RE: Web Application Vulnerability Assessment Tools

"Medzich, Maik" <[email protected]> Fri, 6 Aug 2004 08:45:18 +0200
Newsgroups gmane.comp.security.programming
Message-ID <2EBE6611E93CD6498A48D2034B6B7976030949A2@cvx02ahyha.hyha.detemobil.de>

Hi, we have recently evaluated "APPSCAN" from Sanctum.inc, available at http://www.sanctuminc.com/.

This is quite a usefull and comprehensive tool, but also very expensive. While they have several versions for different purposes, we found the "audit" version will fit most of security related needs.

Take a look at the trial versions and see if this will fit your expectations.

cheers,
Maik

PS: For the more non-technical people you may try out the "Sentinel" service form WhiteHatSecurity at http://www.whitehatsec.com/...

> -----Original Message-----
> From: [email protected] [mailto:[email protected]] 
> Sent: Freitag, 6. August 2004 02:19
> To: [email protected]
> Subject: Web Application Vulnerability Assessment Tools
> 
> 
> Greetings list,
> 
> I'm in the process of evaluating web application 
> vulnerability assessment tools and was wondering if you would 
> be willing to share advice with me regarding tools available 
> and how they've worked in your experience.  I'm looking for a 
> tool to scan web applications for SQL injection, scripting 
> attacks, buffer overflows, etc...  It would be nice to find a 
> tool that could be used by the security group to do black box 
> testing and something that could also be used by the 
> application development team for white box testing.
> 
> Thanks in advance,
> -Brett
>