|
|||||||||||
|
RE: Web Application Source Vulnerability Scanners
From: Dawes, Rogan (ZA - Johannesburg) <rdawes(at)deloitte.co.za>
Date: Fri Feb 28 2003 - 02:45:42 EST
It is the homepage of Exodus, a Java web proxy currently under development, but it also has links to a number of other similar tools. >From the page: Functionality existing in Exodus today
Exodus may be added to the OWASP project, as a complementary tool to PenProxy, OpenProxy and WebScarab. Since they are all GPL'd, there will almost certainly be cross-pollenation between them if that does not happen. Rogan
-----Original Message-----
Does anyone know of open source vulnerability scanners in the Web Application Source Code security market segment? I am familiar and aware of the most common commercial tools (AppScan from Sanctum and WebInspect from SpiDymanics). The Open Web Application Application Security Project (OWASP) has started the development of an open source Weeb Application Vulnerability scanner called WebScarab, however, it is in the early stages of development.
Rafael Rosado, CISSP, CISA
+1 954-885-2176 (voice) * +1 954-885-3861 (fax) * +1 954-648-3532 (mobile) or 9546483532@mobile.att.net (text message) *rarosado@lucent.com (email) * This electronic mail message contains information belonging to Lucent Technologies, which may be confidential and/or legal privileged. The information is intended only for the use of the individual or entity named above. If you are not the intended recipient, you are hereby notified that any disclosure, printing, copying, distribution, or the taking of any action in reliance on the contents of this electronically mailed information is strictly prohibited. If you receive this message in error, please immediately notify us by electronic mail and delete this message. Received on Fri Feb 28 11:38:46 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:49 EDT |
||||||||||
|
|||||||||||