Re: Vuln scan tool for web

From: El C0chin0 (mr.nasty_at_ix.netcom.com)
Date: 07/15/03

  • Next message: Balwant Rathore: "PenTest Study Group Madrid meeting: MODERATOR PLEASE DELETE PREVIOUS MAIL since I forgot to mention date"
    Date: 15 Jul 2003 18:16:02 -0000
    To: pen-test@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) In-Reply-To: <017c01c34af6$8fa39ae0$6401a8c0@bilder.com>

    This is a relatively new commercial tool used for just
    that purpose. It's has a nice flexible front end and
    can be configured with just about any type of attack
    you might want to try.

    It's called WebInspect by SPI Dynamics.

    http://www.spidynamics.com

    They allow a download of the product for testing and
    will probably grant a 30 day temp key.

    ---------------------------------------------------------------------------
    Your network Firewall and IDS products do not prevent Web application
    exploits - the most common form of online attack - resulting in Web
    defacement, data theft, sabotage and fraud.

    KaVaDo is the first and only company that provides a complete and an
    integrated suite of Web application security products, allowing you to
    assess your entire environment, automatically set positive security
    policies and maintainĀ it without compromising business performance.

    For more information on KaVaDo and to download a FREE white paper on Web
    applications - security policy automation, please visit:
    http://www.kavado.com/ad.htm
    ----------------------------------------------------------------------------


  • Next message: Balwant Rathore: "PenTest Study Group Madrid meeting: MODERATOR PLEASE DELETE PREVIOUS MAIL since I forgot to mention date"

    Relevant Pages

    • Re: Detecting DNS Servers
      ... Your network Firewall and IDS products do not prevent Web application ... integrated suite of Web application security products, ... For more information on KaVaDo and to download a FREE white paper on Web ...
      (Pen-Test)
    • Re: File extensions spoofable in MSIE download dialog
      ... File extensions spoofable in MSIE download dialog ... I don't have internet explorer to test but rfc 2616 describes some "security considerations". ... > extension without a sign of EXE, and issue no Security Warning dialog ...
      (Bugtraq)
    • Re: Some mail opens a blank page
      ... YW, Dan, and thanks again for your valuable feedback. ... Save that download link and Product or User ID for CA Internet Security ... and then run the Removal Tool to rid the machine of all Norton crapware. ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: Short List of Security Questions
      ... Do you have a list of recommendations for windows? ... I think there are three separate aspects to PC security: ... get and download the latest Firefox and Thunderbird. ...
      (microsoft.public.security)
    • RE: Smiley central Active X controls
      ... security setting was selected. ... It still will not allow me to download ... Does NOT monitor behavior on the Internet ... Why some spyware services may mistake Fun Web Products and its MyWebSearch ...
      (microsoft.public.windowsxp.help_and_support)