|
|
|
Welcome To Tools Directory - 2010
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
QA Inspect
|
|
|
|
|
Incorporate fully automated
web application security testing into the overall test management process. Now,
Mercury users can conduct and manage both functional testing and security
testing from a single platform.
|
|
Additional Information |
|
HP QAInspect lets you conduct and manage functional testing and website security testing from a single
platform without the need for specialized security knowledge. It features deep
and intuitive integrations, helping you test web applications for security
without leaving the QA environment.
HP QAInspect finds and prioritizes website security
vulnerabilities in a web application and presents detailed information and
remediation advice for each vulnerability. With this software, you can
incorporate fully automated website security testing into the overall test
management process without affecting aggressive product release schedules.
|
|
|
Hewlett-Packard Company
3000 Hanover Street Palo Alto, CA 94304-1185 USA Phone: (650) 857-1501 Fax: (650) 857-5518
|
|
|
Nessus |
|
|
|
|
It is a remote security
scanner for Linux, BSD, Solaris, and other Unices. Nessus is plug-in-based, has
a GTK interface, and performs over 1200 remote security checks. It allows for
reports to be generated in HTML, XML, LaTeX, and ASCII text, and suggests
solutions for security problems.
|
|
|
Tenable Network Security
provides a suite of solutions which unify real-time vulnerability, event and
compliance monitoring into a single, role-based, interface for administrators,
auditors and risk managers to evaluate, communicate and report needed
information for effective decision making and systems management.
The suite of products described in this section enables our customers to
leverage the benefits of the Unified Security Monitoring strategy.
|
|
|
|
Tenable Network Security,
Inc. (Tenable) is a US-based Delaware C Corporation. Tenable’s corporate offices
are located in
Columbia,
Maryland
with additional offices in
New England,
California
,
Virginia
,
Pennsylvania
, and
Georgia
. Tenable was founded in
September of 2002 and is privately owned. Tenable has hundreds of Global 2000
customers in the US
,
Canada
, Asia Pacific, and
Europe
.
Tenable Network Security,
Inc.
7063 Columbia Gateway
Drive
Suite 100
Columbia,
MD
21046
Email: sales@tenablesecurity.com
support@tenablesecurity.com
Phone: 14108720555
|
|
|
Web Vulnerability Scanner
|
|
|
|
|
Web site security testing
tool from Acunetix first identifies web servers from a particular IP or IP range. It then
crawls entire site, gathering information about every file it finds, and displaying
website structure. After this discovery stage, it performs an automatic audit for
common security issues. Applications utilizing CGI, PHP, ASP, ASP.NET can all be
tested for vulnerabilities such as cross site scripting, SQL injection, CRLF injection,
code execution, directory traversal and more.
|
|
|
Web site security and compliance
should be a top priority for organizations intent on protecting sensitive company,
customer, and employee data, on meeting regulatory and corporate compliance requirements,
and on defending against the high cost of a data breach. Web sites and their applications
are high-focus targets for hackers because they provide a direct route to corporate
or personal data regardless of network security implementations.
IBM provides Rational AppScan
and Rational Policy Tester, scanning and testing solutions that automate application
and content analysis to help organizations identify vulnerabilities, to assess compliance
requirements, and to improve the accuracy and reliability of online systems.
|
|
|
Contact IBM
http://www.ibm.com/contact/us/
|
|
|
Codenomicon
Test Tool
|
|
|
|
|
Codenomicon test tools are used
for robustness testing, security assessment, software development, risk analysis,
purchase criteria and acceptance testing. Codenomicon tools test implementations
using black-box testing methods. Proactive flaw discovery introduces tremendous
cost savings for our customers and promotes reliability and responsibility.
|
|
|
- Codenomicon DEFENSICS enables companies to preemptively mitigate unknown and published threats in products and services prior to release or deployment - before systems are exposed, outages occur and zero-day attacks strike.
- DEFENSICS offers unparalleled blackbox, negative testing against the broadest set of applications; spanning over 130 Internet, wireless and digital media protocols.
- Unlike code analyzers and after-the-fact vulnerability scanners, the DEFENSICS platform empowers developers and security analysts to rapidly extend rigorous robustness and vulnerability tests at the protocol-level to identify and resolve issues that can result in reputation, quality, compliance and liability risks.
- Discover how our award-winning preemptive robustness and security test platform is helping software developers, carriers and enterprises around the world extend quality assurance and protect their systems, services and sensitive data from zero-day attacks and availability exposures.
|
|
|
|
Headquartered in Oulu,
Finland , with offices
in Silicon Valley
and Hong Kong
, the company markets its testing software and services directly and through international
partners. Codenomicon’s customers include Adobe, Alcatel-Lucent, AT&T, Cisco
Systems, F5 Networks, Nordea, Nortel, Microsoft and Siemens AG among many others.
The company is privately held with investments from Eqvitec Partners and Prime Technology
Ventures.
Codenomicon Ltd. (Headquarters)
Tutkijantie 4E
FIN-90570 OULU
FINLAND
Tel. +358 424 7431 (international)
Tel. 0424 7431 (inside
Finland )
Fax: +358 8 340 141 (international)
Fax: 08 340 141 (inside
Finland )
Email:
sales@codenomicon.com
|
|
|
Sara
|
|
|
|
|
It is a comprehensive network
security scanner that discovers, analyzes, and reports on security vulnerabilities
of network-based computers, server, routers, and firewalls.
|
|
|
|
The Security Auditor's Research Assistant (SARA) is a
third generation network
security analysis tool that is:
Operates under UNIX, Linux, MAC
OS/X or Windows (through coLinux) OS'.Integrates the National
Vulnerability Database (NVD).Performs SQL injection tests. Performs
exhaustive XSS tests can adapt to many firewalled environments. Support remote self
scan and API facilities. Used for CIS benchmark initiatives. Plug-in facility
for third party apps. CVE standards support. Enterprise
search module Standalone or daemon mode. Free-use open
SATAN oriented
license. Updated twice a month (we try). User extension support Based on the
SATAN
model .
|
|
Company Overview
and Contact:
|
|
Computer security is
the Company's primary focus where we provide the community with tools, services,
and training. We are proud that we provide "24/7" security protection
and remediation for our Government and Commercial clients.
http://www-arc.com/contact/index.php
|
|
| STAT Scanner
|
|
|
|
|
STAT Scanner is built to deliver
a solid balance of speed and accuracy via its adaptive scanning techniques and false-response
correlation technology. Through deep inspection of target systems that include redundant
file attribute and registry value correlation, as well as SSH tunneling and authenticated
OS fingerprinting refinement, STAT Scanner dramatically reduces the risk of false
positives and false negatives.
|
|
|
|
Features & Benefits
- Flexible
Architecture
- Flat or Hierarchical implementations, with a single management console instance
or multiple consoles rolling up into a centralized, master console.
- Common
Criteria EAL2 Certified - Complies with the all specified security requirements
of the CCS Certification Body
- Consolidated
Views
- Multiple scan and remediation reports can be merged together to form a comprehensive
security posture
- Highly
Scalable
-Currently deployed by customers across hundreds of thousands of endpoints.
- Role-Based Administration - Delegate remediation and reporting activities to improve
productivity while maintaining security
- Policy-Based Administration - Push out mandatory baseline
policies to all endpoints — a key aspect of regulatory compliance
- Standard Industry Classifications - Identified vulnerabilities are
linked to common industry vulnerability classifications like CVE, BugTraq and IAVA
codes for easy identification, analysis and remediation.
- Comprehensive Reporting - Document changes and demonstrate progress toward audit
and compliance requirements with enterprise & local reporting of asset inventory,
network or agent-based scans, vulnerability remediation and much more
- Global Installation Support - Inclusion of international date
/ time designations for assessment and remediation activities and A4 support for
report generation.
|
|
Company Overview
and Contact:
|
|
Lumension Security™,
Inc., formed by the combination of PatchLink and SecureWave S.A., is a leading global
security management company, providing unified protection and control of all enterprise
endpoints, applications and devices. The ineffectiveness of silo endpoint solutions
that are reactive in nature has sparked demand for a shift in the security paradigm
as organizations look to a more proactive approach to security.
Global
Headquarters
15880 North Greenway Hayden Loop, Suite 100
Scottsdale, AZ 85260
United States of America
phone:
+1 888 725 7828
fax: +1 480 970 6323
Sales:
patchlink.sales@lumension.com ; sanctuary.sales@lumension.com
|
|
|
Snort Bastille
|
|
|
|
|
The Bastille Hardening program
"locks down" an operating system, proactively configuring the system for
increased security and decreasing its susceptibility to compromise. Bastille can
also assess a system's current state of hardening, granularly reporting on each
of the security settings with which it works.
|
|
|
|
This hardening tool supports such Linux
distributions as the Debian, Red Hat, Gentoo, Mandrake, SuSE and Fedora Core;
and it can also be used for such operating systems as HP-UX and Full Mac OS X.
Moreover, Bastille has been recommended by the Center for Internet Security's
Linux Hardening Guide as one of the best hardening systems. This system can also
be called an educational tool which helps users learn more about
the security process and its work.
|
|
Company Overview
and Contact:
|
Contact URL:
http://www.bastille-linux.org/Contact-Us.htm
|
|
|
Cenzic
Hailstorm
|
|
|
|
|
With a Cenzic vulnerability assessment and risk assessment solution, a company can
rely on the most innovative and accurate Web application security products and services
available in the industry today.
|
|
|
|
For CISOs, information security teams, developers and QA professionals alike Cenzic’s
vulnerability assessment and risk management solutions provide:
-
Reduced risk
and liability through most secure applications possible on the Web today
-
Reduced
costs for security assessment
-
Keeps
companies up to date on regulatory compliance for security
-
Reduced
development and testing costs
-
Faster
time-to-market for internally developed applications
- Ability to
safely test and re-test production applications
|
|
Company Overview
and Contact:
|
|
Cenzic is the innovative leader
in application security risk management, vulnerability assessment, and compliance
solutions. Voted #1 by eWeek and InfoWorld, lauded by Gartner Group and IDC, and
recipient of many prestigious awards, Cenzic has state-of-the-art, next-generation
solutions — changing the dynamics of the application security industry.
Cenzic Inc.
455 El Camino
Real
Suite 100
Santa
Clara,
CA
95050
Tel: +1 866-4-CENZIC (866-423-6942 )
Fax: +1 408 200-0701
Email:
request@cenzic.com
|
|
|
Internet
Security Scanner
|
|
|
|
|
IBM Internet Security Systems
(ISS) products secure your IT infrastructure, ensuring business continuity and enabling
cost-effective processes while supporting compliance and risk management requirements.
|
|
|
|
IBM Internet Security Systems
(ISS) offers a comprehensive portfolio of IT security products and services for
organizations of all sizes. Our
threat mitigation solutions afford preemptive protection against a wide
variety of attacks and Internet nuisances, including hackers, worms, viruses, spam,
spyware and more. We also provide
data security solutions to safeguard valuable information while preserving
accessibility.
|
|
Company Overview
and Contact:
|
|
IBM Corporation
1 New Orchard Road
Armonk,
New York 10504-1722
United States
Email:
ews@us.ibm.com
|
|
|
Team Mentor
|
|
|
|
|
TeamMentor™ is a sophisticated
application security guidance system that delivers the collected experience of Security
Innovation engineering to development teams of all sizes.
|
|
|
|
Security Innovation has guided
software development teams through the process of developing secure applications
for years. This experience allows our engineers to recognize the problems
that software development teams typically encounter and drive the behaviors they
need to adopt to succeed. TeamMentor™, the industry’s first Web-based application
security learning and knowledge management system, encapsulates this cumulative
know-how and experience. In a wiki-like format, TeamMentor™ provides each development
team member complete SECURITY GUIDANCE up front and as they code - in a way that
can be leveraged immediately and repeatedly.
|
|
Company Overview
and Contact:
|
|
Security Innovation is an authority
on application security and leading independent provider of risk assessment, risk
mitigation and education services to mid-size and Fortune 500 companies. Global
technology vendors and enterprise IT organizations such as Microsoft, IBM, FedEx,
ING, Symantec, Visa, Coca-Cola and GE rely on our expertise to understand the security
risks in their software systems and facilitate the software and process change necessary
to mitigate them.
U.S. Headquarters:
Boston , MA
187 Ballardvale Street,
Suite A195
Wilmington, MA
01887
Ph.: +1.978.694.1008
Fax: +1.978.694.1666
Sales: +1.978.694.1008 x24 or
Email: sales@securityinnovation.com
Contact:
http://www.sisecure.com/contact/index.shtml
|
|
|
WebInspect
|
|
|
|
|
HP WebInspect identifies
security vulnerabilities that are undetectable by traditional scanners. With innovative
assessment technology, such as simultaneous crawl and audit (SCA) and concurrent
application scanning, you get fast and accurate automated web application security
testing and web services security testing.
|
|
|
- Get innovative assessment technology for web services and web application security
- Automate web application security testing and assessment
- Enable application security testing and collaboration across the lifecycle
- Run interactive scans easily via a sophisticated user interface
- Meet legal and regulatory compliance requirements
- Conduct penetration testing with advanced tools (HP Security Toolkit)
- Configure to support any web application environment.
|
|
Company Overview
and Contact:
|
Contact:
Hewlett-Packard Company
3000 Hanover Street Palo Alto, CA 94304-1185 USA Phone: (650) 857-1501 Fax: (650) 857-5518
|
|
|
|
AppInspect
|
|
|
|
|
HP AppInspect identifies security
vulnerabilities that are undetectable by traditional scanners. With innovative assessment
technology, such as simultaneous crawl and audit (SCA) and concurrent application
scanning, you get fast and accurate automated web application security testing and
web services security testing.
|
|
Additional
Information:
|
-
Get innovative assessment technology for web services
and web application security
-
Automate web application security testing and
assessment
-
Enable application security testing and collaboration
across the lifecycle
-
Run interactive scans easily via a sophisticated user
interface
-
Meet legal and regulatory compliance requirements
-
Conduct penetration testing with advanced tools (HP
Security Toolkit)
-
Configure to support any web application environment
|
|
Company Overview
and Contact:
|
Hewlett-Packard Company
3000 Hanover Street Palo Alto, CA 94304-1185 USA Phone: (650) 857-1501 Fax: (650) 857-5518
|
|
|
Achilles |
|
|
|
|
Securing your information and
protecting your company's reputation isn't just about technology.
|
|
|
|
Services Overview
Our consulting and education
services focus on the areas of firewall, web site, web-based application, and dial-in
architectures.
- Ethical hacking & vulnerability
assessments (networks, web apps, wifi, VoIP and NGN)
(Assessment Phase of Security Life Cycle)
- Web application security
architecture reviews
(Design Phase of Security Life Cycle)
- Web application development
best practices
(Design Phase of Security Life Cycle)
- Security training & education
(All Phases of the Security Life Cycle)
- Maven Security has provided
expert testimony in a computer-security related criminal
Company Overview
and Contact:
|
|
Maven Security Consulting
Inc. is a vendor-independent security consulting firm that helps companies secure
their information assets and digital infrastructure by providing a wide range of
customized consulting and training services.Services include ethical hacking; web
application security testing; network security architecture reviews; training;
Maven Security Consulting,
Inc.
14525 SW Millikan #50645
Beaverton,
Oregon
97005-2343
Phone: +1-877-MAVEN-HQ
( +1-877-628-3647 )
Email: contact-us@mavensecurity.com
|
|
|
Holodeck
|
|
|
|
Holodeck is a unique test tool
that uses fault injection to simulate real-world application and system errors for
Windows applications and services. Testers and Developers work in a controlled,
repeatable environment to analyze and debug error-handling code and application
attack surface – it’s ideal for adept testers doing application
fragility and
security testing.
|
|
|
|
Holodeck provides testers and developers with the following benefits:
- Safe fault injection and
environment simulation
- Comprehensive reporting
- Application insight via detailed
application monitoring
- API integration with automated
testing tools
- Built-in debugger for fast
problem solving
- Automated scheduled and random
test generation
-
more features and benefits .
|
|
Company Overview
and Contact:
|
|
Security Innovation is an authority
on application security and leading independent provider of risk assessment, risk
mitigation and education services to mid-size and Fortune 500 companies. Global
technology vendors and enterprise IT organizations such as Microsoft, IBM, FedEx,
ING, Symantec, Visa, Coca-Cola and GE rely on our expertise to understand the security
risks in their software systems and facilitate the software and process change necessary
to mitigate them.
U.S. Headquarters:
Boston , MA
187 Ballardvale Street,
Suite A195
Wilmington, MA
01887
Ph.: +1.978.694.1008
Fax: +1.978.694.1666
Sales: +1.978.694.1008 x24 or
Email:
sales@securityinnovation.com
|
|
|
Fault Factory
|
|
|
|
|
Fault
Factory injects socket API failures and SOAP/HTTP faults into any running application
|
|
|
- Very safe and easy-to-use
- No system configuration changes needed
- No build-time instrumentation needed - uses dynamic instrumentation
- Language-neutral - works with virtually any winsock application, written in C/C++, Java, Perl, Python, and pretty much any other language
- Does not modify your system and therefore very safe
|
|
Company Overview
and Contact:
|
ExtraData Technologies
Founded in 1998 in the heart of the Silicon Valley Privately held
Headquarters:
1922 White Oaks Road
Second Floor
Campbell,CA95008
USA
Phone: 866-580-9168
E-mail:
Sales: sales@extradata.com
Support: support@extradata.com
Public Relations:
info@extradata.com
|
|
|
Breaking point
|
|
|
|
At the core of BreakingPoint’s
application performance and security testing solution is our patent-pending Test
Expression Engine™. It features multiple Field Programmable Gate Arrays, network
processors, and an array of embedded processors to produce millions of real application
data streams, while pushing security to the max.
|
|
|
|
Highlighted
Features:
- 10 Gigabits per
second and faster, 7.5 million simultaneous TCP sessions and 750,000 TCP/IP requests
per second.
- Supports transmissions
and verification of up to 30 million packets per second at 64 byte packets.
- An extensive library
of pre-configured tests.
- 1 Gigabit and 10
Gigabit models
- Built-in power
receptacle on the front of the system for power cycle testing of the device under
test.
- Built-in serial
and Ethernet ports for controlling the device under test.
- Point and click
automation via Telnet, SSH and Serial for any device under test.
|
|
Company Overview
and Contact:
|
BreakingPoint Global Headquarters
10535 Boyer Blvd, Suite 300
Austin, Texas 78758
email: nasales@bpointsys.com
tel: + 512.821.6000
toll free (US only): 866.352.6691
fax: 512.997.9861
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|