Hacker News new | ask | show | jobs
by tptacek 5017 days ago
Nobody should ever be using Nessus as their first-line tool to test web applications. Nessus isn't a web application tool.

A much more realistic option is Burp Suite, which is $299.

1 comments

True; wasn't saying Nessus is a good tool for web applications. Quite the opposite.

Burp Suite is great for anyone who knows what they're doing; for anyone that isn't already a security guy/gal the UI is near impossible to figure out, and the results aren't particularly actionable. That's much of what we try to fix.

Not trying to be argumentative, just clarifying! :)