{"id":2503,"date":"2010-02-05T07:27:18","date_gmt":"2010-02-05T07:27:18","guid":{"rendered":"https:\/\/www.darknet.org.uk\/?p=2503"},"modified":"2015-09-09T19:37:43","modified_gmt":"2015-09-09T11:37:43","slug":"secubat-modular-web-vulnerability-scanner","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2010\/02\/secubat-modular-web-vulnerability-scanner\/","title":{"rendered":"SecuBat – Modular Web Vulnerability Scanner"},"content":{"rendered":"

[ad]<\/p>\n

As the popularity of the web increases and web applications become tools of everyday use, the role of web security has been gaining importance as well. The last years have shown a significant increase in the number of web-based attacks. For example, there has been extensive press coverage of recent security incidences involving the loss of sensitive credit card information belonging to millions of customers.<\/p>\n

Typical web application security vulnerabilities result from generic input validation problems. Examples of such vulnerabilities are SQL injection and Cross-Site Scripting (XSS). Although the majority of web vulnerabilities are easy to understand and to avoid, many web developers are, unfortunately, not security-aware. As a result, there exist many web sites on the web that are vulnerable.<\/p>\n

SecuBat is a generic and modular web vulnerability scanner that, similar to a port scanner, automatically analyzes web sites with the aim of finding exploitable SQL injection and XSS vulnerabilities.<\/p>\n

Software Requirements<\/strong><\/p>\n