dimanche 8 février 2015

Is it worth it to install the same web application on different kind of web servers in a vulnerability assessment?



When doing a web vulnerability assessment with tools such as Acunetix and w3af, is it worth it to install the same web application on multiple types of web servers (Apache, IIS, etc.)?


If differences could be found, in the scanning results, between the different web servers, what type of different vulnerabilities could be found? Also, please keep in mind that I am solely testing the web application; I'm not testing Apache, PHP, MySQL, etc.





Aucun commentaire:

Enregistrer un commentaire