Asp.Net Security Analyser (new security tool by DDPlus)

D

Dinis Cruz

Hello

I'm happy to announce that we (DDPlus) have just released the first
stable version of our new Open Source Project: the Asp.Net Security
Analyser (ANSA)

Asp.Net Security Analyser (ANSA) is a Open Source, Windows based,
online tool, that tests the server's security for known
vulnerabilities and mis-configurations. The tool was initially
designed to allow the protection of ISPs that provide shared hosting
services. You can download the source code, use it in your servers and
distribute it to who ever you feel appropriate.

The project's objective is to create an Open Source tool that allows
system administrators (responsible for windows based shared hosting
environments) to easily identify and solve existent security problems.

The current version is focused on identifying security vulnerabilities
such as: remote command execution, pour website isolation (i.e. the
user from website A can see the data from website B), disclosure of
sensitive information (such as usernames/passwords, running processes,
installed services), ability to do a server based port scan, etc..

Eventually the tool should evolve to a "Asp.Net Security Configuration
Tool" where it will also allow the SysAdmins to securely configure
their servers

This project is currently hosted in a Workspace in GotDotNet
(www.gotdotnet.com) and this is the direct link to the project:
http://www.gotdotnet.com/Community/Workspaces/Workspace.aspx?id=36ae9a2c-8740-4b52-924e-320edf64fba5
(if this link doesn't work please visit this page
http://www.gotdotnet.com/community/workspaces/directory.aspx and
search for 'ANSA')

Thanks for your time, and don't hesitate to contact me if you require
any further help.


Dinis Cruz
..Net Security Consultant
DDPlus
(e-mail address removed)
 
D

Dinis Cruz

Hello

The Asp.Net Security Analyser must be copied to an website that accepts
Anonymous requests.

The idea is to test the security of your server in normal circunstances.

If you login has an administrator then all scripts will be executed with
administrative rights, which defeats the principle of the exercise.

Hope this helps

Dinis Cruz
..Net Security Consultant
DDPlus (www.ddplus.net)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

Forum statistics

Threads
473,733
Messages
2,569,439
Members
44,829
Latest member
PIXThurman

Latest Threads

Top