VTMScan (Malware, Threat, Vulnerability Scanner) Enterprise Class Security Scanner
0
https://www.esds.co.in
Agenda 01 About Scanning tools 02 VTMScan Flow 03 VTMScan Product Features 04 VTMScan Portal 05 VTMScan Report https://www.esds.co.in
About Scanning tools Web application scanner Performs vulnerability assessment of web applications It is SAAS, agentless scanner
OWASP Top 10 Vulnerabilities
Manual Security Audit Provides report with recommendation https://www.esds.co.in
VTMScan Flow
User
Banner Grabbing
Domain Reputation Main Domain External Domain Reverse IP
CMS Detection WordPress Joomla Drupal vBulletine
Link Crawling
Port Scanning SSL Check WAF Detection OS Detection
OWASP Audit
Malware Scan Page Defacement JS Codes/Functions JS Obfuscation Third Party Link check
Content Change Monitoring
Phishing Detection
SQLi Detection XSS Detection Insecure Deserialization Click Jacking Security Misconfiguration
Reports https://www.esds.co.in
VTMScan Product Features Domain Reputation
PORT scan Security Misconfiguration
XSS
SQL injection
Phishing Detection Cross Site Scripting
Malware Scan https://www.esds.co.in
OS Detection
VTMScan Product Features File Serialization OBJECT
Stream of Bytes
Deserialization Stream of Bytes
OBJECT
Insecure Deserialization https://www.esds.co.in
VTMScan Product Features 05
SSL Scan .03
CMS Scan
01 SSL
Content Change Monitoring 02
04
WAF Detection .
Banner Grabbing https://www.esds.co.in
VTMScan Product Features Domain Reputation Checks domain reputation in Google , SURBL , Malware Patrol , clean MX, Phish Tank Domain mail server IP check in 58 Real time Black hole list and DNS based black hole list
PORT scan Checks for Open ports on the server and services running on it. An open port could be potentially a threat to the server if not properly managed
SQL injection Support for multiple DBMSs, including MySQL, Oracle, PostgreSQL, Microsoft SQL Server, Microsoft Access, IBM DB2, SQLite, Firebird and SAP MaxDB‘ Checks for poorly filtered or in-correct escaped SQL queries into parsing variable data received from user https://www.esds.co.in input
VTMScan Product Features Malware Scan
1
Protect your customers and safeguard your Web application with VTMScan Phishing Find similar looking domains that adversaries can use to attack you. Can detect typosquatters, phishing attacks, fraud and corporate espionage. Corporate intelligence & Punycode phishing attack detection VTMscan takes in your domain name as a seed, generates a list of potential phishing domains and then checks to see if they are registered Additionally it can test if the mail server from MX record can be used to intercept misdirected corporate e-mails and it can generate fuzzy hashes of the web pages to see if they are live phishing sites.
Scans for Page defacement and JavaScript's codes against generic signatures Special algorithm developed to detect JavaScript Obfuscation Third party links found in page are checked in Google malware database
3
Cross Site Scripting XSS enables attackers to inject client side scripts into web pages viewed by others Scans each and every form in the webpages and scans for GET and POST request to detect XSS
2
Phishing Detection https://www.esds.co.in
VTMScan Product Features We look for Deserialization Vulnerabilities in multiple java frameworks, platforms and applications (e.g. Jenkins , Seam Framework, RMI over HTTP, Remote, Java Server Faces - JSF) We check Deserialization Vulnerabilities in Servlet , Apache Struts2 , JBoss Application ,Jmx-console, adminconsole, web-console, JMXInvokerServlet
File Serialization OBJECT
Stream of Bytes
Desearlization Stream of Bytes
OBJECT
Insecure Desearlization https://www.esds.co.in
VTMScan Product Features Security Misconfiguration Automatically detects CMS (word press, Joomla, etc. ) Scans all themes , Plugins, Unprotected admin area File path disclosure scanning
3
SSL Scan
Checks Authenticity of SSL Certificate Checks if algorithm used in SSL are weak or not Check poodle, heartbleed, DRWON, Beast, Logjam etc. Detects if SSL Certificate is expired
Check for misconfigured HTTP security headers Check for http flag secure, trace method enabled Check for directory indexing & access
2
CMS Scan
VTMScan Product Features Checks Operating system and its version of Web Server Verifies OS and its version with Vulnerability database
OS Detection
Reports if Vulnerability present on detected OS Version
https://www.esds.co.in
VTMScan Product Features WAF Detection Creates a snapshot of current state of your website Compares each time current state of website with snapshot and informs if any changes are observed on website
Detects if website is protected by Web Application Firewall Sends malicious payloads to website and checks if any defense mechanism is used by website which is blocking or filtering requests
3
Banner Grabbing Finds all possible information regarding website. Finds sub domains Finds webserver information.
2
Content Change Monitoring https://www.esds.co.in
VTMScan Portal- Home Scan Grid
Upcoming Scans
Last Scans
Queued Scans
Closed Domains
https://www.esds.co.in
VTMScan Portal- Adding and Editing Domain List of scanned website Details of scanned website
https://www.esds.co.in
VTMScan Portal -Troubleshoot using Ping
https://www.esds.co.in
VTMScan Portal– Troubleshoot using Telnet
Enter hostname/IP with port number and submit to check if website is live & active. Example: esds.co.in 80
https://www.esds.co.in
VTMScan Portal– Adding and Editing Domain
Enter hostname to check if website is live & active by checking page status. Example: esds.co.in
https://www.esds.co.in
VTMScan Portal– Reports
Click here to get detail Click here to report about get detail the website report about scan the website scan Short Description about vulnerabilities type and links affected by it. https://www.esds.co.in
VTMScan Portal– Scan Info
Scan short summary
Vulnerabilities and its severity
Details of scanned website
Export Scan Report
https://www.esds.co.in
VTMScan Portal – Scan Info
SOCIAL MEDIA Types of Reports
Scan Report : Complete Report without recommendations Scan Report with Recommendations Complete Report
Brief Scan Report: Report containing only vulnerability count
URL Report: Report containing full list of websites Content Change Report: Report containing CCM results. https://www.esds.co.in
VTMScan Portal – Banner Grabbing Report Domain reputation in Top RBL’s
OS Detection Open ports and services running on it
https://www.esds.co.in
VTMScan Portal – Flag Set Detection Report
Detects HTTPOnly Flag set status
https://www.esds.co.in
VTMScan Portal – Sensitive URL’s Report
Lists Admin/Login Pages/ sensitive URL’s/ Directory Access
https://www.esds.co.in
VTMScan Portal – OWASP Audit Report
OWASP Attack types
Attack type, affected URL and alert generated
https://www.esds.co.in
VTMScan Portal – Page Vulnerability Scan Report
Detects Sensitive data exposure, shell found, unsecure view state found
https://www.esds.co.in
VTMScan Portal – Content Change Monitoring Report
Shows individual links and amount of content change in percentage
Click here to get detailed Report on content change
https://www.esds.co.in
VTMScan Portal – Content Change Monitoring Report Changed Website page
Actual website page
Red indicates where the changes are observed
https://www.esds.co.in
Thank You