Re: Know such a web's server tool?

From: Bill Weiss (houdini_at_nmt.edu)
Date: 07/17/03

  • Next message: chaitan_at_nullcube.com: "Re: Know such a web's server tool?"
    Date: Thu, 17 Jul 2003 10:13:28 -0600
    To: pen-test@securityfocus.com
    
    

    MARTIN M. B?noni(benoni_martin@hotmail.com)@Thu, Jul 17, 2003 at 11:40:17AM +0000:
    > Hi list!
    >
    > I am currently writing an application which will allow to find out all
    > (well the maximum of them! :) ) the servers on a network. Here is how it
    > works:
    > 1- I feed it with a list of targets (command-line or file): CIDR subnets,
    > hostnames, IP address(es),..
    > 2- I specify a type of scan: looking for FTP, HTTP, POP, ... servers /
    > intrusive scan or not / ....
    > 3- It tries to find them out.
    > 4- Gets its OS and vulnerabilities. And if desired, it will try to breack
    > down the systems using the found vulnerabilities.
    > 5- Creates a simple HTML page with the results.
    >
    > I have been wandering around Internet, and I could not find any tool like
    > that (well doing all these features). So, if you know such a tool, could
    > you tell me about it? If you have any idea/clue/help, feel free to mail me!

    That sounds sort of like a vulnerability scanner. Nessus, ISS, Retina all
    do that (theoretically), but they won't do much exploitation. CORE Impact
    says it does that sort of thing.

    Where have you been looking?

    -- 
    Bill Weiss
     
    That ["because the customer is always right"] has been repealed by the 
    Axiom Review Board and replaced with "because the customer is a probably 
    a criminal". 
    	-- TheRaven64, slashdot
    ---------------------------------------------------------------------------
    Your network Firewall and IDS products do not prevent Web application
    exploits - the most common form of online attack - resulting in Web
    defacement, data theft, sabotage and fraud.
    KaVaDo is the first and only company that provides a complete and an
    integrated suite of Web application security products, allowing you to
    assess your entire environment, automatically set positive security
    policies and maintain it without compromising business performance.
    For more information on KaVaDo and to download a FREE white paper on Web
    applications - security policy automation, please visit:
    http://www.kavado.com/ad.htm
    ----------------------------------------------------------------------------
    

  • Next message: chaitan_at_nullcube.com: "Re: Know such a web's server tool?"

    Relevant Pages

    • Re: ARIN Handle IP block whois query
      ... Just use the whois web form and type the company name - ... > Your network Firewall and IDS products do not prevent Web application ... > integrated suite of Web application security products, ... > For more information on KaVaDo and to download a FREE white paper on ...
      (Pen-Test)
    • RE: Vuln scan tool for web
      ... I can't get them to work on servers with the latest version of PHP, and don't know why, so if you get them working could you please let me know. ... Your network Firewall and IDS products do not prevent Web application ... integrated suite of Web application security products, ... For more information on KaVaDo and to download a FREE white paper on Web ...
      (Pen-Test)
    • Re: Vuln scan tool for web
      ... I'm looking for a web tool that allow a user connected to my lan scan his own computer for ... Your network Firewall and IDS products do not prevent Web application ... integrated suite of Web application security products, ... For more information on KaVaDo and to download a FREE white paper on Web ...
      (Pen-Test)
    • RE: Check point eng allowing Nmap NULL access
      ... Pretty sure GTA do not use the check point engine. ... Your network Firewall and IDS products do not prevent Web application ... integrated suite of Web application security products, ... For more information on KaVaDo and to download a FREE white paper on Web ...
      (Pen-Test)
    • Re: IRC Sites
      ... > Your network Firewall and IDS products do not prevent Web application ... > integrated suite of Web application security products, ... > assess your entire environment, ... > For more information on KaVaDo and to download a FREE white paper on Web ...
      (Pen-Test)