I code up sites written for ASP.NET 3.5.
They have security built in but I'd like to go further.
I'd like to understand what exploits are currently being used and attempt those on various versions of sites. (Staging and live.)
Having had a quick look at cracker tools, I'd prefer a tech. savvy high level view, and insight from others who've been through this.
What suggestions?