OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Injection attacks in ASPX/ASP.NET applications

From: Romain Gaucher (romain.gauchernist.gov)
Date: Thu Sep 04 2008 - 15:26:42 CDT


Look especially for the source code analyzers and web application
scanners...

Romain

Marco Ivaldi wrote:
> Nikhil,
>
> On Sat, 30 Aug 2008, Nikhil Wagholikar wrote:
>
>> Hello All,
>
> [snip]
>
>> 3. Is there any tool specially developed for finding vulnerabilities
>> in ASP.NET application from penetration testing/vulnerability
>> assessment point of view?
>> 4. Any free tool and thorough methodology, that could help one in
>> doing source code audit/review of ASP.NET (ASPX) application? (I know
>> one tool to be scancode.py)
>
> You may want to take a look at NIST's SAMATE (Software Assurance Metrics
> And Tool Evaluation) project page:
>
> https://samate.nist.gov/index.php/Tools
>
> Hope this helps,
>

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes in
Securing Web Applications
Get 45 Min Video and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------