WebApp Sec mailing list archives

webapp audit and forensics


From: Serg Belokamen <serg.belokamen () gmail com>
Date: Thu, 20 Oct 2005 13:01:44 +1000

Hi All,

I have been asked to perform web application security audit and
perform intrusion analysis/forensics tasks. I am not an expert in the
forensics field (I am very comfortable on a Linux system though) so
any pointers would be appreciated.

Main question however is, what would one charge (in AU$ if possible)
for a webapplication security audit. If replying on here makes anyone
uncomfortable feel free to email me directly. However I do need to
know the figure asap. Also, should the client be charged if no
vaulnarabilities are detected.

Application in question: can't really give a lot of details on here
but it would be something simular in size and complexity to an open
source CMS product: Mambo.

Any help would be appreciated.

   Thanks,
      Serg


Current thread: