Penetration Testing mailing list archives

Re: Database Scanners


From: Joey Peloquin <joeyp () cotse net>
Date: Thu, 17 Jun 2004 18:54:55 -0500

Frank Boldewin wrote:

hi,
the only good database scanner i know is appdetective.
http://www.appsecinc.com/products/appdetective/
scans several databases: oracle, db2, mssql, mysql, notes, sybase and web
apps.
hope that helps.

cheers,
frank

I'll second the AppDetective recommendation. We bought AppDetective for Web Apps, too. Great tools for getting audit-level assessment done. Their tools combined satisfy, IIRC, eight, or so, of the ~12 Visa CISP requirements.

cheers,
joey


Current thread: