Presentation is loading. Please wait.

Presentation is loading. Please wait.

 Chirita Ionel  Application Security  OWASP Chapter board member.

Similar presentations


Presentation on theme: " Chirita Ionel  Application Security  OWASP Chapter board member."— Presentation transcript:

1

2  Chirita Ionel  Application Security Analyst @  OWASP Chapter board member

3  Wide Coverage  Fast scans  Low number of false positives  Low number of false negatives  Scalability  Easy to use  Permanent vulnerability database updates  To be Cheap !?

4  Hardware Requirements & support  Protocol support  Authentication  Session management  Crawling  Data Parsing  Testing  Command and control  Reporting

5  Thick client vs cloud

6 Transport support  HTTP1.0 & HTTP1.1  SSL/TLS  HTTP keep alive  HTTP compression  HTTP user agent configuration Proxy support  HTTP1.0 & HTTP1.1 proxy  Socks 4 proxy  Socks 5 proxy  PAC file support

7  Basic  Digest  HTTP negotiate – NTLM & Kerberos  Html form-based  Automated  Scripted  Non-automated  Single sign on  Client SSL certificates  Other

8  Session management capabilities  Start a new session  Detect if the session is expired  Reacquire session token  Session management token type support  HTTP cookies  HTTP parameters  HTTP URL path  Session token detection  Session token refresh policy

9  Define starting URL  Define additional hostname or exclusions for specific criteria  Support automated from submission  Detect error pages and custom 404 pages  Redirect support

10  HTML  JavaScript  VBScript  XML  Plaintext  ActiveX Objects  Flash

11

12  Schedule scans  Pause / resume  Real-time status of running scans  Run multiple scans simultaneously  GUI, CLI and web based interface  Extensibility & interoperability

13  Executive summary  Technical detailed report  Delta reports  Compliance report  Customization  Report data file format

14  Why do you mean by “best” ?  Or the cheapest ?

15  By Larry Suto

16  … running each vendor's scanner against each of the vendor's test sites and comparing the results

17

18

19  By Chirita Ionel

20

21

22

23

24


Download ppt " Chirita Ionel  Application Security  OWASP Chapter board member."

Similar presentations


Ads by Google