Publisher's Description
From Acunetix:
Audit your website security with Acunetix Web Vulnerability Scanner
Hackers are concentrating their efforts on attacking applications in your website: 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Web applications are accessible 24 hours a day, 7 days a week and control sensitive data such as customer details, credit card numbers and proprietary corporate data.
Firewalls, SSL and locked-down servers are futile against web application hacking
Any defense at network security level will provide no protection against web application attacks since they are launched on port 80 - which has to remain open. In addition, web applications are often tailor-made, therefore tested less than off-the-shelf software, and are more likely to have undiscovered vulnerabilities. Manually auditing a website for vulnerabilities is virtually impossible - it needs to be done automatically and regularly.
Acunetix WVS automatically checks your web applications for SQL Injection, XSS other web vulnerabilities. * Ensures your website is secure against web attacks * Automatically checks for SQL injection & Cross site scripting vulnerabilities * Checks password strength on authentication pages (HTTP or HTML forms) * Scans Javascript / AJAX applications for security vulnerabilities * Automatically audits shopping carts, forms, dynamic content and other web applications * Creates professional website security audit reports.
More Products to Consider
- Download files faster and safer with your Web and Windows appli...Download
Installed
Smart Install - Inspect and edit any file, main memory, or disk/disk image.Download
Installed
Smart Install - Compile, debug, and run Java applications on your computer.Download
Installed
Smart Install - Edit plain text files, HTML documents, PHP, and Java code.Download
Installed
Smart Install - Enable Entity Framework against relational databases and create...Download
Installed
Smart Install - Develop and deploy Java applications on desktops and servers.Download
Installed
Smart Install - C/C++ compiler and IDE.Download
Installed
Smart Install - Create and manage your MySQL databases over the Web.Download
Installed
Smart Install - View your databases with ease.Download
Installed
Smart Install - Run and develop applications targeting .NET Framework.Download
Installed
Smart Install - Manage and view your database with ease.Download
Installed
Smart Install - Edit several programming languages running under the MS windows...Download
Installed
Smart Install - Manage and view your database with ease.Download
Installed
Smart Install - Create and design any Web site possible, with no programming re...Download
Installed
Smart Install - Manage and view your database with ease.Download
Installed
Smart Install - Manage your Web sites design, content, and functionality.Download
Installed
Smart Install - Manage and view your database with ease.Download
Installed
Smart Install - Deploy TurboC, TurboC++ for Windows 7, Vista.Download
Installed
Smart Install - Advice for Mainstream Marketers from a High Traffic Industry We...Download
Installed
Smart Install - Simplify the development of your Oracle database design.Download
Installed
Smart Install - Add shopping cart functionality to your Web site.Download
Installed
Smart Install - Compile, debug, and run Java applications on your computer.Download
Installed
Smart Install - Simplify the development of your Oracle database design.Download
Installed
Smart Install - Perform business process modeling (UML, BPMN) and process Web s...Download
Installed
Smart Install
-
All versions:
2.3 starsout of 3 votes
-
Current version:
1.0 starsout of 1 votes
-
My rating:
Write review
Results 1-1 of 1
-
"Do Not Run Acunetix WVS On An Active Website!"
Version: Acunetix Web Vulnerability Scanner 6.0.20081209
Pros
Extremely thorough even though the 30 Day demo only scans for XSS (Cross-site scripting).
Cons
Quote from the Acunetix blog: ""Will it damage my website?". Similar questions are common since black box scanners tend to cause email floods, as well as publishing of garbage blog posts and comments on blogs. If the automated scanner is configured to access a database-driven CMS administrator interface, the chances of garbage data being injected into the database or — even worse — records being deleted and damaging a live web application, are indeed very high."
This warning is not shown anywhere else on the Acunetix Free 30 Day Download page nor the Quick-Start PDF. As a result of not knowing this critical tid-bit, my company's web site, email, and database were all thoroughly attacked and all data corrupted. We lost a week's worth of internet sales, customer service inquiries, and product inventory updates.Summary
If you have an exact clone of your entire website available on a completely separate server solely designated as a "test environment" with no connection to your live production environment, then Acunetix can render powerful "real-life" security information to you regarding your vulnerabilities. But first PLEASE go to the Acunetix blog (http://www.acunetix.com/blog/docs/invasive-vs-non-invasive-web-application-security-scan/)and read this warning from Robert Abela of Acunetix before using this product.
Add Your Review
Submit your reply
E-mail this review
Report offensive content
See more CNET content tagged:
Previous Versions:








