Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Rolling Review: Cenzic's Hailstorm Enterprise Application Risk Controller: Page 3 of 5

Cenzic has an open-signature format, with all existing signatures visible and written in JavaScript--a language any Web application assessment professional certainly should understand. Hailstorm doesn't have the slick extensions we found in SPI Dynamics' WebInspect 7.0--the first product in this Rolling Review--nor is its interface nearly as usable and pretty. But it was much more accurate in identifying vulnerabilities in our sample applications. It suffered fewer false positives and no false negatives (unless later scanners find new vulnerabilities).

In addition, though Hailstorm couldn't automatically spider our Ajax application, much as WebInspect failed to do, it did learn the site when we manually walked it through the application, a feat WebInspect could not manage.

Unfortunately, Hailstorm found no vulnerabilities after the scan. Is the result of a relatively small application that is simply well-written, or did Hailstorm miss faults? That will be obvious by the end of this Rolling Review series. Stay tuned.

Continue Reading This Story...

NWC ANALYTICS

bulletHost Intrusion Prevention
How does host IPS compare with traditional anti-virus solutions? What's the difference between network IPS and host IPS? These questions and more are answered in this in-depth Analytics Tech Report.

Don't Hate Me Because I'm Cramped