Vulnerability assessment for OS, XML, web services

Vulnerability assessment for OS, XML, web services

Secure Home | Search | About
 Computer Software Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Vulnerability assessment for OS, XML, web services SAD 09-27-2005
Posted by SAD on September 27, 2005, 11:16 am
If you were  Registered and logged in, you could reply and use other advanced thread options
This article discusses XML and web services vulnerabilities based on
libraries, operating systems, databases, protocols and so on.

http://www.webservicessummit.com/Vulnerabilities.htm

Can anyone recommend a vulnerability assessment tool that works for a
network with a mix of software and operating systems?



Posted by Winged on September 28, 2005, 1:38 am
If you were  Registered and logged in, you could reply and use other advanced thread options
SAD wrote:
> This article discusses XML and web services vulnerabilities based on
> libraries, operating systems, databases, protocols and so on.
>
> http://www.webservicessummit.com/Vulnerabilities.htm
>
> Can anyone recommend a vulnerability assessment tool that works for a
> network with a mix of software and operating systems?
>

For general scanning ISS works fairly well for vulnerability assessment,
there are a number of others however ISS has fewer false positives than
others I have worked with. False positives even with ISS can be a pain
in the petute as they too must be examined and ensure that the
vulnerability does not exist. This is much harder than confirming the
existence of a vulnerability. It looks for nix and winx vulnerabilities.

http://www.iss.net/


ISS however does not detect issues with website construction.

For that there are a number of tools however a good start to identify
website application issues however a good start is a tool by Spi
Dynamics called Web Inspect that will identify a number of exploitable
issues with website security irrespective of hosting OS. Note ISS
should also be run in conjunction with webinspect. Webinspect also may
be run against NIX and Winx hosts.

http://www.spidynamics.com/

There are other tools that assist in examining other facets of network
host vulnerability but these will get you 95% where you need to be on
assessment of network vulnerabilities. Without knowing further the
specific facets of what you wish an automated inspection of, I am
limited by space as to recommendations.



Winged




Similar ThreadsPosted
sp800-26 NIST self assessment test June 7, 2005, 3:15 pm
Looking for Face capture and image quality assessment SDK March 29, 2006, 4:37 am
TPM and Windows Vista TPM Services December 29, 2006, 5:40 pm
Is it Illegal to offer concealment services? August 13, 2007, 9:23 am
Is Someone Reading My E-mails? How secure are BT online services? October 28, 2006, 3:01 pm
Cisco IPv6 Vulnerability August 1, 2005, 6:23 pm
National Vulnerability Database August 16, 2005, 6:55 pm
Has anyone heard of this MS Word vulnerability June 3, 2008, 9:40 am
Snort vulnerability "wormable" but not widespread October 20, 2005, 11:51 pm
WMF Vulnerability patch for win98 etc., REALTIME LOG January 5, 2006, 1:50 pm

The site map in XML format XML site map

Contact Us | Privacy Policy