
bmartin at tenablesecurity
Mar 12, 2009, 2:41 AM
Post #3 of 3
(2191 views)
Permalink
|
|
Re: Extending the generic web application vulnerability checks
[In reply to]
|
|
Hi Piet, > I have the following questions: > 2. What is the development roadmap for these kind of checks? There is no firm roadmap for more application checks. However, it is something that we have been having extensive discussions on internally. While I cannot promise any specifics, it is certainly our goal to move Nessus a bit farther into the application testing realm. > 3. Are new generic plug-ins currently being in development? There is currently some internal development of such plugins. > 4. Are there plans to extend torturecgis.nasl? Yes, it actively being worked on. > 5. Why isn't there a good set of plug-ins for these kind of checks? They are considerably more difficult to write than plugins that check for a single 'static' vulnerability. > In comparison with other (generic) web application vulnerability > scanners, there is a lot of improvement to achieve. In comparison to Nessus, web application vulnerability scanners have a lot of improvement to achieve when detecting vulnerabilities in Sendmail and FTP. =) Please remember, Nessus has a 10 year history of being a network vulnerability scanner, and that we are looking to evolve it even more, especially toward web application testing. Brian Tenable Network Security _______________________________________________ Plugins-writers mailing list Plugins-writers [at] list http://mail.nessus.org/mailman/listinfo/plugins-writers
|