본문 바로가기
IT 와 Social 이야기/Security

취약점 분석(Vulnerability Assessments) 솔루션 소개 : Database Scanner

by manga0713 2012. 8. 7.




○ Databse Scanner List


1. Application Security AppDetectivePro

2. DBAPPSecurity MatriXay 3.6

3. Fortinet FortiDB

4. Imperva® Scuba

5. McAfee Repscan and McAfee Vulnerability Manager for Databases

6. NGSSecure NGS SQuirreL for DB2, SQL Server, Oracle, Informix, Sybase ASE

7. Safety-Lab Shadow Database Scanner



1. Application Security AppDetectivePro


Type Database Scanner
Target(s) SQL databases
Format Software
OS Windows XP Pro SP2+/Vista/7, running IE 7+
Optional: SQL Server 2005/2008
Hardware 1Ghz CPU(2GHz recommended)
1GB RAM(2GB recommended)
300MB disk
License Commercial
SCAP Validated  
Standards CVE
Supplier Application Security, Inc.
Information http://www.appsecinc.com/products/appdetective



2. DBAPPSecurity MatriXay 3.6


Type Database Scanner (with limited pen testing)
Target(s) Oracle, Microsoft SQL Server, Microsoft Access,
IBM DB2
Format Software
OS  
Hardware  
License Commercial
SCAP Validated  
Standards  
Supplier DBAPPSecurity Inc. (China)
Information http://www.dbappsecurity.com/Webscan.html



3. Fortinet FortiDB


Type Database Scanner
Target(s)  
Format Appliance or Software
OS AIX and Solaris 10, Red Hat Enterprise Linux, Vmware
Windows XP/Vista/Server 2003
Hardware  
License Commercial
SCAP Validated  
Standards  
Supplier Fortinet, Inc.
Information http://www.fortinet.com/products/fortidb/



4. Imperva® Scuba


Type Database Scanner
Target(s) Oracle, DB2, SQL Server, Sybase
Format Software
OS Client: Windows 98/NT/2000/XP running Java JRE 1.5+
Hardware  
License Freeware
SCAP Validated  
Standards  
Supplier Imperva Inc. (U.S./Israel)
Information http://www.imperva.com/products/dle_downloads-and-evaluations-overview.html



5. McAfee Repscan and McAfee Vulnerability Manager for Databases


Type Database Scanner
Target(s) Oracle 9.1+, SQL Server 2005 SP1+, DB@ 8.1+(on Linux, UNIX, Windows), MySQL 4.0+
Format Software
OS Repscan: Windows XP
Hardware Vulnerability Manager: Windows Server 2003 SP2+/2005
SP1+ running McAfee ePolicy Orchestrator 4.5
Console: Firefox 2.0+, IE 7.0+
License Commercial
SCAP Validated  
Standards  
Supplier McAfee
Information http://www.sentrigo.com/repscan
http://www.mcafee.com/us/products/vulnerability-manager-database.aspx



6. NGSSecure NGS SQuirreL for DB2, SQL Server, Oracle, Informix, Sybase ASE


Type Database Scanner
Target(s) DB2 7x-9x, SQL Server 2000+, Oracle 7r3-11g, Informix® Dynamic Server 9x-11x, Sybase ASE versions through 15.5
Format Software
OS Windows
Hardware  
License Commercial
SCAP Validated  
Standards  
Supplier NGSSecure (UK)
Information http://www.ngssecure.com/ngssecure/services/information-security-software/ngs-squirrel-for-db2.aspx
http://www.ngssecure.com/ngssecure/services/information-security-software/ngs-squirrel-for-sql-server.aspx
http://www.ngssecure.com/ngssecure/services/information-security-software/ngs-squirrel-for-oracle.aspx
http://www.ngssecure.com/ngssecure/services/information-security-software/ngs-squirrel-for-informix.aspx
http://www.ngssecure.com/ngssecure/services/information-security-software/ngs-squirrel-for-sybase-ase.aspx



7. Safety-Lab Shadow Database Scanner


Type Database Scanner
Target(s) SQL Server, Oracle, DB2, MiniSQL, MySQL, Sybase, SAP DB, Lotus® Domino
Format Software
OS Windows 95/98/Me/NT/2000/XP/2003/Vista/7
Hardware  
License Commercial
SCAP Validated  
Standards  
Supplier Safety-Lab (Russia)
Information http://www.safety-lab.com/en/products/6.htm