With up to 80% of today's vulnerabilities occurring in web apps, Google gives us Skipfish to help fast and in web app scanning speed kills.
Today’s Open Source Friday Focus is on Google’s Skipfish web application vulnerability scanner. Google recently released Skipfish to combat one of the biggest problems in information security today, web application vulnerabilities.
According to recent reports, over 80% of all known new vulnerabilities are in web applications. It is the new battleground in the cyber security war. Skipfish is a tool that will help you find these weak spots in your web app hopefully before the bad guys do.
There are other tools and services that you can use for web app scanning. Nikto is one and it is open sourced. The formerly open source tool Nessus is another. There are also software as a service providers such as WhiteHat security who do web app scanning. NTSpyder is another non-open tool for web app testing.
So what makes Skipfish worthy? Speed. In web application scanning speed kills. Skipfish is very fast. One of my partners at The CISO Group, Josh Karp has been working with vulnerability scanning for over 12 years now. Josh says hands down Skipfish is the fastest he has ever seen. He was blown away by how fast it worked. Josh says that the results and feature set of Skipfish were “not bad for a first implementation.” He is very optimistic that with the base Google has built, they will be adding more features and functionality as they go.
Jeremiah Grossman, CTO and founder of WhiteHat Security, as well as one of the world’s foremost authorities on web application security had this to say about Skipfish, “Google is a name synonomous with speed and ease of use. While still an early release, Skipfish has the right approach and pedigree to become an invaluable tool in the arsenal and a great contribution to the website security industry.”
But I don’t want to give you a false sense of a half-baked project here. Even as it is now Skipfish is a great scanner and a very valuable addition to your security tool chest.
Below is a screen shot of a sample report:

Skipfish is released under an Apache license. It is stored on Google Code (of course) and is available to run on a wide range of platforms.
If you are maintaining any web sites, you owe it to yourself and your users to be scanning the sites for vulnerabilities. With Skipfish there is no excuse. Go download it now, run a scan and let me now what you think.
Please visit the Google Subnet home page for more news, blogs and podcasts. Sign up for the weekly Google newsletter.More blog posts from Alan Shimel:
- Finding God Through Open Source
- To Live and Die in a Socially Networked World
- Will Open Source Video Kill Flash?
- Open Source, preferred by 9 out 10 Supercomputers
- Getting Gist of Twitter’s Love of Open Source
- Bang, Zoom, Is Open Source The Right Way To The Moon?
- Are You Ready For An Open Source Car?
- Open Source: Why You Care
- Open Source Friday Focus: Pidgin
- Apple and Microsoft As Underdog? I Don’t Think So
- Welcome to the Personal Cloud, Thanks to Open Source and Pogoplug
Smartphones, the Next Great Open Source Battleground
Subscribe to all Google Subnet bloggers or Follow Google Subnet on Twitter
Check out Alan Shimel’s Podcast and other blogs, too.




