Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
Core WebVerify Web
Application Security Testing Software
SHARE

WebVerify vs. Scanning

Mitigating web application vulnerabilities typically requires developers to rework code, so it’s critical for web application security testing to pinpoint actual threats and eliminate false positives. Core WebVerify both identifies potential vulnerabilities and validates them against dynamically generated exploits. By revealing how and where a data breach could unfold and by exposing at-risk information assets, WebVerify enables you to work with developers to confidently plan remediation efforts and avoid unnecessary code changes for both new and existing applications.

Go Beyond Scanning to Pinpoint and Demonstrate Real Risks

WebVerify enables you to pinpoint, demonstrate and confirm web application exposures with confidence and clarity.

  • Identify and prove the exploitability of all OWASP Top 10 web application vulnerabilities
  • Eliminate false positives and ensure that development resources are focused on fixing actual exposures
  • Reveal the implications of a vulnerability by demonstrating how an attacker could steal and manipulate data
  • Validate cross-site scripting (XSS) exposures by crafting and emailing URLs that exploit XSS vulnerabilities
  • Detect sensitive data exposed by vulnerabilities, such as email addresses, credit card numbers, and social security numbers
  • Gain information about available patches and other necessary security updates for out-of-the-box applications
  • Reveal exploitable OS, services and application weaknesses in underlying web servers
  • Determine if an attacker could gain administrative privileges on the web server via local privilege escalation techniques
  • Conduct application penetration tests as mandated by PCI DSS Requirement 11.3
  • Validate that FISMA-mandated security measures are in-place and working effectively

How WebVerify Can Work With Your Existing Web Scanner

While you don’t need a scanner to use WebVerify, the software is able to import scan results and filter them for exploitable vulnerabilities.

Core WebVerify integrates with web application scanning tools such as IBM Rational AppScan, HP WebInspect, and NTOSpider to help you filter scan results and identify your most significant points of exposure. By feeding the results of your web application scans directly into WebVerify, you can:

  • Prove the exploitability of web application vulnerabilities, with no false positives, to both prioritize and inform remediation efforts to minimize the time and money spent on re-coding efforts.
  • Leverage industry-leading privilege escalation and pivoting capabilities to gain administrative access on web servers and leverage them as beachheads for additional attacks against backend network systems – just as an attacker would.
  • Use scan results to identify pages (URLs) to penetration test, in addition to utilizing the software’s onboard page identification capabilities. And it makes it complete and the simple thing where have you gone