|
|||||||||||
|
Re: Distributed Vulnerability Scanners
From: Peter Mercer <inom(at)ozemail.com.au>
Date: Thu Mar 06 2003 - 22:24:41 EST For discussion purposes, here are 2 of my concerns with automated and "coin operated scanners".
Disclaimer) I know that both of the above are extreme cases... I hope that in selling these tools the vendors are push the above facts and not just their bottom line. Thanks for your time.
Kind regards,
[When I spend any money on security I like to ask, "is this money I spend now, still going to be of benefit to me in 1 to 5 years"]
From: "charl van der walt" <charl@sensepost.com>
To: <pen-test@securityfocus.com>
hey, i wasn't going to mention this until i saw qualys and vigilante being mentioned. it feels awfully like i'm doing a plug, but i think this approach is worth mentioning: over the last few years we've been developing an Internet-based scanning solution called "HackRack" - check www.hackrack.com. The live site is running version 2 of the system but i'm going to describe version 3, which is currently in Alpha testing. HackRack is essentially a web front end for Nessus, but is also more, less and different.
it's more because, in addition to the Nessus scans, we also scan for key
DNS entries, open and closed ports and 'pingable' ips within a given
range. in addition, HackRack stores all its findings in a database and
presents its findings in an interactive web interface that allows for
HackRack is less because it doesn't attempt to be a heavy-duty scanner. rather, it attempts to provide only the most important vulnerability information timeously in a simple, succinct form.
HackRack is different because it focuses on detecting changes. we don't
deliver full reports, only reports on what has changed since the previous
day's scans. with this approach, combined with the support and the
it's a humble product, but a philosophy i believe in. rgds charl
Are your vulnerability scans producing just another report?
Manage the entire remediation process with StillSecure VAM's
Vulnerability Repair Workflow.
Are your vulnerability scans producing just another report?
Manage the entire remediation process with StillSecure VAM's
Vulnerability Repair Workflow.
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:33 EDT |
||||||||||
|
|||||||||||