2015年6月9日 星期二

源碼檢測 Visual Code Grepper

哈囉~ 大家好

今天我們就來聊一聊 —「源碼檢測 (Source Code Analysis)」的議題。

記得之前我們有談過「弱點掃描 (Vulnerability Scanning)」的部分,如果各位還記得的話,這個部份是比較屬於系統層面的弱點檢測,也是屬於「黑箱測試 (Black-Box Testing)」的範圍。而今天所要談到的源碼檢測也就是所謂的「程式碼掃描 (Code Review)」,這個部份是直接對程式碼做掃描,進而檢測出弱點並即時做程式碼的修正,這個範疇就是所謂的「白箱測試 (White-Box Testing)」。

一般做軟體程式開發時,研發人員在開發的過程中就會進行所謂的「單元測試 (Unit Test)」,在Alpha版 release 之前會就進行所謂的 Code Review,初次的程式碼掃描多數是由 RD 完成,到最後要 release 到 Beta版 前就會交由 QA 進行最後的 Source Code Analysis。因為大多數的程式開發人員,都沒有資訊安全的背景,所以做源碼檢測是有其必要性的。

而今天就要來介紹一個源碼檢測工具 —VCG(Visual Code Grepper),之所以會選擇這個工具的原因,不外乎它是一個 Freeware 免費軟體,再來就是它可以檢測的程式語言,包含支援 C/C++、C#、VB、PHP、Java、PL/SQL 等等,它所產出的測試報告除了可以明確指出有風險的程式碼之外,還可以提供建議的修正方法,並有圖表說明各種程度的風險所佔的百分比,還可以將掃描結果另存成文字檔,以提供正式測試報告說明使用。

以下就這一節的圖解說明:



Step 1: Download the installer from official website or File link as below.
VCG-Setup.msi
http://sourceforge.net/projects/visualcodegrepp/?source=typ_redirect

Step 2: After download file "VCG-Setup.msi" double click to install the tool.

Step 3: Welcome the VCG Setup Wizard. Click "Next"

Step 4: Select Installation Folder. If want to install to other folder click "Browse" to changed, if not please keep for default then click "Next"

Step 5: Confirm Installation click "Next"

Step 6: Click "Yes" to continue installation.


Step 7: Installation Complete click "Close"

Step 8: Check the Start menu then double click "VisualCodeGrepper" to start the tool GUI.

Step 9: Select Language to do the scanning click "OK" to show the main GUI.


Step 10: Select scanning language.
Settings | Java

Step 11: Select the scanning target folder or file.
File | New Target Directory... or New Target File...

Step 12: Select the target directory form your source code directory then click "OK" (Ex: select directory "TargetSourceCode")


Step 13: After loaded whole source code show like below.

Step 14: Run for full scan.
Scan | Full Scan


Step 15: After scanning complete then tick "Always display Visual Breakdown after every scan" and click "OK"

Step 16: Finished the scanning show the Code Breakdown like below.

Step 17: Results show like below.

Step 18: Select "Target File" show completed scanning target files and path.

Step 19: Select "Summary Table" show results summary sort by tables.



Step 20: Select more detailed text results sort by severity.
Scan | Sort Rich Text Results on Severity


Step 21: Select more detailed text results sort by file name.
Scan | Sort Rich Text Results on FileName


Step 22: Show comments to fix issues.
Scan | Show All 'FixMe' Comments


Step 23: Show results group by issues.
View | Group Rich Text Results by Issue


Step 24: Export and import results as XML or CSV formats.

Step 25: Save results as a text file.
File | Save Results as Text...





這一節介紹到這裡,各位對於這 VCG 源碼檢測工具,應該有了更進一步的瞭解。
特別對於檢測報告的解讀,應該可以透過不同選項來幫助使用者更容易找出問題,甚至提供建議的解決方法。

這套源碼檢測工具,雖然是 Freeware 但是功能性與準確性,並不輸給動輒幾百萬的商業檢測工具,唯一的差別應該只在商業工具會提供較完美的圖表測試報告。這當然是免費工具無法相提並論的。

今天我們就介紹到這裡,希望大家都能有所收穫。我們下次見~ 掰掰!

~ See you ~

參考出處:
http://sourceforge.net/projects/visualcodegrepp/


2015年5月18日 星期一

Apache JMeter 壓力測試 Mobile API

Hello 大家好!!!

記得上一節是介紹如何用 WAPT 做壓測 Mobile API。這一節我們就來介紹一下如何用 Apache JMeter 做 Mobile API 的壓力測試。

在開始實做之前,我們先來介紹一下 Apache JMeter:
  1. 100%由 Java 開發的測是工具。
  2. 開放原碼軟體 (Open Source)。
  3. 支援效能測試、功能測試和負載測試。
  4. 原先設計做 Web 測試,現在已延伸可以做其它功能測試。
  5. 對附載及效能測,支援多項服務和協定:HTTP, HTTPS, SOAP, REST, FTP, JDBC, LDAP, JMS, SMTP, POP3, IMAP, NoSQL, Commands, Shell Scripts and TCP...
  6. GUI介面方便建立測試計畫和除錯。
  7. 高擴充性核心等等...
缺點:
  1. JMeter 並不像瀏覽器可以執行 CSS 或 JavaScript 等等瀏覽器語言。
  2. 因受 thread 的限制,所以無法長時間執行測試。
  3. Debug 較不易。
  4. 測試報告不夠完整性。
  5. 需要安裝 JRE 6 以上版本才能執行。 
現在就來開始我們這一節的實作說明:


Step 1: Download JRE from the official website.
https://www.java.com/en/download/ie_manual.jsp?locale=en

Step 2: Install JRE from download folder then double click the installation file "JavaSetup8u45.exe"

Step 3: Click "Yes" for continuous.

Step 4: Click "Install" for the installation.

Step 5: Un-tick the check box then click "Next"


Step 6: Click "Close" for finished the JRE installation.

Step 7: Download from the link as below or the official website.

Step 8: Unzip file "apache-jmeter-2.13.zip"

Step 9: Double click the file "jmeter.bat" for start JMetrer.
C:\"Download Folder" \apache-jmeter-2.13\bin

Step 10: Show the JMeter main GUI as below.

Step 11: Create the first test plan.
Test Plan | Add | Threads(Users) | Thread Group

Step 12: Set every 5 seconds(blue), ramp-up 5 VUs(yellow) and loop 100 times(red) then total 500 VUs.

Step 13: If want to repeat the VUs for this test plan set in red. For our case just set loop 1 time means doesn't want any VUs to do repeat test.
Thread Group | Add | Logic Controller | Loop Controller


Step 14: If need to test more APIs for HTTP Request, we can set the defaults for the HTTP Request then separate the APIs HTTP Request. For our case just create a "HTTP Request Defaults" don't do any setup with this.
Loop Controller | Add | Config Element | HTTP Request Defaults


Step 15: Create the API "HTTP Request"
Loop Controller | Add | Sampler | HTTP Request

Step 16: Set IP for HTTP server in red, Path in green and API parameters in blue. Click "Add" in yellow to add the parameters.

Step 17: Create the graph results.
Loop Controller | Add | Listener | Graph Results

Step 18: Create the results tree for recording the results bit by bit.
Loop Controller | Add | Listener | View Results Tree

Step 19: Click the icon   on navigation bar to save this test plan.

Step 20: Click the icon  to start the test plan.

Step 21: Click the icon  to clear all results.

Step 22: Graph Results of "No of Samples" means total requests, "Average" means average of response time, "Deviation" means deviation of response time if the number near 0 will be the best. "Throughput /minute" means per minute of response requests if the number much higher will be the better of the performance.

Step 23: List of Results Tree.

Step 24: Check the back-end of management GUI page to verify the requests.

介紹到這裡相信各位對於 JMeter 這套壓測工具,應該有了初步的認識和基本的使用方式。

這套壓測工具就如同上圖所見,並沒有很清楚或漂亮的圖形表現,這也是 Freeware 的測試工具普遍存在的問題,但是就單純的以一個實用性的壓力測試工具來說,JMeter 的測試表現算是一個蠻專業的測試工具,唯一的缺點就是在製作測試報告時,需要花較多的時間在圖表和測試報告的說明上面。

這一節 JMeter 的說明我們就先介紹到這裡,以後如果還有需要,我們再來做更深入的說明。那我們就下次見~ 掰掰!!!

~ See you ~

參考出處:
https://www.java.com/
http://jmeter.apache.org/