Home > Security Tips > Security Buyer's Guide > WebInspect Enterprise Edition 4.0
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY BUYER'S GUIDE

WebInspect Enterprise Edition 4.0


Michael D. Rogers
09.29.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


WebInspect Enterprise Edition 4.0
SPI Dynamics
Price: Starts at $4,995 per server

SPI Dynamics' WebInspect 4.0 can assess Web apps for regulatory compliance and scan them against known attack signatures.

WebInspect scans proprietary and commercial Web apps for compliance with enterprise policies and HIPAA, GLBA and Sarbanes-Oxley regulations. The software includes a policy editor and 11 templates, which list government requirements and checks for proper access control, error handling, remote administration flaws, etc. The templates, which can be customized to company content policies, can flag vulnerabilities that would allow unauthorized access to backend databases, for example, to secure credit card numbers by checking for SQL injection vulnerabilities. Web-Inspect provides a wizard for configuring an audit of an app or a set of Web sites.

Of course, WebInspect is also a QA/troubleshooting tool for development and production apps, although scanning live apps consumes bandwidth and causes latency. You select the app server IP address and the type of scan to identify vulnerabilities to common attacks--such as buffer overflows. You can choose various scan methodologies, including site mapping, with and without attack signature audits, and regulation-specific compliance.
More Information

Learn how to secure Web-based applications.

Visit our Web Application Security resource center for news, tips and advice.

SPI Dynamics' WebInspect Enterprise Edition 4.0 scans development apps for security vulnerabilities and regulatory compliance. WebInspect's agents catalog all aspects of the application. They evaluate the data and apply attack signatures and heuristics to determine the presence and severity of vulnerabilities, which are rated according to values assigned by organizations such as CERT. A mouse click updates the database with new assessment methodologies and vulnerability signatures from SPI Dynamics.

WebInspect performed admirably in our scanning of Microsoft- and Linux-based development and production apps. Scans took up to 20 minutes and revealed our misconfigurations and missing patches; we created reports with just a few mouse clicks. You can access templates to create reports by summary, vulnerability and severity levels and graphical site views. You can sort the data by potential risks, such as command injection or path truncation attacks to create reports for specific programmers, auditors, etc.

It also suggests remediation steps, such as not backing up source code in the Web root for correcting 'backup file of source found' vulnerabilities. It includes steps for correcting ColdFusion error messages and fixing known vulnerabilities, such as an Ikonboard arbitrary file source disclosure. It even specifies tips for developer vulnerabilities, such as path parameter file source disclosure. WebInspect integrates with Citadel Software Security's Hercules patch manager to automate vulnerability remediation.

WebInspect's ease of use, depth and breadth of assessments and reporting options make it an essential application security assessment tool and a must-have for any app development toolbox.

About the Author
Michael D. Rogers is a contributor to Information Security magazine.

This review orginally appeared in Information Security magazine.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Application and Platform Security,   Web Security Tools and Best Practices,   Web Application Security,   Security Buyer's Guide,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Web Application Security
Black box and white box testing: Which is best?
InZero Systems launches hardware-based security gateway
Web application vulnerability assessment shows patching progress
Preventing SQL injection attacks: A network admin's perspective
Cisco acquires SaaS security vendor ScanSafe
Web application firewall use goes beyond compliance, company finds
Gumblar Trojan drive-by exploits spike following Adobe update
Some Facebook applications lead to Russian attack sites
Barracuda acquires Purewire expanding Web security reach
An enterprise strategy for Web application security threats

Security Buyer's Guide
Keystroke dynamics makes BioPassword Internet Edition a viable authentication option
Access security with KoolSpan's SecurEdge
NetChk Protect 5.5
Biometrics: Best practices, future trends
2006 Products of the Year: Emerging Technologies
Secure Sphere 2.0
Scan & Deliver: SLAs force service providers and outsources to hit the mark ... or hit the road
Secure remote access: SSH Tectia Manager
Spycatcher Enterprise 3.2
Configuresoft's Enterprise Configuration Manager v4.7

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
anonymous Web surfing  (SearchSecurity.com)
buffer overflow  (SearchSecurity.com)
cache cramming  (SearchSecurity.com)
cookie poisoning  (SearchSecurity.com)
dictionary attack  (SearchSecurity.com)
distributed denial-of-service attack  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
National Computer Security Center  (SearchSecurity.com)
threat modeling  (SearchSecurity.com)
trigraph  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts