the content of your web page.
5- Its possible to crash a browser
6- Some harmful software installation.
and many more..................................
So this is our (Testers) job to find such vulnerabilities while testing. So the question is How to Determine Whether a Web page Is Vulnerable or not?
This is very common vulnerability and can be check easily whether you page is vulnerabile or not.
To check Supply the string"<></>" to your form field which display string.
* If you see "<></>" returned, most likely not vulnerable.
* If you see "<>" returned, most likely vulnerable.
one more simple easy test is to take a current parameter that is sent in the HTTP GET request and modify it. Take for example the following request in the browser address URL bar. This url will take a name parameter that you enter in a textbox and print something on the page. Like "Hello Vishal, thank you for coming to my site"
http://www.yoursite.com/index.html?name=vishal
Now lets modify this request For example try entering something similar to the following request in the browser address URL bar.
http://www.yoursite.com/index.html?name=<script> Alet('You just found a XSS vulnerability')</script>
If this pops up an alert message box stating "You just found a XSS vulnerability", then you know this parameter is vulnerable to XSS attacks. The parameter name is not being validating, it is allowing anything to be processed as a name, including a malicious script that is injected into the parameter passed in. Basically what is occurring is normally where the name George would be entered on the page the message is instead being written to the dynamic page. The alert message just is an example of how to test for the XSS vulnerability. A malicious hacker would be much more devious to this type of security vulnerability.
Cross-site scripting (XSS) attacks are a type of attack in which a variety of techniques are used to attempt to execute malicious script code by injecting it into form input, query strings, or cookies.
XSS vulnerabilities are caused by a failure in the web application to properly validate user input.
what should developer do?
If you are using post method for data submission then client side checks might be sufficient but it is all the more necessary to do server side validation if you are using Get method to retrieve data.
# Always do input validation.
# If possible do output validation as well.
# Never rely on client side scripting.
# Avoid Get method for sending data.
# Always use validateRequest=True;
# Always replace ‘(single quote-if you are storing data in a database especially) to prevent SQL Injection.
# Avoid using Cookies.
# Always verify and check the lengths of string to safeguard against stack-overwriting attacks and SQL errors
So bieng a tester , we need to test our site for this and let dev team know abt this.
There are many tools available to check thesase vulnerabilities. I tried one which is paid but its taril version is available to use. This will facilitate the XSS checking.
http://www.acunetix.com/vulnerability-scanner/
steps:
->open this link
->you need to fill a form with basic info. Make sure you must have to put a valid email id.
->later you wil recieve a mail having a link to download this tool.
->you will get an exe file. install the ......Now what.... play with this and find more.
Happy QA,ing
References:
http://www.nus.edu.sg/
http://www.lboro.ac.uk/
http://www.testingsecurity.com/
Wednesday, August 6, 2008
Cookies Testing
Test1-
----------------------------------------------------------------------------------------------
Purpose: Test for Disable cookies
Steps action: Disable the cookies on browser and open the application.
Expected Result: The major functionalities should not work properly. Appropriate message like “For smooth functioning of this site make sure that cookies are enabled on your browser” should be displayed. There should not be any page crash
Test2-
------------------------------------------------------------------------------------------------
Purpose: Test for Delete cookies
Steps action: Open site/page and allow cookies to be written and then delete these cookies and then navigate application.
Expected Result:No crash should be there. Site should function well.
Test3-
-------------------------------------------------------------------------------------------------
Purpose: Test for Corrupt cookies
Steps action: Allow cookies to be written and edit them in note pad by changing the parameters by some vague values. eg. Alter the name or its expiry date. Now navigates the site.
Expected Result:
Test4-
-----------------------------------------------------------------------------------------------
Purpose: Test Session cookies
Steps action: allow cookies to be written and then close the browser. Now check for stored cookies
Expected Result: There should be no any cookie stored.
these are some possible points to keep in mind while testing for cookies. Revert back with your feedback. Thanks
Wednesday, July 30, 2008
Web Testing- Common Checklist
When you are testing a web application, your task become more challenging. Every web application need a strong testing and this task is more critical specially working with middle organization where budget is often limited. I have been involved in such application testing. Every site needs to be thoroughly tested to ensure that it is accessible, user-friendly , and error free.
So to meet this, I would always prefer to make a checklist for this. I am sharing this here. Generally some points which are very common and recommended to test for most web application.
Here are some common points which must be covered while testing any web application.
1- Test every page individually: Here I always prefer to test each page individually. For this List out all the page and test them one by one.
2- Validate the Markup for every page: Validate every page for markup. You can use some markup validation tools. For this use W3C's HTML and CSS validator.
3- Test for link and navigation: Test whole application for links and their navigation. Every link should navigate to its target page. Navigation should be user friendly. Every page should have links.
Check if any page not having any links.
4- Perform Cross-Browser testing: This is very important point. As you never know that in which browser , your site is going to be access. So You need to test site for cross-browser compatibility. Find out the target audience and test it with all possible browsers. Test it on IE6, IE7, Mozilla Firefox, safari and opera on different OS.
5- Test error page : Test for 404 error pages. There should have a common 404 page which navigates the user to home page. Also check for error message which should be user friendly and meaning full.
6- Test application on various display and color setting: Always prefer to check the site on varrious color setting and display. This become very essential if your application have video related functionality
7- Test application on various resolution: check application on various resolution. I.e 1024x768, 600x800, 640x480.
8- Security Test: Always check the application for security. You can check the authorization and authentication. User login password. Other than this I always check the application for cookies. Here are some possible test cases for cookies testing.
* Test for Disable cookies
* Test for Delete cookies
* Test for Corrupt cookies
* Test for Session cookies
9- Form validation:
* Check for acceptance of invalid inputs
* Check for Manadatory fields
* Check for field range
For this you can use Boundary Value analysis to test range.
So these are some basics point to check while testing a web site. I hope post is helpful to readers.
Please revert back with your feed back and suggestion.