Fwd: Google Launches Free Web Application Scanning Tool (Skipfish)

Isaias Calderon <[email protected]>
Newsgroups gmane.comp.security.web-applications,gmane.comp.security.penetration
Message-ID <[email protected]>
Apologies for the Cross-posting..

http://www.darkreading.com/vulnerability_management/security/app-security/showArticle.jhtml?articleID=224000380

skipfish - web application security scanner

Written and maintained by Michal Zalewski <[email protected]>.
Copyright 2009, 2010 Google Inc, rights reserved.
Released under terms and conditions of the Apache License, version 2.0.

What is skipfish?

Skipfish is an active web application security reconnaissance tool. It
prepares an interactive sitemap for the targeted site by carrying out
a recursive crawl and dictionary-based probes. The resulting map is
then annotated with the output from a number of active (but hopefully
non-disruptive) security checks. The final report generated by the
tool is meant to serve as a foundation for professional web
application security assessments.

Obviously, the direct link:  http://code.google.com/p/skipfish/wiki/SkipfishDoc

Hoping to share experiencies...

--
Isaias Calderón, CISSP, ECSA, CEH



This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.