--web vulnerability scanning of network attack and defense

Source: Internet
Author: User
Cadaver

This tool is a UNIX command-line program for browsing and modifying WebDAV shares. This tool is a client-side, command-line format for linking WebDAV Davtest

Test uploading files to servers that support WebDAV

Syntax: Davtest-url http://222.28.136.226/dav/ Deblaze

Enumerations for flash remote calls, which are typically used in XSS or deeper web security, may be fimap

file contains vulnerability utility grabber

Grabber is a Web application vulnerability scanner that allows you to specify a scan vulnerability type combined with a crawler to securely scan a Web site joomscan

Similar to Wpscan scanner, for a specific CMS skipfish

Skipfish is a Google-produced automated network security Scanning Tool, and nikto,nessus and other tools have similar functions. Its syntax is as follows:

Start the contract scan after execution

After the scan is finished, open the report123 directory you created before, find the index.html file in the directory, and open it in your browser to see this page

Uniscan

This tool can select some options, then add the URL, and then start scanning directly on the line

W3AF

W3AF is a Web application attack and inspection framework that includes checking web crawler, SQL injection, Cross station (XSS), local file inclusion (LFI), remote file inclusion (RFI), etc. The goal of the project is to build a framework for finding and developing Web application security vulnerabilities, so it is easy to use and extend
Wapiti

Wapiti works in the same way as Nikto, and uses a black box to proactively scan Web applications under test for potential security flaws.

The way it scans is, Python wapiti.py http://www.xxxxxx.com-v 2 webshag

A comprehensive call framework that can call Nmap,uscan, information collection, reptiles and other functions, is the scanning process simpler Websploit

Mainly used for remote scanning and analysis of system vulnerabilities, using it can be very easy and rapid detection of problems in the system, and for in-depth analysis

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.