|
Penetration Testing
Nmap Sep 30 2011 09:17PM Ukpong (ukpong ukpong gmail com) (3 replies) Re: Nmap Oct 02 2011 02:37AM Jeffory Atkinson (jatkinson zelvin com) (1 replies) Re: Nmap Oct 02 2011 09:35PM John M. Martinelli (john martinelli redlevel org) (2 replies) Opinions on Burp Suite Web App Scanner Oct 12 2011 03:31PM Derrenbacker, L. Jonathan (JDerrenbacker KSHGS com) (5 replies) RE: Opinions on Burp Suite Web App Scanner Oct 12 2011 04:41PM Ben de Bont (bendebont gmail com) (1 replies) Re: Opinions on Burp Suite Web App Scanner Oct 19 2011 05:15AM Meenal Mukadam (meenal mukadam gmail com) (1 replies) Re: Opinions on Burp Suite Web App Scanner Oct 21 2011 01:24PM Yiannis Koukouras (ikoukouras gmail com) |
|
Privacy Statement |
<JDerrenbacker (at) kshgs (dot) com [email concealed]> wrote:
> I have budget for a web app vulnerability scanner, and I was wondering if anyone has opinions on the professional version Burp Suite with the scanner option.
> Is the scanner any good? Accurate?
>
> This is the website if anyone doesn't know what it is:
> http://portswigger.net/burp/scanner.html
It is a brilliant tool, well worth the cash compared to the much more
expensive alternatives. The built in scanner is fairly accurate, has a
few problems with LDAP injection false positives but tends to find XSS
and SQLi pretty well.
Robin
>
>
>
> Thanks,
> Jon
>
> ------------------------------------------------------------------------
> This list is sponsored by: Information Assurance Certification Review Board
>
> Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
>
> http://www.iacertification.org
> ------------------------------------------------------------------------
>
>
------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board
Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
http://www.iacertification.org
------------------------------------------------------------------------
[ reply ]