Website Security Scanners

Pyxis

Platinum Member
Jan 28, 2001
2,554
0
76
I'm looking for some recommendations on decent website security scanners. Something that will scan my site directory structure and tell me if there are any vulnerabilities.

Thanks
 

kamper

Diamond Member
Mar 18, 2003
5,513
0
0
Are you thinking of something that runs locally or actually analyses via the web?
 

kamper

Diamond Member
Mar 18, 2003
5,513
0
0
Tbh, I don't have anything to recommend and I'm sure there's stuff out there that can do far more than I'm imagining, but nothing that analyzes via the web can give you any real guarantee of security. Via the web, it can't analyze your php (or other dynamic content) for coding errors, it can't detect files that aren't linked directly (unless you have directory listings on for every dir) and it can't do things like analyze for appropriate file permissions. I'd recommend following the vulnerability reports for all products you use and doing a common sense scan of what you have up there by hand.

For instance, I recently discovered that a php blog I'd been running had been hacked. I could have prevented it by:
1) checking back at the website where I found it, because the vulnerability had been fixed months ago
2) putting sane write permissions on everything that the webserver has access to (the exploit should not have had permission to create the directories it did)
3) doing a basic scan of the product and hacking out things that I wasn't going to use and/or that were just begging for trouble (like image upload, or allowing a hacker to download the password hash)

Of course if you've done that and still want a tool (sounds like this is a business willing to throw money at it), then go nuts
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |