Report PDF
Report PDF
Report PDF
Skipfish
Tirth Shah (1611108)
Shruti Dhariya (1611094)
A. Introduction
Websites experience an average of 22 attacks per day — more than 8,000 attacks a
year, according to SiteLock results. A vulnerability of a website is a weakness or
misconfiguration in a website or web application code that enables an attacker to gain some
degree of control over the site, and possibly the host server. Most vulnerabilities, such as
vulnerability scanners and botnets are exploited by automated means.When such vulnerabilities
are found, data are stealed, malicious content spread, or spam and defacement in the
vulnerable section. Vulnerability scanning is an examination of possible access points on a
device or a network to find security holes. A vulnerability analysis detects and classifies device
vulnerabilities in computers, networks, and communications equipment and predicts the efficacy
of counter-measures.
B. Problem Definition
To scan a website using the tool skipfish and determine vulnerabilities if any in it.
C. Scope
1. Install Skipfish.
2. Set up a website to be scanned for vulnerabilities.
3. Start scanning.
4. Scan with brute force option
5. Scan without brute force option.
6. Check the vulnerabilities found in the generated files.
Skipfish is an active web application security reconnaissance tool created by lcamtuf for Google.
It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and
dictionary-based probes. The resulting map is then annotated with the output from a number of
active security checks. The final report generated by the tool is meant to serve as a foundation
for professional web application security assessments.
Some features of Skipfish are:
1. High Performance.
2. Ease Of use.
3. Well designed for security checks.
F. Implementation along with screenshots
1. Install Skipfish
2. Skipfish Options
c. Performance settings
d. Other settings
3. Dictionaries