Home > Ask the Software Quality Experts > Application Security Questions & Answers > Open source application security testing tools
Ask The Software Quality Expert: Questions & Answers
EMAIL THIS

Open source application security testing tools

Chris Wysopal EXPERT RESPONSE FROM: Chris Wysopal

Pose a Question
Other Software Quality Categories
Meet all Software Quality Experts
Become an Expert for this site


Software quality news and advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 10 December 2007
What are the famous open source tools for Web application security testing?

>
EXPERT RESPONSE

Some of the popular open source Web proxies are WebScarab, Paros Proxy, and Burp Proxy. These are essentially man-in-the-middle proxies that sit between the Web browser and the Web server and allow the assessor to observe and manipulate the Web traffic.

Security testing tools:
What to look for in a Web application security testing tool

How to evaluate testing software and tools

Free Web application security testing tools you need to get to know

There aren't many open-source automated scanners for Web applications -- that is, things that you just point at a URL and say "scan it." One is Nikto, but it tests mostly for misconfigured Web servers and doesn't really touch the Web application logic itself.

-- Chris Eng, director of security services at Veracode, contributed to this response.


Sound Off! -   Be the first to post a message to Sound Off!


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Application Security
How to prevent anti-DNS pinning attacks
Java application security features and measures
Web application security testing basics
Password recovery with .NET 2.O using C#
Free load and performance testing tools
The most effective time to do security testing
Finding backdoor threats within applications
SPML and SAML enhance application security in different ways
Authentication and authorization for Web applications
How to implement security in Java EE and Java ME

Software security testing tools
Dynamic analysis tool from Coverity looks at concurrency defects
Veracode provides security audits for externally sourced code
The effectiveness of code coverage tools in software testing
Enhanced application protection in Dotfuscator Professional 4.3
Developers get bigger role in software quality, security
Automated testing tools for a payment gateway
Cracking passwords the Web application way
Application security testing goes virtual
BMC uses source code analysis to improve software line
AppScan Web application security scanner enhanced

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts