20080925 Thursday September 25, 2008

Rational Appscan do what others cant...

Interesting product. IBM accquired it from Watchfire Corporation, a security and compliance testing software company based in Waltham, Massachusetts.  It appears that Appscan provides Web application security testing and compliance management software and services that help clients evaluate, understand and resolve issues impacting their online businesses. 

The product is very comprehensive in what it can provide:

    •  Established attacks and string based manipulation of URLs to detect vulnerabilities with regard to session hi-jacking, login avoidance, stray pages that don't have any security on them. This includes static AND dynamic testing.

    •  Port scanning for security holes like SQL injection

    •  A comprehensive report on all the exploits it found to work

    •  A recommendation on how to repair / patch these exploits.

Most products / suite of of products on the market do not have the reporting tool which has recommendations. I am usually skeptical of all-in-one products that claim to provide recommendations. Appscan seems to deliver what it promises.

Posted by Gusius Gus in Security at 20080925 Comments[0]

Click me to subscribe
Securing Obscurity
« September 2008
SunMonTueWedThuFriSat
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
26
28
29
30
    
       
Today

Recent Entries