Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > Vulnerability assessment for OS, XML, web services

Reply
Thread Tools

Vulnerability assessment for OS, XML, web services

 
 
SAD
Guest
Posts: n/a
 
      09-27-2005
This article discusses XML and web services vulnerabilities based on
libraries, operating systems, databases, protocols and so on.

http://www.webservicessummit.com/Vulnerabilities.htm

Can anyone recommend a vulnerability assessment tool that works for a
network with a mix of software and operating systems?

 
Reply With Quote
 
 
 
 
Winged
Guest
Posts: n/a
 
      09-28-2005
SAD wrote:
> This article discusses XML and web services vulnerabilities based on
> libraries, operating systems, databases, protocols and so on.
>
> http://www.webservicessummit.com/Vulnerabilities.htm
>
> Can anyone recommend a vulnerability assessment tool that works for a
> network with a mix of software and operating systems?
>


For general scanning ISS works fairly well for vulnerability assessment,
there are a number of others however ISS has fewer false positives than
others I have worked with. False positives even with ISS can be a pain
in the petute as they too must be examined and ensure that the
vulnerability does not exist. This is much harder than confirming the
existence of a vulnerability. It looks for nix and winx vulnerabilities.

http://www.iss.net/


ISS however does not detect issues with website construction.

For that there are a number of tools however a good start to identify
website application issues however a good start is a tool by Spi
Dynamics called Web Inspect that will identify a number of exploitable
issues with website security irrespective of hosting OS. Note ISS
should also be run in conjunction with webinspect. Webinspect also may
be run against NIX and Winx hosts.

http://www.spidynamics.com/

There are other tools that assist in examining other facets of network
host vulnerability but these will get you 95% where you need to be on
assessment of network vulnerabilities. Without knowing further the
specific facets of what you wish an automated inspection of, I am
limited by space as to recommendations.



Winged


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How .NET web services client handles exceptions from Java web services? John ASP .Net Web Services 4 03-31-2006 10:13 PM
Skill Assessment web site error =?Utf-8?B?U3VyamVldCBHaWxs?= Microsoft Certification 2 11-24-2005 08:47 PM
SharePoint security/vulnerability assessment? Michael Herman \(Parallelspace\) ASP .Net Security 0 11-12-2004 07:03 PM
Vulnerability Assessment Sherman H. Computer Security 2 08-04-2004 02:54 AM
Windows vulnerability assessment tools Cosmic Cruizer Computer Security 3 02-19-2004 01:41 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57