1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Program or Site to scan my sites

Discussion in 'Security' started by TheSyndicate, Jan 20, 2009.

  1. #1
    Is there any site or program where i can scan my sites, all of them in one go. I have many sites so i want to put in all.

    I want to scan for 777 and things like that.
     
    TheSyndicate, Jan 20, 2009 IP
  2. Voxelite

    Voxelite Peon

    Messages:
    151
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #2
    What you're looking for is a web security scanner. There's quite a few of them, and some good free ones too. What I would recommend is Nikto and Wikto. They're both free and work extremely well. If you want to put out some cash, and are a bit of a newbie in the security area, I'd recommend using Acunetix's WVS. There's a great list of these at SecTools Top Ten Web Scanners. They'll be able to help you make a decision. For any more info on web scanners and vuln scanners in general, this Wikipedia article will help.
     
    Voxelite, Jan 22, 2009 IP
    TheSyndicate likes this.
  3. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #3
    Thanks alot i download a trial for the Acu it looks like it is something i am looking for.
     
    TheSyndicate, Jan 22, 2009 IP
  4. ahbuneh

    ahbuneh Active Member

    Messages:
    204
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    58
    #4
    Please post the result if you have time would like to know more.
     
    ahbuneh, Jan 23, 2009 IP
  5. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #5
    for my computer it takes alot of time to scan one site i think for me 12 hours for 1 site but then i see all the problem i have and it is alot WOW i never think some of my code was this weak.
     
    TheSyndicate, Jan 24, 2009 IP
  6. Voxelite

    Voxelite Peon

    Messages:
    151
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Yea, Acunetix is a great scanner. It's caught some things that I had no idea were even vulnerable. Most people forget or don't think about wrong permissions. I've seen tons of sites with config files just sitting out in the open. Good luck securing your site!
     
    Voxelite, Jan 24, 2009 IP
  7. devsn

    devsn Active Member

    Messages:
    156
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    70
    #7
    I recommend you hire a PHP coder(if you do not know how to code in php) or a Perl coder, create a server side script that can do the scanning, also those which can audit your scripts (Check for RFI, LFI, SQL Inj. etc..) and put it in cron..

    takes some memory but its just for 2 hours per day... If you have a dedicated server, I recommend this for you..
     
    devsn, Jan 24, 2009 IP
  8. justdoit1

    justdoit1 Peon

    Messages:
    100
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Why not scan offline ?
     
    justdoit1, Jan 25, 2009 IP
  9. Cr1T1c4L

    Cr1T1c4L Peon

    Messages:
    23
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Its better to hire somebody in to check over your website for any kind of vurnabilities if you want help on that hit me up on msn i pmed you about it =].
     
    Cr1T1c4L, Jan 26, 2009 IP
  10. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #10
    Sorry no its not better to hire somebody its. I do not want strange people in my code i have enough of that already. I think Acunetix working very good
     
    TheSyndicate, Jan 26, 2009 IP
  11. Cr1T1c4L

    Cr1T1c4L Peon

    Messages:
    23
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    acutunix may work but as your using a free copy etc, it will only scan simple things meaning even if acutunix find things your still vurnable and you will need to fix premissions useing your ssh if you don't trust me you can ask mark henderson about me i helped him out with his private vps he was scared but he was totally happy when we fixed his things.
     
    Cr1T1c4L, Jan 26, 2009 IP
  12. justdoit1

    justdoit1 Peon

    Messages:
    100
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Yes, Acutunix free version checks only one vulnerability type - XSS. I like it best among others.
     
    justdoit1, Jan 26, 2009 IP
  13. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #13
    i have the real version now it even made test attacks with me site it working very good.
     
    TheSyndicate, Jan 26, 2009 IP
  14. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #14
    Posting your own site is spam and the forum do not like that :)
     
    TheSyndicate, Jan 26, 2009 IP
  15. justdoit1

    justdoit1 Peon

    Messages:
    100
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Don't rely on scanners for sole security. They are still weak in identifying all types of flaws in various web applications. There are dozens of other flaws that no scanners can detect and warn you. Logic flaw is one kind.

    See web app security scanners comparison report:

    http://drop.io/anantasecfiles/
     
    justdoit1, Feb 8, 2009 IP
  16. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #16
    I am NOW looking for a text search program FTP style that can go trough my php files search for problems. Since my server can not run the script people been telling me about.
     
    TheSyndicate, Feb 9, 2009 IP
  17. justdoit1

    justdoit1 Peon

    Messages:
    100
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #17
    What do you mean FTP Style?

    You mean ?


    - A program that uses FTP and then search problematic files there ?

    I never heard of it. Hire someone to write such.
     
    justdoit1, Feb 9, 2009 IP
  18. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #18
    do not need to search for problem files just search is enough since i know how the the code look like i should search for.
     
    TheSyndicate, Feb 9, 2009 IP
  19. justdoit1

    justdoit1 Peon

    Messages:
    100
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #19
    OK, Dreamweaver will do.

    - Load all files from FTP in Dreamweaver
    - Use Dreamweaver's advanced search feature

    You're done.
     
    justdoit1, Feb 9, 2009 IP
  20. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #20
    You can search inside FTP files with dreamveaver?
     
    TheSyndicate, Feb 9, 2009 IP