WebApp Sec mailing list archives

Re: Automagic webapp testing tools


From: robert () dyadsecurity com
Date: Sun, 13 Mar 2005 17:37:19 -0800

Evans, Arian(Arian.Evans () fishnetsecurity com)@Thu, Mar 10, 2005 at 12:35:58PM -0600:
4. No substitute for manual testing.

In my mind, these tools are most powerful when used by the manual
testers.  It allows for a stimulus to be consistently applied to all inputs in
the application the same way every time.  No human has the stamina for
that on a large app :).

That said, the commercial tools I've evaluated are all lacking in
important features.  I think it's still an immature market with plenty
of room for new players who have good ideas.

Robert

-- 
Robert E. Lee
CTO, Dyad Security, Inc.
W - http://www.dyadsecurity.com
E - robert () dyadsecurity com
M - (949) 394-2033


Current thread: