4 ms·
Any details on this ? : "After getting permission to use a tool we here at the ASC lovingly refer to as the SQL Injector" What's the tool ?
by cake 17y ago
Any details on this ? : "After getting permission to use a tool we here at the ASC lovingly refer to as the SQL Injector"
What's the tool ?
- PonyGumbo 17y agoI'd love to know this too. Edit: looks like Webinspect: https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&cp=1-11-201-200^9570_4000_100__ https://h10078.www1.hp.com/cda/hpms/display/main/hpms_conten...
- fragmede 17y agoWebInspect looks interesting, but for this usage, does it actually offer anything above Metasploit? (The marketing copy for it doesn't give much detail, though it does claim you can use this for hipaa compliance, among other things https://h10078.www1.hp.com/cda/hpdc/fetchPDF.do https://h10078.www1.hp.com/cda/hpdc/fetchPDF.do)
- tptacek 17y agoYes. Metasploit is a delivery vehicle for known exploits, principally for non-web applications. It's not designed to find new web vulnerabilities. WebInspect is a web application scanner. It includes a not-very-useful database of known application vulnerabilities, but also has a well-regarded fuzzer that generates random scary inputs to every input it finds on a site that it spiders. That's what Raf is talking about (his job is, in part, to promote that very expensive tool). You don't want WebInspect, or AppScan, or any other scanner. If you're a professional, you want Burp Suite, which costs something like EU120 and does just as good a job as a fuzzer as WebInspect. If you're a hobbyist, you want OWASP WebScarab, which is free. Both are Java apps, and will run anywhere Java does.