Email this article   Print article 

SPI Dynamics Takes Aim At Web 2.0 Security

By Kevin McLaughlin, CRN
January 29, 2007    4:40 PM ET

SPI Dynamics on Monday rolled out a revamped threat-scanning technology and new software that target the rising number of vulnerabilities in Web 2.0 technology.

AJAX, RSS, SOAP and other Web 2.0 technologies have created a broader attack surface for Web applications, which has led SPI to improve the accuracy of the vulnerability scanning technology it uses in its products, said Caleb Sima, co-founder and CTO at the Atlanta-based vendor.

WebInspect 7, SPI's first product based on the new technology, is equipped to weed out security vulnerabilities in Web applications and can test Web sites that use two-factor authentication and "captchas," technologies that have been traditional stumbling blocks, according to Sima.

"Web applications have grown so complex that automated vulnerability scanners only get to 25 percent of the Web sites, which means you are missing flaws you should be finding in the discovery phase," Sima said.

Vincent Liu, managing director of Stach & Liu, a Phoenix-based security services firm, said WebInspect 7 reduces the burden of doing assessments. "The lack of a tool out there for Web 2.0 assessments means we have to review every single line of code that's on the client. But WebInspect 7 takes care of a lot of that manual code review," he said.

Another key feature is a new method for crawling Web applications that combines the crawl and audit phase into a single process and saves time by reporting results to the tester on an ongoing basis during the scan, Sima said.

Overall scan times been reduced by 50 percent, and users can now launch multiple concurrent scans, Sima added.

WebInspect 7 single-server perpetual licenses start at $6,000, and perpetual user licenses begin at $25,000. Enterprise pricing and consultant licenses are also available.


Email this article   Print article 

More

Recent Articles

Five Companies That Dropped The Ball This Week

For the week ending Feb. 10, CRN looks at five companies that were either asleep at the wheel or just didn't make good decisions.

Five Companies That Came To Win This Week

For the week ending Feb. 10, CRN looks at five companies that brought their 'A' game and made moves to beat out competitors

Symantec's Code Red: The Law Enforcement/Anonymous E-Mail Exchange

Law enforcement officials negotiated via e-mail for more than two weeks with an Anonymous group member trying to extort $50,000 from Symantec to keep stolen product code off the Internet.

  More Slide Shows




Related Videos
Loading...