Penetration Testing mailing list archives

[PEN-TEST] Pen-testing a website


From: Charles <techno1976 () HOTPOP COM>
Date: Fri, 22 Dec 2000 18:00:40 +0530

Hi

I want to test out the application that my developers have made for an E-Commerce site (E-Commerce meaning 
transaction-enabled).
Essentially to test issues like these:
- Mucking around with Cookies/Session IDs to find holes
- Ability to hijack sessions
- URL sequencing, etc

I am looking for an exhaustive list of such cases.

Any links, tools, help would be appreciated.

Thanks
-C

Current thread: