• Site Info
    h2


    Podango

    • podPress
    • Click to donate thru PayPal
    • Mighty Forums
    • Email
    • Instant Messenger

    FREE Security Scan from NT OBJECTives, Inc

    Create Animations With Stickman

    Custom Plugins

    Podcast/Blog
    h2

    Podcast Links

    • Podcast Feed
    • Blog Feed
    • View in iTunes
    • Mighty Seek on PodcastAlley.com
    • Mighty Seek on PodcastPickle.com
    • Sites that link to here
    • Podcasting Setup
    • Check out our Frappr!

    WebAppSec Links

    Categories

    Archives

    Yahoo


Mighty Seek
home
h1

Evaluating Web Application Security Scanners

August 23rd, 2007

Theres been alot of discussion lately about an issue thats near and dear to my heart. The capabilities and of web application security scanning is something I have been living and breathing for about 5 years with NT OBJECTIves. AT NTO I lead the development and research teams involved in building our own scanner called NTOSpider,  and have been trying to increase what is possible to test for in an automated tool.

This is a really difficult and challenging issue, with a bunch of issues that are fuzzy at best. I have high hopes that the WASSEC Project thats being hosted by the Web Application Security Consortium, because its going to bring a bunch of us from the app sec tool vendor space and the web app sec community  together to discuss the issue and attempt to come up with a good reference document for the ways to evaluate scanners.

I’m curious how we will be able to come up with any consensus, but with any luck and some hard work and compromise I think this could be a turning point to helping public understanding of this issue.



Comments:

Add your comments
 
Mighty Seek Podcast, MightySeek Podcast, Mighty Seek Blog, MightySeek Blog, Web application security podcast, Web application security blog, Web application development blog, Web application development podcast
Mighty Seek Podcast, MightySeek Podcast, Mighty Seek Blog, MightySeek Blog, Web application security podcast, Web application security blog, Web application development blog, Web application development podcast