Penetration Testing mailing list archives

Re: RE: Informing Companies about security vulnerabilities...


From: stillnone () none com
Date: 5 Oct 2006 21:13:17 -0000

"What in the world are you talking about? If you read his email, he said that he was doing XXS and SQL injections on 
someone else's web site. In order for him to say that the SQL attack worked, he would have to see some data."

--when you get the script alert testing XSS is that seeing private data?  if you get an SQL error code is that seeing 
private data?  i dont think you know what the heck you are talking about.

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


Current thread: