
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Online Security Scanner &#187; Site Updates</title>
	<atom:link href="http://hackertarget.com/category/site-updates/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackertarget.com</link>
	<description>Vulnerability Testing and Assessments</description>
	<lastBuildDate>Tue, 15 May 2012 09:53:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>WPScan added to WordPress Security Scan</title>
		<link>http://hackertarget.com/wpscan-added-to-wordpress-security-scan/</link>
		<comments>http://hackertarget.com/wpscan-added-to-wordpress-security-scan/#comments</comments>
		<pubDate>Tue, 15 May 2012 09:53:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=2482</guid>
		<description><![CDATA[For all you wordpress lovers we have added wpscan to our existing WordPress Security Scan. WPScan is a handy wordpress focused vulnerability scanner developed by Ryan Dewhurst (ethicalhack3r.co.uk). The scan uses techniques that include brute forcing the plugins directory of a wordpress installation to find installed plugins. This is an accurate way to find plugins [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/wpscan-added-to-wordpress-security-scan/' addthis:title='WPScan added to WordPress Security Scan' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<p>For all you wordpress lovers we have added <a href="http://hackertarget.com/wordpress-security-scan/">wpscan to our existing WordPress Security Scan</a>. <a href="http://www.ethicalhack3r.co.uk/security/introducing-wpscan-wordpress-security-scanner/">WPScan</a> is a handy wordpress focused vulnerability scanner developed by <a href="http://www.ethicalhack3r.co.uk">Ryan Dewhurst (ethicalhack3r.co.uk)</a>.</p>
<p>The scan uses techniques that include brute forcing the plugins directory of a wordpress installation to find installed plugins. This is an accurate way to find plugins and can even pinpoint plugins that are disabled within the site but still installed in the wp-content/plugins directory and possibly a security risk.</p>
<p><strong>Features of the active WPScan component include:</strong><br />
<div class="shortcode-unorderedlist tick"></div>
</p>
<ul>
<li>Username discovery; with usernames an attacker can then start brute forcing account passwords</li>
<li>Enhanced version enumeration, from both the meta generator tag and client side files</li>
<li>Vulnerability identification, comparing current version with known vulnerabilities</li>
<li>Timbthumb file discovery &#8211; this is a vulnerability affecting hundreds of thousands of WordPress sites</li>
<li>Plugin enumeration (over 2000 plugins tested)</li>
<li>Plugin vulnerability identification (from plugin name)</li>
<li>Test for directory indexing on any discovered plugins</li>
</ul>
<p>Due to the aggressive nature of the plugin and username discovery techniques we have decided to make the WPScan component of our online scanner available only to <a href="http://hackertarget.com/scan-membership/">members</a>.</p>
<p>If you would like to run WPScan from your own installation there are excellent getting started guides on the google-code site and in the README file. Getting it installed and running on Ubuntu or Back-track does not take much effort; so fire up your Linux distro and start testing.</p>
<p><em>Did you known that wordpress runs more than <a href="http://hackertarget.com/wordpress-infographic/" title="Infographic showing wordpress usage in the top 100000 web sites">11% of the worlds top web sites</a>. </em></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/wpscan-added-to-wordpress-security-scan/' addthis:title='WPScan added to WordPress Security Scan' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/wpscan-added-to-wordpress-security-scan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monitor Internet facing systems with regular port scanning</title>
		<link>http://hackertarget.com/monitor-internet-facing-systems-with-regular-port-scanning/</link>
		<comments>http://hackertarget.com/monitor-internet-facing-systems-with-regular-port-scanning/#comments</comments>
		<pubDate>Mon, 30 Apr 2012 08:45:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=2416</guid>
		<description><![CDATA[How do you know if something changes on your external services? We have launched our new monitoring tool; use it to alert you to changes that occur on your network perimeter or Internet facing servers. Systems administrators and security teams should be aware of what services are available from the Internet. With regular monitoring you [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/monitor-internet-facing-systems-with-regular-port-scanning/' addthis:title='Monitor Internet facing systems with regular port scanning' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<p><strong><em>How do you know if something changes on your external services?</em></strong></p>
<p>We have launched our new monitoring tool; use it to <strong>alert you to changes</strong> that occur on your network perimeter or Internet facing servers. Systems administrators and security teams should be aware of what services are available from the Internet.</p>
<p>With regular monitoring you can be alerted when something changes; here are a few examples:</p>
<h2>Detect firewall changes</h2>
<div class="shortcode-unorderedlist arrow"></p>
<ul>
<li>Was a firewall reconfigured during testing and not returned to a production state?</li>
<li>Why was the local firewall stopped on our web server?</li>
<li>Do you have IT staff who do not always follow change control?</li>
<li>Did a malicious party open a port in your firewall for unauthorised access?</li>
<li>Who forwarded ports on the router to access some torrents / and or games?</li>
</ul>
<p></div>

<h2>Detect Internet facing service changes</h2>
<div class="shortcode-unorderedlist arrow"></p>
<ul>
<li>Why was your FTP service shutdown?</li>
<li>Who opened remote desktop (RDP) or VNC services to the Internet?</li>
<li>Was the Web server upgrade fully tested before deployment (detect version changes)?</li>
<li>Why is there two different versions of SSH running on the web server (22 and 1337)?</li>
<li>FTP service changes, who installed a vulnerable version of the FTP server?</li>
</ul>
<p></div>

<p>These questions will not be answered by the new monitoring service; but you will know a change has occurred and at least be able <strong>to ask the question</strong>.</p>
<h2>Features of the new monitoring service include:</h2>
<div class="shortcode-unorderedlist star"></p>
<ul>
<li>Daily or Weekly Port Scans</li>
<li>Receive an email after every scan or only if something has changed</li>
<li>Uses the stable Nmap Port Scanner to ensure quality results</li>
<li>Scan IPv4 or IPv6 targets</li>
<li>Scan a range of IPv4 addresses (up to 254 IP&#8217;s or a class C network)</li>
<li>Scan is from a static IP address; whitelist your security monitoring (IDS / IPS).</li>
</ul>
<p></div>

<p>These screen shots, give a brief overview of what the service looks like. There is essentially two components from an end user perspective; a dashboard giving a summary of enabled scans and a form to schedule new tests.</p>
<p style="font-size: 0.8em"><strong>Screenshot 1: Dashboard</strong></p>
<p><a href="#" data-reveal-id="myModal"><img src="/port-scan-monitoring-dashboard-small.jpg" style="box-shadow: 3px 4px 4px rgb(204, 204, 204); padding-right: 10px;"></a><span style="color: #EBF4FB;"></span></p>
<p><strong><span style="font-size: 0.8em;">Screenshot 2: Schedule New Monitor</span></strong></p>
<p><a href="#" data-reveal-id="myModal2"><img src="/schedule-port-scan-screenshot-small.jpg" style="box-shadow: 3px 4px 4px rgb(204, 204, 204); padding-left: 10px;"></a></p>
<p>Gold or Silver membership is required to use the scheduled port scanning. Immediate access is available to <a href="/scan-membership/">new members</a> or <a href="/wp-login.php">login now</a> if you have a valid membership.</p>
<div id="myModal" class="reveal-modal" style="top: 20px; width: 800px; margin-left: -440px; background: #fff;">
<img src="/port-scan-monitoring-dashboard.jpg" style="border: 0px;"><br />
<a class="close-reveal-modal">&#215;</a>
</div>
<div id="myModal2" class="reveal-modal" style="top: 20px; width: 800px; margin-left: -440px; background: #fff;">
<img src="/schedule-port-scan-screenshot.jpg" style="border: 0px;"><br />
     <a class="close-reveal-modal">&#215;</a>
</div>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/monitor-internet-facing-systems-with-regular-port-scanning/' addthis:title='Monitor Internet facing systems with regular port scanning' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/monitor-internet-facing-systems-with-regular-port-scanning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPv6 added to online port scanner</title>
		<link>http://hackertarget.com/ipv6-added-to-online-port-scanner/</link>
		<comments>http://hackertarget.com/ipv6-added-to-online-port-scanner/#comments</comments>
		<pubDate>Sat, 03 Mar 2012 11:39:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=2022</guid>
		<description><![CDATA[Our online nmap port scanner is now IPv6 capable. Nmap has had the ability to scan IPv6 ip addresses for some time now and recently Linode also added IPv6 to its VPS offerings. These additions mean we can now provide on-line port scanning of both IPv4 and IPv6 addresses or Host names that have an [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/ipv6-added-to-online-port-scanner/' addthis:title='IPv6 added to online port scanner' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<p>Our <a href="http://hackertarget.com/nmap-scan/" title="Nmap Online Port Scanner">online nmap port scanner</a> is now IPv6 capable. <a href="http://www.nmap.org" title="Nmap Port Scanner">Nmap</a> has had the ability to scan IPv6 ip addresses for some time now and recently <a href="http://www.linode.com/?r=798ba6bf0c7bf7abd54b5fddbeef8966f13113de" title="Linode VPS Hosting">Linode</a> also added IPv6 to its VPS offerings. These additions mean we can now provide on-line port scanning of both IPv4 and IPv6 addresses or Host names that have an appropriate AAAA DNS record.</p>
<p>It is important to understand what ports are open and listening on your perimeter network or hosted Internet servers. With the updated tool you can now quickly determine what ports are listening on both your IPv4 based address and your IPv6 address. As people move towards IPv6 (will 2012 be the year of IPv6?), it is necessary to ensure that network protection devices and software are configured and capable of protecting both IPv4 and IPv6 traffic.</p>
<p>An <a href="http://en.wikipedia.org/wiki/AAAA_record#IPv6_in_the_Domain_Name_System" title="AAAA Record">AAAA DNS record</a> has been added to our main site, and if you try our <a href="http://hackertarget.com/powered-by/" title="Powered By Technology Tool">powered by tool</a> (part of the <a href="http://hackertarget.com/ip-tools/" title="Network IP Tools">IP Tools</a>), you will be able to see that we are serving pages to both IPv4 and IPv6 addresses.</p>
<p>If 2012 is going to be year of IPv6 we are ready to go. <img src='http://hackertarget.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/ipv6-added-to-online-port-scanner/' addthis:title='IPv6 added to online port scanner' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/ipv6-added-to-online-port-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 100K Sites WordPress Usage Infographic</title>
		<link>http://hackertarget.com/top-100k-sites-wordpress-usage-infographic/</link>
		<comments>http://hackertarget.com/top-100k-sites-wordpress-usage-infographic/#comments</comments>
		<pubDate>Mon, 22 Aug 2011 13:08:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[infographic]]></category>
		<category><![CDATA[visualization]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=1555</guid>
		<description><![CDATA[WordPress.org have a post up detailing the &#8220;state of the word&#8221;. Around the same time we have been putting a wordpress infographic that highlights some of the findings from our analysis of wordpress usage among the top 100K sites (as rated by Alexa). WordPress Usage in the Top 100K Infographic<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/top-100k-sites-wordpress-usage-infographic/' addthis:title='Top 100K Sites WordPress Usage Infographic' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<p>WordPress.org have a <a href="http://wordpress.org/news/2011/08/state-of-the-word/" title="State of the Word" target="_blank">post</a> up detailing the &#8220;state of the word&#8221;. </p>
<p>Around the same time we have been putting a wordpress <a href="http://www.good.is/infographics" title="What is an Infographic?" target="_blank">infographic</a> that highlights some of the findings from our analysis of wordpress usage among the top 100K sites (as rated by Alexa).</p>
<p><a href="http://hackertarget.com/wordpress-infographic/" title="WordPress Usage Statistics Infographic">WordPress Usage in the Top 100K Infographic</a></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/top-100k-sites-wordpress-usage-infographic/' addthis:title='Top 100K Sites WordPress Usage Infographic' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/top-100k-sites-wordpress-usage-infographic/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Winter Updates</title>
		<link>http://hackertarget.com/winter-updates/</link>
		<comments>http://hackertarget.com/winter-updates/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 03:49:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=1383</guid>
		<description><![CDATA[Being mid-winter down here in Sydney, its been a time to hunker down and drink copious amounts of coffee. While doing that we have also pushed out many changes and updates to the scanning system and site. If you find any bugs, drop us a line.<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/winter-updates/' addthis:title='Winter Updates' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<p>Being mid-winter down here in Sydney, its been a time to hunker down and drink copious amounts of coffee.</p>
<p>While doing that we have also pushed out many changes and updates to the scanning system and site.</p>
<div class="shortcode-unorderedlist star"></p>
<ul>
<li>Backend, bug fixes in some of the backend scans. Improvements to other scans including improved results layout and more security checks.</li>
<li>Theme Refresh, we have stuck with the same Wootheme but have tidied up and done some updates. Hopefully the options and information is now clearer making it easier for you to get on with scanning and securing your systems.</li>
<li>Look out for upcoming exploitation demonstration posts and tutorials for the security newbies.</li>
</ul>
<p></div>

<p>If you find any bugs, drop us a line.</p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/winter-updates/' addthis:title='Winter Updates' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/winter-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure WordPress</title>
		<link>http://hackertarget.com/secure-wordpress/</link>
		<comments>http://hackertarget.com/secure-wordpress/#comments</comments>
		<pubDate>Thu, 26 May 2011 00:18:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=1043</guid>
		<description><![CDATA[WordPress Scanner is the latest tool added to our kit. It can be used to test the security of your wordpress installation from an external perspective. No plugin installation is required, our systems will do an external passive analysis of your wordpress installation and highlight wordpress security issues along with recommendations to improve the security [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/secure-wordpress/' addthis:title='Secure WordPress' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<p><a title="WordPress Scanner to Test Security of Installations" href="http://hackertarget.com/wordpress-security-scan">WordPress Scanner</a> is the latest tool added to <a title="Online Security Scan" href="http://hackertarget.com/">our kit</a>. It can be used to test the security of your <a href="http://wordpress.org">wordpress</a> installation from an external perspective. No plugin installation is required, our systems will do an external passive analysis of your wordpress installation and highlight wordpress security issues along with recommendations to improve the security of your installation.</p>
<p>Did you know that wordpress is the most popular web publishing platform? When looking at the Top 1 Million sites it is well ahead of other big players such as the Google owned <a href="http://www.blogger.com">Blogger</a> and open source frameworks such as <a href="http://www.joomla.org">Joomla</a> and <a href="http://www.drupal.org">Drupal</a>. In March <a href="http://hackertarget.com/2011/03/web-tech-2011-report/">HackerTarget.com produced a report</a> on the popularity of technologies in the Alexa Top 1 Million Sites.</p>
<p>Operating a secure WordPress installation is not a difficult task, it does require a small amount of work to stay on top of things, afterall with WordPress being so popular the security is constantly being tested.</p>
<blockquote><h3>Tips for securing your WordPress CMS</h3>
<ul>
<li> Back It Up &#8211; Be ready to lose it all at anytime. If you have an up to date backup restoring is much easier</li>
</ul>
<ul>
<li> Keep WordPress System up to date</li>
</ul>
<ul>
<li>Keep all Plugins up to date</li>
</ul>
<ul>
<li> Beware of untrusted Themes</li>
</ul>
<ul>
<li> Rename admin account to a non-generic name</li>
</ul>
<ul>
<li> Use strong passwords ( a dictionary word with a number after it is not a strong password! )</li>
</ul>
<ul>
<li> Keep your password safe! Do not re-use it on other sites.</li>
</ul>
<ul>
<li> Ensure you have up to date AV on your Windows Machine. Malware collects passwords.</li>
</ul>
<ul>
<li> The underlying server must be well managed and in a secure state</li>
</ul>
<ul>
<li> VPS or Dedicated server? Set up server monitoring (<a href="http://www.ossec.net" title="Host Based Log and IDS Analyser">ossec.net</a> is a good start)</li>
</ul>
</blockquote>
<p>There are a multitude of guides to securing your WordPress installation, in the mean time why not test your sites security now with our easy to use <a title="WordPress Scanner to Test Security of Installations" href="http://hackertarget.com/wordpress-security-scan">online scanner</a>.</p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/secure-wordpress/' addthis:title='Secure WordPress' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/secure-wordpress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New OpenVas Report Option</title>
		<link>http://hackertarget.com/new-openvas-report-option/</link>
		<comments>http://hackertarget.com/new-openvas-report-option/#comments</comments>
		<pubDate>Thu, 05 May 2011 03:14:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[openvas]]></category>
		<category><![CDATA[security reporting]]></category>
		<category><![CDATA[vulnerability scan]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=1008</guid>
		<description><![CDATA[OpenVas is one the most popular tools we have online, and is an excellent way to perform a thorough vulnerability scan of a system to determine if there are any security issues or holes present. We have in the past couple of weeks added a new &#8220;Enhaned PDF&#8221; reporting option to our scanner, that is [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/new-openvas-report-option/' addthis:title='New OpenVas Report Option' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.openvas.org" title="OpenVas Scanner">OpenVas</a> is one the most popular tools we <a href="http://hackertarget.com/openvas-scan/" title="online vulnerability scan">have online</a>, and is an excellent way to perform a thorough vulnerability scan of a system to determine if there are any security issues or holes present.</p>
<p>We have in the past couple of weeks added a new &#8220;Enhaned PDF&#8221; reporting option to our scanner, that is a simple wrapper script around the html report. The idea is that it provides an easy to read and more understandable format for some of our less technical users, or those who would like to pass the report with the nice charts onto management.</p>
<p>In addition it does some basic data and geoip collection around the IP address and includes this in a map format.</p>
<p>If you have any further ideas or comments let us know.</p>
<p><a href="http://hackertarget.com/openvas-scan/">Online OpenVas Scan</a></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/new-openvas-report-option/' addthis:title='New OpenVas Report Option' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/new-openvas-report-option/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>sqlmap 0.9 added to online security scans</title>
		<link>http://hackertarget.com/sqlmap-0-9-added-to-online-security-scans/</link>
		<comments>http://hackertarget.com/sqlmap-0-9-added-to-online-security-scans/#comments</comments>
		<pubDate>Wed, 20 Apr 2011 09:22:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=912</guid>
		<description><![CDATA[Latest update to the site tools is the addition of the new SqlMap 0.9 release to the sql injection test page. This is a tool that takes SQL Injection to the next level and beyond. While our online scan tests for Sql Injection in HTTP GET requests, this is only the beginning. This tool can [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/sqlmap-0-9-added-to-online-security-scans/' addthis:title='sqlmap 0.9 added to online security scans' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<p>Latest update to the site tools is the addition of the new SqlMap 0.9 release to the <a title="Free SQL Injection Scan Online" href="http://hackertarget.com/free-sql-scan/">sql injection test page</a>.</p>
<p>This is a tool that takes SQL Injection to the next level and beyond. While our online scan tests for Sql Injection in HTTP GET requests, this is only the beginning. This tool can exploit sql injection to give the tester an full operating system access either via an inserted shell or by external command execution. Does not matter if you are on Windows or Linux it can do both.</p>
<p>All the details are on the <a title="SQLmap - sql injection test site" href="http://sqlmap.sourceforge.net/">main site</a>. Or here is a quick list of improvements:</p>
<div>
<ul>
<li>Full support for <strong>MySQL</strong>, <strong>Oracle</strong>, <strong>PostgreSQL</strong>, <strong>Microsoft SQL Server</strong>, <strong>Microsoft Access</strong>, <strong>SQLite</strong>, <strong>Firebird</strong>, <strong>Sybase</strong> and <strong>SAP MaxDB</strong> database management systems.</li>
<li>Full support for five SQL injection techniques: <strong>boolean-based blind</strong>, <strong>time-based blind</strong>, <strong>error-based</strong>, <strong>UNION query</strong> and <strong>stacked queries</strong>.</li>
<li>Support to <strong>directly connect to the database</strong> without passing via a SQL injection, by providing DBMS credentials, IP address, port and database name.</li>
<li>Support to enumerate <strong>database users</strong>, <strong>users&#8217; password hashes</strong>, <strong>users&#8217; privileges</strong>, <strong>users&#8217; roles</strong>, <strong>databases</strong>, <strong>tables</strong> and <strong>columns</strong>.</li>
<li>Automatic recognition of password hashes format and support to <strong>crack them with a dictionary-based attack</strong>.</li>
<li>Support to <strong>dump database tables</strong> entirely, a range of entries or specific columns as per user&#8217;s choice. The user can also choose to dump only a range of characters from each column&#8217;s entry.</li>
<li>Support to <strong>search for specific database names, specific tables across all databases or specific columns across all databases&#8217; tables</strong>. This is useful, for instance, to identify tables containing custom application credentials where relevant columns&#8217; names contain string like <em>name</em> and <em>pass</em>.</li>
<li>Support to <strong>download and upload any file</strong> from the database server underlying file system when the database software is MySQL, PostgreSQL or Microsoft SQL Server.</li>
<li>Support to <strong>execute arbitrary commands and retrieve their standard output</strong> on the database server underlying operating system when the database software is MySQL, PostgreSQL or Microsoft SQL Server.</li>
<li>Support to <strong>establish an out-of-band stateful TCP connection between the attacker machine and the database server</strong> underlying operating system. This channel can be an interactive command prompt, a Meterpreter session or a graphical user interface (VNC) session as per user&#8217;s choice.</li>
<li>Support for <strong>database process&#8217; user privilege escalation</strong> via Metasploit&#8217;s <code>getsystem</code> command which inclhttp://testphp.vulnweb.com/artists.php?artist=2ude, among others, the  <a href="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0346.html">kitrap0d</a> technique ( <a href="http://www.microsoft.com/technet/security/bulletin/ms10-015.mspx">MS10-015</a>).</li>
</ul>
<p>Have a look at the help file on the <a title="Free SQL Scanner" href="http://hackertarget.com/free-sql-scan/">scan page</a> for a sample run against the <a title="Acunetix Web Application Home Page" href="http://www.acunetix.com/">Acunetix</a> <a title="Acunetix Test Site" href="http://testphp.vulnweb.com/artists.php?artist=2">Test Site</a>.</p>
</div>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/sqlmap-0-9-added-to-online-security-scans/' addthis:title='sqlmap 0.9 added to online security scans' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/sqlmap-0-9-added-to-online-security-scans/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Tech 2011 &#8211; Part 2</title>
		<link>http://hackertarget.com/web-tech-2011-part-2/</link>
		<comments>http://hackertarget.com/web-tech-2011-part-2/#comments</comments>
		<pubDate>Thu, 07 Apr 2011 06:42:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[fortune 1000]]></category>
		<category><![CDATA[mail hosting comparison]]></category>
		<category><![CDATA[web hosting]]></category>
		<category><![CDATA[web server survey]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=878</guid>
		<description><![CDATA[google.load("visualization", "1", {packages:["corechart"]}); google.setOnLoadCallback(drawChart); function drawChart() { var data = new google.visualization.DataTable(); data.addColumn('string', 'Type'); data.addColumn('number', 'Top 1 million'); data.addColumn('number', 'Netcraft'); data.addColumn('number', 'Fortune 1K'); data.addRows([ ['Apache', 66.3, 60.1, 28.5], ['IIS', 17.3, 20.0, 55.1], ['nginx', 7.5, 7.6, 0.5], ['Google', 3.0, 5.1, 0.1], ['LiteSpeed', 1.1, 0, 0], ['lighttpd', 0.5, 0.7, 0.1], ['IBM HTTP', 0.3, 0, 7.7], ]); var [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/web-tech-2011-part-2/' addthis:title='Web Tech 2011 &#8211; Part 2' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript" src="https://www.google.com/jsapi"></script><br />
<script type="text/javascript">
google.load("visualization", "1", {packages:["corechart"]});
google.setOnLoadCallback(drawChart);
function drawChart() {
var data = new google.visualization.DataTable();
data.addColumn('string', 'Type');
data.addColumn('number', 'Top 1 million');
data.addColumn('number', 'Netcraft');
data.addColumn('number', 'Fortune 1K');
data.addRows([
['Apache', 66.3, 60.1, 28.5],
['IIS', 17.3, 20.0, 55.1],
['nginx', 7.5, 7.6, 0.5],
['Google', 3.0, 5.1, 0.1],
['LiteSpeed', 1.1, 0, 0],
['lighttpd', 0.5, 0.7, 0.1],
['IBM HTTP', 0.3, 0, 7.7],
]);
var chart = new google.visualization.BarChart(document.getElementById('chart_div'));
chart.draw(data, {width: 550, height: 400, title: 'Web Server Comparison (% in use)', legend: 'bottom',
vAxis: {title: 'Web Server', titleTextStyle: {color: 'grey'}
}
});
}
</script><br />
Now available is Part 2 of our Web Tech Report 2011 data mining project. We have compared the results of the <a href="http://hackertarget.com/2011/03/web-tech-2011-report/" title="most popular web servers, operating systems and technologies">most popular web technologies of the Top 1 Million Web Sites</a> with the most popular Technologies in use by the Forbes Fortune 1000 US Corporations.</p>
<p>There is a clear preference by the largest corporations to build systems around proprietary technology, as opposed to top million where the preference is for open source based solutions. See the full reports for details.</p>
<div id="chart_div"></div>
<p>See the following chart for a comparison of our numbers comparing the results from the <a href="http://hackertarget.com/2011/03/web-tech-2011-report/">Alexa Top 1 Million Survey</a>, the results from this report and the results from the ongoing web server report from <a href="http://news.netcraft.com/archives/2011/">Netcraft</a>.</p>
<p>Full details are in the linked report:<br />
<strong>Download from</strong> <a href="http://hackertarget.com/whitepapers/web-tech-2011-top-1000-corporations.pdf">HackerTarget.com</a><br />
or<br />
<strong>View online at</strong> <a href="http://www.scribd.com/doc/52468434/Web-Tech-2011-Top-1000-Corporations">Scribd</a></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/web-tech-2011-part-2/' addthis:title='Web Tech 2011 &#8211; Part 2' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/web-tech-2011-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Tech 2011 Report</title>
		<link>http://hackertarget.com/web-tech-2011-report/</link>
		<comments>http://hackertarget.com/web-tech-2011-report/#comments</comments>
		<pubDate>Mon, 28 Mar 2011 10:27:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[cms]]></category>
		<category><![CDATA[cms popular]]></category>
		<category><![CDATA[cms review]]></category>
		<category><![CDATA[cms security]]></category>
		<category><![CDATA[content management system comparison]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[web server]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=832</guid>
		<description><![CDATA[The HackerTarget.com Web Tech 2011 Report has just been released. This is the first edition of the report and aims to provide insight into the web technologies in use by the worlds most popular websites. Based on the Alexa top 1 million sites; content management system popularity, web servers, server side scripting, web development frameworks, [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/web-tech-2011-report/' addthis:title='Web Tech 2011 Report' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://hackertarget.com" title="Vulnerability Assessment Services">HackerTarget.com</a> Web Tech 2011 Report has just been released. This is the first edition of the report and aims to provide insight into the web technologies in use by the worlds most popular websites. Based on the <a href="http://www.alexa.com" title="Alexa Web Metrics">Alexa</a> top 1 million sites; content management system popularity, web servers, server side scripting, web development frameworks, client side scripting and other detected technologies have all been assessed.</p>
<p>Data was collected by running <a href="http://hackertarget.com/whatweb-scan/">whatweb</a> from <a href="http://www.morningstarsecurity.com/research/whatweb" target="_blank">morningstar security</a> against the Alex 1 million top sites.</p>
<p><em>* Note the report was updated on 7/4/11 due to a data parsing error that resulted in some sites with no English characters in the Title having some data missed. Links below have been updated.</em></p>
<p>Full details are in the linked report:<br />
<strong>Download from</strong> <a href="http://hackertarget.com/whitepapers/web-tech-2011.pdf" title="Web Technology Survey 2011">HackerTarget.com</a><br />
or<br />
<strong>View online at</strong> <a href="http://www.scribd.com/doc/51690209/web-tech-2011" target="_blank">Scribd</a>.</p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://hackertarget.com/web-tech-2011-report/' addthis:title='Web Tech 2011 Report' ><a class="addthis_button_facebook"></a><a class="addthis_button_twitter"></a><a class="addthis_button_delicious"></a><a class="addthis_button_reddit"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/web-tech-2011-report/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced

Served from: www.hackertarget.com @ 2012-05-17 23:01:12 -->
