How To Do Web Penetration Testing?

What are the metrics that has to be considered while designing Benchmarks for Web Application penetration testing tools? What benchmarks for cloud based tools?

  • I have a job to evaluate best cloud based vulnerability assessment and PT tools like https://enprobe.io , http://Risk.io. Also best standalone tools like IBM App scanner, Acunetix etc. Can anyone help with required link if there is an existing benchmark or how do we create?

  • Answer:

    I have done a big research in regards to benchmarking tools for web application used in penetration testing and assisting red team. I have a very in-depth analysis report on all of them. With that said, there is very little to look down against the opensource side. Let alone the enterprise industry are at stack of producing blind software for detection of vulnerabilities, we spend less or no time benchmarking the tools based out of it's AI capabilities. The AI to detect, manipulate cloud based request and response, fetch additional resources are an added blend to any tool which a company could get licensed to per annual basis. During this analysis, I found much lesser of the toolbox you had talked here does that. That doesn't mean none of them do. There are some out of the box static analysis as well as dynamic analysis tools. The problem with them is being too opensource to get out-focused and due to this very reason they never get the recognition. I will share the analysis report, feel free to mail at

Shritam Bhowmick at Quora Visit the source

Was this solution helpful to you?

Related Q & A:

Just Added Q & A:

Find solution

For every problem there is a solution! Proved by Solucija.

  • Got an issue and looking for advice?

  • Ask Solucija to search every corner of the Web for help.

  • Get workable solutions and helpful tips in a moment.

Just ask Solucija about an issue you face and immediately get a list of ready solutions, answers and tips from other Internet users. We always provide the most suitable and complete answer to your question at the top, along with a few good alternatives below.