Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

Re: Vulnerability Assessment

Subject: Re: Vulnerability Assessment
Date: Mon, 23 Jul 2007 20:18:17 -0400
I have used them all extensively and would highly recommend that you
use Foundstone and Nessus.   Additionally one lesser known tool worth
mentioning is Harris Guardian.   I have never been a fan of Qualys,
especially when I do third party assessments and find stuff that they
miss.  They also used to require that all external data be stored on
their network which is a security vulnerability in itself.

Whoever said that Qualys has the checks a week before everyone else..
yeah they all claim to do that.  I know of many fortune 100 companies
along with full state and even federal governments that rely solely on
Foundstone.  I can make claims all day long, but ultimately it does
not matter.

With that said, these days they all are getting closer and closer with
their functionality.   The best advice that anyone *should* give you
is to do a proof of concept and compare them side by side against the
same test systems.   This will determine which is currently better for
YOUR environment.

Also, while checking out Foundstone be sure to look at Preventsys
which McAfee bought as well.  Coupled together the two tools meet a
LOT of security departments needs for compliance and auditing.

Good Luck!

On 7/23/07, Deepak Parashar <deep231982@gmail.com> wrote:
Uzair,

I would to say to go for Foundstone-I have worked on this solution for
long and it's really good product for vuln. assessment if designed
correctly and have good reporting feature as well, it'll give you
options to drill down to dll versions and gives you liberty to create
your own tests as well........... other best option would be
Retina....

-DP

http://www.linkedin.com/in/deepakparashar

http://deepakparashar.blogspot.com/

"Vision is the art of seeing the invisible"...Jonathan Swift


On 6/4/07, Uzair Hashmi <uzair@kse.com.pk> wrote: > Hello list, > > I have been evaluating an automated vulnerability assessment software, have found two of them better for the organizational needs. I need your help to select only one out of the two. > > 1- QualysGuard (http://www.qualys.com) > 2- Foundstone Enterprise (http://www.mcafee.com/us/enterprise/products/vulnerability_management/foundstone_enterprise.html) > > Please advice. > > Regards, > Uzair > > > ------------------------------------------------------------------------ > This List Sponsored by: Cenzic > > Are you using SPI, Watchfire or WhiteHat? > Consider getting clear vision with Cenzic > See HOW Now with our 20/20 program! > > http://www.cenzic.com/c/2020 > ------------------------------------------------------------------------ > >

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



------------------------------------------------------------------------ This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>