Websecurify – Free Web Application Vulnerability Scanner

Posted by rajivvishwa On April - 2 - 2010

Websecurify is a powerful web application security testing environment designed from the ground up to provide the best combination of automatic and manual vulnerability testing technologies. This tool automatically identifies web application vulnerabilities by using advanced discovery and fuzzing technologies.

Wensecurify Scan in Progress

Websecurify Scan in Progress


Running the Scanner

Initiating a scan with Websecurify is simple and is achieved in 2 steps.

  1. Create a workspace with the target’s URL
  2. and then just Start the scan :)

Once the Scan is Complete

Once the scan is complete, scan results are displayed, sorted based on the severity of the vulnerabilities discovered. Clicking on each of the category will further display the instances found and the technical details of analysis.

Websecurify Scan Complete - Issues Tab

Websecurify Scan Complete - Issues Tab

Scan results can be rendered in a report format by clicking on the Report Tab and can be exported in CSV, HTM, XML and JSON formats.

Websecurify Scan Complete - Report Tab

Websecurify Scan Complete - Report Tab

Comments/Observations

  1. A scan was initiated for an average sized application during evaluation of websecurify and following were identified
  2. Memory consumption was increasing with time but its far better than many other free/commercial scanners
  3. Progress of scan was normal till it reached almost 97% (in around 2 hrs), then it stayed in 97-98 and back to 97 for a loooong time. So I had it running and checked it the next day.
  4. This tool doesn’t provide the statistics of the scan, like pages crawled, time consumed, etc.
  5. This tool has the simplest interface of all the other tools available in the market.
Websecurify Logo


Subscribe RSS
Follow me on TwitterTechnoratiYoutube VidsLinkedIn ProfileDelicious

    Recent Comments