Answer the question
In order to leave comments, you need to log in
Pentest utilities - reviews?
I would like to hear feedback on commercial solutions for automated site penetration testing.
A dry squeeze from foreign blogs is of course also not bad, but the experience of living people will also be interesting to listen to.
Answer the question
In order to leave comments, you need to log in
For me, the following tools are not bad at all:
from open source:
w3af
OWASP ZAP
And if it is commercial, then:
Acunetix Web Vulnerability Scanner , but it is under Windows.
I recommend paying attention to BackTrack .
This is a distribution for security auditing.
The already mentioned Burp Suite is the best open source solution.
I worked on one site that was regularly attacked and had to be constantly "raised". I used scanners from Positive Technologies and METASCAN , both are good, but I liked METASCAN more, it had a more understandable interface and a fairly detailed scan report. In addition, I scanned not only for web vulnerabilities, I also checked system vulnerabilities and even, for the sake of interest, tried to brute SSH. In general, I scanned the entire infrastructure and found vulnerabilities in OpenSSH and a couple of pages with XSS, after I corrected everything, the site stopped "falling".
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question