Automated Crawler towards Vulnerability Scan Report Generator

A Network Based Vulnerability Scanner for Detecting SQLI Attacks in Web Applications


Today is the world of information era, where information is available on just our single click. Web applications are playing a magnificent role in this, every organizations are mapping their business from a room to the world with the help of these Web Apps. Web applications generally consist of a three tier architecture where database is in the third pole, which is the most valuable assets in any organization, as the adaptation of web applications are increases day by day, various attacks are possible against this. SQL injection is an attack in which an attacker directly compromises the database, that's why this is a most threatening attack. Various Vulnerability scanners has been proposed to deal with this, but none of them are able to detect SQLI completely, the existing tools have the accuracy ratio very less as well as they produce a high rate of false positive, apart from that all these tools take much time to scan. So here we are presenting a network based vulnerability scanner approach which provides a better coverage and with no false positive within a short span of time.

Automated Crawler towards Vulnerability Scan Report Generator


A vulnerability scanner is a minor computer program designed to assess/analyze the computers, computer systems, networks or applications for prone to weaknesses.There are many number of vulnerability scanners available in the market, distinguished from another by a focus on particular targets.The goal of running/executing a vulnerability scanner is used to identify devices on your network that are open to known vulnerabilities.To determine what types of software is present, along with additional information about the possible issues in the computers—such as the type and version of the OS. This information can be used to analyze for known or recently discovered vulnerabilities that can be exploited to gain access to secure networks and computers.One major issue with vulnerability scanners is their performance impact on the devices they are scanning. On the one hand you want the scan to be able to be performed in the background without affecting the application. On the other hand, you want to be sure that the application scan should be thorough.In our project, we are going to use the concept of crawling the entire application and identify the possible attacks happening on the system.


