List of Security Checks

Top  Previous  Next

These are the security checks currently available in N-Stalker X version.

 

Custom Design Errors

 

Cross-site Script Injection Module
Database Tampering - SQL Injection Module, including:
oDirect mode
oBlind mode
Buffer & Integer Overflow attack Module
Format String attack Module
File & Directories Tampering Module
Parameter Tampering Module, including:
Special Parameter Addition attacks
LDAP, XPath, XQuery injections
Boolean Parameter Tampering attacks
Hidden Parameter Discovery
Parameter Deletion attacks
Remote Execution attacks
File & Directory traversal attacks
Header Splitting & CRLF Injection attacks
Remote File Include PHP-based attacks

 

Web Server Exposure

 

Web Server Infrastructure Analysis Module, including:
oWeb Server version vulnerabilities
SSL encryption and x.509 certificate vulnerabilities
HTTP Method Discovery Module
HTTP Fingerprint Module, including:
oWeb Server Fingerprint Module
oWeb Server technology Discovery Module
Directory Brute-Force
HTTP Protocol vulnerabilities

 

Web Signature Attacks (40,000 attack database)

 

Web Attack Signatures Module, including:
oIIS CGI Decode Test
oIIS Extended Unicode Test
oIIS File Parsing Test
oFrontPage Security Test
oLotus Domino Security Test
oGeneral CGI Security Test
oHTTP Devices Security Test (routers, switches)
oWindows-based CGI Security Test
oPHP Web Application Security Test
oASP Web Application Security Test
oJ2EE Web Application Security Test
oColdfusion Web Application Security Test
Attack templates such as:
oComplete, SANS/FBI Top10, Top20

 

Confidentiality Exposure Checks

 

Look for Web forms vulnerabilities, including:
oPassword cache feature
oInsecure method for sending data
oLack of Encryption for sensitive data
oInsecure location to send data (leakage)
Information Leakage module, including:
oFind directory listing
oFind available objects to download
oFind meta-tag leakage
oFind sensitive keywords in comments and scripts
Compliance analysis, including:
oFind Copyright statements
oFind content rating statements
oFind custom content on web pages and forms

 

Cookie Exposure Checks

 

Cookie Security Analysis Module, including:
oFind weakness in cookie information
oFind cookies sent without encryption
oFind information leakage in cookie information
oFind cookies vulnerable to malicious client-side script

 

File & Directory Exposure Checks

 

Search for backup files
Search for information leakage files
Search for configuration files
Search for password files