Web application security: automated scanning versus manual penetration testing There are two primary methods for discovering Web
application vulnerabilities: using manual penetration testing and code review or using automated scanning tools and static analysis. The purpose of this paper is to compare these two methods.
Understanding Web application security challenges This paper explains what you can do to help protect your organization, and it discusses an approach for improving your organization’s Web application security.