Author Topic: Website security analysis  (Read 1000 times)

jellied

  • skip to the end
    • Ealing Bike Hub
Website security analysis
« on: 23 May, 2012, 08:10:39 pm »
I've used Shieldsup and the like to scan a PC for any issues.
Is there something similar for checking a website? I've had some issues with a site I look after [written in Wordpress] and am concerned there's something not quite right in terms of permissions and the like..

Seems to be a wealth of paid for services which doesn't surprise me, but anything of a trust worthy and free nature out there?
A shitter and a giggler.

Re: Website security analysis
« Reply #1 on: 23 May, 2012, 09:01:56 pm »
How about http://www.siteadvisor.com/ ?

Enter address in box under "View a Site Report".

jellied

  • skip to the end
    • Ealing Bike Hub
Re: Website security analysis
« Reply #2 on: 23 May, 2012, 09:12:34 pm »
Nice - not seen that before.

It's not quite what I was after - more something to detect vulnerabilities for a website.

A shitter and a giggler.

vorsprung

  • Opposites Attract
    • Audaxing
Re: Website security analysis
« Reply #3 on: 24 May, 2012, 12:37:27 pm »
You could

  • run a remote penetration test using a tool like Nessus


http://en.wikipedia.org/wiki/Nessus_(software)
Nessus has 80 wordpress specific "plugins" that detect flaws

  • Or look at your policies and take an overview with OSSTMM (Open Source Security Testing Methodology Manual)


http://www.isecom.org/research/osstmm.html

  • If you have root access to the server with wordpress on then you could do static testing of the files that make up the site

Sorry, I can't find any suitable programs to do this that are free

  • Finally, there is a "security" plugin for wordpress


http://wordpress.org/extend/plugins/wp-security-scan/

jellied

  • skip to the end
    • Ealing Bike Hub
Re: Website security analysis
« Reply #4 on: 24 May, 2012, 05:09:09 pm »
brilliant - that's exactly what i needed. already found some loop holes.
A shitter and a giggler.