Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

Email Email  Print  Share


Rolling Review: Acunetix Finishes Strong

Tags: , , , , , , , , ,

Channel: Data Protection

The Upshot

Claim
Web application scanners in this Rolling Review must not only find traditional vulnerabilities, like XSS and SQL injection flaws, but also handle Ajax applications, in which part of the app is running locally in the browser.
Context
Complex Ajax apps represent a new twist for these products, and we don't recommend purchasing a scanner that isn't able to handle Web 2.0 environments, given that so much future development is moving in that direction. And, Web application scanners should be just one element in a comprehensive, layered program—educating developers and integrating security reviews into the development lifecycle are just as crucial.
Credibility
Acunetix puts together a complete package that escapes most of the flaws and bugs other products were tripped up by. It's not superlative in anything, but it also doesn't have any big weaknesses. Its Ajax support was better than some, but still doesn't meet our standards.

Acunetix Ltd. Web Vulnerability Scanner

If there's such a thing as seminars on product naming, marketing managers for N-Stalker's Web Application Security Scanner 2006 Enterprise Edition and Acunetix's Web Vulnerability Scanner Enterprise must have attended the same session. Fortunately for Acunetix, a descriptive name is where the similarities end. While N-Stalker did not fare well in this Rolling Review, Acunetix topped off a nearly trouble-free experience with a full feature set and accurate findings.

We found WVS the smoothest, easiest to use Web application scanner in this Rolling Review series. Almost everything worked exactly as it should, with no fiddling of options or calls to support required. This is a surprisingly rare occurrence but one that we as reviewers welcome—and not only because it saves us work. More importantly, we know our readers will have a good experience. There's nothing like buying an expensive piece of software only to feel like you're paying for the privilege of beta testing.

Of course, there's more to scoring well in a review than avoiding interface bugs and configuration quirks and catching the (relatively) simple vulnerabilities in our sample applications. Our requirements also include the ability to expose advanced features and capabilities for users who have the know-how to really dig deep into an application. WVS is not quite the most flexible or powerful product in the group in that regard, but it compares well. With the expected set of built-in utilities (HTTP Request Editor, Fuzzer, Password Brute force tool and more), WVS is missing only a few of the flashier features of the most extensible products.

This article is part of NWC's Rolling Review of Web Applications Scanners. Click on that link to go to the Rolling Reviews home page to read all the features and reviews now.


Page:  1 | 2 |3 |4 |5 |Next Page »

Related Reading


More data-protection Insights



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers