Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Web Application Source Vulnerability Scanners

From: Javier Fernandez-Sanguino <jfernandez(at)germinus.com>
Date: Fri Mar 07 2003 - 07:53:33 EST

Ory Segal wrote:
> Hi,
>
> The problem with most open source tools is that they are very strong in

Ok. Not completely true. Let's take a look at httpush: http://sourceforge.net/projects/httpush
(the answers would be similar if you took Spike proxy or other inline proxies)

> 1) Application level tests such as manipulation of : HTML form

It has a Plugin API in which you can code this tests. Some are already available.

> 2) Automatic testing validation.

It does not have those. But I don't understand the point of doing it either.

> 3) Good reporting abilities

Do you need help?X

Good ol' text files.

> 4) Session management/Transient management - Keeping the scanner 'in
> session'. This gives you the ability to scan web applications that force
> you to login, and may kick you out of session, if you caused some error
> - I believe that most large web apps have this. I believe that AppScan
> is the only scanner to perform this action.

It does this fairly well since it's managed by the browser, httpush is a semi-transparent proxy.

> 5) Good performance

Fairly good performance as a proxy.

> 6) Contstant updates.

Not in httpush case but not really necessary.

> 7) Logging of raw HTTP traffic

Do you need more help?X

Httpush can do that.

> 8) The ability to easily implement new tests.

Same here.

Now, I don't develop httpush myself. But I find it a _very_ useful web application scanner. I think the same of Spike proxy and RFP Procy BTW. However, it's not a "web application _Source_ vulnerability scanner". But, then again, your answer does not answer the original post either (since you are not talking of _source_ scanners either)

Regards

Javi Received on Fri Mar 7 11:05:52 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:49 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library