Acunetix Web Vulnerability Scanner Version 3.0 Combats Rise in "Google Hacking" Attacks

Seattle, Washington - November 21, 2005 - Acunetix, aProtects Against Google Hacking and Other New
leading security software company focusedThreats
exclusively on helping enterprises secure their webWith this newest release of Acunetix Web
applications and web sites, today announced theVulnerability Scanner, security administrators have
next-generation version of Acunetix Web Vulnerabilityaccess to a host of new features that will protect their
Scanner, which provides a comprehensive solution toweb applications and web sites.
detecting system vulnerabilities that are frequentlyPrevention of Google Hacking
exploited by hackers.Google hacking is the term used when a hacker tries
Acunetix Web Vulnerability Scanner provides ato find exploitable targets and sensitive data by using
complete solution by automatically auditing websitesearch engines. The Google Hacking Database
security. The software crawls an entire website,(GHDB) is a hacker database of queries that can
launches popular web attacks (SQL Injection, Crossidentify sensitive data. Although Google blocks some
Site scripting, Google hacking, etc.) and identifiesof the better known Google hacking queries, nothing
vulnerabilities that need to be fixed.stops a hacker from crawling sites and launching the
The Achilles Heel in Enterprise Security Strategies:Google Hacking Database queries directly onto the
Web Applicationscrawled content.
Increasingly, hackers are concentrating their efforts onVersion 3.0 of Acunetix Web Vulnerability Scanner
web-based applications - shopping carts, forms, loginlaunches all the queries found in the Google hacking
pages, and dynamic content. A Gartner Group studydatabase onto the crawled content of enterprise
determined that 75% of cyber attacks are done at thewebsites thus finding any sensitive data or exploitable
web application level. Web applications are accessibletargets before a "search engine hacker" does.
24 hours a day, 7 days a week and are aAcunetix is first to market with a solution that detects
passageway to valuable data: customer andGoogle hacking vulnerabilities.
employee databases, transaction information andOther New Features
proprietary corporate data. Many enterprises haveOver forty new features and enhancements have
addressed network security issues and havebeen introduced in the latest release of Acunetix Web
implemented firewall technology but have not yetVulnerability Scanner. Enhancements include
protected their "crown jewels" - data that can besophisticated testing for buffer overflows & input
compromised via web application hacks.validation, automatic detection of custom error pages,
The first reported instance of a Web applicationenhanced abilities to scan websites which are
attack was perpetrated in 2000. While making onlinepassword protected, automatic HTML form fillers, the
transactions with a large bank, a 17 year-oldability to crawl Macromedia Flash files, and numerous
Norwegian boy noticed that the URLs of the pages heother new features. A complete description of
was viewing displayed his account number as one ofenhancements is available:
the parameters. He substituted his account numberPricing & Availability
with the account numbers of random bank customersAcunetix WVS is available as an enterprise or as a
and immediately gained access to customer accountsconsultant version. A subscription based license can be
and personal details. Myriad other hackers havepurchased for as little as $1,495, whereas a perpetual
followed in his footsteps, exploiting hundreds oflicense starts at $2,995. For more information visit:
different techniques to compromise web applicationsAcunetix is available through its network of partners.
and exploit what is fast becoming the biggest AchillesPartner inquiries from value added resellers are
heel in an organization's security strategy.welcome. For more information, visit
"Web applications are now the prime target forAbout Acunetix
hackers. A quick hack of a vulnerable web applicationAcunetix was founded to combat the alarming rise in
can give instant access to valuable data such asweb attacks. Its flagship product, Acunetix Web
customer credit cards and employee social securityVulnerability Scanner, is the result of several years of
numbers" said Nick Galea, CEO of Acunetix. "Newdevelopment by a team of highly experienced security
hacking techniques emerge every day. Auditing one'sdevelopers. Acunetix is a privately held company with
web applications should be the number one securityheadquarters based in Europe (Malta) and a US office
concern for every enterprise."in Seattle, Washington.
Version 3.0 of Acunetix Web Vulnerability Scanner