Re: Vulnerability and Penetration testing software

From: Alice Bryson (abryson@bytefocus.com)
Date: Wed Apr 12 2006 - 03:59:34 EDT


hi there
    i am engaged in developping vulnerability and penetration testing
products for 3 years. i would say that the best penetration testing
tools is CANVAS and Core Impact. Metesploit is a free version of pen
test tool, which i feel complex to use.

    Nessus is, should say 'was' here, an open source vulnerability
scanner, it functional as a security audit tool. The feature of it i
think would be: an very large vulnerability signature database. but
not all of the signature have good quailty.

    There are a lot of commercial product of vulnerability scanner.
SAINT, ISS scanner, FortiAnalyzer for Fortinet and etc.

2006/4/11, Sherita <sherita_m@hotmail.com>:
> Hi
>
> I would like to get some feedback from those who have had lots of security
> experience about the best security vulnerability and penetration testing
> products or software out there.
>
> Thanks
> Sherita
>
> ------------------------------------------------------------------------------
> This List Sponsored by: Cenzic
>
> Concerned about Web Application Security?
> Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
> Choice Award from eWeek. As attacks through web applications continue to rise,
> you need to proactively protect your applications from hackers. Cenzic has the
> most comprehensive solutions to meet your application security penetration
> testing and vulnerability management needs. You have an option to go with a
> managed service (Cenzic ClickToSecure) or an enterprise software
> (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
> help you: http://www.cenzic.com/news_events/wpappsec.php
> And, now for a limited time we can do a FREE audit for you to confirm your
> results from other product. Contact us at request@cenzic.com for details.
> ------------------------------------------------------------------------------
>
>

--
http://www.lwang.org
lwang.org provides online base64 encode and decode, crc32 md5 and sha1
hashing, online ciphers, encryption and decryption. We are engaged in
adding more common use lookup service.
We collect spam for research at abryson@bytefocus.com
------------------------------------------------------------------------------
This List Sponsored by: Cenzic
Concerned about Web Application Security? 
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's 
Choice Award from eWeek. As attacks through web applications continue to rise, 
you need to proactively protect your applications from hackers. Cenzic has the 
most comprehensive solutions to meet your application security penetration 
testing and vulnerability management needs. You have an option to go with a 
managed service (Cenzic ClickToSecure) or an enterprise software 
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can 
help you: http://www.cenzic.com/news_events/wpappsec.php 
And, now for a limited time we can do a FREE audit for you to confirm your 
results from other product. Contact us at request@cenzic.com for details.
------------------------------------------------------------------------------


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:55:49 EDT