Google Blogoscoped

Forum

New Web application security scanner from Google: skipfish

Juha-Matti Laurio [PersonRank 10]

Monday, March 22, 2010
14 years ago2,482 views

http://code.google.com/p/skipfish/wiki/SkipfishDoc

Juha-Matti Laurio [PersonRank 10]

14 years ago #

Skipfish is written and maintained by Googler Michal Zalewski

From the referenced Web page:

"Skipfish is an active web application security reconnaissance tool. It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated with the output from a number of active (but hopefully non-disruptive) security checks. The final report generated by the tool is meant to serve as a foundation for professional web application security assessments.
...."

Juha-Matti Laurio [PersonRank 10]

14 years ago #

Mentioned also at

http://googleonlinesecurity.blogspot.com/2010/03/meet-skipfish-our-automated-web.html

Roger Browne [PersonRank 10]

14 years ago #

There seems to be a lot of overlap between skipfish and Google's other security tool, ratproxy. It's not clear which would be the best one to start with, given that both appear to have quite a big learning curve.

Ratproxy may require more configuration (because it involves running a proxy server on your computer so that ratproxy can intercept your interaction with your website), but it's probably less invasive (because in its default mode it "follows along" with the interaction between you and your website, rather than initiating it).

But both tools can be run in a number of different modes, with different degrees of invasiveness. I would be interested to hear from anyone who uses both of them.

Forum home

Advertisement

 
Blog  |  Forum     more >> Archive | Feed | Google's blogs | About
Advertisement

 

This site unofficially covers Google™ and more with some rights reserved. Join our forum!