<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Secure2S &#187; Web Vulnerability Scanners</title>
	<atom:link href="http://secure2s.net/en/category/tools/web-scanners/feed/" rel="self" type="application/rss+xml" />
	<link>http://secure2s.net/en</link>
	<description>Security Tools</description>
	<lastBuildDate>Sat, 10 Jul 2010 13:44:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>N-Stealth</title>
		<link>http://secure2s.net/en/tools/web-scanners/n-stealth/243/</link>
		<comments>http://secure2s.net/en/tools/web-scanners/n-stealth/243/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 13:46:45 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Web Vulnerability Scanners]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=243</guid>
		<description><![CDATA[N-Stealth : Web server scanner N-Stealth is a commercial web server security scanner. It is generally updated more frequently than free web scanners such as Whisker/libwhisker and Nikto, but do take their web site with a grain of salt. The claims of &#8220;30,000 vulnerabilities and exploits&#8221; and &#8220;Dozens of vulnerability checks are added every day&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.nstalker.com/nstealth/">N-Stealth</a> : Web server scanner<br />
N-Stealth is a commercial web server security scanner. It is generally updated more frequently than free web scanners such as <a href="http://sectools.org/tools3.html#whisker-libwhisker">Whisker/libwhisker</a> and <a href="http://sectools.org/index.html#nikto">Nikto</a>, but do take their web site with a grain of salt. The claims of &#8220;30,000 vulnerabilities and exploits&#8221; and &#8220;Dozens of vulnerability checks are added every day&#8221; are highly questionable. Also note that essentially all general VA tools such as <a href="http://sectools.org/index.html#nessus">Nessus</a>, <a href="http://sectools.org/tools3.html#iss">ISS Internet Scanner</a>, <a href="http://sectools.org/tools2.html#retina">Retina</a>, <a href="http://sectools.org/tools4.html#saint">SAINT</a>, and <a href="http://sectools.org/tools3.html#sara">Sara</a> include web scanning components. They may not all be as up-to-date or flexible though. N-Stealth is Windows only and no source code is provided.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fweb-scanners%2Fn-stealth%2F243%2F&amp;title=N-Stealth"><img src="http://secure2s.net/en/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/web-scanners/n-stealth/243/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watchfire AppScan</title>
		<link>http://secure2s.net/en/tools/web-scanners/watchfire-appscan/239/</link>
		<comments>http://secure2s.net/en/tools/web-scanners/watchfire-appscan/239/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 13:44:46 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Web Vulnerability Scanners]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=239</guid>
		<description><![CDATA[Watchfire AppScan : Commercial Web Vulnerability Scanner AppScan provides security testing throughout the application development lifecycle, easing unit testing and security assurance early in the development phase. Appscan scans for many common vulnerabilities, such as cross site scripting, HTTP response splitting, parameter tampering, hidden field manipulation, backdoors/debug options, buffer overflows and more.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.watchfire.com/products/appscan/default.aspx">Watchfire AppScan</a> : Commercial Web Vulnerability Scanner<br />
AppScan provides security testing throughout the application development lifecycle, easing unit testing and security assurance early in the development phase. Appscan scans for many common vulnerabilities, such as cross site scripting, HTTP response splitting, parameter tampering, hidden field manipulation, backdoors/debug options, buffer overflows and more.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fweb-scanners%2Fwatchfire-appscan%2F239%2F&amp;title=Watchfire%20AppScan"><img src="http://secure2s.net/en/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/web-scanners/watchfire-appscan/239/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Acunetix WVS</title>
		<link>http://secure2s.net/en/tools/web-scanners/acunetix-wvs/233/</link>
		<comments>http://secure2s.net/en/tools/web-scanners/acunetix-wvs/233/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 13:43:14 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Web Vulnerability Scanners]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=233</guid>
		<description><![CDATA[Acunetix WVS : Commercial Web Vulnerability Scanner Acunetix WVS automatically checks web applications for vulnerabilities such as SQL Injections, cross site scripting, arbitrary file creation/deletion, weak password strength on authentication pages. AcuSensor technology detects vulnerabilities which typical black box scanners miss. Acunetix WVS boasts a comfortable GUI, an ability to create professional security audit and [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.acunetix.com/">Acunetix WVS</a> : Commercial Web Vulnerability Scanner<br />
Acunetix WVS automatically checks web applications for vulnerabilities such as SQL Injections, cross site scripting, arbitrary file creation/deletion, weak password strength on authentication pages. AcuSensor technology detects vulnerabilities which typical black box scanners miss. Acunetix WVS boasts a comfortable GUI, an ability to create professional security audit and compliance reports, and tools for advanced manual webapp testing.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fweb-scanners%2Facunetix-wvs%2F233%2F&amp;title=Acunetix%20WVS"><img src="http://secure2s.net/en/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/web-scanners/acunetix-wvs/233/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wikto</title>
		<link>http://secure2s.net/en/tools/web-scanners/wikto/198/</link>
		<comments>http://secure2s.net/en/tools/web-scanners/wikto/198/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 12:37:57 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Web Vulnerability Scanners]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=198</guid>
		<description><![CDATA[Wikto : Web Server Assessment Tool Wikto is a tool that checks for flaws in webservers. It provides much the same functionality as Nikto but adds various interesting pieces of functionality, such as a Back-End miner and close Google integration. Wikto is written for the MS .NET environment and registration is required to download the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.sensepost.com/research/wikto/">Wikto</a> : Web Server Assessment Tool<br />
Wikto is a tool that checks for flaws in webservers. It provides much the same functionality as <a href="http://sectools.org/index.html#nikto">Nikto</a> but adds various interesting pieces of functionality, such as a Back-End miner and close <a href="http://sectools.org/tools2.html#google">Google</a> integration. Wikto is written for the MS .NET environment and registration is required to download the binary and/or source code.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fweb-scanners%2Fwikto%2F198%2F&amp;title=Wikto"><img src="http://secure2s.net/en/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/web-scanners/wikto/198/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Burpsuite</title>
		<link>http://secure2s.net/en/tools/web-scanners/burpsuite/183/</link>
		<comments>http://secure2s.net/en/tools/web-scanners/burpsuite/183/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 10:18:47 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Web Vulnerability Scanners]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=183</guid>
		<description><![CDATA[Burpsuite : An integrated platform for attacking web applications Burp suite allows an attacker to combine manual and automated techniques to enumerate, analyze, attack and exploit web applications. The various burp tools work together effectively to share information and allow findings identified within one tool to form the basis of an attack using another.]]></description>
			<content:encoded><![CDATA[<p><a href="http://portswigger.net/suite/">Burpsuite</a> : An integrated platform for attacking web applications<br />
Burp suite allows an attacker to combine manual and automated techniques to enumerate, analyze, attack and exploit web applications. The various burp tools work together effectively to share information and allow findings identified within one tool to form the basis of an attack using another.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fweb-scanners%2Fburpsuite%2F183%2F&amp;title=Burpsuite"><img src="http://secure2s.net/en/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/web-scanners/burpsuite/183/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>QualysGuard</title>
		<link>http://secure2s.net/en/tools/web-scanners/qualysguard/175/</link>
		<comments>http://secure2s.net/en/tools/web-scanners/qualysguard/175/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 09:49:04 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Web Vulnerability Scanners]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=175</guid>
		<description><![CDATA[QualysGuard : A web-based vulnerability scanner Delivered as a service over the Web, QualysGuard eliminates the burden of deploying, maintaining, and updating vulnerability management software or implementing ad-hoc security applications. Clients securely access QualysGuard through an easy-to-use Web interface. QualysGuard features 5,000+ unique vulnerability checks, an Inference-based scanning engine, and automated daily updates to the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.qualys.com/">QualysGuard</a> : A web-based vulnerability scanner<br />
Delivered as a service over the Web, QualysGuard eliminates the burden of deploying, maintaining, and updating vulnerability management software or implementing ad-hoc security applications. Clients securely access QualysGuard through an easy-to-use Web interface. QualysGuard features 5,000+ unique vulnerability checks, an Inference-based scanning engine, and automated daily updates to the QualysGuard vulnerability KnowledgeBase.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fweb-scanners%2Fqualysguard%2F175%2F&amp;title=QualysGuard"><img src="http://secure2s.net/en/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/web-scanners/qualysguard/175/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Whisker_libwhisker</title>
		<link>http://secure2s.net/en/tools/web-scanners/whisker_libwhisker/168/</link>
		<comments>http://secure2s.net/en/tools/web-scanners/whisker_libwhisker/168/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 09:43:15 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Web Vulnerability Scanners]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=168</guid>
		<description><![CDATA[Whisker/libwhisker : Rain.Forest.Puppy&#8217;s CGI vulnerability scanner and library Libwhisker is a Perl module geared geared towards HTTP testing. It provides functions for testing HTTP servers for many known security holes, particularly the presence of dangerous CGIs. Whisker is a scanner that used libwhisker but is now deprecated in favor of Nikto which also uses libwhisker.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.wiretrip.net/rfp/">Whisker/libwhisker</a> : Rain.Forest.Puppy&#8217;s CGI vulnerability scanner and library<br />
Libwhisker is a Perl module geared geared towards HTTP testing. It provides functions for testing HTTP servers for many known security holes, particularly the presence of dangerous CGIs. Whisker is a scanner that used libwhisker but is now deprecated in favor of <a href="http://sectools.org/index.html#nikto">Nikto</a> which also uses libwhisker.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fweb-scanners%2Fwhisker_libwhisker%2F168%2F&amp;title=Whisker_libwhisker"><img src="http://secure2s.net/en/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/web-scanners/whisker_libwhisker/168/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WebInspect</title>
		<link>http://secure2s.net/en/tools/web-scanners/webinspect/100/</link>
		<comments>http://secure2s.net/en/tools/web-scanners/webinspect/100/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 09:03:55 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Web Vulnerability Scanners]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=100</guid>
		<description><![CDATA[WebInspect : A Powerful Web Application Scanner SPI Dynamics&#8217; WebInspect application security assessment tool helps identify known and unknown vulnerabilities within the Web application layer. WebInspect can also help check that a Web server is configured properly, and attempts common web attacks such as parameter injection, cross-site scripting, directory traversal, and more.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spidynamics.com/products/webinspect/">WebInspect</a> : A Powerful Web Application Scanner<br />
SPI Dynamics&#8217; WebInspect application security assessment tool helps identify known and unknown vulnerabilities within the Web application layer. WebInspect can also help check that a Web server is configured properly, and attempts common web attacks such as parameter injection, cross-site scripting, directory traversal, and more.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fweb-scanners%2Fwebinspect%2F100%2F&amp;title=WebInspect"><img src="http://secure2s.net/en/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/web-scanners/webinspect/100/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WebScarab</title>
		<link>http://secure2s.net/en/tools/web-scanners/webscarab/88/</link>
		<comments>http://secure2s.net/en/tools/web-scanners/webscarab/88/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 08:55:56 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Web Vulnerability Scanners]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=88</guid>
		<description><![CDATA[WebScarab : A framework for analyzing applications that communicate using the HTTP and HTTPS protocols In its simplest form, WebScarab records the conversations (requests and responses) that it observes, and allows the operator to review them in various ways. WebScarab is designed to be a tool for anyone who needs to expose the workings of [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project">WebScarab</a> : A framework for analyzing applications that communicate using the HTTP and HTTPS protocols<br />
In its simplest form, WebScarab records the conversations (requests and responses) that it observes, and allows the operator to review them in various ways. WebScarab is designed to be a tool for anyone who needs to expose the workings of an HTTP(S) based application, whether to allow the developer to debug otherwise difficult problems, or to allow a security specialist to identify vulnerabilities in the way that the application has been designed or implemented.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fweb-scanners%2Fwebscarab%2F88%2F&amp;title=WebScarab"><img src="http://secure2s.net/en/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/web-scanners/webscarab/88/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Paros proxy</title>
		<link>http://secure2s.net/en/tools/web-scanners/paros-proxy/43/</link>
		<comments>http://secure2s.net/en/tools/web-scanners/paros-proxy/43/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 08:21:42 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Web Vulnerability Scanners]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=43</guid>
		<description><![CDATA[Paros proxy : A web application vulnerability assessment proxy A Java based web proxy for assessing web application vulnerability. It supports editing/viewing HTTP/HTTPS messages on-the-fly to change items such as cookies and form fields. It includes a web traffic recorder, web spider, hash calculator, and a scanner for testing common web application attacks such as [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.parosproxy.org/">Paros proxy</a> : A web application vulnerability assessment proxy<br />
A Java based web proxy for assessing web application vulnerability. It supports editing/viewing HTTP/HTTPS messages on-the-fly to change items such as cookies and form fields. It includes a web traffic recorder, web spider, hash calculator, and a scanner for testing common web application attacks such as SQL injection and cross-site scripting.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fweb-scanners%2Fparos-proxy%2F43%2F&amp;title=Paros%20proxy"><img src="http://secure2s.net/en/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/web-scanners/paros-proxy/43/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

