TechSpott - Computer and technology forums

Go Back   TechSpott - Computer and technology forums > News
News Find here the latest news on windows and other popular windows related software!

Reply
 
Thread Tools Display Modes
Old March 21st, 2010, 12:08 PM   #1 (permalink)
mldebo
The Technical Man
 
mldebo's Avatar
 
Join Date: Feb 2010
Location: Iowa
Posts: 2,665
Thanks: 0
Thanked 1 Time in 1 Post
mldebo has a reputation beyond reputemldebo has a reputation beyond reputemldebo has a reputation beyond reputemldebo has a reputation beyond reputemldebo has a reputation beyond reputemldebo has a reputation beyond reputemldebo has a reputation beyond reputemldebo has a reputation beyond reputemldebo has a reputation beyond reputemldebo has a reputation beyond reputemldebo has a reputation beyond repute
Post Google releases skipfish, an application security tool

Google releases skipfish, an application security tool

As someone who manages web applications, skipfish is a really easy and quick way to run your website through a fairly comprehensive set of tests. Today, Google officially released the tool to the public in hopes to help make the web a safer place. On the flip side, a tool that does a good job of detecting vulnerabilities like this, will naturally be used by people looking to abuse it as well.

Skipfish runs through a set of tests which detect high, medium and low risk flaws. Some of the higher risk ones include:
Quote

Server-side SQL injection (including blind vectors, numerical parameters).
Explicit SQL-like syntax in GET or POST parameters.
Server-side shell command injection (including blind vectors).
原帖地址: TechSpott - Computer and technology forums http://www.techspott.com//showthread.php?p=1130
Server-side XML / XPath injection (including blind vectors).
Format string vulnerabilities.
Integer overflow vulnerabilities.



These specific flaws can lead to system compromise detecting them early, and proactively is surely something worth doing.

This isnt the only tool of its kind though. There are several free and commercial tools available that can do the same job (like Nikto2 and Nessus) in some cases better. In any case, its about time people started taking security seriously, and using a tool like this is a good step in the right direction.

Source: ZDNet
mldebo is offline   Reply With Quote Share with Facebook
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Google Chrome 4.1.249.1036 - Final amitash News 0 March 17th, 2010 05:49 PM
Apple patches Safari vulnerabilities ahead of Pwn2Own amitash News 0 March 12th, 2010 03:27 PM
Google launches the Google Apps marketplace amitash News 0 March 10th, 2010 06:26 AM
COMODO Internet Security 4.0.4167.742 Released amitash News 0 March 3rd, 2010 07:40 PM
Google Acquires Online Image Editing Tool Picnik amitash News 0 March 2nd, 2010 02:00 AM

 
Forum Stats
Members: 14,365
Threads: 20,373
Posts: 27,836
Total Online: 35

Newest Member: ddylanf

Latest Threads

Advertisements

Support our advertisers!

Amazon
Sears
Macys
1800flowers.com
Drugstore.com


Carbonite Online-Backups
Tiger Direct
Tech Depot
Buy.com
Office Depot
Fatcow
HostGator


TripsNow.us
Marriott
Expedia
CheapTickets.com
OneTravel
Hotwire

Are you a Fan?

Share this on Facebook

Tag Cloud

Partner Links


Contact Us - Home - Archive - Privacy Statement - Top - Copyright © 2009-2010, TechSpott - All times are GMT -4. Time is 05:42 PM

Powered by vBulletin® Copyright © Jelsoft Enterprises Ltd. :: SEO by vBSEO