Grendel Scan: Open Source Web Application Security Scanner

September 21, 2009 0:42 am · 0 comments

by Black

in Open Source,Penetration Testing,Web Application Penetration Testing

In one of our posts earlier this month, we spoke of XSS Rays. Whats special about  Grendel Scan you might ask? First of all, it is OPEN SOURCE. Second, it is FREE. Third, it is only one of those scanners which allows automatic 404 error detection. Fourth, it is Multi-Platform.

Do we have your attention yet? Okay.. moving on to some more meatier stuff. These are a few of the functions that the Grendel Scan performs:

  • Internal intercepting / testing proxy
  • HTTP request fuzzer
  • Manual requests
  • Automatic file-not-found profiles
  • Upstream proxy support
  • HTTP request & connection throttling
  • HTML form-based authentication; multiple user accounts
  • Granular scan settings
  • Blocked query parameters
  • URL white-lists & blacklists
  • Known session ID names

In addition to all of these, it has built in modules for the following:

  • SQL injection
  • Error-based checks
  • SQL tautologies – experimental
  • Miscellaneous tests
  • CRLF injection
  • Cross-site request forgery (CSRF) tests
  • Directory traversal tests
  • Generic fuzzing
  • Information Leakage
  • Platform error messages
  • Robots.txt testing
  • Comment lister
  • Web server configuration
  • Cross-site tracing (XST)
  • Proxy detection
  • Application architecture
  • Input / output flows
  • Offline website mirror

In short, it is an automated testing tool for detecting common web application vulnerabilities. It can also aid in manual testing as it has a intercepting proxy module.

All you need is Java 5 and above! Download this tool here!

P.S: We did not post about it any earlier as the download site was down for most of the time!

Searches leading to this post:
grendel scan tutorial, Grendel-Scan tutorial, websecurify tutorial

If you enjoyed this article, you might also like:

  • January 15, 2010 -- List of Free Web Application Scanners!
    I was on another site helping someone with the available options on FREE Web Application Scanners. W...
  • August 16, 2010 -- UPDATE: Websecurify 0.7!
    Good news for Websecurify lovers, as we have an updated Websecurify version 0.7 amongst us finally! ...
  • August 9, 2010 -- UPDATE: Websecurify 0.7RC2!
    Right on time this time! We have an updated Websecurify version 0.7RC2 amongst us now!“Websecu...
  • August 3, 2010 -- UPDATE: Websecurify 0.7RC1!
    Also, pretty late with this one (almost 6 days!), but here it is - we have an updated Websecurify ve...
  • June 25, 2010 -- UPDATE: Websecurify 0.6!
    Websecurify has been updated to Websecurify 0.6 about 12 hours ago!“Websecurify is a web and w...
  • May 31, 2010 -- UPDATE: Websecurify 0.6RC1!
    Websecurify has recently been updated! It's current version is Websecurify 0.6RC1!"Websecurify...
  • March 8, 2010 -- UPDATE: Websecurify 0.5!
    Seems like we missed a WebSecurify update - the Websecurify 0.5RC1. But now, Websecurify has been up...
  • February 23, 2010 -- UPDATE: Websecurify 0.5Beta1!
    It has been a long time since we spoke about WebSecurify. But now, after a few updates later, we are...
  • November 15, 2009 -- UPDATE: WebSecurify 0.4RC2
    It has been a long time since we spoke about WebSecurify. But now, after a few updates later, we are...

Previous post:

Next post: