|
| |||||||||
| Tags: nikto, security scanner, web application |
![]() |
| | Thread Tools | Search this Thread |
|
#1
| |||
| |||
| Web application security scanner
Can any one tell me why security scanner are required for web application. How it works and what are different scanner are available for scanning web application. |
|
#2
| ||||
| ||||
| Re: Web application security scanner
A web application security scanner is program which communicates with a web application through the web front-end in order to identify potential security vulnerabilities in the web application and architectural weaknesses. It performs a black-box test. Unlike source code scanners, web application scanners don't have access to the source code and therefore detect vulnerabilities by actually performing attacks. |
|
#3
| ||||
| ||||
| Re: Web application security scanner
Nikto Web Scanner is a Web server scanner that scan web application for dangerous files/CGIs, outdated server software and other problems. Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3500 potentially dangerous files/CGIs, versions on over 900 servers, and version specific problems on over 250 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired). |
|
#4
| ||||
| ||||
| Re: Web application security scanner
WebScarab is a framework for analysing applications that communicate using the HTTP and HTTPS protocols. It is written in Java, and is thus portable to many platforms. WebScarab has several modes of operation, implemented by a number of plugins. In its most common usage, WebScarab operates as an intercepting proxy, allowing the operator to review and modify requests created by the browser before they are sent to the server, and to review and modify responses returned from the server before they are received by the browser. WebScarab is able to intercept both HTTP and HTTPS communication. The operator can also review the conversations (requests and responses) that have passed through WebScarab. |
|
#5
| |||
| |||
| Re: Web application security scanner
well, WebScarab and Nikto Web Scanner are both free web scanners. If you want a commercial web application scanner ,i can introduce you Matrixay 3.0. It is a web application vulnerability scanner based on in-depth analysis of typical security vulnerabilities as well as popular attack techniques in B/S structure application system. Last edited by rupesh : 09-10-2009 at 05:30 PM. Reason: Link removed |
![]() |
|
| Thread Tools | Search this Thread |
| |
Similar Threads for: "Web application security scanner" | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Is Windows Live OneCare security scanner of any use | lickdafun | Networking & Security | 5 | 10-05-2011 12:30 PM |
| Skipfish - Web App Security Scanner | Dewei | Technology & Internet | 6 | 10-05-2010 11:51 PM |
| Nmap Vs Nessus Security Scanner | CrazeD | Windows Software | 4 | 11-11-2009 07:29 PM |
| Barcode Scanner a new Android Application | monsitj | Portable Devices | 3 | 02-04-2009 06:37 PM |
| Problem with Norton Security Scanner | Ashlin | Networking & Security | 3 | 29-01-2009 12:03 PM |