Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


gumdigger

429 posts

Ultimate Geek
+1 received by user: 3


#34366 22-May-2009 15:09
Send private message

Hi

currently i am assessing the security of a e-commerce website, it is created on a cms called oscommerce. i was wondering if anyone knows any free tools that will test common vulnerabilities. preferred a windows based tool. so far i have come across acunetix but its a commercial tools.


would appreciate any help.

thanks

Create new topic
nate
6473 posts

Uber Geek
+1 received by user: 458

Retired Mod
Trusted
Lifetime subscriber

  #217095 23-May-2009 01:08
Send private message

gumdigger:currently i am assessing the security of a e-commerce website, it is created on a cms called oscommerce. i was wondering if anyone knows any free tools that will test common vulnerabilities. preferred a windows based tool. so far i have come across acunetix but its a commercial tools.


osCommerce is a very popular e-commerce tool, there should be plenty of online information about known vulnerabilities which you can test.

Why are you testing it?  Are you trying to get PCI compliant?



gumdigger

429 posts

Ultimate Geek
+1 received by user: 3


  #217101 23-May-2009 07:21
Send private message

Not trying to get pci compliance. just want to test the website against cross site scripting, sql injection. directory traversal attacks etc... you know all the common attacks.

itxtme
2102 posts

Uber Geek
+1 received by user: 557


  #217141 23-May-2009 10:02
Send private message

Head over to their forums and look through the forum on vunrubilities. If you are using the latest version you should be fine..



nate
6473 posts

Uber Geek
+1 received by user: 458

Retired Mod
Trusted
Lifetime subscriber

  #217199 23-May-2009 12:44
Send private message

itxtme: Head over to their forums and look through the forum on vunrubilities. If you are using the latest version you should be fine..


Exactly what I was going to reply.  osCommerce is very popular so it would be pretty safe to assume they have most of their bases covered.

Ragnor
8279 posts

Uber Geek
+1 received by user: 585

Trusted

  #217395 24-May-2009 13:19
Send private message

Vulnerability Report: osCommerce 2.x
http://secunia.com/advisories/product/1308/

Metasploit Framework for testing
http://www.metasploit.com/

Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.