Web Application Security Testing

Posted on by Blogbugger

For web application security testing Automated & Manual both approaches need to be applied. There are plenty of automated security testing tools available open source as well as commercial. Here in this article I will be discussing about some of the automated security testing tools which I have used recently.

Selection of the security testing tool was not so easy; even though there are hundreds of tools available I was looking for one which is reliable, well known, and having good and detailed report generating capabilities.

Finally I landed upon selecting Acunetix Web Security Scanner, Shadow Security Scanner, IBM Rational AppScan, Syhunt Collapse, and N-Stalker web application security.

All of them give almost the same results; there was the major variation in the results given by Acunetix. It provides the feature for recording user logins in online forms as well as http authentications. Runs very fast as to compare with the other tools. The results were not so complicated; it generates cool reports will all details. While analyzing the results the most helpful feature I found was the capability of showing “HTML Response”; Acunetix scanner shows the attack details as well as corresponding HTML Response in the same place; that helps a lot to understand what exactly happened during the scan. I give 9/10 to this software; the only problem I faced with this software is it crashed or handed my system couple of times.

IBM Rational AppScan looks good..! Yes it only looks good. It also provides the feature for recording user logins in online forms as well as http authentications. I saved the scanning profile on one computer and tried to run it again on another system it simply displayed the “Visual Studio debugger” and application stopped responding. I guess this is the bug with the release which I was using. This application runs very slow; it displays the splash screen for almost half a minute, especially when there is antivirus installed on the computer. It has an update features; it’s a different executable which runs at the program startup. Having separate ugly window for update only feels annoying.There is one feature given under the “Scan” is “Explore Only” means the program crawls the application under test and generates the results so called as “Recommendations” by “Evaluation Scan” which are scan configuration related. It’s simply eats up most of the time; once the recommendations are applied the scan starts again and the most irritating moment comes – it shows the “visual studio error” again and again after this there no way to use this application. It means you will have to wait for a comparatively longer time to see the actual scan results. I will give 4/10 for this application.

Using N-Stalker is all together a different experience; the program actually makes you feel of being part of the SDLC. The first screen of the scan wizard itself shows the phases where an application security testing has to be done or supposed to be done; select the desired phase and continue. It has a very strong report generation and analysis capability. Browser view of crawled web pages can be seen at runtime. Also, the identified vulnerability details can be seen as it is traced. Problem is it does not provide any feature to record user logins to online forms. Will give 8/10 to this software.

Syhunt Collapse and Shadow Security Scanner are good for Web Host Scans does not give any feature to record user logins. It generates good reports but the GUI needs to be improved. The software is not much user friendly would say not for beginners. An advanced user can get what he wants from this Shadow Security Scanner. For the technical details, attack database and execution speed will give 7/10 to both of these applications.

Why I think PayDotCom is the Best Affiliate Marketplace on the Net!

Posted on by Blogbugger

Blogger Labels: , , , If you are familiar with Clickbank.com (R), or even if you are not but you want to make profits online, then you will want to check this out ASAP ...

While I like Clickbank, and they are a great marketplace... they are limited to many restrictions to sell products or earn affiliate commissions...

Well, there is a GREAT NEW SERVICE now...

It is a new FREE marketplace where you can sell any product you want.

Yours OWN product...

- OR - (the best part)
You can become an INSTANT Affiliate for ANY item in their HUGE marketplace.

It is called PayDotCom.com!

Did I mention it is 100% FREE to Join!

This site is going to KILL all other marketplaces and I by now, almost EVERY SINGLE SERIOUS online marketer has an account with PayDotCom.com

So get yours now and see how much they offer...


OH! - Also, they have their won affiliate program now that pays you COLD HARD cash just for sharing the site with people like I am doing with you...

They give you cool tools like BLOG WIDGETS, and they even have an advertising program to help you get traffic to your site.

If you want an ARMY of affiliates to sell your products for you, they also allow you to have Free placement in their marketplace!

Even better... If your product becomes one of the Top 25 products in its category in the marketplace (not that hard to do)...

...then you will get Free advertising on the Blog Widget which is syndicated on THOUSANDS of sites World Wide and get Millions of impressions per month.

So, what are you waiting for...

PayDotCom.com ROCKS!

Get your FREE account now...

http://paydotcom.net/?affiliate=428178

Thanks,

Sandeep Manikrao Maske

P.S. - Make sure to get your Account NOW while it is Free to join.