Hacker News new | past | comments | ask | show | jobs | submit login

We've written a lot of custom tools to do some heavier auditing of a website than off-the-shelf Nessus. With that said, we are definitely targeting those companies and teams that don't have the time or experience to be focused on setting up and running Nessus consistently.

Our SQLi and XSS modules in particular are quite a bit heavier than Nessus', but there are other features like page de-duplication that optimize speed as well.




Nobody should ever be using Nessus as their first-line tool to test web applications. Nessus isn't a web application tool.

A much more realistic option is Burp Suite, which is $299.


True; wasn't saying Nessus is a good tool for web applications. Quite the opposite.

Burp Suite is great for anyone who knows what they're doing; for anyone that isn't already a security guy/gal the UI is near impossible to figure out, and the results aren't particularly actionable. That's much of what we try to fix.

Not trying to be argumentative, just clarifying! :)




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: