Grendel-Scan : A new Web Application Security Scanner from Defcon :)

In the last August 10th , 2008 , Eric Duprey and David Byrne just finished their presentation at DEFCON 16 . They introduced a new web application security scanner which they ‘ve developed , called Grendel-Scan. According to its official website , Grendel-Scan is known to be an open-source web application security testing tool which has automated testing modules for detecting common web application vulnerablitiews. The best part of this tool is , it’s multi-platform! It can be run under windows , linux or even Macintosh!

Some known features of Grendel-Scan :

  • Internal intercepting / testing proxy
  • HTTP request fuzzer
  • Manual requests
  • Automatic file-not-found profiles
  • Upstream proxy support
  • HTTP request & connection throttling
  • HTML form-based authentication; multiple user accounts
  • Granular scan settings
  • Blocked query parameters
  • URL white-lists & blacklists
  • Known session ID names

Some known modules of Grendel-scan :

  • SQL injection
  • Error-based
  • SQL tautologies - experimental
  • Miscellaneous tests
  • CRLF injection
  • Cross-site request forgery (CSRF) – experimental
  • Directory traversal – experimental
  • Generic fuzzing
  • Information Leakage
  • Platform error messages
  • Robots.txt
  • Comment lister
  • Web server configuration
  • Cross-site tracing (XST)
  • Proxy detection
  • Application architecture
  • Input / output flows
  • Offline website mirror

The current release of Grendel-scan can be found here.

Some people come to this post with this search term: grendel scan, grendel-scan, grendel scan tutorial, grendel security, grendel scanner, open source web application scanner, grendel-scan tutorial, grendel hack, gendel scan, application, using grendel scan, using grendel-scan, Tutorial Grendel, grendel scan howto, grendel fuzzer, defcon grendel scan, usb switchblade download mirror, Grendel proxy, eric duprey grendel, open shource application security scanner,

And here is the related entries of this post:

Leave a Reply