Educause Security Discussion mailing list archives

Re: Experiences with Web application vulnerability assessment (1) software (2) companies


From: Randy Marchany <marchany () CANDI2 CIRT VT EDU>
Date: Wed, 27 Feb 2008 16:09:54 -0500

We use:

1. Accunetix - commercial www vulnerability scanner
2. Core Impact - commercial pen test tool
3. Webscarab - freeware www testing tool
4. Paros - freeware www vulnerability scanner with injection testing

Each one reports slight different info but the reports in combination with a
good security team analysis should help discover most www app problems.

        -Randy Marchany
        VA Tech IT Security Office & Lab

Current thread: