Whitepaper: Managing Your Data Protection Infrastructure with the HP All-in-One Storage System and Data Protector Express Software. Click here to open this PDF.
 Internet.com ISP-Planet
Search ISP-Planet


Search internet.com
internet.com

IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

internet.commerce
Partner With Us
Corporate Awards
Rackmount LCD Monitor
Imprinted Gifts
Online Shopping
Promote Your Website
Domain registration
Data Center Solutions
Shop
Career Education
Online Education
Remote Online Backup
Promotional Pens
Promos and Premiums
Holiday Gift Ideas
ISP Technology

 

General

Security Tools for the Budget Conscious ISP, Part II: Web Vulnerability Assessment Tools

by Lisa Phifer
VP Core Competence, Inc.
[January 30, 2004]
Email a colleague

Web Vulnerability Assessment Tools
According to last year's FBI/CSI annual survey, one in four organizations experienced Web site attacks last year—primarily vandalism (36 percent) and DoS attacks (35 percent). Given this and the fact that most ISPs offer Web hosting, your toolbox should probably include utilities to assess the security of Web services, related objects, and supported applications.

Web assessment tools are aimed at popular Web server platforms like Apache or IIS. They can scan servers themselves for CVEs, missing patches, and weak directory permissions, and/or assess Web applications for vulnerabilities like cross-site scripting, SQL injection, hidden form field manipulation, and cookie poisoning. To learn more about Web application vulnerabilities and penetration test methodologies, we recommend Penetration Testing for Web Applications by Jody Melbourne and David Jorm, published by SecurityFocus as parts One, Two, and Three.

A few representative commercial products in this category include:

If Web hosting is your business, you should probably invest in at least one commercial Web vulnerability assessment product. Products like these will save you time in the long run by automating thorough tests and facilitating test result analysis. Even so, you may want to add some free Web penetration test tools to your security toolbox:

  • Nikto is a popular open source Web server scanner based on Perl. Nikto can test for over 2600 potentially dangerous files and look for version-specific problems on over 230 Web servers. To learn more, check out the Nikto README.
  • N-Stalker's N-Stealth is available in a free version that runs on Win32 and WINE for Linux. N-Stealth tests Web servers for over 30,000 weaknesses that attackers could exploit to gain privileged server access. Unlike the commercial version, the free version does not support IP ranges, log analysis, or SSL/XML testing. To view sample N-Stealth output, click here.
  • SPIKE Proxy is a free Python-based Web test platform for Windows and Linux. SPIKE runs as an SSL-enabled Web proxy, letting you identify Web application vulnerabilities by examining and changing HTTP request variables, cookies, headers, and other fields mid-stream.
  • Webgoat is an open source Java/JVM-based tool that provides an interactive environment for teaching Web developers cross-site scripting, SQL injection, and other vulnerabilities. Hands-on lessons demonstrate sample Web exploits. Webgoat isn't really for testing your server—it teaches your Web developers what to avoid.
  • Whisker [.tar.gz] is a very popular open source vulnerability scanner, based on Perl, from the now-retired RainForestPuppy. Whisker is a script-driven command line tool that determines what kind of server software a target is running (e.g., IIS, Apache) and then runs server-specific penetration tests. Nikto builds upon Whisker.

Security Tools for the Budget Conscious ISP, Part II:
Web Vulnerability Assessment Tools

 

 

ISP News
IDC: Microsoft's Yahoo Deal Could be a Big Hit
Ballmer Fills in 'Software-Plus-Services' Plan
Report: Enterprise Search Will Top $1 Billion by 2010

More >


ISP Glossary
Find an ISP Term

Newsletters!
ISP-Planet Weekly


Best of ISP-Planet

 

Feedback


Advertising inquiry? Click here!

ISP-Planet's RSS feed



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: HyperV-The Killer Feature in WinServer ‘08
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Win Server ‘08
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES