Hello,

Just reviewed the Secunia product(Way to expensive but very sweet) and was wondering what everyone was using for an Application Vulnerability Scanner…Nessus/GFI??..

I just contacted www.qualys.com who has a customer list a mile long…

Thanks in advance…

3 Spice ups

We turn on our vm of Nessus every couple of months and run a scan. In fact i should probably do that soon, its been awhile. Going to be tons of updates.

We also run nessus as a quarterly vulnerability test that our auditors require.

What I really Liked about the Secunia is the Reporting…Very Unified and within a centralized desktop…Charts, ect…

I used to run with Qualys and I do remember them being not cheap, they were very good and thorough. They’d scan and send a list of what they found but also would have a very specific set of instructions on how to resolve, or links to find the right info we could call their techs and they’d help us resolve harder things or just answer general questions. Also they had the ability to assign problems to users and keep track of resolutions if you are in an industry that needs a paper trail.

I really liked them, but they were not cheap.

Yes,

they want like 5K for 50-60 ip’s… There really enterprise Priced-Not SMB…

I have looked at a dozen app scanners, they all do a good job but the one I keep falling back to is Nessus. You can’t beat the price but the one thing it is missing that most of the others do well is Reports. It has taken awhile but I have finally put together a template that I can pull the information from Nessus into to get a nice report but it still takes more time than just clicking a report button.