Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 31 guests and 1 member online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Web Applications
tools
EH-Net
May 19, 2013, 12:32:36 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Web Applications
(Moderator:
don
) >
tools
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: tools (Read 6438 times)
0 Members and 1 Guest are viewing this topic.
alucian
Full Member
Offline
Posts: 225
tools
«
on:
February 16, 2012, 09:25:59 AM »
Hi,
I am planning to buy a commercial vulnerability scanner. Given the fact that my budget is limited I am oscilating between NTOSpider and Acunetix.
According to some studies (2009), Accunetix is better, but I like the fact that NTOSpider integrates with Core Impact. We don't have Core Impact yet, but I will try to sell the idea of having a commercial pentesting tool (Core or Canvas).
So what do you recommend between the 2 of them?
I know that Webinspect is probably better, but is almost 30k, I have Burp Pro,... I need a good scanner, that will produce nice and useful reports.
Thanks
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
3xban
Hero Member
Offline
Posts: 605
Re: tools
«
Reply #1 on:
February 16, 2012, 12:16:00 PM »
Have you looked at NeXpose from Rapid 7 or Nessus (Tenable)? The pro versions of those are pretty solid. NeXpose has metasploit integration so you can "test" some of the findings out. I think they are also slightly cheaper than the other products. Though Core seems to be the one to go with for its reporting alone.
Also what are you looking to accomplish? Do you want to just find vulns or find and test? Find, test, patch? GFI LANGuard is useful for finding and patching. NeXpose finds and provides you with the fixes, including links to patches if available. It also provides the metasploit module to test the vuln. Nessus, will find and test the vuln and produce decent report data. It will also provide the information to fix the vuln.
Logged
Certs: GCWN
(@)Dewser
alucian
Full Member
Offline
Posts: 225
Re: tools
«
Reply #2 on:
February 16, 2012, 02:54:04 PM »
I have both Nessus and Nexpose, the commercial versions.
Actually, I will have the money to buy a web application vulnerability scanner because we might get rid of Nexpose. It simply does not add any value to us. It is more expensive than Nessus (for ex a Nessus license, unlimited IPs costs 1200$, and Nexpose 1000 Ips costs around 10.000$).
Also, I did some scans and I didn't see big differences between the results. I even saw more false positives and more false negatives in Nexpose, but I don't want to go in there yet.
It is true that Nexpose integrates with Metasploit, but the pro version of Metasploit is 15.000$. I rather buy CANVAS or Core Impact if I really want a penetration testing framework. I know how to use Metasploit framework, Burp..., but the other guy who is working with me has no idea about this. So, we have to buy tools he is able to use
I know that it is stupid, but the good side is that I can justify an excellent tool, saying that it is easy to use. I don't know if they will accept my request, but I can try.
Also, if (when) I'll leave, they must be able to produce the scans. That's the advantage of the commercial tools. The disadvantage is that some analysts have no idea of what they are doing; they produce hundreds of pages of reports without any value for the overall security.
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
3xban
Hero Member
Offline
Posts: 605
Re: tools
«
Reply #3 on:
February 16, 2012, 03:04:06 PM »
I hear ya there, the tools make the job easy for us to gather the data, but the hard part is clensing it for management. Good point about the MSF Pro and NexPose costs, completely forgot about that.
As for Web App, how about Cenzic Hailstorm? I haven't used it personally but we were looking at it at my last job. Right now I am messing with w3af (another Rapid 7 creation so I am sure the pro version will cost alot).
Logged
Certs: GCWN
(@)Dewser
cd1zz
Hero Member
Offline
Posts: 561
Re: tools
«
Reply #4 on:
February 17, 2012, 07:54:16 AM »
@alucian
Can you break down why you like Nessus more? Is the equalizer the pricing and the functionality is the same? You mentioned false positives but I'm curious since we're a Nexpose shop too.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
alucian
Full Member
Offline
Posts: 225
Re: tools
«
Reply #5 on:
February 17, 2012, 10:36:00 AM »
@cd1zz
The main reason I prefer Nessus is that it produces better results. Also, when you are analysing the results, you have an option to see only the vulnerabilities for which "Exploit exists". This is extremely useful. In Nexpose you can see the ones where you have exploits in Metasploit and in exploit-db (very useful and not present in Nessus). Also, in Nessus you have the mention that a Metasploit, CANVAS or Core Impact exploit exists. For the rest you have to search the net.
Among the false positives in Nexpose, the most annoying ones where the ones detected when I executed a scan using admin credentials. As an example, for one server it reported a browser exploit. In Metasploit the exploit applies to IE 6, but our machine had IE 8. Another one was valid for Win 2003 SP0, and our machine wasn't for sure SP0.
Last year I did a comparison between the two vuln scanners using regular network scans (without credentials). After the scan I tried to identify as many as possible false positives. The results from Nessus were much more accurate, and Nexpose missed a lot of vulnerabilities.
Another disadvantage of Nexpose is that if you enter for scan a class C, it will consume 255 ips (from a total of 1000 in my case). Because we are using many subnets I would have to do a scan with Nmap first, and then import the results in Nexpose. I think that sometimes, when you do this, it will erase old entries.
The advantages with Nexpose are the facts that you have a nice management of the zones and extra scan engines, and that it produces more detailed reports, that gives detailed remediation steps.
For a big company the management of zones and scanners is a plus, because the Tenable Security Center (necessary to integrate the results from multiple Nessus scanners) costs 80.000$. So, if you have many zones, with many scanners and you want all of the results in one place Nessus vulnerability scanner is not the solution to go. You either buy Tenable Security Center, either go for another solution (Nexpose being one of them).
In our case, we have a scanner internally, one in the DMZ and another one on a machine connected directly to the internet. With Nexpose, the first two could be combined, and have all the results in the same place.
I didn't try yet the integration of Nexpose in Arcsight, but I might try before our license expires.
And, yes, the price is important for me. Scanning 2500 real IPs (and I give him ranges that will cumulate almost 10 000 IPs) with Nessus costs us 1200$/year. With Nexpose will cost way more.
Worst, we have Nexpose through Symantec, which resells it as CCS. When you have a problem, and you need support, you have to deal first with Symantec, and when they are not able to fix the problem, they will escalate it to Rapid7 (which gave me the solution very rapidly).
Maybe I am biased, but this is my opinion. If you want, I can provide some tables with the results of two scans. My analysis is not 100% accurate, but there is a big difference between the two scanners.
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
Seen
Full Member
Offline
Posts: 134
Re: tools
«
Reply #6 on:
February 18, 2012, 01:05:39 AM »
I've been thinking about playing around with Nessus and Nexpose, and this thread has been really informative. Thanks guys!
Logged
Sec+, eCPPT
millwalll
Guest
Re: tools
«
Reply #7 on:
February 19, 2012, 04:10:44 PM »
There another tool that my old company used called web inspector that was ok for web applications
Logged
dbest
Jr. Member
Offline
Posts: 79
Re: tools
«
Reply #8 on:
February 19, 2012, 11:11:18 PM »
Are you looking for a app scanner or a vuln scanner? I think that would help determine what tool you need.
Nessus, while an awesome vuln scanner, might not give you that many results for applications.
Logged
CISM, CEH, CISA, ISO 27001 LA
jinwald12
Jr. Member
Offline
Posts: 77
Re: tools
«
Reply #9 on:
March 06, 2012, 10:12:04 PM »
i am personally against web vulnerability scanners they are noisy, blocked/detected by most WAFs/IDS/IPSes and often generate false positives or miss things for a vulnerability assessment they are ok but for a pen test they are stupid and sometimes a game ender i personally do all my assessments by hand with firefox, tamper data and firebug, my logic behind that is i get a better idea how the application works and an attacker is going to use a setup that maximizes his or her anonymity and also its easier to look like a legitimate user if i am using a web browser then if i am sending huge numbers of packets with a automated tool and hoping the WAF only checks user agents. if i where doing a whitebox/vulnerability assessment type thing i use nikto/W3af community tools generally have more frequent updates in my experience. but for a pen test i suggest you all do your tests by hand, they are paying you not the tool :-p
Logged
where did all the fun go?
eyenit0
Jr. Member
Offline
Posts: 51
Re: tools
«
Reply #10 on:
April 17, 2012, 04:44:54 PM »
I'm a little late getting around to this but I'll throw in my thoughts as well.
Nessus is pretty good for vulnerability scanning, but has been a little lacking in the web application scanning from my point of view. It does find certain things, but it also misses a lot(depending on the application, of course). It also isn't as customizable as many other web scanners.
I evaluated a lot of different scanners recently, both open source and commercial, and most of them are pretty close in terms of the findings. In fact, open source tools that you can find in Backtrack found many of the same vulnerabilities that $30k commercial scanners found.
Even though the results are roughly the same, you still get a lot more from most commercial scanners in terms of usability, support, and reporting. It's up to you on whether or not that justifies the cost. Also, you can try to talk the price down with the vendor. I got a $36,000 quote down to $20,000. Still a ton of money, but if you can swing it...
Either way you'd have to do a good amount of manual testing to find all of the things that the scanner missed!
We got a commercial scanner because of the support and reporting. However, I still use that as a baseline and starting point for my manual tests, where I do most of my work.
Hope that helps.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(6) by
Grendel
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: Red Team/Blue Team
(0) by
n37sh@rk
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.