Web Application Vulnerability Scanner

Helping departments secure their web applications

[Nov 23, 2009 14:09] Web access to Microsoft Live@edu accounts now works.

The Process of Web Application Vulnerability Scanning

A web application vulnerability scanner is server based software that runs security tests against web applications. Since web applications are constantly facing the Internet, they are common targets for attacks. The detailed reports from the scanner will give you mitigation techniques and fixes that you can implement in a timely manner. Given the address of a web application, the scanner will create a report of the vulnerabilities found in the application. The bigger and more complex the web app, the more likely the scanner will find vulnerabilities. While the vulnerabilities vary in degree of importance, the report will allow you to concentrate on those vulnerabilities that cause the most concern in your computing environment.

Here is a sample of some information you might find in a report:

Severity High
Type Application level test
Classification Command Execution: SQL Injection
Security Risk It is possible to view, modify or delete database entries and tables
Fix Recommendation Sanitize user input
Severity Low
Type Infrastructure
Classification Information Disclosure: Information Leakage
Security Risk Disclosing the directory structure
Fix Recommendation Issue a "404 - Not Found" response instead of "403 -Forbidden" response

Web applications are best scanned in a development environment. If a development environment is not available, then scheduling the scan to avoid service disruption is recommended. The size of the web application determines the time it takes to scan.

If you would like to request a web application vulnerability scan, please contact ISPRO using our online form. Please note that requests for scans must be approved by the owning department's management.

© 2009 by the Rector and Visitors of the University of Virginia.

The information contained on the University of Virginia’s Department of Information Technology and Communication (ITC) website is provided as a public service with the understanding that ITC makes no representations or warranties, either expressed or implied, concerning the accuracy, completeness, reliability or suitability of the information, including warrantees of title, non-infringement of copyright or patent rights of others. These pages are expected to represent the University of Virginia community and the State of Virginia in a professional manner in accordance with the University of Virginia’s Computing Policies.