Grendel-Scan : A new Web Application Security Scanner from Defcon :)

In the last August 10th , 2008 , Eric Duprey and David Byrne just finished their presentation at DEFCON 16 . They introduced a new web application security scanner which they ‘ve developed , called Grendel-Scan. According to its official website , Grendel-Scan is known to be an open-source web application security testing tool which has automated testing modules for detecting common web application vulnerablitiews. The best part of this tool is , it’s multi-platform! It can be run under windows , linux or even Macintosh!

Some known features of Grendel-Scan :

  • Internal intercepting / testing proxy
  • HTTP request fuzzer
  • Manual requests
  • Automatic file-not-found profiles
  • Upstream proxy support
  • HTTP request & connection throttling
  • HTML form-based authentication; multiple user accounts
  • Granular scan settings
  • Blocked query parameters
  • URL white-lists & blacklists
  • Known session ID names

Some known modules of Grendel-scan :

  • SQL injection
  • Error-based
  • SQL tautologies – experimental
  • Miscellaneous tests
  • CRLF injection
  • Cross-site request forgery (CSRF) – experimental
  • Directory traversal – experimental
  • Generic fuzzing
  • Information Leakage
  • Platform error messages
  • Robots.txt
  • Comment lister
  • Web server configuration
  • Cross-site tracing (XST)
  • Proxy detection
  • Application architecture
  • Input / output flows
  • Offline website mirror

The current release of Grendel-scan can be found here.

Recenly search

Incoming search terms for the article:

grendel scan tutorialgrendel scanGrendel scannerGrendel-Scantutorial grendel scanhow to grendel scangrendel-scan tutorialgrendel through proxygrendel scan tutoGrendel scan backtrackwebsite security scanner tutorial,  
Popular Today naruto shippuden 170 videologcat physics walkthroughnaruto shippuden 168 videologfacebook spybacktrack 3shy enginevtunnelBackTrack tutorialbacktrack 3 tutorialfacebook photo viewerSee The Shocking Hidden Message In The Google Logo that GOOGLE Does NOT Want You To Know About!how to view private myspace picturesmy empire hackview private myspace picturesSHOCKING: RUDE HIDDEN MESSAGE in Toy Story 3!facebook keyloggerHIDDEN MESSAGE IN GOOGLE LOGOTerri Moulton Hormanrapidleechbrute force facebook,   Computer Security Stuff on eBay!
Electronics stuffs on ebay

One Response to “Grendel-Scan : A new Web Application Security Scanner from Defcon :)”

  1. I had used the services of http://www.gamasec.com website vulnerability scan SaaS and I am very please with the result for our website security

    Monthly scan and clear report with recommendations to close the vulnerabilties that was found

    DR

Leave a Reply