RE: Vulnerability and Penetration testing software



Gotta toss it out there because I haven't seen it yet, Nessus. Great
open source vuln scanner.

-----Original Message-----
From: Desai, Manish [mailto:MDESAI@xxxxxxxxxx]
Sent: Wednesday, April 12, 2006 2:47 PM
To: Jay Tumas; Pravin Jayakumar
Cc: Sherita; pen-test@xxxxxxxxxxxxxxxxx
Subject: RE: Vulnerability and Penetration testing software

Try METASPOLIT - a free ware which is good. Version 2.5 version has 105
exploits and 74 payload. www.metaspolit.org

HTH. Cheers


Manish Desai


-----Original Message-----
From: Jay Tumas [mailto:jay_tumas@xxxxxxxxxxx]
Sent: Tuesday, April 11, 2006 11:12 AM
To: Pravin Jayakumar
Cc: Sherita; pen-test@xxxxxxxxxxxxxxxxx
Subject: Re: Vulnerability and Penetration testing software

Core Impact from Core Technologies and Watchfires AppScan.

J

****************************************************************
Jay Tumas, NSA/IAM,IEM

- Network Operations Manager
- Network Security and Incident Response Team Manager
- Longwood Medical Area Technical Subcommittee Chair
- NEECTF/InfraGard Member, Board of Directors

Harvard University - UIS/Network Operations Center 60 Oxford Street,
Suite 132 Cambridge, MA. 02138

Office: 617-496-8500 VoIP/SoftPhone: 617-384-6530
Cell: 617-733-6169 Cell 2-way/Email: 6177336169@xxxxxxxxx
****************************************************************
"The first method for estimating the intelligence of a ruler is to look
at the men he has around him." - Niccolo Machiavelli



Pravin Jayakumar wrote:
Best Tools : NMAP, NESSUS

On 4/10/06, Sherita <sherita_m@xxxxxxxxxxx> wrote:

Hi

I would like to get some feedback from those who have had lots of
security experience about the best security vulnerability and
penetration testing products or software out there.

Thanks
Sherita

---------------------------------------------------------------------
---------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the
Analyst's Choice Award from eWeek. As attacks through web
applications continue to rise, you need to proactively protect your
applications from hackers. Cenzic has the most comprehensive
solutions to meet your application security penetration testing and
vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service

can help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm

your results from other product. Contact us at request@xxxxxxxxxx for
details.
---------------------------------------------------------------------
---------




----------------------------------------------------------------------
--------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the
Analyst's Choice Award from eWeek. As attacks through web applications

continue to rise, you need to proactively protect your applications
from hackers. Cenzic has the most comprehensive solutions to meet your

application security penetration testing and vulnerability management
needs. You have an option to go with a managed service (Cenzic
ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download
FREE whitepaper on how a managed service can help you:
http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm
your results from other product. Contact us at request@xxxxxxxxxx for
details.
----------------------------------------------------------------------
--------


------------------------------------------------------------------------
------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the
Analyst's Choice Award from eWeek. As attacks through web applications
continue to rise, you need to proactively protect your applications from
hackers. Cenzic has the most comprehensive solutions to meet your
application security penetration testing and vulnerability management
needs. You have an option to go with a managed service (Cenzic
ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download
FREE whitepaper on how a managed service can help you:
http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm
your results from other product. Contact us at request@xxxxxxxxxx for
details.
------------------------------------------------------------------------
------


------------------------------------------------------------------------
------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the
Analyst's
Choice Award from eWeek. As attacks through web applications continue to
rise,
you need to proactively protect your applications from hackers. Cenzic
has the
most comprehensive solutions to meet your application security
penetration
testing and vulnerability management needs. You have an option to go
with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service
can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm
your
results from other product. Contact us at request@xxxxxxxxxx for
details.
------------------------------------------------------------------------
------



------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@xxxxxxxxxx for details.
------------------------------------------------------------------------------



Relevant Pages

  • Re: [lists] Re: What to spend on a pentest
    ... Only the vulnerability test needs to be performed by a visa certified vulnerability tester. ... You'll notice the annual pen-test requirement in 11.3 doesn't specify that ... > Officer Information Systems Security infosysec.net ... You have an option to go with a managed service (Cenzic ...
    (Pen-Test)
  • Re: [lists] Re: What to spend on a pentest
    ... The PCI standard does require a business obtain quarterly vulnerability ... You'll notice the annual pen-test requirement in 11.3 doesn't specify that ... > Officer Information Systems Security infosysec.net ... You have an option to go with a managed service (Cenzic ...
    (Pen-Test)
  • Re: Vulnerability Assessment vs. PenTest
    ... They do most of the banner grabbing, hence, it is important for the security tester to have the experience and knowledge to identify which are false positives. ... Subject: Vulnerability Assessment vs. PenTest ... > Download FREE whitepaper on how a managed service can help ...
    (Pen-Test)
  • Re: how an hacker can bypass a chrooted environement ?
    ... Although this specific vulnerability has been patched, ... Concerned about Web Application Security? ... Download FREE whitepaper on how a managed service can ...
    (Pen-Test)
  • Re: Is there an Open Source Vulnerability Analysis Framework?
    ... Is there an Open Source Vulnerability Analysis Framework? ... end-to-end framework for security assessment. ... Download FREE whitepaper on how a managed service can ...
    (Pen-Test)