Penetration Testing mailing list archives
RE: MQ Series ....
From: "Philip Cox" <phil.cox () systemexperts com>
Date: Wed, 8 Mar 2006 06:07:16 -0800
My experience with MQ is limited, but I should think triggers would be one area that could be open to exploits. Another thing that could be tried is exceeding the max handle limits or max uncommited messages for a queue manager.
I'll try those. Also, is there a tool/platform that you would recommend for testing with? I have been playing with the Perl MQSeries module, but also noticed a number of potential "tools" in the sample directory of the WebSphere MQSeries install.
Shall think about this some more and get back Are the target systems clustered on MQ? And what version of MQ are you running?
Yes, they are clustered, and I believe the it is version 5.3. Phil ------------------------------------------------------------------------------ This List Sponsored by: Cenzic Concerned about Web Application Security? As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com ------------------------------------------------------------------------------
Current thread:
- MQ Series .... Philip Cox (Mar 03)
- RE: MQ Series .... Victor Chapela (Mar 06)
- <Possible follow-ups>
- RE: MQ Series .... Philip Cox (Mar 08)