4 ms·
oh, ok, that makes it a lot more clear. thanks! If I were you I would consider a model where I would be to do a full scan, display only the top X vulnerabiliti
by jenandre 14y ago
oh, ok, that makes it a lot more clear. thanks!
If I were you I would consider a model where I would be to do a full scan, display only the top X vulnerabilities found, and simply charge more to show the rest of the results.
Another thing I'm curious about: does this work on a pure client-side web application (e.g. my app is just one html page + javascript that loads all the html from templates)? Are you including static urls or somehow tracking "clicks" into a web app? Actually, most of the things I would concerned about in my web applications are things like not validating that I'm correctly doing correct validation in POST-requests. I'd be interested in seeing if you guys are doing that kind of "fuzzing" in that respect (though not sure if there is an automated way to do that safely). Additionally, I'd be curious to see what you detect Nessus/BurpSuite etc doesn't in terms of web application security.
Anyway, neat idea, perhaps I'll check it out a bit more thoroughly and do a comparison.
- ainsleyb 14y agoWe've done some tests, and many of our customers would much rather have a basic scan and see the full results of the scan, than only be shown a piece of the scan. It gives off the impression that we're holding their vulnerabilities hostage, and that's definitely not what we hope to do! The best test to see how we differ from Nessus/Burp is to try it yourself! A lot of the vulnerability classes we scan for are very similar, but the ways in which we scan for them are different. We do offer our Standard Plan for a free 30 day trial. Would love to hear what you think :) If you have any issues, ping us at http://tinfoilsecurity.com/supportchat http://tinfoilsecurity.com/supportchat