Download Web Vulnerability Scanner v5.1.70829
February 26, 2008
Audit your website security with Acunetix Web Vulnerability Scanner
Website security is possibly today's most overlooked aspect of securing the
enterprise and should be a priority in any organization. Hackers are
concentrating their efforts on web-based applications - shopping carts, forms,
login pages, dynamic content, etc. Web applications are accessible 24 hours a
day, 7 days a week and control valuable data since they often have direct access
to backend data such as customer databases.
Firewalls, SSL and locked-down servers are futile against web application
hacking
Any defense at network security level will provide no protection against web
application attacks since they are launched on port 80 - which has to remain
open. In addition, web applications are often tailor-made therefore tested less
than off-the-shelf software and are more likely to have undiscovered
vulnerabilities. Acunetix WVS automatically checks your web applications for SQL
Injection, XSS & other web vulnerabilities.
Audit your web site security with Acunetix Web Vulnerability Scanner
If web applications are not secure, then your entire database of sensitive
information is at serious risk. Why?
Websites and related web applications must be available 24 x 7 to provide the
required service to customers, employees, suppliers and other stakeholders
Firewalls and SSL provide no protection against web application hacking, simply
because access to the website has to be made public
Web applications often have direct access to backend data such as customer
databases and, hence, control valuable data and are much more difficult to
secure
Custom applications are more susceptible to attack because they involve a lesser
degree of testing than off-the-shelf software
Hackers prefer gaining access to the sensitive data because of the immense
pay-offs in selling the data.
Acunetix Web Vulnerability Scanner (WVS) is an automated web application
security testing tool that audits your web applications by checking for
exploitable hacking vulnerabilities. Automated scans may be supplemented and
cross-checked with the variety of manual tools to allow for comprehensive web
site and web application penetration testing.
In depth checking for SQL Injection, Cross Site Scripting (XSS) and Other
Vulnerabilities
Acunetix checks for all web vulnerabilities including SQL injection, Cross site
scripting and others. SQL injection is a hacking technique which modifies SQL
commands in order to gain access to data in the database. Cross site scripting
attacks allow a hacker to execute a malicious script on your visitor’s browser.
Detection of these vulnerabilities requires a sophisticated detection engine.
Paramount to web vulnerability scanning is not the number of attacks that a
scanner can detect, but the complexity and thoroughness with the scanner
launches SQL injection, Cross Site scripting and other attacks. Acunetix has a
state of the art vulnerability detection engine which quickly finds
vulnerabilities with a low number of false positives. It also locates CRLF
injection, Code execution, Directory Traversal, File inclusion and
Authentication vulnerabilities.
Scan AJAX and Web 2.0 technologies for vulnerabilities
The state of the art javascript analyzer allows you to comprehensively scan the
latest and most complex AJAX / Web 2.0 web applications and find
vulnerabilities.
Detailed reports enable you to meet Legal and Regulatory Compliance
Acunetix Web vulnerability scanner includes an extensive reporting module which
can generate reports that show whether your web applications meet the new VISA
PCI Data Compliance requirements.
Analyzes your site against the Google Hacking Database
The Google Hacking Database (GHDB) is a database of queries used by hackers to
identify sensitive data on your website such as portal logon pages, logs with
network security information, and so on. Acunetix launches the Google hacking
database queries onto the crawled content of your web site and identifies
sensitive data or exploitable targets before a “search engine hacker” does.
Advanced penetration testing tools included
In addition to its automated scanning engine, Acunetix includes advanced tools
to allow penetration testers to fine tune web application security checks:
HTTP Editor - With this tool you can easily construct HTTP/HTTPS requests and
analyze the web server response.
HTTP Sniffer - Intercept, log and modify all HTTP/HTTPS traffic and reveal all
data sent by a web application
HTTP Fuzzer - Performs sophisticated testing for buffer overflows and input
validation. Test thousands of input variables with the easy to use rule builder
of the HTTP fuzzer. Tests that would have taken days to perform manually can now
be done in minutes.
Create custom attacks or modify existing ones with the Web Vulnerability Editor
Size :
Download
Web Vulnerability Scanner v5.1.70829
|