Re: RE: RE: Informing Companies about security vulnerabilities...

From: none@none.com
Date: Thu Oct 05 2006 - 17:06:44 EDT


('binary' encoding is not supported, stored as-is) so sticking ' or 1=1 or any variant like that is all that it takes to conduct a pen test?

or just sticking <script> tags into forms and seeing the response is a pen test?

is using an web scanner that tests for XSS or SQL injection a pen test?

running some BS web scanner against a site isnt a pen test even though alot of people on this list seem to think it is...

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:57:07 EDT