[10285] in bugtraq

home help back first fref pref prev next nref lref last post

EC app security

daemon@ATHENA.MIT.EDU (Stout, Bill)
Tue Apr 20 14:10:52 1999

Date: 	Mon, 19 Apr 1999 14:00:36 -0400
Reply-To: "Stout, Bill" <StoutB@PIONEER-STANDARD.COM>
From: "Stout, Bill" <StoutB@PIONEER-STANDARD.COM>
To: BUGTRAQ@NETSPACE.ORG

Has anyone done a security audit/analysis of Electronic Commerce software
packages, such as catalog, database, and payment systems rolled into one?
There seems to be a deafening silence on what seems to be the most
vulnerable products.  Most bug issues are at the 'bit level' (O.S., stack,
or services) and not typically at the higher layer applications or workflow
process.

One experience; searching for database performance info one day, and pulling
up the 'catalog administrator' page of one (political) commerce site.  Had a
hell of a time convincing the admin that that was a problem, without
actually changing anything.

Bill Stout

home help back first fref pref prev next nref lref last post