Syhunt Code
The most comprehensive white box testing solution for web developers.
|
Syhunt Code enables developers and QA (Quality Assurance) testers to automatically scan any kind of application source code for potential security vulnerabilities. Overview
Syhunt Code has been designed to scan PHP web applications for various types of issues, such as Cross-Site Scripting (XSS), File Inclusion, SQL Injection, Command Execution and weak validation. Additionally, by identifying key areas of the code, Syhunt Code can also help auditors perform code reviews better, faster and more efficiently. When used from within Syhunt Hybrid, Syhunt Code can also perform classic ASP, ASP.NET, Perl & Python source code scans that are complementary to its dynamic scans. Vulnerabilities like the one below and many other variants can be detected $a = $_GET['file']; include($a);
Key Features
Syhunt Code is a perfect complement to the already extensive set of remote scanning capabilities available in the Syhunt Dynamic scanner, making it the most comprehensive solution for those concerned about web application security.
New in 4.0
Syhunt Hybrid 4.03 features new, enhanced versions of the Syhunt code scanners plus some minor user experience improvements: What's New in Syhunt Code for PHP (2.1)Syhunt Code for PHP's database has been significantly expanded in this release to cover File Manipulation, HTTP Response Splitting (HRS) and SQL Injection involving several types of SQL servers.
The recently introduced code scanners for ASP & JSP also evolved to include checks for additional vulnerability classes such as File Inclusion, Command Execution, SQL Injection and others (listed below). What's New in Syhunt Code for ASP.NET (0.2 Beta)
What's New in Syhunt Code for Classic ASP (0.2 Beta)
What's New in Syhunt Code for JSP (0.2 Beta)
Other Improvements
Specs
|
More on Syhunt Code Vulnerability Coverage |



