WebApp Sec mailing list archives

Re: Vulnerability solution


From: Guillermo Caminer <flaco.webappsec () gmail com>
Date: Fri, 16 Nov 2012 20:08:32 -0300

Dear Mohamed,
as somebody already said, there is not a single scanner wich can cover -all- these components
(silver bullet), you will have better luck using different scanners for different components.

Like everybody said, Nessus is the most general/overall solution.

That been said, if you're serious about your systems security (as I think you are, because you're
looking for a complete scanner solution) I strongly recommend using a professional pentester,
review, among other things, the source code of your applications and educate your programmers and
network administrators. These are the -only- things that will effectively reduce your risk and can
give you a -real- measure of your systems security.

Scanners only should NOT be used to do a -real- evaluation as this is misleading.

It's a cliche, but: Security is not a product, is a process.

Sorry for answering something you didn't ask ;)

Best regards.

On 11/14/2012 03:53 AM, mdaa.uae () gmail com wrote:
Dear All

Is there anyone can refer me to vulnerability solution tool that can scan the system which consists of 
applications,database and web.the solution should provide detailed information regarding all the layers in the 
enterprise systems.

Thank you

Mohamed





This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------





This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------


Current thread: