Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 28 guests and 6 members online

els_120_600.jpg

EH-Net News Feeds
Latest Additions
Book Recommendations



 

You are here: Home arrow Forum arrow Featuresarrow /rootarrow [Article]-Interview: Ferruh Mavituna on Netsparker
EH-Net
September 02, 2010, 11:35:02 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article]-Interview: Ferruh Mavituna on Netsparker  (Read 6456 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 3281


Editor-In-Chief


View Profile WWW
« on: January 07, 2010, 01:47:33 PM »

Jason Haddix continues his fine work with another interview. If you have any questions for Mr. Mavituna, please feel free to ask them in this thread, and we'll do our best to get him to answer them personally.

Permanent link: [Article]-Interview: Ferruh Mavituna on Netsparker

Quote




Review by Jason Haddix

Today we showcase a new web application scanner called Netsparker, and believe us when we say we put this app through the ringer.

There's a big distinction between testing a tool against dummy apps in a lab and using it first hand against a large environment. Luckily for us we got to do both.

Over the course of a month we ran several engagements and specifically watched Netsparker’s performance compared to other tools we normally use in the assessment process (w3af, Grendel Scan, Nikto, Wikto, Websecurify, Paros, Burp, etc). We have to say, we are very impressed. Netsparker not only caught vulnerabilities that other scanners missed but also had excellent remediation and a documentation section for most of its findings.

For injection it does a full-scale attack, testing every parameter it can spider (which it also does very well), and, although this lengthens the testing time, it also awarded us with some valuable injection findings. Netsparker is developed by Mavituna Security, and more specifically our guest, Ferruh Mavituna.


Don
Logged

CISSP, MCSE, CEH, Security+ SME
Ketchup
Hero Member
*****
Online Online

Posts: 966



View Profile
« Reply #1 on: January 07, 2010, 11:38:37 PM »

Jason, good work, as always.   I am wouldn't mind trying the tool out.  It's a bit pricey, but if it does what it says it could be worth a shot.  Is there a trial version for Netsparker?
Logged

~~~~~~~~~~~~~~
Ketchup
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.09 seconds with 23 queries.
 

careeracademy130x200.jpg

Support EH-Net

eh-net_amazonstore.jpg
Help Support EH-Net with Our Amazon Store


cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2010 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.