WebApp Sec mailing list archives

Re: OS XSS and SQL scanner


From: Eoin <eoinkeary () gmail com>
Date: Wed, 2 Aug 2006 12:53:58 +0100

Hi,
RE:
"This situation is no doubt due to the utter lack of skill
and understanding of the subject on the part of the authors."

I thought these tools were to assist one, so not as much skill is required?
Otherwise one would do it in a manual fashion?

What does one think?

-ek

On 01/08/06, Arian J. Evans <arian.evans () anachronic com> wrote:


> -----Original Message-----
> From: Mandeep Khera [mailto:mandeep () cenzic com]
>
> I am sorry to hear that you perceive some problems with our
> product. We take pride in being the most accurate product
> with least amount of false positives in the industry. This
> has been proven in many bake-offs by customers and
> independent journalists.

Hate to take this a little off topic, but do you have any facts
that can support or back up these claims? Any data produced by
anyone competent that speaks to your "false positives" and also
your "false negatives"?

I have failed to read a review yet to date that contains useful
information. So far what I've read varies from useless data
organized around features like "reflective buttons" (e.g.-the
Acunetix review posted to this list written by some woman
who writes windows software articles) to the other extreme
of uninformed opinion and inability to keep features between
the products straight (secure enterprise computing review).
This includes infosec magazine and online reviews, bake-offs,
and Gartner-style evals. Every one I have read so far is garbage.

Not one covers actual tests run & and the how & why around them.

This situation is no doubt due to the utter lack of skill
and understanding of the subject on the part of the authors.

However, I think all on this list would welcome information
of a high-quality nature regarding scanner quality, if you
have anything like that to point us at.

-ae





-------------------------------------------------------------------------
Sponsored by: Watchfire

Do you test web applications for XSS, SQL Injections, Buffer Overflows,
Logical issues and other web application security threats? Why not
automate this work with Watchfire's AppScan, the world's leading
automated web application scanner. Download AppScan today!

https://www.watchfire.com/securearea/appscancamp.aspx?id=701300000008BP9
--------------------------------------------------------------------------




--
Eoin Keary OWASP - Ireland
http://www.owasp.org/local/ireland.html

-------------------------------------------------------------------------
Sponsored by: Watchfire

Do you test web applications for XSS, SQL Injections, Buffer Overflows, Logical issues and other web application security threats? Why not automate this work with Watchfire's AppScan, the world's leading automated web application scanner. Download AppScan today!

https://www.watchfire.com/securearea/appscancamp.aspx?id=701300000008BP9
--------------------------------------------------------------------------


Current thread: