找回密码
 注册账户
查看: 431|回复: 0

Acunetix Web Vulnerability Scanner Consultant Edition 8.0.20120305 Retail

[复制链接]
admin 发表于 2012-7-15 04:11:03 | 显示全部楼层 |阅读模式

Acunetix Web Vulnerability Scanner Consultant Edition 8.0.20120305 Retail | 51.3 MB

Acunetix Web Vulnerability Scanner automates the task of monitoring the security of Web applications and allows you to identify vulnerabilities in the protection of a web-site before they find the attacker and uses.

Website security is possibly today's most overlooked aspect of securing the enterprise and should be a priority in any organization. Hackers are concentrating their efforts on web-based applications - shopping carts, forms, login pages, dynamic content, etc. Web applications are accessible 24 hours a day, 7 days a week and control valuable data since they often have direct access to backend data such as customer databases. Firewalls, SSL and locked-down servers are futile against web application hacking Any defense at network security level will provide no protection against web application attacks since they are launched on port 80 - which has to remain open. In addition, web applications are often tailor-made therefore tested less than off-the-shelf software and are more likely to have undiscovered vulnerabilities. Acunetix WVS automatically checks your web applications for SQL Injection, XSS & other web vulnerabilities.

How does Acunetix Web Vulnerability Scanner:

Acunetix Web Vulnerability Scanner (WVS) works as follows:
Acunetix WVS explores and forms the structure of the site, handling all the found links, and collecting information about all detected files;
The program then tests all web-pages with elements for data entry, data entry modeling using all possible combinations and analyzing the results;
Finding vulnerabilities, Acunetix WVS provides a warning that describes the vulnerabilities and recommendations for its elimination;
The final report of WVS can be written to a file for further analysis and comparison with results of previous audits.
What reveals the vulnerability of Acunetix Web Vulnerability Scanner
Acunetix Web Vulnerability Scanner automatically detects the following vulnerabilities:
Cross site scripting (execution of malicious script in the user's browser in the handling and security in the context of a trusted site);
SQL injection (also Blind injective, but yet he only finds the injection site - but it does not make itself an injection)
Database GHDB (Google hacking database) - a list of typical queries used by hackers to gain unauthorized access to web-applications and websites.
Running the code:
Bypass the catalog;
Box files (File inclusion);
Disclosure of source scenario;
CRLF injection
Cross frame scripting;
Public backup files and folders;
Files and folders that contain important information;
Files that contain information necessary to carry out attacks (system logs, trace logs, applications, etc.);
Files containing lists of folders;
Folder with a low level of protection, allowing you to create, modify, or delete files.
And also identifies the involved server technology (WebDAV, FrontPage, etc.) and permission to use potentially dangerous http-methods (PUT, TRACE, DELETE).

Audit your web site security with Acunetix Web Vulnerability Scanner

If web applications are not secure, then your entire database of sensitive information is at serious risk. Why?

?Websites and related web applications must be available 24 x 7 to provide the required service to customers, employees, suppliers and other stakeholders
?Firewalls and SSL provide no protection against web application hacking, simply because access to the website has to be made public
?Web applications often have direct access to backend data such as customer databases and, hence, control valuable data and are much more difficult to secure
?Custom applications are more susceptible to attack because they involve a lesser degree of testing than off-the-shelf software
?Hackers prefer gaining access to the sensitive data because of the immense pay-offs in selling the data.

In depth checking for SQL Injection, Cross Site Scripting (XSS) and Other Vulnerabilities

Acunetix checks for all web vulnerabilities including SQL injection, Cross site scripting and others. SQL injection is a hacking technique which modifies SQL commands in order to gain access to data in the database. Cross site scripting attacks allow a hacker to execute a malicious script on your visitor's browser.

Detection of these vulnerabilities requires a sophisticated detection engine. Paramount to web vulnerability scanning is not the number of attacks that a scanner can detect, but the complexity and thoroughness with the scanner launches SQL injection, Cross Site scripting and other attacks. Acunetix has a state of the art vulnerability detection engine which quickly finds vulnerabilities with a low number of false positives. It also locates CRLF injection, Code execution, Directory Traversal, File inclusion and Authentication vulnerabilities.

Scan AJAX and Web 2.0 technologies for vulnerabilities

The state of the art javascript analyzer allows you to comprehensively scan the latest and most complex AJAX / Web 2.0 web applications and find vulnerabilities.

Detailed reports enable you to meet Legal and Regulatory Compliance

Acunetix Web vulnerability scanner includes an extensive reporting module which can generate reports that show whether your web applications meet the new VISA PCI Data Compliance requirements.

Analyzes your site against the Google Hacking Database

The Google Hacking Database (GHDB) is a database of queries used by hackers to identify sensitive data on your website such as portal logon pages, logs with network security information, and so on. Acunetix launches the Google hacking database queries onto the crawled content of your web site and identifies sensitive data or exploitable targets before a "search engine hacker" does.

Advanced penetration testing tools included

In addition to its automated scanning engine, Acunetix includes advanced tools to allow penetration testers to fine tune web application security checks:

?HTTP Editor - With this tool you can easily construct HTTP / HTTPS requests and analyze the web server response.
?HTTP Sniffer - Intercept, log and modify all HTTP / HTTPS traffic and reveal all data sent by a web application
?HTTP Fuzzer - Performs sophisticated testing for buffer overflows and input validation. Test thousands of input variables with the easy to use rule builder of the HTTP fuzzer. Tests that would have taken days to perform manually can now be done in minutes.
?Create custom attacks or modify existing ones with the Web Vulnerability Editor

Test password protected areas and web forms with Automatic HTML form filler

Acunetix Web Vulnerability Scanner is able to automatically fill in web forms and authenticate against web logins. Most web vulnerability scanners are unable to do this or require complex scripting to test these pages. Not so with Acunetix: Using the macro recording tool you can record a logon or form filling process and store the sequence. The scanner can then replay this sequence during the scan process and fill in web forms automatically or logon to password protected areas.

Download Links
Download Uploaded
http://ul.to/0alxyxq7/webvulnscan8.rar

Download RapidGator
http://rapidgator.net/file/776177/webvulnscan8.rar.html
您需要登录后才可以回帖 登录 | 注册账户

本版积分规则

存档|黑屋|手机|网络实验室 本站服务器由美国合租以及IDCLayer国际数据提供!!!

GMT+8, 2026-6-6 15:39 , Processed in 0.008331 second(s), 5 queries , Gzip On, Redis On.

Powered by Discuz! X3.5

© 2001-2025 Discuz! Team.

快速回复 返回顶部 返回列表