A closer look at Acunetix Web Vulnerability Scanner 6.5

by Zeljka Zorz - Thursday, 29 October 2009.
Bookmark and Share

Web applications are accessible 24 hours a day, 7 days a week and control valuable data since they often have direct access to backend data such as customer databases. SSL and locked-down servers are futile against web application hacking. Any defense at network security level will provide no protection against web application attacks since they are launched on port 80 - which has to remain open. In addition, web applications are often tailor-made therefore tested less than off-the-shelf software and are more likely to have undiscovered vulnerabilities.

Acunetix Web Vulnerability Scanner (WVS) is an automated web application security testing tool that audits your web applications by checking for exploitable vulnerabilities (complete list.) Automated scans may be supplemented and cross-checked with the variety of manual tools to allow for comprehensive web site and web application penetration testing.

The installation process is short and simple. The only thing worth mentioning about it is that at one point you're asked if you want to install a Firefox add-on that allows you to audit individual pages directly from the browser.

Upon starting the software, you will be greeted by a Scan Wizard window that will help you start using it through a step-by-step process. First, you must choose between 4 scan options (click on the screenshot to enlarge it):



We'll deal with the most basic option - the scanning process is the same for every choice. To test the software first, Acunetix offers a few test sites – of course, if you’re planning to get down to business you won’t be needing them.

First, you have to choose the target:




Then you can choose the crawling options:



And the scan options:



The last step allows you to configure login details for password protected areas or HTML forms (if you have them, of course).

Upon starting the scan, we finally get to see the main screen (click on the screenshot to enlarge it):



Lets break it down. On the left there is a choice of tools, configuration settings and general information:

 1  |  2  |   Next page >>