Acunetix

Acunetix

Gestion intégrée des vulnérabilités et sécurité Internet

4.5/5 (31 avis)

Acunetix - Présentation

Acunetix est une solution de scanner de sécurité et de vulnérabilité web offrant une technologie de test de sécurité web automatique permettant aux organisations de scanner et d'auditer des sites web complexes, authentifiés, réalisés en HTML5 et JavaScript. Acunetix permet de détecter plus de 45 000 vulnérabilités web telles que XSS, XXE, SSRF, injection SQL, injection d'en-tête d'hôte, etc., susceptibles de compromettre le site web et les données de l'entreprise.

Le scanner de vulnérabilité d'Acunetix permet de détecter avec précision les vulnérabilités critiques des applications web, y compris pour les logiciels open source et les applications sur mesure. Les technologies innovantes de la solution incluent DeepScan, qui permet d'explorer la robustesse des applications Ajax d'une seule page (SPA), AcuSensor, qui combine les techniques de scan boîte noire avec les retours des capteurs placés dans le code source, ainsi que l'injection SQL et tests de script sur site. Acunetix a également la capacité de scanner des installations WordPress pour plus de 1 000 vulnérabilités connues dans le noyau, les extensions et les thèmes de la plateforme, tandis que l'outil enregistreur de séquence de login automatise l'analyse des zones protégées par mot de passe complexe.

Une combinaison de tests en boîte noire et en boîte blanche, ainsi que la vérification automatique de plusieurs vulnérabilités particulièrement sérieuses permettent d'améliorer le taux de détection d'un scan et contribuent à réduire les taux de faux positifs. La visibilité de la ligne de code indique quelle est la ligne de code vulnérable et pointe sur ce qui doit être réparé en indiquant à quel endroit. Acunetix analyse également les services de réseau de périmètre pour éviter toute violation de données et teste les réseaux en fonction des vulnérabilités et des erreurs de configuration. Les fonctionnalités avancées incluent des procédures manuelles de test de pénétration, la configuration automatique du pare-feu des d'applications web (WAF) et une API REST permettant d'intégrer Acunetix à d'autres flux de travail et processus personnalisés.

Prix

À partir de
6 995,00 $US
Types de licence
version d'essai gratuite
Abonnement
Rapport qualité-prix

Appareils

Type d'entreprise

S
M
L

Disponible dans les pays suivants

Asie, Australie, Brésil, Canada, Europe et 5 autres, Allemagne, Inde, Japon, Amérique latine, Mexique

Langues

anglais

Acunetix - Avis

Note globale
4.5/5
90% d'avis positifs
18
Excellent
10
Très bien
3
Moyen
0
Médiocre
0
Horrible
Juho W.
Traduire avec Google Translate

The guarantee of safety

Logiciel utilisé tous les jours pendant plus d'un an
Publié le 11/03/2019
Provenance de l'avis : Capterra

The only thing about using the Acunetix is takin it seriously and really use the instructions it gives you. The reporting system sends the instructions of providing complete security to your documents and all you have to do is to follow those instructions.

Avantages

The unique thing about the program which makes it distinguish among the many other programs of this type is the security system. Overtime you add a document to your profile the program analyzes the risks of the document to be stolen and creates a kind of the special defense for this particular document.
This way, the program not only provides the user with the incredibly convenient service and saves his or her time, but also prevents from losing money and getting stressed. It is hard to imagine a scanner to be that universal. The Acunetix can easily cope with documents of any format and keeps everything you are working with really secure so that the really important documents or the catching fire ideas are totally under your control, there is no need to worry.

Inconvénients

The only inconvenient thing about the Acunetix is something the people call «Overprotection». Once you are signed in the security system is on and covers not only the documents dowloaded to the program, but it also washes every activity you might possibly do in the Internet and regularly sends you the warning alerts about the unsecured websites.

Réponse de Acunetix

Thank you for your review. Your feedback is very important to us.

Note détaillée

Rapport qualité-prix
Simplicité d'utilisation
Support client

Probabilité de recommander le produit

8.0/10
Utilisateur vérifié
Traduire avec Google Translate

Simple, but very powerful web vunlerability scanner

Logiciel utilisé toutes les semaines pendant 6 à 12 mois
Publié le 13/08/2018
Provenance de l'avis : Capterra

Good thing for a web application pentesting, can give You insight of a present vulnerabilities. Would recommend using in tandem with infrastructure scanner (like Nessus) to create a complete testing solution. Also presence of continous scanning and scheduler could be used for a regular security assesment of Your web applications.

Avantages

Ease of use, good customer support, very insightful reports (especially Developer raport), good vulnerability management. Also continous scanning option is an interesting thing for having continous security awareness of Your vulnerability level. Also login sequence recorder is an awesome tool.

Inconvénients

Not a lot of scan options to configure - especially in comparison to Nessus - every check is done in default, You can't choose specifically which test is done in selected scan, only the type of scan (full, high-risk vulnerabilities, xss, sqli, weak passwords, crawl only ) or technology in which the scanned web app is written.

Réponse de Acunetix

Thank you for your feedback ¿ we¿re glad that Acuneix is working for you.

Regarding your comment about choosing what to scan for ¿ you can already do this in Acunetix, although the feature is slightly hidden away in Settings > Scan Types. Here you can create your own custom Scan Types, and you will be able to choose which vulnerabilities to check for. When creating a new custom Scan Type, you can filter the vulnerability checks from the top right hand corner of the page.

Remember that you can also easily retest for a specific vulnerability identified in a previous scan.

Note détaillée

Rapport qualité-prix
Simplicité d'utilisation
Support client

Probabilité de recommander le produit

8.0/10
Utilisateur vérifié
Traduire avec Google Translate

Easy to setup, nice results

Logiciel utilisé toutes les semaines pendant plus de deux ans
Publié le 13/08/2018
Provenance de l'avis : Capterra

As a scanner it is quite good, relevant and well described findings, so far no false positives. Following an initial trial and PoC with couple of competitors, Acunetix had the best features, most suitable licensing model, good support, so we purchased a three year license. However, at some point, it all changed. The license became based on other criteria, the testing and verification tools were removed, there is no support or way of reverting to a previous version, after you realise that the changes introduced and making the software unusable or insufficient. Overall, unless there are guarantees that it won't happen again, I will be very reluctant to renew.

Avantages

Very easy to setup initially, running scans quite fast, good crawler, very nice and understandable results.

Inconvénients

The license model changed somehow in the middle of the three years, so it became impossible to continue to use it as planned without paying much more. Tools were removed.

Réponse de Acunetix

Thank you for your feedback.

You can download the free Acunetix Manual Pentesting Tools from https://www.acunetix.com/vulnerability-scanner/free-manual-pen-testing-tools/. You can copy the Request done by Acunetix from the Vulnerability details, and use this in the Acuneix Manual Tools

Note détaillée

Rapport qualité-prix
Simplicité d'utilisation
Support client

Probabilité de recommander le produit

8.0/10
Utilisateur vérifié
Traduire avec Google Translate

Ok tool, but fix your business model and add more settings to the interface

Logiciel utilisé tous les jours pendant plus de deux ans
Publié le 17/08/2018
Provenance de l'avis : Capterra

Continuation of the cons section (number of chars was limited).

* Settings are sometimes unclear, an info icon with a popup would be nice.

Example 1: In the "Site Structure" of a scan it is possible to press "exclude", does it exlude the path from futre scans? If so why don't I see anything in the target settings? Or does "exlude" exclude vulnerabilities from the report? BTW after pressing exlude I'm not able to "include" it again.

Example 2: "scan speed", how many threads per setting are we talking about?

* Would definitly like to get some more feedback from scans directly in the interface, what is it doing, why did it fail, did all the "allowed hosts" got scanned etc. I know you can debug a target, but this is not what I mean.

Avantages

* The number of checks that take place.

* The quality of the issues found.

* After years it is finally possible to pause a scan, hallelujah.

Inconvénients

* As a pentester I absolutely miss a more flexible way to configure settings like it was possible in v10. The interface is built as "point a shoot", idiot proof. Currently, If I want to configure things I need to change xml config files on the server and reload acunetix...

* After the release of v12 we were called by a sales agent as we suddently couldn't add targets anymore. The license model suddenly changed completely. The entire business model is now based on scanning an applications continuously over the year. However, as a pentesting business for we mostly scan apps just 1 time for our security assessments. It absolutely makes no sense to apply the same costs! Just like Netsparker, acunetix should have plans for pentesters and consultants.

* Scanning an app that spans multiple domains always results in problems. Currently you have the "Allowed hosts" settings which is crappy in setting up. I need to set all (sub) domains to a different target. And ofcourse with the current business model you are charged per target, lol.

Réponse de Acunetix

Thank you for your honest feedback:

As you rightly say, we try to keep an easy to use interface, with the intention of automatically detecting the best way to scan the site. There are some settings which are not used by most of our customers, and which can be manually tweaked from the settings file.

I think you might have missed the little help icon at the top right corner of the Acunetix interface. When clicked, this provides help on the settings loaded in the current page. But to answer your queries:

Example 1 - When you Exclude a path from the Site Structure, the exclusion will be stored with the Target, and will affect subsequent scans. You can delete the exclusion from the Target settings.

Example 2: this is explained on our website at https://www.acunetix.com/blog/docs/configure-scan-speed-acunetix/. I have forwarded your comment about the scan feedback to the product team.

Regarding licensing, I would suggest that you get in touch with our sales team, who can work

Note détaillée

Rapport qualité-prix
Simplicité d'utilisation
Support client

Probabilité de recommander le produit

7.0/10
Utilisateur vérifié
Traduire avec Google Translate

Great for developers for self evaluation

Logiciel utilisé tous les jours pendant plus d'un an
Publié le 19/07/2018
Provenance de l'avis : Capterra

Avantages

I have been using acunetix web vulnerability scanner since last 2 years as I develop Web apps and Websites in my professional career so I like to test it by myself for the vulnerabilities.
It gives me scope for improvement in my programming skills.
As it gives the developer report as a part of the report its very indepth report and very useful for me to develop secure web apps
I really like the web interface they have provided It reduces the dependancy of a device to carry.
really good.

Inconvénients

There is nothing so far to dislike this software.
As my needs are getting fulfilled by the available functionalities.
Looking forward to new updates.

Réponse de Acunetix

Thank you for your feedback

Note détaillée

Rapport qualité-prix
Simplicité d'utilisation
Support client

Probabilité de recommander le produit

9.0/10

Acunetix - Prix

À partir de
6 995,00 $US
Types de licence
version d'essai gratuite
Abonnement
Rapport qualité-prix

Acunetix - Fonctionnalités

  • API
  • Audit
  • Gestion de la conformité
  • Gestion des autorisations
  • Intégration de tiers
  • Sécurité des sites web
  • Tableau de bord d'activités

  • Alertes et remontée des problèmes
  • Authentification
  • Authentification unique
  • Authentification à 2 facteurs
  • Contrôle d'accès
  • Gestion des mots de passe
  • Monitoring
  • Notifications automatiques
  • Piste d'audit
  • Rapports et statistiques
  • Surveillance en temps réel
  • Sécurité SSL
  • Sécurité des applications

Acunetix - FAQ

Voici quelques-unes des questions fréquentes sur Acunetix.

Q. Quels sont les types de licence disponibles pour Acunetix ?

Types de licences disponibles pour Acunetix :

À partir de: 6 995,00 $US

Type de licence: Abonnement

version d'essai gratuite: Disponible

Q. Quelles sont les principales fonctionnalités du logiciel Acunetix ?

Nous n'avons pas d'informations sur les fonctionnalités de Acunetix.

Q. Qui utilise Acunetix ?

Utilisateurs habituels du logiciel Acunetix :

Grandes entreprises, Entreprises de taille moyenne, PME

Q. Dans quelles langues Acunetix est-il disponible ?

Langues dans lesquelles Acunetix est disponible :

anglais

Q. Quels sont les types de licence disponibles pour Acunetix ?

Types de licences disponibles pour Acunetix:

Abonnement

Q. Acunetix prend-il en charge les appareils mobiles ?

Nous n'avons pas d'informations sur les appareils pris en charge par Acunetix.

Q. Avec quelles applications Acunetix peut-il s'intégrer ?

Applications s'intégrant à Acunetix :

Centraleyezer, GitHub, JIRA Software, Keylight Platform, Wordpress

Q. Quelles sont les ressources d'aide disponibles pour Acunetix ?

Ressources d'aide disponibles pour Acunetix :

FAQ, Support en ligne, Support téléphonique