Temas ActivosTemas Activos  Mostrar la lista de miembros del foroLista de miembros  calendariocalendario  Buscar en el foroBuscar  AyudaAyuda
  RegistrarRegistrar  Iniciar sesionIniciar sesion
Newbie's - Aprendices de Hackers
 Foros Cantv.net : Ciencia y tecnología : Seguridad en Internet general : Newbie's - Aprendices de Hackers  
Icono del mensaje Tema: Seguridad de Pagina Web Responder mensaje Escribir nuevo tema
Autor Mensaje
virus13
Intermedio
Intermedio
Avatar

Fecha de ingreso: 10 Junio 2007
Localidad: Venezuela
Estatus conectado: Desconectado
Mensajes: 422
Envíar un Mensaje Privado
Citar virus13 Responderbullet Tema: Seguridad de Pagina Web
    Escrito el: 19 Noviembre 2009 a las 11:06am
Hola buenos dias abro este post con la finalidad de solicitar algo de su ayuda ya que un compañero de estudios esta diseñando una pagina web, mejor dicho ya esta montada, pero queremos saber como confirmamos que posee una buena seguuridad, osea que no tiene esos huecos, para poder ser hackiada o algo por el estilo. hay alguna manera de hacer algun test o algo por el estilo para determinar la seguridad del site? espero me ayuden con esto. saludos
IP IP registrada
BlackShadow7777
Moderador
Moderador
Avatar
Newbie’s Hackers.Seguridad en Internet

Fecha de ingreso: 18 Mayo 2005
Localidad: Venezuela
Estatus conectado: Desconectado
Mensajes: 2118
Envíar un Mensaje Privado
Citar BlackShadow7777 Responderbullet Escrito el: 19 Noviembre 2009 a las 3:24pm
existen varios programas que pueden probar la seguridad de tu servidor y hasta algunas fallas en la programacion pueden dar lugar a vulnerabilidades:
 
prueba con:
 
nmap, gfilanguard, nessus, y los que te dejo aca abajo:
 
#1
Linux
*BSD
OS%20X
Windows
Command-line%20interface
Source%20code
Nikto : A more comprehensive web scanner
Nikto is an open source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3200 potentially dangerous files/CGIs, versions on over 625 servers, and version specific problems on over 230 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired). It uses Whisker/libwhisker for much of its underlying functionality. It is a great tool, but the value is limited by its infrequent updates. The newest and most critical vulnerabilities are often not detected.

#2
new
Linux
*BSD
OS%20X
Windows
Command-line%20interface
GUI%20Interface
Source%20code
Paros proxy : A web application vulnerability assessment proxy
A Java based web proxy for assessing web application vulnerability. It supports editing/viewing HTTP/HTTPS messages on-the-fly to change items such as cookies and form fields. It includes a web traffic recorder, web spider, hash calculator, and a scanner for testing common web application attacks such as SQL injection and cross-site scripting.

#3
new
Linux
*BSD
OS%20X
Windows
GUI%20Interface
Source%20code
WebScarab : A framework for analyzing applications that communicate using the HTTP and HTTPS protocols
In its simplest form, WebScarab records the conversations (requests and responses) that it observes, and allows the operator to review them in various ways. WebScarab is designed to be a tool for anyone who needs to expose the workings of an HTTP(S) based application, whether to allow the developer to debug otherwise difficult problems, or to allow a security specialist to identify vulnerabilities in the way that the application has been designed or implemented.

#4
new
%20%20TITLE=
Windows
GUI%20Interface
WebInspect : A Powerful Web Application Scanner
SPI Dynamics' WebInspect application security assessment tool helps identify known and unknown vulnerabilities within the Web application layer. WebInspect can also help check that a Web server is configured properly, and attempts common web attacks such as parameter injection, cross-site scripting, directory traversal, and more.

#5
Linux
*BSD
OS%20X
Windows
Command-line%20interface
Source%20code
Whisker/libwhisker : Rain.Forest.Puppy's CGI vulnerability scanner and library
Libwhisker is a Perl module geared geared towards HTTP testing. It provides functions for testing HTTP servers for many known security holes, particularly the presence of dangerous CGIs. Whisker is a scanner that used libwhisker but is now deprecated in favor of Nikto which also uses libwhisker.

#6
new
Linux
OS%20X
Windows
GUI%20Interface
Burpsuite : An integrated platform for attacking web applications
Burp suite allows an attacker to combine manual and automated techniques to enumerate, analyze, attack and exploit web applications. The various burp tools work together effectively to share information and allow findings identified within one tool to form the basis of an attack using another.

#7
new
Windows
GUI%20Interface
Source%20code
Wikto : Web Server Assessment Tool
Wikto is a tool that checks for flaws in webservers. It provides much the same functionality as Nikto but adds various interesting pieces of functionality, such as a Back-End miner and close Google integration. Wikto is written for the MS .NET environment and registration is required to download the binary and/or source code.

#8
new
%20%20TITLE=
Windows
Command-line%20interface
GUI%20Interface
Acunetix WVS : Commercial Web Vulnerability Scanner
Acunetix WVS automatically checks web applications for vulnerabilities such as SQL Injections, cross site scripting, arbitrary file creation/deletion, weak password strength on authentication pages. AcuSensor technology detects vulnerabilities which typical black box scanners miss. Acunetix WVS boasts a comfortable GUI, an ability to create professional security audit and compliance reports, and tools for advanced manual webapp testing.

#9
new
%20%20TITLE=
Windows
GUI%20Interface
Rational AppScan : Commercial Web Vulnerability Scanner
AppScan provides security testing throughout the application development lifecycle, easing unit testing and security assurance early in the development phase. Appscan scans for many common vulnerabilities, such as cross site scripting, HTTP response splitting, parameter tampering, hidden field manipulation, backdoors/debug options, buffer overflows and more. Appscan was merged into IBM's Rational division after IBM purchased it's original developer (Watchfire) in 2007.

#10
%20%20TITLE=
Windows
GUI%20Interface
N-Stealth : Web server scanner
N-Stealth is a commercial web server security scanner. It is generally updated more frequently than free web scanners such as Whisker/libwhisker and Nikto, but do take their web site with a grain of salt. The claims of "30,000 vulnerabilities and exploits" and "Dozens of vulnerability checks are added every day" are highly questionable. Also note that essentially all general VA tools such as Nessus, ISS Internet Scanner, Retina, SAINT, and Sara include web scanning components. They may not all be as up-to-date or flexible though. N-Stealth is Windows only and no source code is provided.
aunque esta en ingles solo necesitas ver los links y bajarlos, los iconos dicen en que sistema operativo puede funcionar.
 
cualquier duda particular no dudes en escribir
IP IP registrada
virus13
Intermedio
Intermedio
Avatar

Fecha de ingreso: 10 Junio 2007
Localidad: Venezuela
Estatus conectado: Desconectado
Mensajes: 422
Envíar un Mensaje Privado
Citar virus13 Responderbullet Escrito el: 20 Noviembre 2009 a las 2:54pm
a ok mi pana muchas gracias voy a revisar a ver q tal, pero me imagino q el q tiene que hacer las pruebas es el q esta creando la pagina? o yo la puedo hacer?
IP IP registrada

Ir arriba...


Responder mensaje Escribir nuevo tema
Printable version Printable version

Saltar al foro
Tu No puedes publicar nuevos temas
Tu No puedes responder a temas
Tu No puedes borrar sus respuestas
Tu No puedes editar sus respuestas
Tu No puedes crear encuestas
Tu No puedes votar en las encuestas

Bulletin Board Software by Web Wiz Forums version 8.05a
Copyright ©2001-2006 Web Wiz Guide

Conoce nuestros aliados | Mapa del Sitio | Recomiéndanos tu página | Publicidad con nosotros | Términos y Condiciones

Cantv.net. Rif: J-30186298-8. Todos los derechos reservados.