Hey all,

The pen-test mailing list @ securityfocus has been recently buzzing with a plethora of information regarding web-application penetration testing.

A lot of people apparently are interested in the methodology on how to "to conduct
a successful application security assessment."

A brief paper has been prepared to "better assess the security of an application - without the overhead of a complex methodology."

Its a good read for consultants, security professionals, and fellow AO'ers. Take a look at it when you have the time (its very comprehensive)
http://www.technicalinfo.net/papers/...Questions.html