Skip to main content

What is WebInspect ?




Image result for WebInspect
WebInspect is a web application security scanning tool offered by HP.
It helps the security professionals to assess the potential security flaws in the web application.
WebInspect is basically a dynamic black box testing tool which detects the vulnerabilities by actually performing the attack.
After initiating the scan on a web application, there are assessment agents that work on different areas of the application.
They report their results to security engine which evaluates the results.
It uses Audit engines to attack the application and determine the vulnerabilities.
At the end of the scan you can generate a report called ‘Vulnerability Assessment Report’ which would list the security issues in desired format.
Using this report, client can fix the issues and then go for validation scanning to confirm the same.
HP WebInspect is a commercial tool and you need license to scan a web site.
With the trail version you will be permitted to scan only zero.webappsecurity.com (HP demo site).
So WebInspect basically comes into picture when the application is hosted in some environment (test/QA/production).
As with every other tool there are both advantages and disadvantages associated with using WebInspect.
  Advantages:
  Saves time when dealing with large enterprise applications
Simulates the attack, shows the results and presents you with a comprehensive view.
It is not dependent on the underlying language.
  Disadvantages:
  It’s hard for any tool to find logical flaws, weak cryptographic storage, severity of the disclosed information etc.
It has a list of payloads that it uses on every web application.
It does not use any wisdom in generating payloads depending on the type of application.
There could be false positives among the listed vulnerabilities.
  _________________________

Comments

Popular posts from this blog

HOW TO BYPASS OR UNBLOCK BLOCKED SITES:-

Today everyone of us is a part of any college,office or any organization. Everywhere we find free open wifi’s , but the major problem with these are there are many websites which are blocked by the servers of college,ofiice or any organization. There are different type of securities that are implemented in these server to block some sites like Facebook ,Twitter etc. So In this post i’ll tell you easy and permanent method to access or bypass blocked sites Steps To Bypass Blocked Sites-   1. Connect your pc or laptop with wifi or your broadband connection in which you want to access blocked websites.   2. Open command prompt by clicking start and the typing “cmd” and then pressing enter.   4. 3. Now a command prompt window will appear.   5. Type ping Websitename (for exp: ping http://facebook.com) and press enter.   6. Now open your browser and enter the site which you had recently ping.   7.You will see the site will get...

How Hackers Look Like and What They Think?

Self-educated hackers are more respected in hacker’s community because that person is really interested in hacking and he passed a lot of things that are not teached in schools and college. The most common things hackers do is computers electrical engineering, physics, mathematics, linguistics and philosophy. However, like every developer is not the hacker, hackers do not always have the skills of programming, but someone of them have. :) Clothing styles: Hackers dress simply, casually: jeans, T-shirt and shoes. T-shirts are usually with some humorous slogans. today there are T-shirts with pictures of Penguin (trademark Linux) or daemon (BSD). A small number of hackers prefers hiking boots. This prefer wearing of black clothes. Hackers care more about comfort, practicality and ease of maintenance of clothes. They hate business suits. OTHER INTERESTS: Hobbies that hackers do are widespread. Mostly they like science fiction, music, medievalism, chess, war games and intel...

What is Pendrive Hacking ?

Windows allows the storage of the passwords, as do modern browsers. While this feature is convenient for users, it has imposed itself as a big security risk among organizations. We know that browsers store most passwords on daily basis, like MSN messenger, Yahoo, Facebook passwords, etc. Most people lack time and ask their browsers to save their passwords. As we know, there are many tools available to recover saved passwords, so in this article I will explain to you how to make a USB password stealer and steal saved passwords. Just to explain the concept, we are going to collect some password stealing tools, tools that are freely available on the internet and capable of stealing the passwords stored in the browsers or other windows files. Then, we create a batch program that will execute these combined programs and store the stolen usernames and passwords in a text file. To further spice up the penetration testing demonstration, we will also make this batch file execute as an...