Network World
Thursday, July 24, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools
  |  

Fave raves

SPI Dynamics' WebInspect

IN THIS ARTICLE

CIO, Priceline: Primavera
IT director, University of Connecticut: Enterprise Policy Manager
IT director, Lucasfilm Entertainment: Remedy Help Desk
IT director, Costello & Sons Insurance: Mimosa NearPoint Server
IT director, Pentair: WebInspect

“It took me a while to find WebInspect. The problem with most vulnerability tools is the false positives.”
Paul Samadani
• Title: Director of corporate technology services, Pentair, in Golden Valley, Minn.
• Years in networking: 23

We do a lot of development in-house and externally on our intranet and extranet sites. We have a global network of sites that spans to all countries. I want to make sure that these portals are secure.

It took me a while to find WebInspect. The problem with most vulnerability tools is the false positives. I demoed this product, and it found a lot of interesting items, but not a lot of false positives.

Some tools tell you there's a problem but don't tell you how to solve it. If you want to be hated in a development environment, point out to people that they have a problem but you don't know how to fix it. WebInspect points out the code and gives references on how to fix that code. Any developer can take my report and learn how to fix what's wrong. Everyone I've given a WebInspect report to has been impressed, because it was a learning experience for them.

We have two people in IT using WebInspect extensively to test sites across the company. We also tell the in-house developers we use WebInspect so they can test their sites against it. Some departments in the company like to work with [application service providers] for their sites. Our concern is that it's our intellectual property and personal information. We want to know how the ASP will handle that data. Before we sign up with an ASP, we run the WebInspect tool against them. We also do periodic checks using the tool. We can tell whether the ASP is secure or not. I have walked away from companies after seeing the results from WebInspect. I show them the vulnerabilities they have, and if they don't want to fix them, then we won't do business with them.

React: Give us your thoughts on the issues here.
Start a public discussion with other Network World users on this article (scroll up to send this article to a colleague).
Log In | Register for an account (Why you should)

Note: Register to have your user name appear; otherwise your comment will show up as "Anonymous."

*Anonymous comments will only appear once they are approved by the moderator.

Copyright 2008 Network World Inc.

Related links

Testing, testing
04/16/03

In brief: SPI Dynamics announces vulnerability-assessment software
11/07/05

RSA show to highlight new security approaches
02/23/04




Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.