Results 1 to 5 of 5

Thread: Web application security scanner

  1. #1
    Join Date
    Apr 2009
    Posts
    36

    Web application security scanner

    Can any one tell me why security scanner are required for web application. How it works and what are different scanner are available for scanning web application.

  2. #2
    Join Date
    Jan 2006
    Posts
    4,221

    Re: Web application security scanner

    A web application security scanner is program which communicates with a web application through the web front-end in order to identify potential security vulnerabilities in the web application and architectural weaknesses. It performs a black-box test. Unlike source code scanners, web application scanners don't have access to the source code and therefore detect vulnerabilities by actually performing attacks.

  3. #3
    Join Date
    May 2008
    Posts
    2,945

    Re: Web application security scanner

    Nikto Web Scanner is a Web server scanner that scan web application for dangerous files/CGIs, outdated server software and other problems. Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3500 potentially dangerous files/CGIs, versions on over 900 servers, and version specific problems on over 250 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired).

  4. #4
    Join Date
    Jan 2006
    Posts
    3,792

    Re: Web application security scanner

    WebScarab is a framework for analysing applications that communicate using the HTTP and HTTPS protocols. It is written in Java, and is thus portable to many platforms. WebScarab has several modes of operation, implemented by a number of plugins. In its most common usage, WebScarab operates as an intercepting proxy, allowing the operator to review and modify requests created by the browser before they are sent to the server, and to review and modify responses returned from the server before they are received by the browser. WebScarab is able to intercept both HTTP and HTTPS communication. The operator can also review the conversations (requests and responses) that have passed through WebScarab.

  5. #5
    Join Date
    Oct 2009
    Posts
    3

    Re: Web application security scanner

    well, WebScarab and Nikto Web Scanner are both free web scanners.
    If you want a commercial web application scanner ,i can introduce you Matrixay 3.0. It is a web application vulnerability scanner based on in-depth analysis of typical security vulnerabilities as well as popular attack techniques in B/S structure application system.
    Last edited by rupesh; 09-10-2009 at 04:30 PM. Reason: Link removed

Similar Threads

  1. Help with a scanner application
    By Dave_Steven in forum Software Development
    Replies: 4
    Last Post: 24-04-2012, 03:26 PM
  2. Is Windows Live OneCare security scanner of any use
    By lickdafun in forum Networking & Security
    Replies: 5
    Last Post: 10-05-2011, 11:30 AM
  3. Skipfish - Web App Security Scanner
    By Dewei in forum Technology & Internet
    Replies: 6
    Last Post: 10-05-2010, 10:51 PM
  4. Nmap Vs Nessus Security Scanner
    By CrazeD in forum Windows Software
    Replies: 4
    Last Post: 11-11-2009, 07:29 PM
  5. Problem with Norton Security Scanner
    By Ashlin in forum Networking & Security
    Replies: 3
    Last Post: 29-01-2009, 12:03 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,751,854,963.24482 seconds with 16 queries