Get a demo Acunetix Website Security Scanner Get a demo
  • Product
  • Why Acunetix?
    • Solutions
      • INDUSTRIES
        • IT & Telecom
        • Government
        • Financial Services
        • Education
        • Healthcare
      • ROLES
        • CTO & CISO
        • Engineering Manager
        • Security Engineer
        • DevSecOps
    • Case Studies
    • Customers
    • Testimonials
  • Pricing
  • About Us
    • Our story
    • In the news
    • Careers
    • Contact
  • Resources
    • Blog
    • Webinars
    • White papers
    • Buyer’s guide
    • Partners
    • Support
  • Get a demo

MANAGE YOUR WEB SECURITY WITH

Bash Shellshock Vulnerability Scanner

Get a demo
Gartner Peer Insights Reviews

Bash Shellshock Vulnerability Scanner – Enter Acunetix!

Shellshock (CVE-2014-6271, CVE-2014-7169) is a security bug discovered by Stephane Chazelas in the popular Bash Linux shell, which allows an attacker to execute commands from environment variables. Essentially, when successfully exploited, the Shellshock vulnerability allows an attacker to attain remote code execution. While Bash is not a publicly exposed Internet service, operating system environment variables are used by many internet-facing services such as web servers to pass configuration values. The reason command execution is possible with the Shellshock bash vulnerability is that Bash did not sanitise environment variables before it executed them. As a result, an attacker can end up executing commands on the target server operating system through nothing but HTTP requests. While the Shellshock bash bug is an old vulnerability, there are still thousands of webservers and applications vulnerable to it. Just like the Heartbleed vulnerability, leaving the Bash Shellshock vulnerability unpatched is a major security risk. This is where Acunetix can help. Acunetix is a web application vulnerability scanner, which automatically tests the security posture of your web applications, as well as any server security misconfigurations. Acunetix allows you to assess web application and web server security by testing for thousands of vulnerabilities quickly and accurately on a regular basis. Acunetix achieves this by combining a crawler and scanner with a vast array of highly tuned test cases, intelligently designed to run as fast and efficiently as possible.
Acunetix web vulnerability scanner

Wide Technology Coverage

Acunetix takes technology support to the next level with the best-of-breed JavaScript support thanks to its fully automated JavaScript and browsing engine called DeepScan. While some attacks may be detectable by server security software such as intrusion detection systems (IDS) and web application firewalls (WAF), these technologies are not able to stop client-side attacks such as DOM-based Cross-site Scripting (DOM XSS). Thanks to its DeepScan technology, Acunetix can combat this blind spot by detecting hard to find DOM XSS vulnerabilities together with other forms of cross-site scripting which would otherwise be invisible to the majority of server security software.
Acunetix web vulnerability scanner

Say Goodbye to Boring Reports

Finally, another area where Acunetix excels, which many other web vulnerability scanners sorely lag behind in, is the ability to produce great reports. After a vulnerability scan is complete, Acunetix can instantly generate a wide variety of technical, regulatory, and compliance reports such as PCI DSS, HIPAA, OWASP Top 10, and many others. Additionally, Acunetix also allows users to export discovered vulnerabilities to issue trackers such as Atlassian Jira, GitHub, GitLab, Buzilla, Mantis, and Microsoft Team Foundation Server (TFS).

Recommended reading

Learn more about prominent vulnerabilities, keep up with recent product updates, and catch the latest news from Acunetix.

Knowledge Sharing

Knowledge Sharing

What is SQL Injection

What is Cross-site Scripting

What Are XML External Entity Attacks

What is Insecure Deserialization

Popular Posts

Popular Posts

SQL Injection Example

Preventing SQL Injection in PHP

TLS/SSL Cipher Hardening

Defending Against CSRF Attacks

In The News

In The News

2020 Web Application Vulnerability Report

Complimentary licenses – COVID-19

Interview with Acunetix President & COO

Innovations in Acunetix v13

Client: Xerox

“We use Acunetix as part of our Security in the SDLC and to test code in DEV and SIT before being promoted to Production.”

Kurt Zanzi, Xerox CA-MMIS Information Securtiy Office, Xerox
Read more case studies >

Take action and discover your vulnerabilities

Get a demo
Client: AWS
Client: Cognizant
Client: Garmin
Client: Airforce
Client: NASA
Client: American Express
Product Information
  • AcuSensor Technology
  • AcuMonitor Technology
  • Acunetix Integrations
  • Vulnerability Scanner
  • Support Plans
Use Cases
  • Penetration Testing Software
  • Website Security Scanner
  • External Vulnerability Scanner
  • Web Application Security
  • Vulnerability Management Software
Website Security
  • Cross-site Scripting
  • SQL Injection
  • Reflected XSS
  • CSRF Attacks
  • Directory Traversal
Learn More
  • White Papers
  • TLS Security
  • WordPress Security
  • Web Service Security
  • Prevent SQL Injection
Company
  • About Us
  • Customers
  • Become a Partner
  • Careers
  • Contact
Documentation
  • Case Studies
  • Support
  • Videos
  • Vulnerability Index
  • Webinars
  • Login
  • Invicti Subscription Services Agreement
  • Privacy Policy
  • Terms of Use
  • Sitemap
  • Find us on Facebook
  • Follow us on Twiter
  • Follow us on LinkedIn

© Acunetix 2024, by Invicti