
Penetration Testing mailing list archives
Re: a "good" vulnerability for educational purposes
From: edjenguele christian eric <c_edjenguele () yahoo it>
Date: Mon, 18 Aug 2008 17:40:30 +0000 (GMT)
Hi, you can start with XSS or Directory Trasversal, they are easy to exploit, check security focus for those vulnerabilities Christian Eric Eddjenguele IT Security Software Developer & Researcher -- Management, Developers, Security Professionals – can only result in one thing…… better security. http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference Sept 22nd-25th 2008 ----- Messaggio originale ----- Da: "dimkovtrajce () yahoo com" <dimkovtrajce () yahoo com> A: pen-test () securityfocus com Inviato: Lunedì 18 agosto 2008, 15:13:13 Oggetto: a "good" vulnerability for educational purposes Hi, Our goal is to teach master students in computer security in pen testing remote servers. As an exercise we want to introduce a vulnerability in IIS or Apache (or any other place you might suggest)which is recognizable with current vulnerability scanners(ex.nessus), but requires some coding/payload generation to exploit the vulnerability. I am considering bugtracq, but there are many vulnerabilities there which i can not filter with the requirements above. Can you point me to any "good" vulnerability for this purpose? Regards, Trajce ------------------------------------------------------------------------ This list is sponsored by: Cenzic Top 5 Common Mistakes in Securing Web Applications Get 45 Min Video and PPT Slides www.cenzic.com/landing/securityfocus/hackinar ------------------------------------------------------------------------ Posta, news, sport, oroscopo: tutto in una sola pagina. Crea l'home page che piace a te! www.yahoo.it/latuapagina ------------------------------------------------------------------------ This list is sponsored by: Cenzic Top 5 Common Mistakes in Securing Web Applications Get 45 Min Video and PPT Slides www.cenzic.com/landing/securityfocus/hackinar ------------------------------------------------------------------------
Current thread:
- a "good" vulnerability for educational purposes dimkovtrajce (Aug 18)
- Re: a "good" vulnerability for educational purposes Andre Amorim (Aug 18)
- Re: a "good" vulnerability for educational purposes Kelly Keeton (Aug 18)
- Re: a "good" vulnerability for educational purposes Jorge L. Vazquez (Aug 19)
- Re: a "good" vulnerability for educational purposes eldraco (Aug 25)
- Re: a "good" vulnerability for educational purposes Kelly Keeton (Aug 18)
- <Possible follow-ups>
- Re: a "good" vulnerability for educational purposes edjenguele christian eric (Aug 18)
- Re: Re: a "good" vulnerability for educational purposes eladexposed (Aug 19)
- Re: a "good" vulnerability for educational purposes Andre Amorim (Aug 18)