VTMScan is the complete feature-rich Website Vulnerability Scanner that detects various online threats and cyberattacks such as OWASP Top-10 Vulnerabilities, SQL Injections, and Cross-Site Scripting. Here is a complete list of its unique features.
Open Web Application Security Project (OWASP) is an online community in the field of web application security which releases a list of the top 10 vulnerabilities every few years. VTMScan detects those vulnerabilities and follows the rules laid out by OWASP. We scan for Cross-Site Scripting (XSS), SQL Injection, Insecure Deserialization, Sensitive Data Exposure, Server-Side Request Forgery (SSRF), etc. and report the vulnerabilities and provide recommendations to fix these issues. HTML injections are similar to Cross-Site Scripting (XSS). It allows the attacker to inject the HTML code into the web pages that the other users view.
Change Monitoring is an important feature provided by VTMScan. We scan every page of the website to detect any changes. Every change and percentage with the respective URLs are monitored throughout the website. Here we first create a snapshot of all the web pages and then scan each & every page for changes and report the irregularities found. This feature helps website owners to check whether there are any changes being done on the website without their concern or if these are just illegitimate changes. In content change monitoring VTMScan provides three features viz, Content change monitoring, Image Change Monitoring, and Visual change monitoring.
Website defacement is an attack on a website that changes the visual appearance of the site or a webpage.
Protect your customers and safeguard your website and web application with VTMScan.
Protect your customers and safeguard your website and web application with VTMScan.
Domain reputation in Google, SURBL, Malware Patrol, Clean-Mx, Phishtank, Sorbs, SpamCop, Abusech, Isc.
VTMScan checks whether your domain is listed in these databases - Google, SURBL, Malware Patrol, Clean MX, PhishTank, Sorbs, SpamCop, Abusech, and Isc.These organizations have databases that store IP addresses and domains extracted for malware, spamming, and phishing activities.
RBL (Real-time Blackhole Lists) have IP addresses whose owners refuse to stop the growth of spam. RBL lists various server IP addresses from multiple ISPs (Internet Service Providers) whose users are responsible for spam. RBL also lists those ISPs whose servers are hijacked for spam relay. VTMScan checks the mail server IPs in 58 such RBL repositories.
Link crawling is a process of capturing all the web pages (their URLs) present on the website. It helps us understand how many web pages are on our website and what these pages are related to. The website owner can also cross-check whether these pages are legitimate or not.
Banner grabbing is a collection of Information related to your websites, such as web server information, header information and open ports. Banner grabbing is a technique used to gain Information about a computer system on a network and the services running on its open ports. An intruder can use banner grabbing in order to find network hosts that are running versions of applications and operating systems with known exploits.
VTMScan checks for SSL Poodle, BEAST, CRIME, Heartbleed, DROWN, SSL grade check, SSL Certificate check etc.
Local File Inclusion (LFI) is a process where a file or a script is injected on a server through a web browser which allows local directory traversals and characters to be injected if the page is not sanitized. This attack leads to sensitive information disclosure.
Remote File Inclusion (RFI) is an attack which looks for vulnerabilities in a web application to include a remote file through a script on the web browser. The perpetrator wants to exploit the functions in an application to upload malware from a different domain.
The new feature of Data Leak has been introduced. Data Leak is the unapproved transmission of data from an organization to an external destination.VTMScan checks whether the data breach has occurred or not and displays it in the form of a proper list under page source. These are informative alerts provided by VTMScan.
VTMScan DMARC inspector does the following things-
VTMScan Page content Scan does the following things-