Penetration Testing mailing list archives

Re: RE: RE: Informing Companies about security vulnerabilities...


From: none () none com
Date: 5 Oct 2006 21:06:44 -0000

so sticking ' or 1=1  or any variant like that is all that it takes to conduct a pen test?

or just sticking <script> tags into forms and seeing the response is  a pen test?

is using an web scanner that tests for XSS or SQL injection a pen test?

running some BS web scanner against a site isnt a pen test even though alot of people on this list seem to think it 
is...

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


Current thread: