RE: Vuln scan tool for web

From: lockdownat_private
Date: Tue Jul 15 2003 - 11:56:28 PDT

  • Next message: R. DuFresne: "RE: Vuln scan tool for web"

    I think you're looking for a combination of these two PHP pages.  They use Nmap to scan.
    
    http://www.davidquintana.com/projects/nmapwebfe/nmapwebfe.html
    
    The second site is now down so e-mail me directly for the code.  The code is for scanning yourself but with only the basic flags.  It's also complete.
    
    I can't get them to work on servers with the latest version of PHP, and don't know why, so if you get them working could you please let me know.  The problem is with the exec() statement.
    
    Ben
    
    -----Original Message-----
    From: Domingos Costa [mailto:domingosat_private] 
    Sent: Tuesday, July 15, 2003 12:00 PM
    To: pen-testat_private
    Subject: Vuln scan tool for web
    
    Hello,
    
    I'm looking for a web tool that allow a user connected to my lan scan his own computer for 
    vulnerabilities. It's something similar to ShieldsUP! at grc.com, but i wanna put it inside my lan, 
    at a web server and the user can just click on to start probbing his ports. Do you know some tool??
    I'm working with linux slackware.
    
    Thanks.
    
    
    
    ---------------------------------------------------------------------------
    Your network Firewall and IDS products do not prevent Web application
    exploits - the most common form of online attack - resulting in Web
    defacement, data theft, sabotage and fraud.
    
    KaVaDo is the first and only company that provides a complete and an
    integrated suite of Web application security products, allowing you to
    assess your entire environment, automatically set positive security
    policies and maintainĀ it without compromising business performance.
    
    For more information on KaVaDo and to download a FREE white paper on Web
    applications - security policy automation, please visit:
    http://www.kavado.com/ad.htm
    ----------------------------------------------------------------------------
    
    ---------------------------------------------------------------------------
    Your network Firewall and IDS products do not prevent Web application
    exploits - the most common form of online attack - resulting in Web
    defacement, data theft, sabotage and fraud.
    
    KaVaDo is the first and only company that provides a complete and an
    integrated suite of Web application security products, allowing you to
    assess your entire environment, automatically set positive security
    policies and maintainĀ it without compromising business performance.
    
    For more information on KaVaDo and to download a FREE white paper on Web
    applications - security policy automation, please visit:
    http://www.kavado.com/ad.htm
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Tue Jul 15 2003 - 12:35:45 PDT