<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>ProductCart Shopping Cart Software Forums : Web Application Penetration Testing?</title>
  <link>https://forum.productcart.com/</link>
  <description><![CDATA[This is an XML content feed of; ProductCart Shopping Cart Software Forums : Getting Started : Web Application Penetration Testing?]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Sat, 11 Apr 2026 07:17:03 +0000</pubDate>
  <lastBuildDate>Mon, 21 Dec 2009 15:23:29 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forum.productcart.com/RSS_post_feed.asp?TID=3243</WebWizForums:feedURL>
  <image>
   <title><![CDATA[ProductCart Shopping Cart Software Forums]]></title>
   <url>https://forum.productcart.com/forum_images/pc_logo_50.png</url>
   <link>https://forum.productcart.com/</link>
  </image>
  <item>
   <title><![CDATA[Web Application Penetration Testing? : Hi, For those following this thread,...]]></title>
   <link>https://forum.productcart.com/web-application-penetration-testing_topic3243_post12427.html#12427</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=303">Hamish</a><br /><strong>Subject:</strong> 3243<br /><strong>Posted:</strong> 21-December-2009 at 3:23pm<br /><br />Hi,<br>&nbsp;&nbsp; For those following this thread, who may be concerned, we can confirm there is not a security issue.<br>]]>
   </description>
   <pubDate>Mon, 21 Dec 2009 15:23:29 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/web-application-penetration-testing_topic3243_post12427.html#12427</guid>
  </item> 
  <item>
   <title><![CDATA[Web Application Penetration Testing? : I discussed the urgency of this...]]></title>
   <link>https://forum.productcart.com/web-application-penetration-testing_topic3243_post12426.html#12426</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=290">Greg Dinger</a><br /><strong>Subject:</strong> 3243<br /><strong>Posted:</strong> 21-December-2009 at 12:22pm<br /><br />I discussed the urgency of this matter with Lora and she is making arrangements to submit a ticket right away.]]>
   </description>
   <pubDate>Mon, 21 Dec 2009 12:22:12 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/web-application-penetration-testing_topic3243_post12426.html#12426</guid>
  </item> 
  <item>
   <title><![CDATA[Web Application Penetration Testing? : I&amp;#039;m buying the support plan...]]></title>
   <link>https://forum.productcart.com/web-application-penetration-testing_topic3243_post12425.html#12425</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=755">loracady</a><br /><strong>Subject:</strong> 3243<br /><strong>Posted:</strong> 21-December-2009 at 12:19pm<br /><br /><P>I'm buying the support plan in a minute.&nbsp; </P>]]>
   </description>
   <pubDate>Mon, 21 Dec 2009 12:19:23 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/web-application-penetration-testing_topic3243_post12425.html#12425</guid>
  </item> 
  <item>
   <title><![CDATA[Web Application Penetration Testing? : Hi Hamish-- Thanks for your response...]]></title>
   <link>https://forum.productcart.com/web-application-penetration-testing_topic3243_post12424.html#12424</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=755">loracady</a><br /><strong>Subject:</strong> 3243<br /><strong>Posted:</strong> 21-December-2009 at 12:09pm<br /><br /><P>Hi Hamish--&nbsp; Thanks for your response and your edit of my post!&nbsp; I didn't buy my version of PC from Early Impact, so I can't raise a support ticket.&nbsp; (At least I don't think I can.)&nbsp; </P>]]>
   </description>
   <pubDate>Mon, 21 Dec 2009 12:09:16 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/web-application-penetration-testing_topic3243_post12424.html#12424</guid>
  </item> 
  <item>
   <title><![CDATA[Web Application Penetration Testing? : Hi Lorcady, Sorry, edited your...]]></title>
   <link>https://forum.productcart.com/web-application-penetration-testing_topic3243_post12423.html#12423</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=303">Hamish</a><br /><strong>Subject:</strong> 3243<br /><strong>Posted:</strong> 21-December-2009 at 11:48am<br /><br />Hi Lorcady,<br>&nbsp; Sorry, edited your post to remove the name of the page, just in case it's a real vulnerability as it's not a good idea to indicate to the bad guys where to go and attack stores !<br>Please raise a support ticket so that we can investigate the issue in detail. Most of the time vulnerabilities are due to false alarms or site specific edits, although the latter seems unlikely on this page.&nbsp; &nbsp; <br>]]>
   </description>
   <pubDate>Mon, 21 Dec 2009 11:48:26 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/web-application-penetration-testing_topic3243_post12423.html#12423</guid>
  </item> 
  <item>
   <title><![CDATA[Web Application Penetration Testing? :  Speaking of McAfee Secure: We...]]></title>
   <link>https://forum.productcart.com/web-application-penetration-testing_topic3243_post12422.html#12422</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=755">loracady</a><br /><strong>Subject:</strong> 3243<br /><strong>Posted:</strong> 21-December-2009 at 11:40am<br /><br />Speaking of McAfee Secure:&nbsp; We recently signed up for it.&nbsp; I keep getting notifications of vulnerabilities:&nbsp; 1.&nbsp; Login is not over a secure connection.&nbsp; I fixed that one (or so I thought, but I keep getting the notifications anyway.)&nbsp; What else can I do to fix this vulnerability? &nbsp;2.&nbsp; Today I received one that is really over my head:&nbsp; Potentially Exploitable SQL Injection on *****.asp.&nbsp; I am using Product Cart 3.51a.&nbsp; I don't have a clue how to fix this one.&nbsp; Any ideas?<br><br>(Edited by Hamish - Sorry Lorcady, See following post in a moment)<br><span style="font-size:10px"><br /><br />Edited by Hamish - 21-December-2009 at 11:42am</span>]]>
   </description>
   <pubDate>Mon, 21 Dec 2009 11:40:03 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/web-application-penetration-testing_topic3243_post12422.html#12422</guid>
  </item> 
  <item>
   <title><![CDATA[Web Application Penetration Testing? : We know of several customers using...]]></title>
   <link>https://forum.productcart.com/web-application-penetration-testing_topic3243_post12133.html#12133</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=1">ProductCart</a><br /><strong>Subject:</strong> 3243<br /><strong>Posted:</strong> 25-November-2009 at 8:02pm<br /><br />We know of several customers using McAfee Secure. We use it ourselves at Early Impact. You can sign up for <a href="http://www.earlyimpact.com/productcart/mcafee/" target="_blank">free PCI compliance testing</a> from McAfee and then upgrade to McAfee Secure <a href="http://www.earlyimpact.com/productcart/mcafee/" target="_blank">here</a>.]]>
   </description>
   <pubDate>Wed, 25 Nov 2009 20:02:10 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/web-application-penetration-testing_topic3243_post12133.html#12133</guid>
  </item> 
  <item>
   <title><![CDATA[Web Application Penetration Testing? : Greetings! Has anyone used a third...]]></title>
   <link>https://forum.productcart.com/web-application-penetration-testing_topic3243_post12129.html#12129</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=1773">bryanb</a><br /><strong>Subject:</strong> 3243<br /><strong>Posted:</strong> 25-November-2009 at 3:58pm<br /><br />Greetings! Has anyone used a third party auditing or security firm to perform web application penetration testing against a fully patched version of 3.x? We've performed and mitigated issues related to network penetration testing from a QSA, now I need to kick the testing into the application. If you've done this, who did you use and were you pleased with the service? What can I expect in terms of cost? Anything you would like to share about the experience would be great!<br /><br />Thx!<br />Bryan]]>
   </description>
   <pubDate>Wed, 25 Nov 2009 15:58:37 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/web-application-penetration-testing_topic3243_post12129.html#12129</guid>
  </item> 
 </channel>
</rss>