Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 20 guests online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow Web App Pen Testing Products
Ethical Hacker Community Forums
December 03, 2008, 01:47:22 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Web App Pen Testing Products  (Read 3037 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« on: March 30, 2006, 03:20:54 PM »

Rooting Out Web App Holes 
By Jim Rapoza (eWeek Mag)
March 13, 2006


Review: Web application penetration-testing tool veterans WebInspect and AppScan show they still have the right security stuff.

Despite all the attention that security holes in various operating systems get, the most likely avenue for successfully compromising a corporate system is a poorly developed Web-based application. It's essential, therefore, for developers to find potential problems before deploying a Web application to a live site.

That's where Web application penetration-testing products come in. These tools let developers perform exhaustive application scans to find known security holes or even poorly designed code that could potentially lead to a security breach.

For full story:
http://www.eweek.com/article2/0,1759,1937372,00.asp

Podcast with Peter Coffee and Jim Rapoza looks at recent reviews of Web security products:
http://www.eweek.com/article2/0,1759,1939546,00.asp

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Dengar13
Full Member
***
Offline Offline

Posts: 224



View Profile
« Reply #1 on: March 30, 2006, 03:34:49 PM »

I will vouch that Webinspect is the real deal!  It rips the web server and finds tons of stuff, the reporting is sweet and it is worth the steep price if you are serious about web security.  My company had a 30 free trial to scan 1 IP address and the damn thing yielded a 450+ page report.  The box we tested was unpatched and an old version if IIS and it found everything from XSS to SQL injections and beyond.  It scans for HIPAA, PCI, Sarbanes-Oxley requirements by themselves or combined.  I highly suggest this product!!!  5 stars!
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Dengar13
Full Member
***
Offline Offline

Posts: 224



View Profile
« Reply #2 on: March 30, 2006, 03:36:18 PM »

Of course if you can't afford Webinspect, I recommend SARA and Nikto together.  They aren't as in-depth or as robust but are good nonetheless.
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
tmartin
Recruiters
Newbie
*
Offline Offline

Posts: 46


View Profile
« Reply #3 on: March 31, 2006, 07:37:05 AM »

Thanks for the input. Did your co buy it?
Logged
Dengar13
Full Member
***
Offline Offline

Posts: 224



View Profile
« Reply #4 on: March 31, 2006, 08:07:59 AM »

No not yet.  I think that once we get certified we may buy it.  It is pretty expensive like I think but don't quote me $20,000 for one machine and can scan unlimited number of IP addresses.  They give you a registry key that locks/binds the registration to only that specified machine.  We had a 30 day trial one one machine to scan 1 IP address.  I am lobbying for us to buy it.
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.098 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.