Re: Mastercard SDP compliance testing.



a few things I can advise you on:

1) make sure you have someone to test during the night. If i remember correctly we had 24 hours to test everything, so you should have someone there to test through the night as well as in the day

2) Make sure your findings (in the report) are backed up with the correct CVE's and BID's.

3) Its a pretty easy test to do, and you should be comfortable with exploiting xss, sql, oracle as well as others.

good luck

Nuri

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php
------------------------------------------------------------------------



Relevant Pages

  • Fwd: Re: tools to scan source code
    ... design) that can only be found with manual secure code reviews and secure architecture ... Need to secure your web apps? ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • RE: Fwd: Re: tools to scan source code
    ... design) that can only be found with manual secure code reviews and secure architecture ... Need to secure your web apps? ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • RE: stupid IE7 question
    ... I am currently testing a proprietary secure web based ... Need to secure your web apps? ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: pentest documentation
    ... Need to secure your web apps? ... Cenzic Hailstorm finds vulnerabilities fast. ... Click the link to buy it, try it or download Hailstorm for FREE. ...
    (Pen-Test)
  • RE: Old @Stake Tools
    ... Anyone know where to find some of the old @stake tools? ... Need to secure your web apps? ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)