<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" ><channel><title>The Web 3.0 &#187; Web Development</title> <atom:link href="http://theweb3.net/category/programming/web-development-programming/feed" rel="self" type="application/rss+xml" /><link>http://theweb3.net</link> <description>Talking about every bits.</description> <lastBuildDate>Mon, 25 Oct 2010 16:49:20 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.2.1</generator> <item><title>Skipfish &#8211; web application security scanner</title><link>http://theweb3.net/programming/web-development-programming/skipfish-web-application-security-scanner.html</link> <comments>http://theweb3.net/programming/web-development-programming/skipfish-web-application-security-scanner.html#comments</comments> <pubDate>Sat, 20 Mar 2010 17:38:07 +0000</pubDate> <dc:creator>Arun Vishnu</dc:creator> <category><![CDATA[Web Development]]></category> <category><![CDATA[asp]]></category> <category><![CDATA[google]]></category> <category><![CDATA[PHP]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[tools]]></category> <category><![CDATA[web]]></category><guid isPermaLink="false">http://theweb3.net/programming/web-development-programming/skipfish-web-application-security-scanner.html</guid> <description><![CDATA[Skipfish is an active web application security reconnaissance tool from Google. It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated with the output from a number of active (but hopefully non-disruptive) security checks. The final report generated by the tool [...]]]></description> <content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"> <a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftheweb3.net%2Fprogramming%2Fweb-development-programming%2Fskipfish-web-application-security-scanner.html"><br /> <img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftheweb3.net%2Fprogramming%2Fweb-development-programming%2Fskipfish-web-application-security-scanner.html&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br /> </a></div><p><a href="http://code.google.com/p/skipfish/" target="_blank">Skipfish</a> is an active web application security reconnaissance tool from Google.</p><blockquote><p><a href="http://theweb3.net/wp-content/uploads/2010/03/skipfishscreen.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; margin-left: 0px; border-left-width: 0px; margin-right: 0px" title="Skipfish screen" border="0" alt="Skipfish screen" align="left" src="http://theweb3.net/wp-content/uploads/2010/03/skipfishscreen_thumb.png" width="244" height="157" /></a>It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated with the output from a number of active (but hopefully non-disruptive) security checks. The final report generated by the tool is meant to serve as a foundation for professional web application security assessments.</p><p>&#160;</p></blockquote><h5>Advantages</h5><ul><li>Free and open source.</li><li>High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint &#8211; easily achieving 2000 requests per second with responsive targets.</li><li>Ease of use: heuristics to support a variety of quirky web frameworks and mixed-technology sites, with automatic learning capabilities, on-the-fly wordlist creation, and form auto completion.</li><li>Automatic wordlist construction based on site content analysis.</li><li>Probabilistic scanning features to allow periodic, time-bound assessments of arbitrarily complex sites.</li><li>Cutting-edge security logic: high quality, low false positive, differential security checks, capable of spotting a range of subtle flaws, including blind injection vectors.</li></ul><h4>Tests Implemented</h4><p>A rough list of the security checks offered by the tool is outlined below.</p><ul><li>Server-side SQL injection (including blind vectors, numerical parameters).</li><li>Explicit SQL-like syntax in GET or POST parameters.</li><li>Server-side shell command injection (including blind vectors).</li><li>Server-side XML / XPath injection (including blind vectors).</li><li>Format string vulnerabilities.</li><li>Integer overflow vulnerabilities.</li><li>Stored and reflected XSS vectors in document body (minimal JS XSS support present).</li><li>Stored and reflected XSS vectors via HTTP redirects.</li><li>Stored and reflected XSS vectors via HTTP header splitting.</li><li>Directory traversal (including constrained vectors).</li><li>HTTP credentials in URLs.</li><li>Self-signed SSL certificates.</li><li>Internal warnings like failed resource fetch attempts,&#160; exceeded crawl limits, Failed 404 behaviour checks etc.</li><li>And many more..</li></ul><h4><a href="http://code.google.com/p/skipfish/" target="_blank">Download skipfish</a></h4><p>The following list of products and tools provide web application security scanner functionality.</p><p><strong>Commercial Tools</strong></p><ul><li><a href="http://www.acunetix.com/">Acunetix WVS</a> by Acunetix</li><li><a href="http://www-01.ibm.com/software/awdtools/appscan/">AppScan</a> by IBM</li><li><a href="http://portswigger.net/suite/pro.html">Burp Suite Professional</a> by PortSwigger</li><li><a href="http://www.cenzic.com/products/software/overview/">Hailstorm</a> by Cenzic</li><li><a href="http://www.milescan.com/hk/">MileScan Web Security Auditor</a> by MileSCAN Technologies</li><li><a href="http://nstalker.com/products/">N-Stalker</a> by N-Stalker</li><li><a href="http://www.nessus.org">Nessus</a> by Tenable Network Security</li><li><a href="http://www.mavitunasecurity.com/">NetSparker</a> by Mavituna Security</li><li><a href="http://www.rapid7.com/products/">NeXpose</a> by Rapid7</li><li><a href="http://www.ntobjectives.com/products/ntospider.php">NTOSpider</a> by NTObjectives</li><li><a href="http://www.eeye.com/Products/Retina/Web-Security-Scanner.aspx">Retina Web Security Scanner</a> by eEye Digital Security<a href="http://www.veracode.com/solutions/web-application-security-dynamic-testing.html"></a></li><li><a href="http://www.ncircle.com/index.php?s=products_webapp360">WebApp360</a> by nCircle</li><li><a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;cp=1-11-201-200%5E9570_4000_100__">WebInspect</a> by HP</li><li><a href="http://www.parasoft.com/jsp/solutions/soa_solution.jsp?itemId=319">WebKing</a> by Parasoft</li></ul><p><strong>Software-as-a-Service Providers</strong></p><ul><li><a href="http://www-01.ibm.com/software/awdtools/appscan/ondemand/">AppScan OnDemand</a> by IBM</li><li><a href="http://www.cenzic.com/products/saas/ctsARC/">ClickToSecure</a> by Cenzic</li><li><a href="http://www.qualys.com/products/qg_suite/was/">QualysGuard Web Application Scanning</a> by Qualys</li><li><a href="http://whitehatsec.com/home/services/services.html">Sentinel</a> by WhiteHat</li><li><a href="http://www.veracode.com/solutions/web-application-security-dynamic-testing.html">Veracode Web Application Security</a> by Veracode</li><li><a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;cp=1-11-201-200%5E9570_4000_100__">WebInspect</a> by HP</li><li><a href="http://www.german-websecurity.com/en/products/webscanservice/">WebScanService</a> by Elanize KG</li></ul><p><strong>Free / Open Source Tools</strong></p><ul><li><a href="http://rgaucher.info/beta/grabber/">Grabber</a> by Romain Gaucher</li><li><a href="http://grendel-scan.com/">Grendel-Scan</a> by David Byrne and Eric Duprey</li><li><a href="http://parosproxy.org/">Paros</a> by Chinotec</li><li><a href="http://www.powerfuzzer.com/">Powerfuzzer</a> by Marcin Kozlowski</li><li><a href="https://www.isecpartners.com/SecurityQAToolbar.html">SecurityQA Toolbar</a> by iSEC Partners</li><li><a href="http://w3af.sourceforge.net/">W3AF</a> by Andres Riancho</li><li><a href="http://wapiti.sourceforge.net/">Wapiti</a> by Nicolas Surribas</li></ul><div class="shr-publisher-188"></div><h3  class="related_post_title">Related posts</h3><ul class="related_post"><li><a href="http://theweb3.net/news/reviews/google-wave-for-dummies.html" title="Google wave for dummies">Google wave for dummies</a></li><li><a href="http://theweb3.net/tips-tricks/using-gmail-advanced-search.html" title="Using Gmail advanced search">Using Gmail advanced search</a></li><li><a href="http://theweb3.net/news/reviews/content-aware-fill-in-adobe-creative-suite-5.html" title="Content-Aware Fill in Adobe Creative Suite 5 ">Content-Aware Fill in Adobe Creative Suite 5 </a></li><li><a href="http://theweb3.net/news/tech-news/android-running-on-windows-mobile.html" title="Android running on Windows Mobile">Android running on Windows Mobile</a></li><li><a href="http://theweb3.net/news/tech-news/google-phone-nexus-one.html" title="Google Phone &#8211; Nexus One">Google Phone &#8211; Nexus One</a></li></ul>]]></content:encoded> <wfw:commentRss>http://theweb3.net/programming/web-development-programming/skipfish-web-application-security-scanner.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: basic (User agent is rejected)
Database Caching 11/42 queries in 0.027 seconds using disk: basic

Served from: theweb3.net @ 2012-05-20 23:01:25 -->
