WebInspect vs Burp Suite Pro??




Posts: 44

Joined: Fri Sep 09, 2011 9:20 am

Post Mon May 07, 2012 9:48 am

WebInspect vs Burp Suite Pro??

Hello All,

Can someone familiar with these products summarize how these 2 products compare?

My understanding was that WebInspect is heavily used for automated testing but then I also notice that Burp Pro has the scanner option which appears to do the same thing.

Any thoughts?


User avatar

Hero Member
Hero Member

Posts: 591

Joined: Tue Feb 23, 2010 4:55 am

Location: Netherlands

Post Tue May 08, 2012 1:48 am

Re: WebInspect vs Burp Suite Pro??

I am not familiar with WebInspect, but i use burp pro every day, and the more i rely on it, the more features i discover (even after multiple years of use).

It is so much more than only a proxy. You can actively or passively scan webapplications, compare requests, use the intruder to perform brute forcing, it even has a compare function for sessions to check for randomness in the received session identifier. Heck, it even helps you spider the website, and if you use the active scanner it will find sql injections, xss, path traversals etc. so you can even use it as an automated tool.

earning my stripes appears to be a road i must travel alone...with a little help of EH.net

Return to Web Applications

Who is online

Users browsing this forum: No registered users and 1 guest

Powered by phpBB® Forum Software © phpBB Group.
Designed by ST Software