Find the Web security scanner when found netsparker4.0, is the new version of 2015, the biggest highlight is the security scan more automated degree! You no longer need to record your login information during a security test, and it also supports two-factor authentication. The interface looks very tall, so download a cracked version of the Internet experience a bit
First Experience
The interface is simple and straightforward, set the URL
Then you can quickly use the default method for crawl and testing
Finally, you can see a neat test report.
Login
For websites that need to be logged in, there are many ways to log in, such as script entry.
such as script, automatically pull up the interface, the input account will be automatically populated into the page
Import URLs that need to be scanned
Supports text mode or other grab file import of URLs that need to be scanned, such as Fidder's Saz file
However, manually entered URLs are displayed in the Get mode, do not know whether the problem is not supported or displayed
Proxy mode
The proxy mode is similar to the Fidder HTTP proxy, listening to the browser's HTTP requests, and as the page operates, the newly captured requests are displayed on the site map, and these URLs can be tested
The shortcomings
Automatic XSS and SQL inject are highlights, while support for automatic scanning and manual is also strong, easy to use, documentation is also very detailed
The biggest disadvantage is that the rest API is not currently supported, which is a pity that cannot be applied to the current project
Security Scanner Netsparker 4 new Simple trial