Penetration Testing mailing list archives

updated legacy mainframe app


From: "Gus Fritschie" <gfritschie () hotmail com>
Date: Tue, 25 Oct 2005 10:26:04 -0400

Our organization is updating a legacy mainframe application to a GUI client-server application. On the mainframe EntireX Broker will be installed. The client software will include the following:

1) Microsoft .NET
2) Software AG Communicator run time
3) Compiled .NET code, dynamic link libraries, and EntireX client

My question is what control weaknesses could be introduced by this change and what tests would you recommend performing, besides basic application control tests.

Thanks!



------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: