Nukemods Forum  
» Log in
User Name:

Password:

Not a member yet?
Register Now!
» .::.
tattoo fonts
http://www.checkoutmyink.com/category/tattoo-fonts-tattoo

Go Back   Nukemods Forum > Nukemods > News

Reply
 
LinkBack Thread Tools Display Modes
Google releases web security scanner
Old
  (#1 (permalink))
Administrator
 
Status: Offline
Posts: 125
Join Date: Feb 2002
Location: USA
Google releases web security scanner - 03-22-2010, 06:27 PM

Google has released an open source scanner that allows web application developers to test their applications for security holes. The application, called Skipfish, offers a similar functionality to that of tools such as Nmap or Nessus, but it's said to be much faster. Using fully automated heuristics, it detects code that is vulnerable to cross-site scripting attacks (XSS), SQL and XML injection attacks and many other attack types. The tool's comprehensive post-processing of the individual test results is designed to help with the interpretation of the final report.

Skipfish is a pure C implementation and according to Google, can easily process 2,000 HTTP requests per second – provided the tested server can handle such a high load. In individual tests across local networks, 7,000+ requests per second have reportedly been sent with a modest CPU load and memory footprint.

Google achieves this high performance via a serial I/O model which processes responses asynchronously and is said to offer much better scalability than traditional multi-threaded approaches with synchronous request processing. Optimised HTTP connection handling via features such as HTTP 1.1 range requests, keep-alive connections and data compression are designed to keep Skipfish's network bandwidth requirements in check.

Google says that it uses the scanner to test its own web applications for insecure interfaces. However, Google also points out that the security checks are far from comprehensive and do not satisfy most of the Web Application Security Consortium's (WASC) Web Application Security Scanner Evaluation Criteria criteria.

The latest release of Skipfish is version 1.10 Beta and a list of known issues is available on the project's Google Code page. Skipfish is released under version 2 of the Apache License.

More...
   
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Pc-Nuke! releases new 8.1.034 versions of Lite! and Max! pcnuke News 3 03-10-2008 04:08 PM
DaDaNuke Releases Legal Module 1.1 dainbramage News 0 06-09-2007 12:03 AM
DaDaNuke Releases PHP-Nuke Basic 7.6.0.3.3 dainbramage News 0 06-08-2007 11:40 PM
DaDaNuke Releases PHP-Nuke Basic 7.6.0.3.3 forgotz Nuke 7.x - General 0 03-06-2007 05:18 AM
best way to get on google? Kristic Nuke 6.5 to 6.9 - Blocks 3 07-23-2003 03:15 PM




vBulletin Skin developed by: vBStyles.com


LinkBacks Enabled by vBSEO 3.3.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31