• Register

Vulnerability Assessment, also known as vulnerability analysis, is a process that defines, identifies, and classifies the security holes (vulnerabilities) in a computer, network, or communications infrastructure. In addition, vulnerability analysis can forecast the effectiveness of proposed countermeasures and evaluate their actual effectiveness after they are put into use.

Vulnerability Assessment consists of several steps:

  • Defining and classifying network or system resources
  • Assigning relative levels of importance to the resources
  • Identifying potential threats to each resource
  • Developing a strategy to deal with the most serious potential problems first
  • Defining and implementing ways to minimize the consequences if an attack occurs.

 

VULNERABILITY ASSESSMENT- SOFTWARE'S / TOOLS / UTILITIES

  1. Vulnerability Analysis
  2. Vulnerability Scanners
  3. Fuzzers
  4. SMB Analysis
  5. SNMP Analysis



VULNERABILITY ANALYSIS

  • Graudit
  • Nessus Parsing Tools
  • WATOBO
  • MagicTree
  • WordPress Security Scanner 1.1
  • Yasca
  • WebSploit Toolkit
  • UrlScan 3.1
  • Sara
  • Gsd
  • Mpack
  • aidSQL
  • Golismero
  • WebGoat
  • FStealer Filesystem Mirroring Tool
  • Websecurify Security Testing Runtime
  • GoLismero
  • Lilith
  • websurgery
  • IronWASP
  • Vasto
  • VEGA
  • BiDiBLAH   



VULNERABILITY SCANNERS

  • DllHijackAuditor
  • Nessus
  • OpenVAS
  • Dark D0rk3r 0.3
  • Fwknop Port Knocking Utility 2.0
  • Nexpose
  • Fluxay
  • GFI LanGuard
  • Acunetix WVS
  • RIPS
  • VulnDetector
  • Uniscan
  • safe3
  • Joomla Folder Scanner
  • maxisploit-scanner
  • sslyze
  • Lycaon Web Vulnerability
  • xss Scanner
  • Gamja
  • xSQL scanner
  • GSCRAPE
  • Vanguard
  • Damn small SQLI Scanner
  • Falcove Web Vulnerability Scanner 2.4
  • N-Stalker
  • Xscan
  • Vanguard Pentesting Scanner
  • Saint
  • Alelier
  • Shadow Security Scanner
  • Mopest
  • WebCruiser
  • XCode Exploit
  • XssScanner
  • CSRFScanner
  • ERPScan SaaS
  • XCobra
  • solarwinds
  • DDosPing
  • DIRE
  • DSScan



FUZZERS

  • Bed
  • Bf2
  • Bunny
  • Dkftpbench
  • FuzzDb
  • Fzem
  • JbroFuzz
  • MiniFuzz File Fuzzer
  • ftp-fuzz
  • Powerfuzzer
  • fuzzer toolkit
  • tftp-fuzz
  • Peach
  • untidy
  • Peach Fuzzing Platform
  • Fuzzer Toolkit
  • Sfuzz
  • Sulley
  • antiparser
  • Fusil
  • Spike
  • Fuzzbox
  • Voiper
  • WSFuzzer
  • ZZuf
  • UniOFuzz Universal Fuzzer Tool
  • Wikto
  • LFI Fuzzploit Tool
  • PHP Vulnerability Hunter
  • CAT
  • AxMan
  • Malybuzz
  • rfuzz



SMB ANALYSIS

  • Impacket Samrdump
  • Impacket Smbclient
  • keimpx
  • Smb4k
  • Smbclient



SNMP ANALYSIS

  • ADMSnmp
  • Braa
  • SnmpCheck
  • SnmpEnum
  • SnmpWalk

CORE Impact Professional

Logo Core ImpactCORE Impact Professional is the most comprehensive software solution for assessing and testing security vulnerabilities throughout your organization.

 
 

Read More...

IBM Security AppScan

Logo IBM Rational AppScanIBM Rational AppScan Enterprise is a scalable solution to help resolve application security vulnerabilities, offering recommendations to simplify remediation.

 

Read More...

HP WebInspect

Logo - HP WebInspectHP WebInspect gives security professionals and security novices alike the power and knowledge to quickly identify and validate critical, high-risk security vulnerabilities.

 

Read More...

Acunetix WVS

logo acunetix web application securityAcunetix Web Vulnerability Scanner (WVS) is an automated web application security testing tool that audits web applications by checking for hacking vulnerabilities. 

 

Read More...

w4rri0r - Hacking Is Not A Crime - It's an art of Awareness

\/ w4rri0r - Hacking Is Not A Crime - It's an art of Awareness \/ -  w4rri0r work in the dark, w4rri0r do what w4rri0r can, w4rri0r give what w4rri0r have, w4rri0r doubt is w4rri0r passion and w4rri0r passion is w4rri0r task. The rest is the madness of art \/ w4rri0r \/ 

\/ w4rri0r.com \/ are the great resource for information security professionals and researcher. \/ w4rri0r \/ offers a extensive variation of information security services that include SECURITY EXPLOITS (Bug or Vulnerability), SECURITY ADVISORIES (Security Alerts), SECURITY RESEARCHER TOOLBOX (Freeware, Shareware & Open-Source), SHELLCODE (Attacker Controller - Chunk of Data), SECURITY TRAINING (Educational Purpose), SECURITY NEWS (Security Recent or Important Events) and with this group you can be assured that you’re in the right hands. \/ w4rri0r gr0up \/  efforts being endorsed and appreciated by administrators, security researchers and members of various underground hacking groups and communities worldwide.

\/ w4rri0r mission \/ are to make the information systems more secure, more aware, more reliable and protect against possible security breaches.