0
Dropped $900 on a pentest suite, then found out the free one did 80% of it
Six months ago I convinced my boss to let me buy Burp Pro for our little app team because I thought the scanner would save us. We spent $900 on it and honestly the active scan found some stuff, but the manual repeater and intruder work is where I live anyway. Then I tried OWASP ZAP on a side project and realized the automated baseline plus the HUD covers most of what we actually use daily. I still think Burp Pro is better for deep testing, but for a small shop I feel like I talked us into a splurge we didn't need. Anyone else had buyer's remorse on a pricey appsec tool and found a free or cheap option that did the job? What made you switch back or stay?
1 comments
Log in to join the discussion
Log In1 Comment
willow11410d ago
Eh, 900 bucks is just a night out for the boss. Stop stressing.
2