Penetration Testing mailing list archives

Re: Pay per use pentesting tool?


From: natron <natron () invisibledenizen org>
Date: Mon, 30 Jun 2008 15:42:48 -0500

I'm sure they have multiple types of licenses, because I know they
have time-limited, network-unlimited licenses.  E.g., any IP addresses
can be scanned, but only for 15 or 30 days.  The license type you're
referring to is unlimited use (no time limit) but limited to what IP
addresses they can scan.

Regards,
N

On Mon, Jun 30, 2008 at 2:44 PM, Mike Duncan <Mike.Duncan () noaa gov> wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Isn't Appscan's licensing model against this very thing? You can only
specify upon installation of the software/license what networks you
would like to scan. Unless I am missing a point by their sales
staff...let me know if so.

Mike Duncan
ISSO, Application Security Specialist
Government Contractor with STG, Inc.
NOAA :: National Climatic Data Center
151 Patton Ave.
Asheville, NC 28801-5001
mike.duncan () noaa gov
828.271.4289


natron wrote:
| Don't most of the automated web application testing tools follow this
| model?  I know IBM's AppScan does.
|
| On Mon, Jun 30, 2008 at 12:12 PM, Ramki B Ramakrishnan
| <bramkie () gmail com> wrote:
|> Thinking out of the box I wonder if there are any pay-per-use pentesting
|> tools, typically this could be used by consultants who are not into full
|> time testing. Are there any tools currently available in this model?.
|>
|> Thanks
|> Ramki
|>
|>
|>
|>
|> ------------------------------------------------------------------------
|> This list is sponsored by: Cenzic
|>
|> Top 5 Common Mistakes in
|> Securing Web Applications
|> Get 45 Min Video and PPT Slides
|>
|> www.cenzic.com/landing/securityfocus/hackinar
|> ------------------------------------------------------------------------
|>
|>
|
| ------------------------------------------------------------------------
| This list is sponsored by: Cenzic
|
| Top 5 Common Mistakes in
| Securing Web Applications
| Get 45 Min Video and PPT Slides
|
| www.cenzic.com/landing/securityfocus/hackinar
| ------------------------------------------------------------------------
|
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFIaTeGnvIkv6fg9hYRAmB8AJ99VIeU17WkUy1EFbh5wdilpJp2ugCfdcP2
DcJagpZqz8vaxYb0ujU3j/g=
=dtJY
-----END PGP SIGNATURE-----


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes in 
Securing Web Applications
Get 45 Min Video and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------


Current thread: