Forum Moderators: coopster

Message Too Old, No Replies

Security Audit

What do you use?

         

henry0

4:23 pm on Mar 2, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Luck, burning a candle and other incantations apart!
How do you find if you left a hole in queries, insert etc.. (PHP & MySQl)

Do you know of any means (affordable) some “specialists” seem charging well above 1K a day. I cannot afford that amount, is there some org or any tools that you know about (short of hiring a pro hacker)?

Thanks

PS)
The E-Comm (not a free one) that I integrated in a new domain has successfully passed such an audit, so I am just concerned with all the other sections (lot of)
Where user input will be accepted)

jatar_k

6:13 pm on Mar 2, 2007 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



the ones I've been part have all been done by large expensive companies, well above the 1K/day mark, the only company name I remember being KPMG, they were doing a full audit of various things including the software security

sorry, anyone have any other experiences?

henry0

6:43 pm on Mar 2, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks,
Actually for a fee, using some tools or any other means is I suppose a good topic for all of us :)