webapp audit and forensics

From: Serg Belokamen (serg.belokamen@gmail.com)
Date: Wed Oct 19 2005 - 23:01:44 EDT


Hi All,

I have been asked to perform web application security audit and
perform intrusion analysis/forensics tasks. I am not an expert in the
forensics field (I am very comfortable on a Linux system though) so
any pointers would be appreciated.

Main question however is, what would one charge (in AU$ if possible)
for a webapplication security audit. If replying on here makes anyone
uncomfortable feel free to email me directly. However I do need to
know the figure asap. Also, should the client be charged if no
vaulnarabilities are detected.

Application in question: can't really give a lot of details on here
but it would be something simular in size and complexity to an open
source CMS product: Mambo.

Any help would be appreciated.

   Thanks,
      Serg

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on your
website. Up to 75% of cyber attacks are launched on shopping carts, forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
futile against web application hacking. Check your website for vulnerabilities
to SQL injection, Cross site scripting and other web attacks before hackers do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:55:04 EDT