RE: Vulnerability scanner for SQL injection, HTML injection- free or commercial ?

From: Aditya (adityald3_at_gmx.net)
Date: 09/24/03

  • Next message: A.Koot_at_Unive.NL: "Blocking and allowing ActiveX"
    To: "Harbar, Spencer" <spencer.harbar@dns.co.uk>, "Milind Nanal" <milindyn@rolta.com>, <focus-ms@securityfocus.com>
    Date: Wed, 24 Sep 2003 10:40:46 +0530
    
    
    

    you may also try the sql auditor which is a free download from nii.co.in... its pretty good

    ------

    Aditya Lalit Deshmukh,

      _____

    Chief Security Officer &
    System and Network Administrator,
    Electronic Security Division,
    Enterprise Security Solutions, Inc

    -----Original Message-----
    From: Harbar, Spencer [mailto:spencer.harbar@dns.co.uk]
    Sent: Tuesday, September 23, 2003 8:47 PM
    To: Milind Nanal; focus-ms@securityfocus.com
    Subject: RE: Vulnerability scanner for SQL injection, HTML injection-
    free or commercial ?

    Check out ScanDo from www.kavado.com, WebInspect from
    www.spidynamics.com and AppScan from www.sanctum.com

    hth
    Spence
     

    -----Original Message-----
    From: Milind Nanal [mailto:milindyn@rolta.com]
    Sent: 19 September 2003 06:31
    To: focus-ms@securityfocus.com
    Subject: Vulnerability scanner for SQL injection, HTML injection- free
    or commercial ?

    Hi,

    Can anyone please tell me information about any vulnerability scanner
    (free or trial version of commercial scanner) which can scan SQL
    injection , HTML injection of IIS web server running with MS sql 2000 as
    a backend database.

    I get many document on the internet which tell me few default techniques
    of SQL injection & trying out those to carry out SQL injection test. I
    am looking out for ready made scanner which has a set of inbuilt
    commands to carry out SQL , HTML injection attack & give a report ,
    recommendations to solve the problem.

    Quick response is appreciated

    Regards,

    Milind

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    ---------------------------------------------------------------------------------------------
    This e-mail was checked and validated by the dns email content management service.
    For information on how to improve email management for your organisation, please contact sales@dns.co.uk
    ---------------------------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    ________________________________________________________________________
    Delivered using the Free Personal Edition of Mailtraq (www.mailtraq.com)
    
    

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: A.Koot_at_Unive.NL: "Blocking and allowing ActiveX"

    Relevant Pages