Netsparker Community Edition – Web Application Security Scanner

Use Netsparker


Netsparker is a Web Application Security Scanner that claims to be False-Positive Free. The developers thought that if you need to investigate every single identified issue manually what’s the point of having an automated scanner? So they developed a new technology which can confirm vulnerabilities on demand which allowed us to develop the first false positive free web application security scanner.

When Netsparker identifies an SQL Injection, it can identify how to exploit it automatically and extract the version information from the application. When the version is successfully extracted Netsparker will report the issue as confirmed so that you can make sure that the issue is not a false-positive.

Same applies to other vulnerabilities such as XSS (Cross-site Scripting) where Netsparker loads the injection in an actual browser and observes the execution of JavaScript to confirm that the injection will actually get executed in the browser.

Thanks to its comprehensive and powerful JavaScript engine it’s possible to simulate a real attacker successfully. This means it can successfully analyse websites that rely on AJAX and JavaScript.

You don’t need to be a security expert, get training or read a long manual to start. Since the user interface is easy to use and can confirm and show you the impact, you can just fire it up and start using it.

Netsparker - Community Edition

You can download Netsparker – Community Edition here:

NetSparkerCommunityEditionSetup.exe

Or read more here.

Posted in: Countermeasures, Database Hacking, Security Software, Web Hacking

, , , , , , , ,


Latest Posts:


Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.
Eraser - Windows Secure Erase Hard Drive Wiper Eraser – Windows Secure Erase Hard Drive Wiper
Eraser is a hard drive wiper for Windows which allows you to run a secure erase and completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns.
Insecure software versions are a problem Web Security Stats Show XSS & Outdated Software Are Major Problems
Netsparker just published some anonymized Web Security Stats about the security vulnerabilities their online solution identified on their users’ web applications and web services during the last 3 years.
CTFR - Abuse Certificate Transparency Logs For HTTPS Subdomains CTFR – Abuse Certificate Transparency Logs For HTTPS Subdomains
CTFR is a Python-based tool to Abuse Certificate Transparency Logs to get subdomains from a HTTPS website in a few seconds.
testssl.sh - Test SSL Security Including Ciphers, Protocols & Detect Flaws testssl.sh – Test SSL Security Including Ciphers, Protocols & Detect Flaws
testssl.sh is a free command line tool to test SSL security, it checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws and more.


4 Responses to Netsparker Community Edition – Web Application Security Scanner

  1. Maximilian Corrientes April 19, 2010 at 11:36 pm #

    We’ve tested several scanners which claim to be “false positive” free.

    It would be great if someone could make an independent test of our result.

    http://labs.german-websecurity.com/en/blog/?p=12

    We made a testpage with a rewrite condition and we were stunned about the bad handling of false positives by the web security scanners.

  2. Ferruh Mavituna April 20, 2010 at 11:28 am #

    Maximilian,

    Thanks for pointing out this problem. Netsparker already has a URL Rewrite detection engine and it works on file extensions as well. However this particular case happens due to a bug.

    We fixed this problem in 1.3.7.32, will release it soon.

    Cheers,

  3. TheLightCosine April 23, 2010 at 6:12 pm #

    I was actually rather pleased with what I saw in the Community Edition. I’d love to see the Enterprise Edition at work to form a complete opinion, but I have written a little review over at my blog:

    http://cosine-security.blogspot.com/2010/04/netsparker-community-edition-review.html

    • Darknet April 23, 2010 at 7:18 pm #

      I’ll see if I can work something out regarding the Enterprise edition, Ferruh has been a long time reader here too :)