.

Sunday 14 December 2014

How to find Vulnerability in Website [2015,tools,top10 bugs]



How to Find Vulnerable Websites :

Website security is a major problem today and should be a priority in any organization or a webmaster, Now a days Hackers are concentrating alot of their efforts to find holes in a web application, If you are a website owner and having a High Page rank and High Traffic then there is a chance that you might be a victim of these Hackers. Few years back their existed no proper tools search for vulnerability, but now a days there are tons of tools available through which even a newbie can find a vulnerable site and start Hacking.



General Method Used for Website Hacking:

There are many methods that can be used to hack a website but most general and common once are as follows:
1.SQL Injection
2.XSS(Cross Site Scripting)
3.Remote File Inclusion(RFI)
4.Directory Traversal attack
5.Local File inclusion(LFI)
6.DDOS attack.



Tools which commonly used to find a vulnerability in website : 

 

Acunetix:

Acunetix is best tool for find a vulnerability even i am also using for many purpose. this is one of the my favorite tool to find a venerability in any web application It automatically checks/find your web applications for SQL Injection, XSS & other web vulnerabilities.





Download Here :

Download Acunetix Web Security Scanner 



Nessus:

Nessus is the best unix venerability testing tool and among the best to run on windows. Key features of this software include Remote and local file securitychecks a client/server architecture with a GTK graphical interface etc.




Download Here :

Download Nessus from the link below :
http://www.nessus.org/download


Metasploit Framework :
The Metasploit Framework is the open source penetration testing framework with the world's largest database of public and tested exploits.

Download Metasploit(For Windows users) from the link below
http://www.metasploit.com/releases/framework-3.2.exe


Download Metaspolit(For Linux users) from the link below http://www.metasploit.com/releases/framework-3.2.tar.gz



Thanks for Reading and do comment if you want any help.

2 comments:

  1. I never thought I will come in contact with a real and potential hacker until I knew   brillianthackers800 at Gmail and he delivered a professional job,he is intelligent and understanding to control jobs that comes his way
    Contact him and be happy

    ReplyDelete
  2. I was so anxiuos to know what my husband was always doing late outside the house so i started contacting hackers and was scamed severly until i almost gave up then i contacted this one hacker and he delivered a good job showing evidences i needed from the apps on his phone like whatsapp,facebook,instagram and others and i went ahead to file my divorce papers with the evidences i got,He also went ahead to get me back some of my lost money i sent to those other fake hackers,every dollar i spent on these jobs was worth it.Contact him so he also help you.
    mail: premiumhackservices@gmail.com
    text or call +1 4016006790

    ReplyDelete

About

Like Us