WebInspect Enterprise Edition 4.0
Price: Starts at $4,995 per server
SPI Dynamics' WebInspect 4.0 can assess Web apps for regulatory compliance and scan them against known attack signatures.
WebInspect scans proprietary
Of course, WebInspect is also a QA/troubleshooting tool for development and production apps, although scanning live apps consumes bandwidth and causes latency. You select the app server IP address and the type of scan to identify vulnerabilities to common attacks--such as buffer overflows. You can choose various scan methodologies, including site mapping, with and without attack signature audits, and regulation-specific compliance.
SPI Dynamics' WebInspect Enterprise Edition 4.0 scans development apps for security vulnerabilities and regulatory compliance. WebInspect's agents catalog all aspects of the application. They evaluate the data and apply attack signatures and heuristics to determine the presence and severity of vulnerabilities, which are rated according to values assigned by organizations such as CERT. A mouse click updates the database with new assessment methodologies and vulnerability signatures from SPI Dynamics.
WebInspect performed admirably in our scanning of Microsoft- and Linux-based development and production apps. Scans took up to 20 minutes and revealed our misconfigurations and missing patches; we created reports with just a few mouse clicks. You can access templates to create reports by summary, vulnerability and severity levels and graphical site views. You can sort the data by potential risks, such as command injection or path truncation attacks to create reports for specific programmers, auditors, etc.
It also suggests remediation steps, such as not backing up source code in the Web root for correcting 'backup file of source found' vulnerabilities. It includes steps for correcting ColdFusion error messages and fixing known vulnerabilities, such as an Ikonboard arbitrary file source disclosure. It even specifies tips for developer vulnerabilities, such as path parameter file source disclosure. WebInspect integrates with Citadel Software Security's Hercules patch manager to automate vulnerability remediation.
WebInspect's ease of use, depth and breadth of assessments and reporting options make it an essential application security assessment tool and a must-have for any app development toolbox.
About the Author
Michael D. Rogers is a contributor to Information Security magazine.
This was first published in August 2005