Site sponsored by: Idera Try Idera’s new SQL admin toolset
SQL Server Performance

  • Home
  • Articles
  • Forums
  • Tips
  • Quiz
  • FAQ's
  • Blogs
  • Software
  • Books
  • About Us
RSS Feeds
Sign in | Join


Product Reviews

All Reviews
Audit Tools
Backup Tools
Change Management Tools
Clustering Tools
Coding Tools
Design Tools
Diff / Compare Tools
Documentation Tools
Job Management Tools
Log Recovery Tools
Monitoring Tools
Remote Access Tools
Reporting Tools
Security Tools
Testing Tools

Write for Us

Share you SQL Server knowledge with others and raise your profile in the community More...
Latest Articles

Policy Based Management in SQL Server 2008
Inside SQL Server Cluster Setup and Troubleshooting Techniques - Part I ...
Configure and Manage Policy Based Management in SQL Server 2008 ...
Using Column Sets with Sparse Columns

More     
 
Latest FAQ's

Cannot Start SQL Server Service
Users are able to connect to report manager but not able ...
Errors when SQL Server Snapshot Replication is Running
How to Display Server Name or IP Address in a Reporting ...

More     
   
Latest Software Reviews

Spotlight on ApexSQL Doc 2008
ApexSQL Enforce
Embarcadero Change Manager
SQL Server DBA Dashboard

More     

reviews >> security tools >> Is Your SQL Server Susceptible to SQL ...

Is Your SQL Server Susceptible to SQL Injection Attacks

By : Dinesh Asanka
Jul 19, 2006

Page 2 / 3

You can test a single Web site by typing the address directly in the application window or load a text file with multiple addresses to test several sites at once. WVS also features a Scan Wizard that will step you through the process of determining the type of scan you want to make, the targets you want to test, and the crawling options you want to set. You can save these settings in a profile for follow-up scans.

In addition to locating pages on your site by following the links from the home page, WVS can also test pages available through a robots.txt file, if available. (For more on robots.txt, see www.searchengineworld.com/robots/robots_tutorial.htm.)

As WVS analyzes and tests pages through which it can input data, it will provide recommendations on how to fix vulnerabilities it has found and suggest resources for learning more about them. Scanning options let you determine whether to disable alerts, report server errors, or sychronize scans on multiple sites.

If the database option is enabled, the results of a scan can be used to generate reports based on three threat-level categories – high, medium and low – in addition to one that summarizes information about the scan. You can even compare the results of the current scan with those of a previous one. The information to include in the reports can be customized and saved to a file or printed.

WVS also comes with an HTTP Editor for building custom HTTP requests, a Target Finder for probing a range of IP addresses, and an Authentication Tester to test password-protected Web sites.

Overall, this is a very helpful tool for developing Web sites. It occurred to me, however, that WVS may also be a good tool for hackers as they can easily use it to find Web sites that are vulnerable to SQL Injection.



Update Service

You can manually check for available updates from within the application or configure it to check automatically at application startup.



Support

As always, support plays a vital role when selecting a tool or product. Acunetix's main support module for the Web Vulnerability Scanner is e-mail. Using an option available from within the application itself, you can automatically gather information about your system and send it to the vendor.


<< Prev Page     Next Page>>    








Home | Peformance Articles | Audit Articles | Business Intelligence Articles | Clustering Articles | Developer Articles | Reporting Services Articles | DBA Articles | ASP.NET / ADO.NET Articles | DBA FAQ's | Developer Peformance FAQ's | DBA Peformance FAQ's | Developer FAQ's | Clustering FAQ's | Error Messages | Audit Tool Reviews | Backup Tool Reviews | Coding Tool Reviews | Compare Tool Reviews | Documentation Tool Reviews | Design Tool Reviews | Monitoring Tool Reviews | Log Tool Reviews | Reporting Tool Reviews | Clustering Tool Reviews | Security Tool Reviews | Change Management Tool Reviews | Remote Access Tool Reviews | Book Reviews | Security Tool Reviews | QDPMA Performance Tuning | ADO.NET / ASP.NET | Administration | Analysis/OLAP Services | Application Development | Configuration | Components | ETL | Hardware | High Availability | Hints | Index | Misc | Operating Systems | Performance Tuning | Replication | T-SQL | Views


              © 1999-2008 by T10 Media. All rights reserved