Scanners Flashcards

1
Q

Nikto

A

a free software command-line vulnerability scanner that scans webservers for dangerous files/CGIs, outdated server software and other problems. It performs generic and server type specific checks. It also captures and prints any cookies received.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Open VAS

A

a full-featured vulnerability scanner. Its capabilities include unauthenticated and authenticated testing, various high-level and low-level internet and industrial protocols, performance tuning for large-scale scans and a powerful internal programming language to implement any type of vulnerability test.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

SQLMap

A

an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Nessus

A

a proprietary vulnerability scanner developed by Tenable, Inc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Open SCAP

A

a command line tool which enables various SCAP capabilities such as displaying the information about specific security content, vulnerability and configuration scanning, or converting between different SCAP formats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Wapiti

A

allows you to audit the security of your websites or web applications. It performs “black-box” scans (it does not study the source code) of the web application by crawling the webpages of the deployed webapp, looking for scripts and forms where it can inject data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

WPScan

A

black box WordPress security scanner written for security professionals and blog maintainers to test the security of their sites.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Brakeman

A

Brakeman is a free vulnerability scanner specifically designed for Ruby on Rails applications. It statically analyzes Rails application code to find security issues at any stage of development.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Scout Suite

A

an open-source cloud security-auditing tool. It queries the cloud API to gather configuration data. Based on configuration data gathered, ScoutSuite shows security issues and risks present in your infrastructure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly