skipfish

Website

  • Libre
  • Mac
  • Windows
  • Linux
  • BSD
Description

Skipfish is a web application security reconnaissance tool. It is designed to scan web applications to detect security issues and vulnerabilities. It is an automated, active web application security reconnaissance tool written in C. It performs a recursive crawl and dictionary-based probes, using a powerful and custom-crafted dictionary of attack payloads. It can also analyze results to identify common web application security issues such as cross-site scripting, SQL injection, directory traversal, and PHP code injection. The report generated by Skipfish is easy to understand and provides a detailed view of uncovered risks and vulnerable parameters. It can also assist in identifying false positives and prioritize remediation efforts.

Categories
OS and utilities

Alternatives