Acunetix

Acunetix software is the leading web vulnerability scanner used by serious and widely acclaimed companies to include the most advanced injection and XSS black box scanning technology.

Fabricantes: Acunetix Ltd
Category: Rede/Segurança
Learn more about Acunetix

Request a Quote

What is Acunetix?

  • In-depth tracking and analysis - automatically scans all sites
  • Higher vulnerability detection rate
  • Integrated vulnerability management - prioritize and control threats
  • Integration with popular WAFs and Problem Trackers
  • Network security verification tools and manual testing

Is your site hackable?

Review your web security with the Acunetix vulnerability scanner

With the use of cloud computing and advances in browser technology, web applications have become a central component of business processes and a lucrative target for hackers. Organizations should make web application security not only a priority, but a key requirement. Enter the Acunetix Vulnerability Scanner!

A firewall is not enough

Firewalls, SSL and hardened networks are useless against hacking web applications. Web attacks are carried out through HTTP and HTTPS; the same protocols that are used to deliver content to legitimate users. Web applications are often tailor-made and tested less than off-the-shelf software; the repercussions of a web attack are often worse than traditional network-based attacks.

  • Detects more than 3000 web application vulnerabilities.
  • Scans open source software and custom applications.
  • Detects Critical Vulnerabilities with 100% Accuracy.

Technology leader in automated application security

Acunetix is a pioneer in automated web application security testing with innovative technologies including:

  • DeepScan technology - for tracking ajax client-side single-page applications (SPAs).
  • The industry's most advanced SQL Injection and Cross-site Scripting tests – include advanced DOM-based XSS detection.
  • AcuSensor Technology – Combines black box scanning techniques with comments from your sensors inserted within the source code.

Fast, accurate, easy to use

Multi-threaded tracker, lightning fast and scanner that can track hundreds of thousands of pages without interruptions.

  • Increased WordPress vulnerability detection – checks WordPress installations for more than 1200 known vulnerabilities in wordpress core, themes, and plugins.
  • An easy-to-use login sequence recorder that allows automatic scanning of complex password protected areas.
  • Review vulnerability data with integrated vulnerability management. Easily generate a wide variety of technical and compliance reports.

Increased SQL Injection and XSS Detection Rate

The holistic and accurate detection of the vulnerability lies in the ability to detect anything, from the most obvious to the darkest of vulnerabilities. Acunetix is the industry leader in detecting the widest variety of SQL Injection and XSS vulnerabilities, including out-of-band SQL Injection and DOM-based XSS, as well as 3,000 other web vulnerabilities.

Detailed SQL and XSS injection vulnerability testing

Acunetix rigorously tests thousands of web application vulnerabilities, including SQL Injection and XSS. However, when it comes to dynamic application security testing (DAST), while the number of tests a scanner can perform is important, it is secondary to how much it can crawl and scan an application. Acunetix DeepScan Technology:

  • Crawl and scan HTML5 Web applications and run JavaScript as a real browser.
  • Industry's highest detection rate for high-severity vulnerabilities.
  • Reliably detects advanced DOM-based scripts based on DOM.

Automated XSS Vulnerability Testing Based on Automated DOM

DOM-based XSS is possible when client-side scripts of the web application write user-provided data to the Document Object Model (DOM). The data is subsequently read from the DOM by the web application and sent to the browser. If the data is handled incorrectly, an attacker could inject a payload, which is stored as part of the DOM and executed when the data is read back from the DOM. This advanced type of XSS is very difficult to detect.

  • Acunetix checks a wide variety of advanced DOM-based XSS vulnerabilities.
  • Reports DOM-based XSS source and evaluation collector.
  • Provides an XSS payload stack trace based on injected DOM.

Blind XSS, XXE, SSRF and Email Header Injection Detection

Traditional methods of detecting vulnerabilities are insufficient when trying to detect out-of-band vulnerabilities; detecting vulnerabilities that do not provide a response to a scanner during testing. Detecting out-of-band vulnerabilities requires an intermediate service, such as Acunetix AcuMonitor that checks:

  • Blind XSS and XML External Entity Injection (XXE).
  • Server spoofing request (SSRF) and host header attacks.

System requirements

Operating system: Microsoft Windows 7 or Windows 2008 R2 and later

CPU: 32-bit or 64-bit processor

System memory: minimum 2 GB of RAM

Storage: 200 MB of available hard drive space.

This does not include the storage required to save the scan results – this will depend on the level of use of Acunetix.

You don't know what software you need or you haven't found what you were looking for?

You don't know what software you need or you haven't found what you were looking for? We have a team ready to help you choose the right software for your company.