Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

RE: Creating API for SSS & Appscan

Subject: RE: Creating API for SSS & Appscan
Date: Fri, 25 May 2007 09:04:01 +0300
Hi Vivek,

You should check out AppScan's eXtensions Framework & SDK at
http://axf.watchfire.com - it will allow you to create more types of
integrations that just simple APIs. You can also download the complete
SDK documentation from that site.

Thanks,
-Ory Segal
Watchfire

 

-----Original Message-----
From: listbounce@securityfocus.com 
[mailto:listbounce@securityfocus.com] On Behalf Of Vivek P
Sent: Thursday, May 24, 2007 11:31 AM
To: Pen-Testing; security-basics@securityfocus.com; 
webappsec@securityfocus.com
Subject: Creating API for SSS & Appscan

Hi to all @securityfocus

I am on look out for some solutions to automate and imrove 
pentesting setup of mine, i use an array of tools & alot of 
internal domains to test atleast 10000 of them. I use SSS, 
Appscan etc for that.

I had a logical solution to make things simple by developing 
an API so that i can run tools like pentest -sss.exe 
-appscan.exe --www.targetsite.com /all options... or 
something like that

I would like to get help on topics

 a) some API's that are available for sss (related documentations)
 b) some API for appscan (or related documentations)
 c) some peek into tools that can sniff queries done from 
core of these testing tools to the kernel (so that i can duplicate the
replies)

This is just a research level discussion. Please reply with 
your valuable suggestions.


thanx for your time..
--
Vivek P Nair
Vice President, Technology
ASG
www.vivekpnair.co.nr
iamherevivek@gmail.com
vivek.p.nair@appingroup.com
d3@d Br@iN
"i thought i would change the world, But they wouldnt gimme 
the source Code !!"

--------------------------------------------------------------
----------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic See HOW Now with 
our 20/20 program!

http://www.cenzic.com/c/2020
--------------------------------------------------------------
----------



<Prev in Thread] Current Thread [Next in Thread>