Monday, 2 January 2012

Test cases For Atm

TEST CASE NAME
TEST CASE DESCRIPTION
P
STEP
NAME
STEP DESCRIPTION
TEST DATA
EXPECTED RESULT
TC01_Bank_
Money withdrawal_ verify card insertion with valid cards
This test case to validate card insertion functionality with valid card
P0
Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
TC02_Bank_
Money withdrawal_ verify
card insertion with invalid cards
This test case to validate card insertion functionality with invalid card

Step1
Insert invalid card of other bank card in the insertion point of atm
Invalid card like other bank card
Atm should not accept the card and display a message ”please insert valid atm card”
Step2
Insert invalid card of expired atm card in the insertion point of atm
Invalid card like expired atm card
Atm should not accept the card and display a message ”Sorry unable to process your request code 1234”
TC03_Bank_
Money withdrawal_ verify
card insertion with valid cards in wrong angle
This test case to validate card insertion functionality with valid card in wrong angle

Step1
Insert invalid card of expired atm card in the insertion point of atm in wrong angle
Valid atm card
Atm should not accept the card and display a message ” Sorry unable to process your request code 1222”
TC04_Bank_
Money withdrawal_ verify language selection
 This test case to verify the language selection functionality

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected


TC04_Bank_
Money withdrawal_ verify pin number entry with valid pin number
This test case is to verify the functionality of pin number functionality with valid pin number

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding languge selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selction page
TC05_Bank_
Money withdrawal_ verify pin number entry with invalid pin number
This test case is to verify the functionality of pin number functionality with invalid pin number

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding languge selected
Step3
Enter the invalid pin number
InValid pinnumber
Atm should display meaning full message” Sorry unable to process your request code 1222”
TC06_Bank_
Money withdrawal_ verify pin number entry with invalid pin number upto 3 times
This test case is to verify the functionality of pin number functionality with invalid pin number upto 3 times

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding languge selected
Step3
Enter the invalid pin number
Invalid pinnumber
Atm should display meaning full message”enter valid pinnumber”
Step4
Enter the invalid pin number
Invalid pinnumber
Atm should display meaning full message”enter valid pinnumber”
Step5
Enter the invalid pin number
Invalid pinnumber
Atm should display meaning full message” Sorry unable to process your request code 1236”
TC07_Bank_
Money withdrawal_ verify account type selection with correct account type
This test is to verify the functionality of the account selection type with correct account type

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change,mini transaction,quick cash.
TC08_Bank_
Money withdrawal_ verify account type selection with wrong account type
This test is to verify the functionality of the account selection type with wrong account type

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the wrongt account type of a/c holder

Atm should display meaningful message” Sorry unable to process your request code 1233”




TC09_Bank_
Money withdrawal_ verify money withdrawal option
This test is to verify the functionality of the money withdrawal option

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change,mini transaction,quick cash.
Step5
Click on money withdrawal

Atm should display amount entry page.
TC10_Bank_
Money withdrawal_ verify amount entry with valid amount
This test is to verify the functionality of amount entry with valid amount

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change,mini transaction,quick cash.
Step5
Click on money withdrawal

Atm should display amount entry page.




Step6
Enter the valid amount and click on OK
Valid amount
Atm need to give money and display the objects want to continue, OK, NO
TC11_Bank_
Money withdrawal_ verify money withdrawal operation with valid amount
This test is to verify the functionality of money withdrawal operation with valid amount

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change, mini transaction, quick cash.
Step5
Click on money withdrawal

Atm should display amount entry page.

Step6
Enter the valid amount and click on OK
Valid amount
Atm need to give money and display the objects want to continue, OK, NO
Step7
Click on NO

Atm should give receipt for the transaction, return the card back, correct amount should deduct from account




TC12_Bank_
Money withdrawal_ verify money withdrawal operation with amount greater than balance amount
This test is to verify the functionality of money withdrawal operation with amount greater than balance amount

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change, mini transaction, quick cash.
Step5
Click on money withdrawal

Atm should display amount entry page.
Step6
Enter the amount greater than balance and click on OK
Amount greater than balan
Atm should display meaningful error message” Sorry unable to process your request code 1230”
TC13_Bank_
Money withdrawal_ verify money withdrawal operation with amount greater than day limit amount
This test is to verify the functionality of money withdrawal operation with amount greater than day limit amount

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change, mini transaction, quick cash.



Step5
Click on money withdrawal

Atm should display amount entry page.
Step6
Enter the amount greater than day limit amount
Click on OK
Amount greater than day limit amt
Atm should display meaningful error message” Sorry unable to process your request code 1220”
TC14_Bank_
Money withdrawal_ verify money withdrawal operation with amount greater than amount in atm
This test is to verify the functionality of amount entry with valid amount greater  than amount in atm

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change,mini transaction,quick cash.
Step5
Click on money withdrawal

Atm should display amount entry page.
Step6
Enter the valid amount and click on OK
Valid amount
Atm should display meaningful error message” Sorry unable to process your request code 1234”






TC15_Bank_
Money withdrawal_ verify money withdrawal operation with amount not in multiples of 100’s
This test is to verify the functionality of money withdrawal with amount not in multiples of 100’s

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change, mini transaction, quick cash.
Step5
Click on money withdrawal

Atm should display amount entry page.

Step6
Enter the valid amount not in multiples of 100’s click on OK
Valid amount
Atm should display meaningful error message ” Sorry unable to process your request code 1111”
TC16_Bank_
Money withdrawal_ verify money withdrawal operation with valid amount but during operation network problem occurred
This test is to verify the functionality of money withdrawal operation with valid amount but during operation network problem occurred

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change, mini ….



Step5
Click on money withdrawal

Atm should display amount entry page.

Step6
Enter the valid amount and click on OK
Valid amtt
And make network down
Atm should display meaningful error message ” Sorry unable to process your request code 1010”
TC17_Bank_
Money withdrawal_ verify amount entry with valid amount
This test is to verify the functionality of amount entry with valid amount

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change,mini transaction,quick cash.
Step5
Click on money withdrawal

Atm should display amount entry page.
Step6
Enter the valid amount and click on OK
Valid amount
Get the amount from atm and display the objects want to continue, OK, NO
Step7
Click on OK

Atm should display amount entry page.
Step8
Enter the valid amount and click on OK
Valid amount
Get the amount from atm and display the objects want to continue, OK, NO



Step9
Click on OK

Atm should display amount entry page.
Step10
Enter the valid amount and click on OK
Valid amount
Get the amount from atm and display the objects want to continue, OK, NO
Step11
Click on OK

Atm should display amount entry page.
Step12
Enter the valid amount and click on OK
Valid amount
Atm should display meaningful error message ” Sorry unable to process your request code 1211”
TC18_Bank_
Money withdrawal_ verify
Cancel with after insert card
This test is to verify the functionality of cancel with after card insert i.e, in language selection page

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI

Step2
Click on cancel button

Atm should display meaningful error message ” Sorry unable to process your request code 1111”” and return the card by atm.
TC19_Bank_
Money withdrawal_ verify
Cancel with pin number entry
This test is to verify the functionality of cancel with pin number entry

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
When the language selection page uploaded click on cancel

Atm should display meaningful error message ” Sorry unable to process your request code 1111”” and return the card by atm.

TC19_Bank_
Money withdrawal_ verify
Cancel with account type
This test is to verify the functionality of cancel with account type

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on cancel button

Atm should display meaningful error message ” Sorry unable to process your request code 1234”” and return the card by atm.
TC20_Bank_
Money withdrawal_ verify
Cancel with service provider
This test is to verify the functionality of cancel with service provider

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change,mini transaction,quick cash.


Step5
Click on cancel button

Atm should display meaningful error message ” Sorry unable to process your request code 1111”” and return the card by atm.
TC21_Bank_
Money withdrawal_ verify
Cancel with amount entity
This test is to verify the functionality of cancel with amount entity

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page
Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change,mini transaction,quick cash.
Step5
Click on money withdrawal

Atm should display amount entry page.
Step6
Click on cancel button

Atm should display meaningful error message ” Sorry unable to process your request code 1111”” and return the card by atm.
TC22_Bank_
Money withdrawal_ verify
Cancel with continue entity
This test is to verify the functionality of cancel with continue entity i.e, after amount entity

Step1
Insert valid card in the insertion point of atm
Valid atm card
Atm should display language page with following objects ENLISH,TELUGU,HINDI
Step2
Click on corresponding language to be used

Atm should display the  pin number page in corresponding language selected
Step3
Enter the valid pin number
Valid pin number
Atm should display the account type selection page



Step4
Click on the correct account type of a/c holder

Atm should display service page with the following object money withdrawal, pin change,mini transaction,quick cash.
Step5
Click on money withdrawal

Atm should display amount entry page.
Step6
Enter the valid amount and click on OK
Valid amount
Get the amount from atm and display the objects want to continue, OK, NO
Step7
Click on cancel button

Atm should display meaningful error message ” Sorry unable to process your request code 1111”” and return the card by atm.

Sunday, 1 January 2012

Security Testing

How to Test Application Security – Web and Desktop Application Security Testing Techniques



Need of Security Testing?
Software industry has achieved a solid recognition in this age. In the recent decade, however, cyber-world seems to be even more dominating and driving force which is shaping up the new forms of almost every business. Web based ERP systems used today are the best evidence that IT has revolutionized our beloved global village.
These days, websites are not meant only for publicity or marketing but these have been evolved into the stronger tools to cater complete business needs. Web based Payroll systems, Shopping Malls, Banking, Stock Trade application are not only being used by organizations but are also being sold as products today.
This means that online applications have gained the trust of customers and users regarding their vital feature named as SECURITY. No doubt, the security factor is of primary value for desktop applications too. However, when we talk about web, importance of security increases exponentially. If an online system cannot protect the transaction data, no one will ever think of using it. Security is neither a word in search of its definition yet, nor is it a subtle concept. However, I would like to list some complements of security.

Examples of security flaws in an application:

1) A Student Management System is insecure if ‘Admission’ branch can edit the data of ‘Exam’ branch
2) An ERP system is not secure if DEO (data entry operator) can generate ‘Reports’
3) An online Shopping Mall has no security if customer’s Credit Card Detail is not encrypted
4) A custom software possess inadequate security if an SQL query retrieves actual passwords of its users
Security Testing Definition:
Now, I present you a simplest definition of Security in my own words. “Security means that authorized access is granted to protected data and unauthorized access is restricted”. So, it has two major aspects; first is protection of data and second one is access to that data. Moreover, whether the application is desktop or web based, security revolves around the two aforementioned aspects. Let us have an overview of security aspects for both desktop and web based software applications.
Desktop and Web Security Testing:
A desktop application should be secure not only regarding its access but also with respect to organization and storage of its data. Similarly, a web application demands even more security with respect to its access, along with data protection. Web developer should make the application immune to SQL Injections, Brute Force Attacks and XSS (cross site scripting). Similarly, if the web application facilitates remote access points then these must be secure too. Moreover, keep in mind that Brute Force Attack is not only related to web applications, desktop software is also vulnerable to this.
I hope this foreword is enough and now let me come to the point. Kindly accept my apology if you so far thought that you are reading about the subject of this article. Though I have briefly explained software Security and its major concerns, but my topic is ‘Security Testing’. In order to know further details of security aspects, kindly refer to – Web application security testing article.
I will now explain how the features of security are implemented in software application and how should these be tested. My focus will be on Whats and Hows of security testing, not of security.

Security Testing Techniques:

1) Access to Application:

Whether it is a desktop application of website, access security is implemented by ‘Roles and Rights Management’. It is often done implicitly while covering functionality, e.g.in a Hospital Management System a receptionist is least concerned about the laboratory tests as his job is to just register the patients and schedule their appointments with doctors. So, all the menus, forms and screen related to lab tests will not be available to the Role of ‘Receptionist’. Hence, the proper implementation of roles and rights will guarantee the security of access.
How to Test: In order to test this, thorough testing of all roles and rights should be performed. Tester should create several user accounts with different as well multiple roles. Then he should use the application with the help of these accounts and should verify that every role has access to its own modules, screens, forms and menus only. If tester finds any conflict, he should log a security issue with complete confidence.

2. Data Protection:

There are further three aspects of data security. First one is that a user can view or utilize only the data which he is supposed to use. This is also ensured by roles and rights e.g. a TSR (telesales representative) of a company can view the data of available stock, but cannot see how much raw material was purchased for production.
So, testing of this aspect is already explained above. The second aspect of data protection is related to how that data is stored in the DB. All the sensitive data must be encrypted to make it secure. Encryption should be strong especially for sensitive data like passwords of user accounts, credit card numbers or other business critical information. Third and last aspect is extension of this second aspect. Proper security measures must be adopted when flow of sensitive or business critical data occurs. Whether this data floats between different modules of same application, or is transmitted to different applications it must be encrypted to make it safe.
How to Test Data Protection: The tester should query the database for ‘passwords’ of user account, billing information of clients, other business critical and sensitive data and should verify that all such data is saved in encrypted form in the DB. Similarly (s)he must verify that between different forms or screens, data is transmitted after proper encryption. Moreover, tester should ensure that the encrypted data is properly decrypted at the destination. Special attention should be paid on different ‘submit’ actions. The tester must verify that when the information is being transmitted between client and server, it is not displayed in the address bar of web browser in understandable format. If any of these verifications fail, the application definitely has security flaw.

3. Brute-Force Attack:

Brute Force Attack is mostly done by some software tools. The concept is that using a valid user ID, software attempts to guess the associated password by trying to login again and again. A simple example of security against such attack is account suspension for a short period of time as all the mailing applications like ‘Yahoo’ and ‘Hotmail’ do. If, a specific number of consecutive attempts (mostly 3) fail to login successfully, then that account is blocked for some time (30 minutes to 24 hrs).
How to test Brute-Force Attack: The tester must verify that some mechanism of account suspension is available and is working accurately. (S)He must attempt to login with invalid user IDs and Passwords alternatively to make sure that software application blocks the accounts that continuously attempt login with invalid information. If the application is doing so, it is secure against brute-force attack. Otherwise, this security vulnerability must be reported by the tester.
The above three security aspects should be taken into account for both web and desktop applications while, the following points are related with web based applications only.

4. SQL Injection and XSS (cross site scripting):

Conceptually speaking, the theme of both these hacking attempts is similar, so these are discussed together. In this approach, malicious script is used by the hackers in order to manipulate a website. There are several ways to immune against such attempts. For all input fields of the website, field lengths should be defined small enough to restrict input of any script e.g. Last Name should have field length 30 instead of 255. There may be some input fields where large data input is necessary, for such fields proper validation of input should be performed prior to saving that data in the application. Moreover, in such fields any html tags or script tag input must be prohibited. In order to provoke XSS attacks, the application should discard script redirects from unknown or untrusted applications.
How to test SQL Injection and XSS: Tester must ensure that maximum lengths of all input fields are defined and implemented. (S)He should also ensure that defined length of input fields does not accommodate any script input as well as tag input. Both these can be easily tested e.g. if 20 is the maximum length specified for ‘Name’ field; and input string “<p>thequickbrownfoxjumpsoverthelazydog” can verify both these constraints. It should also be verified by the tester that application does not support anonymous access methods. In case any of these vulnerabilities exists, the application is in danger.

5. Service Access Points (Sealed and Secure Open)

Today, businesses depend and collaborate with each other, same holds good for applications especially websites. In such case, both the collaborators should define and publish some access points for each other. So far the scenario seems quite simple and straightforward but, for some web based product like stock trading, things are not so simple and easy. When there is large number of target audience, the access points should be open enough to facilitate all users, accommodating enough to fulfill all users’ requests and secure enough to cope with any security-trial.
How to Test Service Access Points: Let me explain it with the example of stock trading web application; an investor (who wants to purchase the shares) should have access to current and historical data of stock prices. User should be given the facility to download this historical data. This demands that application should be open enough. By accommodating and secure, I mean that application should facilitate investors to trade freely (under the legislative regulations). They may purchase or sale 24/7 and the data of transactions must be immune to any hacking attack. Moreover, a large number of users will be interacting with application simultaneously, so the application should provide enough number access point to entertain all the users.
In some cases these access points can be sealed for unwanted applications or people. This depends upon the business domain of application and its users, e.g. a custom web based Office Management System may recognize its users on the basis of IP Addresses and denies to establish a connection with all other systems (applications) that do not lie in the range of valid IPs for that application.
Tester must ensure that all the inter-network and intra-network access to the application is from trusted applications, machines (IPs) and users. In order to verify that an open access point is secure enough, tester must try to access it from different machines having both trusted and untrusted IP addresses. Different sort of real-time transactions should be tried in a bulk to have a good confidence of application’s performance.  By doing so, the capacity of access points of the application will also be observed clearly.
Tester must ensure that the application entertains all the communication requests from trusted IPs and applications only while all the other request are rejected. Similarly, if the application has some open access point, then tester should ensure that it allows (if required) uploading of data by users in secure way. By this secure way I mean, the file size limit, file type restriction and scanning of uploaded file for viruses or other security threats. This is all how a tester can verify the security of an application with respect to its access points.

Saturday, 31 December 2011

What Makes Your Bug Report PERFECT?

We live with bugs! Yes, everything revolves around a bug for us software testers. Whatever we talk, measure, find, Report are all in terms of bugs. But, do we actually know how much responsibility lies in our hands when we find a bug? How much contribution we are making towards the Product we are testing to make it usable by millions of people across the globe? A ‘Bug’ is the only way we communicate with our client to tell them what is missing or what is wrong with their product. So, when you submit a bug, you are not actually breaking the product to see how well you are at it! Instead, you are helping the product to be perfect.
Bug Report
So, just submitting a bug is not enough. You need to understand what we have submitted as well. I have heard lot of new joiners tell this- “What big deal in submitting a bug? We have a readymade defect logging template, we just fill it and so a bug is logged”. Should this be the attitude, then we can log millions of bugs in a single day! But, just submitting hundreds of bugs and increasing your bug count is not enough.
Will you be called a good tester if you only have your large bug count? NO- You also need to make the developer understand your bug. What’s the point if you just submit it and there is no one who can solve the problem? All your effort of finding the issue is gone waste. Suppose, you logged a bug which breaks a major functionality but while writing your report, you missed out some info which says in which area the bug was caused. Can anyone understand? Will they be able to solve it? It will either be rejected as improper info or will be assigned back to you. It will just result in a waste of time for you as well as developer.
And, if it’s a major issue then imagine how much impact it could have on the business, on the client? And, of course your job :)
There is no perfect mantra for a good bug report. The basic point here is you should be able to convey the issue to the developer in a proper manner and with all the data so that it will be solved easily. Below are some of the ‘ingredients’ of a good bug report.
Bug reports usually consist of a bug title, the steps, and a screenshot. But, it can be made more helpful if you add a couple of points more:

A bug report should go like this:

#1 Bug Title:

This should be a short (Just about a line) and easy to understand description of what exactly the problem is. It should ideally describe the area in which the bug is along with the error message if any. For example, if there is a bug in the Installation of a product when you select custom install, your bug title should be something like- “Error during custom install” or “Product fails to install, gives 1234 error when custom installation”. The second one would be more apt as it also describes your error code. But, if the error code is very long, try avoiding it in the title, you can write the same in description

#2 Repro Steps:

The repro steps or the reproducibility steps are the most important in a bug report. These steps tell you how you would arrive at the problem. They should be steps from the start of what you did to arrive at this problem. Here, generally we tend to avoid some simple steps which we think are not necessary. But, no step is unimportant. Yes, but also avoid duplicate steps.
Example of repro steps would be-
  1. Install app
  2. Go to fileàopen
  3. Give a file name
  4. Click on cancel
  5. Observe the error
Do not forget to mention where the problem is. That means, don’t just leave the steps as it is. Tell them where you encountered the problem. Also, mention any pre-requisites installed before performing these steps. Do not make the steps repeatable and lengthy.

#3 Actual and Expected Results:

This will describe what is the actual result got and what is the expected result of the issue.

#4 Description:

This might or might not be necessary. It depends if you have some issue that requires explanation like a long error message of any special note.

#5 Priority:

How important the bug is, and how soon it should be resolved.

#6 Severity:

How severe the problem is.

#7 Frequency:

How frequent the issue occurs. For ex- every time, only once etc.

#8 Environment info:

This is your system info like OS version, Browser used (if it’s a Web app), any updates installed on top of it, Flash version if required etc.

#9 Screenshot:

When you give the screenshot make sure you Highlight the area where you think the bug is. This would be very helpful while logging UI bugs. The developer will be able to understand where actually the bug is if the issue is very small to detect otherwise. Naming your screenshots according to the issue would also be a good idea here.

#10 Additional Info:

This will be any additional info like what do you think might cause the problem. Or, if the issue is browser/OS specific.
The basic point to remember while you are submitting a bug is – ‘The person who is reviewing your bug should understand the bug, and in one way it should also help him in solve the problem’. Also, make sure you are not “bugging” the developer too much!! After all, he is also a busy man like us