Re: [ACFUG Discuss] Security Tests for ColdFusion site

2010-01-05 Thread Ajas Mohammed
Thanks Dean. As always, your input is much appreciated. :-) http://ajashadi.blogspot.com We cannot become what we need to be, remaining what we are. No matter what, find a way. Because thats what winners do. You can't improve what you don't measure. Quality is never an accident; it is always the

Re: [ACFUG Discuss] Security Tests for ColdFusion site

2010-01-05 Thread Dean H. Saxe
I spent the past 5 years doing pen testing for a living and there are many, many companies out there performing this service. You get what you pay for! So ask yourself this question: What do I want to know from a test? Do you want to know what can be found by a machine running automated scans,

[ACFUG Discuss] Security Tests for ColdFusion site

2010-01-05 Thread Ajas Mohammed
Hi, I have heard of http://www.coresecurity.com/ who do security testing for web applications etc. Does anyone know of this company or any similar companies who do security/penetration tests for web applications. Needless to say, our applications are CF based. Is there anything to worry about or