Re: JIRA Pentest

Patrick Webster <[email protected]>
Newsgroups gmane.comp.security.penetration
Message-ID <CAJN6cdcsneDH3SQh1ud8zrTRpLV51xKsx0AX-3B-Zxc2q2QvNA@mail.gmail.com>
Check for embedded 3rd party software bugs.

E.g. http://www.osisecurity.com.au/advisories/jfreechart-path-disclosure
applies to some Atlassian products. Path disclosure ain't much but may
help you combined with other bugs.

-Patrick

On Wed, Oct 19, 2011 at 2:28 AM, Bog Witch <[email protected]> wrote:
> All,
>
> Is there anyone on this list with commercial JIRA pentest exposure?
>
> Please email responses directly.
>
> Thanks,
>
> Bog
>
> ------------------------------------------------------------------------
> This list is sponsored by: Information Assurance Certification Review Board
>
> Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
>
> http://www.iacertification.org
> ------------------------------------------------------------------------
>
>

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.