WINDOWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>

WEEKLY HIGHLIGHTS

DVD Cloner45
Spyware Doctor40
1Click DVD Copy40
Apollo DVD Copy40
ABC Amber BlackBer...45
Protected Music Co...40

7-DAY TOP DOWNLOAD

#
Program
Avira AntiVir
Personal - Free
Antivirus 9.0.0.415

156,527
Windows Live
Messenger 2009
14.0.8089.726

133,723
Avira Antivir Virus
Definition File
Update November 27,
2009

115,807
Nexus Radio 4.2.2
115,644
FreeZ Online TV 1.30
87,708
Y! Multi Messenger
8.x and 9.x

67,581
Microsoft Office
2010 14.0.4536.1000
Beta / 2007

65,198
DVD Shrink 3.2.0.15
47,260
Windows Live
Messenger
8.5.1302.1018

47,185
AVG Free Edition 9.0
Build 707a1765

42,129

WEEK'S BEST

  • VirtualBox 3.1.0 r...
  • SiSoftware Sandra ...
  • Kaspersky Virus Re...
  • Faststone Image Vi...
  • Vuze (formerly Azu...
  • Softpedia Wallpape...
  • Softpedia Wallpape...
  • Softpedia Wallpape...
  • RSSOwl 2.0.1
  • Internet Explorer ...
  • Online Armor ++ 4....
  • cFosSpeed 5.01 Bui...
  • SONY Vegas Pro 9.0...
  • Firefox 3.6 Beta 4...
  • Nokia Photos 1.6.434
  • Windows Server 200...
  • Skype Portable 4.1...
  • Google Chrome Port...
  • PCMark Vantage Bas...
  • Kaspersky Anti-Vir...
  • Microsoft Virtual ...
  • Messenger Plus! Li...
  • WinX DVD Author [F...
  • SoftPerfect Networ...
  • System Mechanic Pr...
  • Ad Muncher 4.81 Bu...
  • Windows 7 Upgrade ...
  • Pidgin 2.6.4
  • OpenOffice.org Dev...
  • VirtualDub 1.9.7 B...
  • Home > Windows > Internet > WEB Design > Source & Site Protectors
     Report spyware

    Acunetix Web Vulnerability Scanner 6.0 Build 20081028

    Download button

    Downloads: 24,266  Add to download basket  Tell us about an update
    User Rating:
    Rated by:
    Good (3.8/5)
    38 user(s)
    Developer:

    License / Price:

    Size / OS:

    Last Updated:

    Category:
    Acunetix | More programs
    Demo / USD 1445.00 | BUY the full version
    13.1 MB / Windows 2K / XP / 2003 / Vista
    November 1st, 2008, 08:10 GMT [view history]
    C: \ Internet \ WEB Design \ Source & Site Protectors

     Read user reviews (0)  Add a review  Refer to a friend  Subscribe

     

    Acunetix Web Vulnerability Scanner description

     

    This application first identifies web servers and then crawls the whole site gathering information about files.

    Acunetix Web Vulnerability Scanner first identifies web servers from a particular IP or IP range. After that, it crawls the whole site, gathering information about every file it finds, and displaying the entire website structure. After this discovery stage, it performs an automatic audit for common security issues.Acunetix Web Vulnerability Scanner is a software that automatically detects file inclusion.

    The Port Scanner and network alerts allow you to perform a port scan against the web server where the scanned website is running. When open ports are found, Acunetix WVS will perform complex network level security checks against the network service running on that port, such as DNS Open recursion tests, badly configured proxy server tests, weak SNMP community strings and many other network level security checks

    SQL Injection is one of the many web attack mechanisms used by hackers to steal data from organizations. It is perhaps one of the most common application layer attack techniques used today. It is the type of attack that takes advantage of improper coding of your web applications that allows hacker to inject SQL commands into say a login form to allow them to gain access to the data held within your database.

    In essence, SQL Injection arises because the fields available for user input allow SQL statements to pass through and query the database directly.

    Web applications allow legitimate website visitors to submit and retrieve data to/from a database over the Internet using their preferred web browser. Databases are central to modern websites – they store data needed for websites to deliver specific content to visitors and render information to customers, suppliers, employees and a host of stakeholders. User credentials, financial and payment information, company statistics may all be resident within a database and accessed by legitimate users through off-the-shelf and custom web applications. Web applications and databases allow you to regularly run your business.

    SQL Injection is the hacking technique which attempts to pass SQL commands (statements) through a web application for execution by the backend database. If not sanitized properly, web applications may result in SQL Injection attacks that allow hackers to view information from the database and/or even wipe it out.

    Such features as login pages, support and product request forms, feedback forms, search pages, shopping carts and the general delivery of dynamic content, shape modern websites and provide businesses with the means necessary to communicate with prospects and customers. These website features are all examples of web applications which may be either purchased off-the-shelf or developed as bespoke programs.

    These website features are all susceptible to SQL Injection attacks which arise because the fields available for user input allow SQL statements to pass through and query the database directly.

    Acunetix AcuSensor Technology is a new security technology that allows you to identify more vulnerabilities than a traditional Web Application Scanner, whilst generating less false positives. In addition it indicates exactly where in your code the vulnerability is. The increased accuracy is achieved by combining black box scanning techniques with dynamic code analyzes while the source code is executed

    Advantages of using Acunetix AcuSensor Technology:

    · Allows you to locate and fix the vulnerability faster because of the ability to provide more information about the vulnerability, such as source code line number, stack trace, affected SQL query.
    · We can significantly reduce false positives when scanning a website because we can internally understand better the behaviour of the web application.
    · Can alert you of web application configuration problems which could result in a vulnerable application or expose internal application details. E.g. If ‘custom errors’ are enabled in .NET, this could expose sensitive application details to a malicious user.
    · Detect many more SQL injection vulnerabilities. Previously SQL injection vulnerabilities could only be found if database errors were reported or via other common techniques.
    · Ability to detect SQL Injection vulnerabilities in all SQL statements, including in SQL INSERT statements. With a black box scanner such SQL injections vulnerabilities cannot be found.
    · Ability to know about all the files present and accessible though the web server. If an attacker will gain access to the website and create a backdoor file in the application directory, the file will be found and scanned when using the AcuSensor Technology and you will be alerted.
    · AcuSensor Technology is able to intercept all web application inputs and builds a comprehensive list will all possible inputs in the website and tests them.
    · No need to write URL rewrite rules when scanning web applications which use search engine friendly URL’s! Using AcuSensor Technology the scanner is able to rewrite SEO URL’s on the fly.
    · Ability to test for arbitrary file creating and deletion vulnerabilities. E.g. Through a vulnerable scripta malicious user can create a file in the web application directory and execute it to have privileged access, or delete sensitive web application files.
    · Ability to test for email injection. E.g. A malicious user may append additional information such as a list or recipients or additional information to the message body to a vulnerable web form, to spam a large number of recipients anonymously.

    Here are some key features of "Acunetix Web Vulnerability Scanner":

    Acunetix Web Vulnerability Scanner automatically detects the following vulnerabilities in web applications:
    · Cross site scripting
    · SQL injection
    · CRLF injection
    · Code execution
    · Directory traversal
    · File inclusion
    · Script source code disclosure
    · Discovers files/directories that may contain sensitive information
    · Looks for common files (such as logs, application traces, CVS web repositories), back-up files or directories
    · Finds directory listings
    · Discovers directories with weak permissions
    · Discovers available web server technologies (such as WebDAV, FrontPage, etc.)
    · Determines if dangerous HTTP methods are enabled on the web server (e.g. PUT, TRACE, DELETE)
    · Inspects the HTTP version banners and looks for vulnerable products
    · Tests password strength of applications.

    Extend attacks:
    · With Acunetix Web Vulnerability Scanner, you can construct HTTP/HTTPS requests and analyze the responses using the HTTP editor.

    Connection spy:
    · By enabling you to log, intercept and modify all HTTP/HTTPS traffic, Acunetix Web Vulnerability Scanner gives you an in-depth insight into what data your web application is sending.

    Test password strength:
    · To test the strength of your passwords, you can perform a dictionary attack on basic HTTP, NTLM or form-based authentication.

    Test database editor:
    · Acunetix Web Vulnerability Scanner includes a text database editor that permits you to add additional attacks to the test database (Enterprise & Consultant versions only).

    Supports all major web technologies:
    · Applications utilizing CGI, PHP, ASP, ASP.NET can all be tested for vulnerabilities.

    Scanning profiles:
    · Acunetix Web Vulnerability Scanner allows you to quickly scan sites with different options and identities.

    Reporting:
    · You can save scan sessions to MS SQL Server/Access databases and generate complex reports from previous scan sessions using information stored in the database.

    Requirements:

    · 128 MB of RAM (256MB or higher recommended)
    · 200 MB of available hard-disk space
    · Microsoft Internet Explorer 5.1 (or higher
    · Microsoft SQL Server / Access if database is enabled (optional)

    Limitations:

    · Nag screen
    · Does not allow saving and generation of scan reports

    What's New in This Release: [ read full changelog ]

    · New Revolutionary AcuSensor Technology for more accurate results
    · New Blind SQL Injector Tool New Port Scanner and Network Alerts
    · Further customization of false positives possible
    · Generates list of uncommon HTTP responses
    · Scans websites with NTLMv2 authentication

     Softpedia guarantees that Acunetix Web Vulnerability Scanner 6.0 Build 20081028 is 100% CLEAN, which means it does not contain any form of malware, including spyware, viruses, trojans and backdoors. [read more >]


    TAGS:

    Vulnerability Scanner | Web scanner | SQL injection | Vulnerability | scanner | detect



    HTML code for linking to this page:


    Go to top

    Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM