Results 1 to 7 of 7

Thread: Skipfish - Web App Security Scanner

  1. #1
    Join Date
    Apr 2010
    Posts
    84

    Skipfish - Web App Security Scanner

    Hello everyone,
    I just came to know that the Google is having open source security scanner. I want to collect information on the Skipfish - Web App Security Scanner. I just know that this is a fully automated, web application security force recognition tool. I am interested in knowing about the key features of it. Any other information related to the topic would be grateful.!! So, please provide some information as soon as possible.

  2. #2
    Join Date
    Feb 2007
    Posts
    234

    Re: Skipfish - Web App Security Scanner

    Google skipfish: a scanner website security Open Source. Its a fully automated, web application security force recognition tool. The following are some Key features of it :
    • High speed: pure C code, Highly optimized handling HTTP, minimal footprint CPU - Easily Achieving 2000 requests per second with responsive targets.
    • Ease of use: heuristics to Support a Variety of web frameworks and quirky mixed-technology sites, with automatic learning Capabilities, on-the-fly creation wordlist, and auto-completion form.
    • Cutting-edge security logic: high quality, low false positive differential security checks, capable of spotting a range of Subtle Flaws, Including Blind injection vectors.

  3. #3
    Join Date
    Feb 2009
    Posts
    266

    Re: Skipfish - Web App Security Scanner

    A rough list of the security checks Offered By The tool IS Outlined below :
    • High Risk Flaws (Potentially Leading to system compromise):
    • Server-side SQL Injection (Including blind vectors, Numerical parameters).
    • Explicit SQL-like syntax in GET or POST parameters.
    • Server-side shell command injection (Including blind vectors).
    • Server-side / XML, XPath injection (Including blind vectors).
    • Format string vulnerabilities.
    • Integer overflow vulnerabilities.
    • Rentals Accepting HTTP PUT.

  4. #4
    Join Date
    Feb 2009
    Posts
    673

    Re: Skipfish - Web App Security Scanner

    Google has launched an open source security scanner, under Apache license 2.0, for websites and web applications that allows developers to detect security vulnerabilities. Google launched an open source security scanner for developers, called Skipfish , which offers similar functionality to Nmap or Nessus example.

  5. #5
    Join Date
    Feb 2009
    Posts
    217

    Re: Skipfish - Web App Security Scanner

    I would like to tell explain some more things about the Skipfish which acts as a Security Scanner for the web applications. It uses heuristics automated, and can detect pieces of code that are vulnerable to attacks such as cross-scripting (XSS), SQL injections, but also XML and many others. The tool also provides a module for interpreting the results as a final report.

  6. #6
    Join Date
    Feb 2006
    Posts
    185

    Re: Skipfish - Web App Security Scanner

    Skipfish is a security analysis tool multi-platform, released under Apache license. Intended for developers of web sites and applications, Skipfish perform an audit of the code for security vulnerabilities. It is written in C, optimized for HTTP, it is presented as little use of CPU. It easily fill 2,000 requests per second with appropriate targets. The tool includes heuristics for most websites and is seen with machine learning capabilities. It also ensures the automatic completion of forms.

  7. #7
    Join Date
    Mar 2008
    Posts
    335

    Re: Skipfish - Web App Security Scanner

    A fully automated, active web application security tool Skipfish recognition is an active web application security tool recognition. It prepared annually for the Targeted Interactive sitemap site by Carrying out a recursive crawl and dictionary-based probes. The Resulting map is then annotated with the output from a number of active non-disruptive purpose Hopefully security checks. The final report generated by the tool is meant to serve as a foundation for professional web application security assessments.

Similar Threads

  1. Document Scanner vs. Droid Scan vs. Cam Scanner
    By Kusumanjali in forum Portable Devices
    Replies: 6
    Last Post: 16-07-2011, 10:28 PM
  2. Is Windows Live OneCare security scanner of any use
    By lickdafun in forum Networking & Security
    Replies: 5
    Last Post: 10-05-2011, 11:30 AM
  3. Nmap Vs Nessus Security Scanner
    By CrazeD in forum Windows Software
    Replies: 4
    Last Post: 11-11-2009, 07:29 PM
  4. Web application security scanner
    By Soggy Bottom in forum Networking & Security
    Replies: 4
    Last Post: 09-10-2009, 03:28 PM
  5. Problem with Norton Security Scanner
    By Ashlin in forum Networking & Security
    Replies: 3
    Last Post: 29-01-2009, 12:03 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,714,254,261.86209 seconds with 17 queries