Can (Automated) Testing Tools Really Find The OWASP Top 10?
Can (Automated) Testing Tools Really Find The OWASP Top 10?
Erwin Geirnaert
Partner & Co-founder, ZION SECURITY
[email protected]
+32478289466
OWASP
AppSec
Europe
May 2006 Copyright © 2006 - The OWASP Foundation
Permission is granted to copy, distribute and/or modify this document
under the terms of the GNU Free Documentation License.
Introduction
Testing
Automated Tools
OWASP Top 10
For free
Run on multi-platforms, thank you Java
No or very limited reporting
Usage-mode: expert security tester
Examples: Oedipus, Paros, Burp Intruder,
WebScarab Fuzzer, Spike, E-Or, …