Friday November 21, 2008 12:35 AM AEST
Latest Comments
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM
 
"I actually love the RoboForm software myself. I use it all of the time and it takes all of the ..."
by Omarra Byrd | Nov 18, 2008 8:19 AM

Typhon

  • Email a Friend
  • Print Page
Product Info
Supplier:
Product Rating
Features:  3
Ease of Use:  5
Performance:  3
Documentation:  4
Support:  5
Value for Money:  3
Overall Rating:  Overall Rating
 
For: Clean interface which is easy to navigate and requires no additional knowledge to use.
Against: More of a network vulnerability assessment application than an application vulnerability assessment application.
Verdict: A large number of web false positives and only one type of report availabe make this a better network vulnerability assessment utility.
The utility did not display the name of URLs found during the crawl or group the vulnerabilities by category. Typhon was fooled with the custom error pages into believing pages existed that did not.

This yielded a list of non-existent pages and directories without much detail as to actual vulnerabilities. The number of false positives reported by the utility was well over 100.

This utility would perform well as a traditional network vulnerability assessment tool, but lacks the features necessary to perform a web-based application vulnerability assessment.

A unique feature to this utility is the ability to check for other ports open (which also created additional false positive responses), as well as an included war dialer. The utility offers one level of report that is easy to read and understand for the technician.

The installation of Typhon was very simple and required only clicking "next" a few times to install the utility. Once Typhon was installed, the utility was logically laid out and included an almost unnecessary wizard to configure the scan. Typhon also uninstalled cleanly and easily leaving the systems in their original states.

Documentation for the utility comes primarily through the included help files with the utility. The files are complete and can assist an administrator with configuration troubles. The utility is simple enough to use that help files and documentation should not be necessary for most administrators.

The primary method of support is through email, with messages said to be responded to the next business day.

The pricing for Typhon was in the middle of the range of products tested at US$10,445 (unlimited IP), which included the email support. The price is a bit high for the included features, and it performs more as a network vulnerability assessment application. It is priced more for that category.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers