Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 103 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow Webinspect vs AppScan
EH-Net
May 26, 2012, 09:10:52 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Webinspect vs AppScan  (Read 1044 times)
0 Members and 1 Guest are viewing this topic.
eyenit0
Newbie
*
Offline Offline

Posts: 36


View Profile
« on: January 17, 2012, 09:07:06 AM »

Hey everyone,

I've been evaluating web application scanners for my company to invest in and was wondering which of these two you guys have experience with and recommend. I know there are open source tools that are just as good or better and discovering vulns, but I'm also interested in their reporting and compliance (FISMA) features.

I've tested out both of them (full evaluation license) against a test site and they both still miss a few vulnerabilities that I know are there. I'm leaning toward AppScan because I like the interface better and find it easier to get around in, but am open to suggestions.

Open source tools will still be a part of my toolkit - there's no doubt about that - but the company also wants to have an established "professional" scanner in place. I'm sure the rest of you are like me and don't like a scanner taking all the fun out of web app testing, but at least I'll still get to do manual testing after initial scans.

Thanks for your input.
Logged
cd1zz
Sr. Member
****
Offline Offline

Posts: 393


View Profile WWW
« Reply #1 on: January 17, 2012, 04:15:34 PM »

We use Hailstorm and have mixed opinions about it. You might want to give it a shot. I've not used those others...........because im burping.
Logged

eyenit0
Newbie
*
Offline Offline

Posts: 36


View Profile
« Reply #2 on: January 17, 2012, 04:25:03 PM »

Thanks for the input.
I actually had a Webex last week with Cenzic to go over Hailstorm. I'm working on getting an evaluation copy, but they won't give it out without setting up another Webex to go through the install process, so I'm still working that out.

The UI to Hailstorm didn't seam very intuitive and looked like it might be difficult to get around in. I'd like to test it out and see how it does finding vulnerabilities, but I wasn't very impressed with its presentation.

I guess I'll get an eval soon enough and will be able to test it. If it does a better job at finding vulnerabilities, then I don't care too much about the UI.

Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.129 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.