Welcome To Tools Directory - 2010

 
QA Inspect
About Tool:
Incorporate fully automated web application security testing into the overall test management process. Now, Mercury users can conduct and manage both functional testing and security testing from a single platform.
Additional Information
HP QAInspect lets you conduct and manage functional testing and website security testing from a single platform without the need for specialized security knowledge. It features deep and intuitive integrations, helping you test web applications for security without leaving the QA environment.
HP QAInspect finds and prioritizes website security vulnerabilities in a web application and presents detailed information and remediation advice for each vulnerability. With this software, you can incorporate fully automated website security testing into the overall test management process without affecting aggressive product release schedules.

Company Overview and Contact:

Hewlett-Packard Company
3000 Hanover Street
Palo Alto, CA 94304-1185 USA
Phone: (650) 857-1501
Fax: (650) 857-5518


Nessus
About Tool:
It is a remote security scanner for Linux, BSD, Solaris, and other Unices. Nessus is plug-in-based, has a GTK interface, and performs over 1200 remote security checks. It allows for reports to be generated in HTML, XML, LaTeX, and ASCII text, and suggests solutions for security problems.
Additional Information:
Tenable Network Security provides a suite of solutions which unify real-time vulnerability, event and compliance monitoring into a single, role-based, interface for administrators, auditors and risk managers to evaluate, communicate and report needed information for effective decision making and systems management.

The suite of products described in this section enables our customers to leverage the benefits of the Unified Security Monitoring strategy.
Company Overview and Contact:

Tenable Network Security, Inc. (Tenable) is a US-based Delaware C Corporation. Tenable’s corporate offices are located in Columbia, Maryland with additional offices in New England, California , Virginia , Pennsylvania , and Georgia . Tenable was founded in September of 2002 and is privately owned. Tenable has hundreds of Global 2000 customers in the US , Canada , Asia Pacific, and Europe .

Tenable Network Security, Inc.
7063 Columbia Gateway Drive
Suite 100

Columbia, MD 21046

Email: sales@tenablesecurity.com
         support@tenablesecurity.com
Phone: 14108720555

Web Vulnerability Scanner
About Tool:
Web site security testing tool from Acunetix first identifies web servers from a particular IP or IP range. It then crawls entire site, gathering information about every file it finds, and displaying website structure. After this discovery stage, it performs an automatic audit for common security issues. Applications utilizing CGI, PHP, ASP, ASP.NET can all be tested for vulnerabilities such as cross site scripting, SQL injection, CRLF injection, code execution, directory traversal and more.
Additional Information:
Web site security and compliance should be a top priority for organizations intent on protecting sensitive company, customer, and employee data, on meeting regulatory and corporate compliance requirements, and on defending against the high cost of a data breach. Web sites and their applications are high-focus targets for hackers because they provide a direct route to corporate or personal data regardless of network security implementations.

IBM provides Rational AppScan and Rational Policy Tester, scanning and testing solutions that automate application and content analysis to help organizations identify vulnerabilities, to assess compliance requirements, and to improve the accuracy and reliability of online systems.
Company Overview and Contact:
Contact IBM

http://www.ibm.com/contact/us/

Codenomicon Test Tool
About Tool:
Codenomicon test tools are used for robustness testing, security assessment, software development, risk analysis, purchase criteria and acceptance testing. Codenomicon tools test implementations using black-box testing methods. Proactive flaw discovery introduces tremendous cost savings for our customers and promotes reliability and responsibility.
Additional Information:
  • Codenomicon DEFENSICS enables companies to preemptively mitigate unknown and published threats in products and services prior to release or deployment - before systems are exposed, outages occur and zero-day attacks strike.

  • DEFENSICS offers unparalleled blackbox, negative testing against the broadest set of applications; spanning over 130 Internet, wireless and digital media protocols.

  • Unlike code analyzers and after-the-fact vulnerability scanners, the DEFENSICS platform empowers developers and security analysts to rapidly extend rigorous robustness and vulnerability tests at the protocol-level to identify and resolve issues that can result in reputation, quality, compliance and liability risks.

  • Discover how our award-winning preemptive robustness and security test platform is helping software developers, carriers and enterprises around the world extend quality assurance and protect their systems, services and sensitive data from zero-day attacks and availability exposures.

Company Overview and Contact:

Headquartered in Oulu, Finland , with offices in Silicon Valley and Hong Kong , the company markets its testing software and services directly and through international partners. Codenomicon’s customers include Adobe, Alcatel-Lucent, AT&T, Cisco Systems, F5 Networks, Nordea, Nortel, Microsoft and Siemens AG among many others. The company is privately held with investments from Eqvitec Partners and Prime Technology Ventures.

Codenomicon Ltd. (Headquarters)
Tutkijantie 4E
FIN-90570
OULU
FINLAND

Tel. +358 424 7431 (international)
Tel. 0424 7431 (inside
Finland )

Fax: +358 8 340 141 (international)
Fax: 08 340 141 (inside
Finland )

Email: sales@codenomicon.com

 


Sara

About Tool:

It is a comprehensive network security scanner that discovers, analyzes, and reports on security vulnerabilities of network-based computers, server, routers, and firewalls.

 

Additional Information:

The Security Auditor's Research Assistant (SARA) is a third generation network

security analysis tool that is:

Operates under UNIX, Linux, MAC OS/X or Windows (through coLinux) OS'.Integrates the National Vulnerability Database (NVD).Performs SQL injection tests. Performs exhaustive XSS tests can adapt to many firewalled environments. Support remote self scan and API facilities. Used for CIS benchmark initiatives. Plug-in facility for third party apps. CVE standards support. Enterprise search module Standalone or daemon mode. Free-use open SATAN oriented license. Updated twice a month (we try). User extension support Based on the SATAN model .

 

Company Overview and Contact:

Computer security is the Company's primary focus where we provide the community with tools, services, and training. We are proud that we provide "24/7" security protection and remediation for our Government and Commercial clients.

http://www-arc.com/contact/index.php

 


STAT Scanner
About Tool:

STAT Scanner is built to deliver a solid balance of speed and accuracy via its adaptive scanning techniques and false-response correlation technology. Through deep inspection of target systems that include redundant file attribute and registry value correlation, as well as SSH tunneling and authenticated OS fingerprinting refinement, STAT Scanner dramatically reduces the risk of false positives and false negatives.

 

Additional Information:

Features & Benefits

  • Flexible Architecture - Flat or Hierarchical implementations, with a single management console instance or multiple consoles rolling up into a centralized, master console.
  • Common Criteria EAL2 Certified - Complies with the all specified security requirements of the CCS Certification Body
  • Consolidated Views - Multiple scan and remediation reports can be merged together to form a comprehensive security posture
  • Highly Scalable -Currently deployed by customers across hundreds of thousands of endpoints.
  • Role-Based Administration - Delegate remediation and reporting activities to improve productivity while maintaining security
  • Policy-Based Administration - Push out mandatory baseline policies to all endpoints — a key aspect of regulatory compliance
  • Standard Industry Classifications - Identified vulnerabilities are linked to common industry vulnerability classifications like CVE, BugTraq and IAVA codes for easy identification, analysis and remediation.
  • Comprehensive Reporting - Document changes and demonstrate progress toward audit and compliance requirements with enterprise & local reporting of asset inventory, network or agent-based scans, vulnerability remediation and much more
  • Global Installation Support - Inclusion of international date / time designations for assessment and remediation activities and A4 support for report generation.
Company Overview and Contact:

Lumension Security™, Inc., formed by the combination of PatchLink and SecureWave S.A., is a leading global security management company, providing unified protection and control of all enterprise endpoints, applications and devices. The ineffectiveness of silo endpoint solutions that are reactive in nature has sparked demand for a shift in the security paradigm as organizations look to a more proactive approach to security.

Global Headquarters
15880 North Greenway Hayden Loop, Suite 100
Scottsdale, AZ 85260
United States of America

phone: +1 888 725 7828  
fax: +1 480 970 6323

Sales: patchlink.sales@lumension.com ; sanctuary.sales@lumension.com


Snort Bastille
About Tool:

The Bastille Hardening program "locks down" an operating system, proactively configuring the system for increased security and decreasing its susceptibility to compromise. Bastille can also assess a system's current state of hardening, granularly reporting on each of the security settings with which it works.

 

Additional Information:

This hardening tool supports such Linux distributions as the Debian, Red Hat, Gentoo, Mandrake, SuSE and Fedora Core; and it can also be used for such operating systems as HP-UX and Full Mac OS X. Moreover, Bastille has been recommended by the Center for Internet Security's Linux Hardening Guide as one of the best hardening systems. This system can also be called an educational tool which helps users learn more about the security process and its work.

 

Company Overview and Contact:
Contact URL:

http://www.bastille-linux.org/Contact-Us.htm

 


Cenzic Hailstorm

About Tool:

With a Cenzic vulnerability assessment and risk assessment solution, a company can rely on the most innovative and accurate Web application security products and services available in the industry today.

 

Additional Information:

For CISOs, information security teams, developers and QA professionals alike Cenzic’s vulnerability assessment and risk management solutions provide:

  • Reduced risk and liability through most secure applications possible on the Web today

  • Reduced costs for security assessment

  • Keeps companies up to date on regulatory compliance for security

  • Reduced development and testing costs

  • Faster time-to-market for internally developed applications

  • Ability to safely test and re-test production applications
Company Overview and Contact:

Cenzic is the innovative leader in application security risk management, vulnerability assessment, and compliance solutions. Voted #1 by eWeek and InfoWorld, lauded by Gartner Group and IDC, and recipient of many prestigious awards, Cenzic has state-of-the-art, next-generation solutions — changing the dynamics of the application security industry.

Cenzic Inc.

455 El Camino Real
Suite 100
Santa Clara, CA 95050
Tel:    +1 866-4-CENZIC (866-423-6942   )
Fax: +1 408 200-0701
Email:
request@cenzic.com

 


 Internet Security Scanner
About Tool:

IBM Internet Security Systems (ISS) products secure your IT infrastructure, ensuring business continuity and enabling cost-effective processes while supporting compliance and risk management requirements.

Additional Information:

IBM Internet Security Systems (ISS) offers a comprehensive portfolio of IT security products and services for organizations of all sizes. Our threat mitigation solutions afford preemptive protection against a wide variety of attacks and Internet nuisances, including hackers, worms, viruses, spam, spyware and more. We also provide data security solutions to safeguard valuable information while preserving accessibility.

Company Overview and Contact:
 

IBM Corporation
1 New Orchard Road
Armonk,
New York 10504-1722
United States

Email: ews@us.ibm.com


Team Mentor
About Tool:

TeamMentor™ is a sophisticated application security guidance system that delivers the collected experience of Security Innovation engineering to development teams of all sizes.

 

Additional Information:

Security Innovation has guided software development teams through the process of developing secure applications for years.  This experience allows our engineers to recognize the problems that software development teams typically encounter and drive the behaviors they need to adopt to succeed.  TeamMentor™, the industry’s first Web-based application security learning and knowledge management system, encapsulates this cumulative know-how and experience. In a wiki-like format, TeamMentor™ provides each development team member complete SECURITY GUIDANCE up front and as they code - in a way that can be leveraged immediately and repeatedly.

 

Company Overview and Contact:

Security Innovation is an authority on application security and leading independent provider of risk assessment, risk mitigation and education services to mid-size and Fortune 500 companies. Global technology vendors and enterprise IT organizations such as Microsoft, IBM, FedEx, ING, Symantec, Visa, Coca-Cola and GE rely on our expertise to understand the security risks in their software systems and facilitate the software and process change necessary to mitigate them. 

U.S. Headquarters Boston , MA

187 Ballardvale Street, Suite A195
Wilmington, MA 01887
Ph.:     +1.978.694.1008  
Fax:   +1.978.694.1666
Sales:   +1.978.694.1008   x24 or

 Email: sales@securityinnovation.com

Contact: http://www.sisecure.com/contact/index.shtml

 




WebInspect
About Tool:

HP WebInspect identifies security vulnerabilities that are undetectable by traditional scanners. With innovative assessment technology, such as simultaneous crawl and audit (SCA) and concurrent application scanning, you get fast and accurate automated web application security testing and web services security testing.

Additional Information:
  • Get innovative assessment technology for web services and web application security

  • Automate web application security testing and assessment

  • Enable application security testing and collaboration across the lifecycle

  • Run interactive scans easily via a sophisticated user interface

  • Meet legal and regulatory compliance requirements

  • Conduct penetration testing with advanced tools (HP Security Toolkit)

  • Configure to support any web application environment.

Company Overview and Contact:
Contact:

Hewlett-Packard Company
3000 Hanover Street
Palo Alto, CA 94304-1185 USA
Phone: (650) 857-1501
Fax: (650) 857-5518


AppInspect
About Tool:

HP AppInspect identifies security vulnerabilities that are undetectable by traditional scanners. With innovative assessment technology, such as simultaneous crawl and audit (SCA) and concurrent application scanning, you get fast and accurate automated web application security testing and web services security testing.

Additional Information:
  • Get innovative assessment technology for web services and web application security

  • Automate web application security testing and assessment

  • Enable application security testing and collaboration across the lifecycle

  • Run interactive scans easily via a sophisticated user interface

  • Meet legal and regulatory compliance requirements

  • Conduct penetration testing with advanced tools (HP Security Toolkit)

  • Configure to support any web application environment

Company Overview and Contact:

Hewlett-Packard Company
3000 Hanover Street
Palo Alto, CA 94304-1185 USA
Phone: (650) 857-1501
Fax: (650) 857-5518


Achilles
About Tool:

Securing your information and protecting your company's reputation isn't just about technology.

 

Additional Information:

Services Overview

Our consulting and education services focus on the areas of firewall, web site, web-based application, and dial-in architectures.

  • Ethical hacking & vulnerability assessments (networks, web apps, wifi, VoIP and NGN)
    (Assessment Phase of Security Life Cycle)
  • Web application security architecture reviews
    (Design Phase of Security Life Cycle)
  • Web application development best practices
    (Design Phase of Security Life Cycle)
  • Security training & education
    (All Phases of the Security Life Cycle)
  • Maven Security has provided expert testimony in a computer-security related criminal

Company Overview and Contact:

Maven Security Consulting Inc. is a vendor-independent security consulting firm that helps companies secure their information assets and digital infrastructure by providing a wide range of customized consulting and training services.Services include ethical hacking; web application security testing; network security architecture reviews; training;

Maven Security Consulting, Inc.

14525 SW Millikan #50645

Beaverton, Oregon 97005-2343

Phone:  +1-877-MAVEN-HQ  
(   +1-877-628-3647  )

Email: contact-us@mavensecurity.com

 


Holodeck
About Tool:
Holodeck is a unique test tool that uses fault injection to simulate real-world application and system errors for Windows applications and services. Testers and Developers work in a controlled, repeatable environment to analyze and debug error-handling code and application attack surface – it’s ideal for adept testers doing application fragility and security testing.

Additional Information:

Holodeck provides testers and developers with the following benefits:

  • Safe fault injection and environment simulation
  • Comprehensive reporting
  • Application insight via detailed application monitoring
  • API integration with automated testing tools
  • Built-in debugger for fast problem solving
  • Automated scheduled and random test generation
  • more features and benefits .
Company Overview and Contact:

Security Innovation is an authority on application security and leading independent provider of risk assessment, risk mitigation and education services to mid-size and Fortune 500 companies. Global technology vendors and enterprise IT organizations such as Microsoft, IBM, FedEx, ING, Symantec, Visa, Coca-Cola and GE rely on our expertise to understand the security risks in their software systems and facilitate the software and process change necessary to mitigate them.

U.S. Headquarters Boston , MA
187 Ballardvale Street, Suite A195
Wilmington, MA 01887
Ph.:     +1.978.694.1008  
Fax:   +1.978.694.1666
Sales:   +1.978.694.1008   x24 or

 Email: sales@securityinnovation.com


Fault Factory
About Tool:

Fault Factory injects socket API failures and SOAP/HTTP faults into any running application

 

Additional Information:
  • Very safe and easy-to-use

  • No system configuration changes needed

  • No build-time instrumentation needed - uses dynamic instrumentation

  • Language-neutral - works with virtually any winsock application, written in C/C++, Java, Perl, Python, and pretty much any other language

  • Does not modify your system and therefore very safe

Company Overview and Contact:

ExtraData Technologies

Founded in 1998 in the heart of the Silicon Valley Privately held
Headquarters:
1922 White Oaks Road
Second Floor
Campbell,CA95008
USA
Phone: 866-580-9168
E-mail:
     Sales:   sales@extradata.com
     Support: support@extradata.com
Public Relations: info@extradata.com


Breaking point

About Tool:
At the core of BreakingPoint’s application performance and security testing solution is our patent-pending Test Expression Engine™. It features multiple Field Programmable Gate Arrays, network processors, and an array of embedded processors to produce millions of real application data streams, while pushing security to the max.

Additional Information:

Highlighted Features:

  • 10 Gigabits per second and faster, 7.5 million simultaneous TCP sessions and 750,000 TCP/IP requests per second.
  • Supports transmissions and verification of up to 30 million packets per second at 64 byte packets.
  • An extensive library of pre-configured tests.
  • 1 Gigabit and 10 Gigabit models
  • Built-in power receptacle on the front of the system for power cycle testing of the device under test.
  • Built-in serial and Ethernet ports for controlling the device under test.
  • Point and click automation via Telnet, SSH and Serial for any device under test.
Company Overview and Contact:
BreakingPoint Global Headquarters
10535 Boyer Blvd, Suite 300
Austin, Texas 78758

email: nasales@bpointsys.com
tel: + 512.821.6000
toll free (US only): 866.352.6691
fax: 512.997.9861



 
    Home  |  SiteMap  |  Terms of Use  |  Privacy Policy  |  Contact Us  |  Report a Bug QAGuild, UK |Copyright© 2010 InvenTest Ltd