Does FusionVM address web application testing?
Yes and No. In general, many of the http checks that are performed do overlap into the ‘custom’ application testing; however, this should not be taken as a complete Web Application test or source code audit. FusionVM looks for sample/default web pages that get left from an install, it also checks for common named files/folders that draw unwanted attention from outsiders. In addition, there are some tools that will check web application for rudimentary validation errors. Again this shouldn’t be a substitute for a complete application audit. For discovered self-created code vulnerabilities, there really is no good substitute for a third party (person or software) to manually review the source code.