pen-test
[Top] [All Lists]

Re: Vulnerability Assessment

To: "Deepak Parashar" <deep231982@gmail.com>, "Uzair Hashmi" <uzair@kse.com.pk>
Subject: Re: Vulnerability Assessment
From: jfvanmeter@comcast.net
Date: Tue, 24 Jul 2007 08:31:31 +0000
Cc: listbounce@securityfocus.com, pen-test@securityfocus.com, security-basics@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Resent-date: Tue, 24 Jul 2007 02:59:13 -0600 (MDT)
Resent-from: pen-test-return-1078484680@securityfocus.com
Resent-message-id: <20070724085913.85216237124@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
My two shiny centvos --- I would use Nessus, its free, there is a port to 
Windows, you can write you own plugins, I've seen tenable fix fail postives in 
a day, if you want to pay for the plug in feed its only 1200 dollars US. if you 
pay for the plugin feed you can use the compliance checks, Tenable has pre 
configured checks you can download or you can write them yourself. 

check it out, www.nessus.org

I'm not a employee of Tenable Security, I've tried all of the others... 
Foundscan, retina, ISS, Satan, Saint, etc and I still personnel like Nessus. 
 -------------- Original message ----------------------
From: "Deepak Parashar" <deep231982@gmail.com>
> Uzair,
> 
> I would to say to go for Foundstone-I have worked on this solution for
> long and it's really good product for vuln. assessment if designed
> correctly and have good reporting feature as well, it'll give you
> options to drill down to dll versions and gives you liberty to create
> your own tests as well........... other best option would be
> Retina....
> 
> -DP
> 
> http://www.linkedin.com/in/deepakparashar
> 
> http://deepakparashar.blogspot.com/
> 
> "Vision is the art of seeing the invisible"...Jonathan Swift
> 
> 
> On 6/4/07, Uzair Hashmi <uzair@kse.com.pk> wrote:
> > Hello list,
> >
> > I have been evaluating an automated vulnerability assessment software, have 
> found two of them better for the organizational needs. I need your help to 
> select only one out of the two.
> >
> > 1- QualysGuard (http://www.qualys.com)
> > 2- Foundstone Enterprise 
> (http://www.mcafee.com/us/enterprise/products/vulnerability_management/foundston
> e_enterprise.html)
> >
> > Please advice.
> >
> > Regards,
> > Uzair
> >
> >
> > ------------------------------------------------------------------------
> > This List Sponsored by: Cenzic
> >
> > Are you using SPI, Watchfire or WhiteHat?
> > Consider getting clear vision with Cenzic
> > See HOW Now with our 20/20 program!
> >
> > http://www.cenzic.com/c/2020
> > ------------------------------------------------------------------------
> >
> >
> 
> ------------------------------------------------------------------------
> This list is sponsored by: Cenzic
> 
> Need to secure your web apps NOW?
> Cenzic finds more, "real" vulnerabilities fast.
> Click to try it, buy it or download a solution FREE today!
> 
> http://www.cenzic.com/downloads
> ------------------------------------------------------------------------
> 


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>