8

What are your favorite tools for checking for vulnerabilities in websites?

Adam
  • 2,810
  • 22
  • 18
Esteban Araya
  • 921
  • 1
  • 8
  • 7

9 Answers9

9

I've used Nessus before. It takes a bit to setup, but has a pretty comprehensive set of tests.

Steven Behnke
  • 335
  • 2
  • 3
4

nmap is great for giving you the ports that are open and what is running on them

trent
  • 3,114
  • 19
  • 17
1

WebInspect is pretty good, but pricey. It takes a lot of handholding as well, not a lot of automated use.

Bill Weiss
  • 10,979
  • 3
  • 38
  • 66
1
K. Brian Kelley
  • 9,034
  • 32
  • 33
0

Check insecure Dot Org... and web scanner There are lots of great security tools there. Some are open source, other are commercial.. nikto praros proxy web scarab web inspect burpsuit whisker wikto acunetix wvs watchfire appscan n-Stealth

Bit Hammer
  • 23
  • 5
0

It's not free, but McAfee Secure does an excellent job and provides very detailed reporting.

Justin Scott
  • 8,798
  • 1
  • 28
  • 39
0

hping

GregD
  • 8,713
  • 1
  • 24
  • 36
0

I suggest you to use a commercial web application security scanner.A list of WASS : http://www.webscanners.net/webscanners/index.html

0

i prefer nessus as wonderful tool that is easy to use

jakarta512
  • 127
  • 8