Website Sql and Penetration Service

Status
Not open for further replies.

DeskJockey

Full Member
Sep 6, 2010
16
0
PA
Website Manual Penetration Testing service description.

During this test we check a working web application or website for vulnerabilities by hacker attacks imitation. Automated tools and manual testing are used to test all the possible entry points of user-defined data.

Website Manual Penetration Testing allows to check your website security for such types of vulnerabilities as: XSS (Cross Site Scripting), SQL Injection, Authentication Bypass, Client-side Attacks, Shell Command Execution, Code Insertion/Execution, Information Disclosure, Path Traversal, Predictable Resource Location, Abuse of Functionality, Insufficient Anti-automation and some other not widely spread security flaws.
Website Manual Penetration Testing steps.



1. Collecting information about the target.

  • collecting information about all the possible entry points of user-defined data
  • third party software detection (we use 2 third party applications in every test for redundancy)
2. Automated scanning for vulnerabilities using special software.
  • automated scanning result analysis
  • manual check of results
3. Manual penetration testing.
  • specific input validation checks
4. Potential damage assessment of each discovered vulnerability.
5. Fixing recommendations release.
6. Detailed report.
  • description of all tests
  • description of all vulnerabilities and ways of fixing

Here is a small list of sites that could of saved themselves with a simple scan using this approach.
It is important to note cost of securing these websites against the attacks that brought them down would of been LESS then 3,000$ The cost to them after the fact OVER 3billion for Sony alone! Are you prepared to offer the customers of the website in question identity theft protection at a cost of around 20$ per customer.

Lets get to the cost of my services.
Consultation and a Quote is Free.
We tend to charge 25$ per Working Web Application tested
If a exploitation is found a free retest after the exploit is fixed and a retest in 6 months is also free.
All services are confidential.
Please pm me via ecf for more info.
 
Last edited:

DeskJockey

Full Member
Sep 6, 2010
16
0
PA
Here a small list (but not complete) of Shopping cart software Some of you are using, A word to the wise they are all INSECURE contact me today for a FREE Quote Usually around 25$ per Working Web Application.
AJ Shopping Cart v1.0
Comersus 8 Shopping Cart
Valdersoft Shopping Cart
Interspire Shopping Cart
DevMass Shopping Cart
osCommerce and osCMax shopping cart
Multi-Vendor E-Commerce
XT-Commerce v1 Beta 1
Tochin Ecommerce
E-commerce Group
webperformance Ecommerce
Speedy-shop
ECShop
phpscripte24 Live Shopping Multi Portal System
GeneShop
ShopSystem
Online shop
PhPepperShop Webshop
ShopCartDx
Shopxp v7.4
TomatoCart 1.0.1
After Shopping Cart
ZeusCart Ecommerce Shopping Cart Software (ALL VERSIONS)
sX-shop
 
Status
Not open for further replies.

Users who are viewing this thread