|
|||||||||||
|
Re: Web Application Source Vulnerability Scanners
From: Javier Fernandez-Sanguino <jfernandez(at)germinus.com>
Date: Fri Mar 07 2003 - 07:53:33 EST
Ory Segal wrote:
Ok. Not completely true. Let's take a look at httpush:
http://sourceforge.net/projects/httpush > 1) Application level tests such as manipulation of : HTML form
It has a Plugin API in which you can code this tests. Some are already available.
> 2) Automatic testing validation.
It does not have those. But I don't understand the point of doing it either. Good ol' text files. > 4) Session management/Transient management - Keeping the scanner 'in
It does this fairly well since it's managed by the browser, httpush is a semi-transparent proxy.
> 5) Good performance
Fairly good performance as a proxy. Not in httpush case but not really necessary. > 7) Logging of raw HTTP traffic
Httpush can do that. > 8) The ability to easily implement new tests.
Same here. Now, I don't develop httpush myself. But I find it a _very_ useful web application scanner. I think the same of Spike proxy and RFP Procy BTW. However, it's not a "web application _Source_ vulnerability scanner". But, then again, your answer does not answer the original post either (since you are not talking of _source_ scanners either) Regards Javi Received on Fri Mar 7 11:05:52 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:49 EDT |
||||||||||
|
|||||||||||