Web Application Scanner results

Locked
nEUrOO
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Thu Aug 09, 2007 6:45 pm

Web Application Scanner results

Post by nEUrOO » Thu Aug 09, 2007 6:54 pm

Hi, my name is Romain Gaucher, I'm working at NIST in the SAMATE project: http://samate.nist.gov
I'm currently studying web application scanners and I've seen on Acunetix website that Joomla! use this tool to ensure the security (http://www.acunetix.com/vulnerability-s ... joomla.htm).

I'd like to know if it's possible to get the number of vulnerabilities/false-positive rate that the tool is making in a product like Joomla. Actually, I didn't find anything in the bug tracker...

I also 'd like to know how/when you are using the tool in the SDLC?

Hope everything is not confidential...
Thanks

user deleted

Re: Web Application Scanner results

Post by user deleted » Thu Aug 09, 2007 7:33 pm

Hi,

I'm actually one of the persons running the tool on Joomla! releases. I'd have to ask around a bit for the false-positive rate though, I usually send the reports to our security specialst(s) and let them review it.

With SDLC you mean Systems Development Life Cycle?

nEUrOO
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Thu Aug 09, 2007 6:45 pm

Re: Web Application Scanner results

Post by nEUrOO » Thu Aug 09, 2007 7:35 pm

yup for the SDLC.
So you don't have any track of vulnerabilties etc.? They don't report the bug as security issue found by the tool (I didn't find such a thing in the bug tracker)?

user deleted

Re: Web Application Scanner results

Post by user deleted » Sat Aug 11, 2007 11:00 am

I'll see what I can dig up. As for keeping records, some security issues are posted on the trackers, others appear on the forums. As far as I know, we never kept one central record.


Locked

Return to “Quality and Testing - Locked and Archived”