Esteban Araya Asked: 2009-05-01 12:27:38 +0800 CST2009-05-01 12:27:38 +0800 CST 2009-05-01 12:27:38 +0800 CST What tools do you use for vulnerability scanning? 772 What are your favorite tools for checking for vulnerabilities in websites? security web-server 9 Answers Voted Steven Behnke 2009-05-01T12:29:29+08:002009-05-01T12:29:29+08:00 I've used Nessus before. It takes a bit to setup, but has a pretty comprehensive set of tests. trent 2009-05-01T13:18:12+08:002009-05-01T13:18:12+08:00 nmap is great for giving you the ports that are open and what is running on them K. Brian Kelley 2009-05-01T13:31:46+08:002009-05-01T13:31:46+08:00 HTTPrint Nessus (which, if installed on linux, typically has nmap as a port mapper) Qualys MetaSploit Fiddler WireShark Bill Weiss 2009-05-29T18:23:40+08:002009-05-29T18:23:40+08:00 WebInspect is pretty good, but pricey. It takes a lot of handholding as well, not a lot of automated use. Justin Scott 2009-05-01T13:50:57+08:002009-05-01T13:50:57+08:00 It's not free, but McAfee Secure does an excellent job and provides very detailed reporting. GregD 2009-05-01T14:43:34+08:002009-05-01T14:43:34+08:00 hping Bit Hammer 2009-05-29T16:01:41+08:002009-05-29T16:01:41+08:00 Check insecure Dot Org... and web scanner There are lots of great security tools there. Some are open source, other are commercial.. nikto praros proxy web scarab web inspect burpsuit whisker wikto acunetix wvs watchfire appscan n-Stealth Fyodor 2009-12-03T03:12:10+08:002009-12-03T03:12:10+08:00 I suggest you to use a commercial web application security scanner.A list of WASS : http://www.webscanners.net/webscanners/index.html jakarta512 2009-12-03T03:37:29+08:002009-12-03T03:37:29+08:00 i prefer nessus as wonderful tool that is easy to use
I've used Nessus before. It takes a bit to setup, but has a pretty comprehensive set of tests.
nmap is great for giving you the ports that are open and what is running on them
WebInspect is pretty good, but pricey. It takes a lot of handholding as well, not a lot of automated use.
It's not free, but McAfee Secure does an excellent job and provides very detailed reporting.
hping
Check insecure Dot Org... and web scanner There are lots of great security tools there. Some are open source, other are commercial.. nikto praros proxy web scarab web inspect burpsuit whisker wikto acunetix wvs watchfire appscan n-Stealth
I suggest you to use a commercial web application security scanner.A list of WASS : http://www.webscanners.net/webscanners/index.html
i prefer nessus as wonderful tool that is easy to use