4 ms·
Show HN: SaaS Vulnerability Scanner for Small Businesses
- dguido 9y agoLiterally no information to judge whether this service is competent or not... As a security expert myself, I mostly have recommended tinfoilsecurity.com and tenable.io to the small businesses I consult with. In cases where you want more than simple web application scanning, CyberGRX.com tries to accumulate a more holistic picture of the security practices of your company.
- ceejayoz 9y agoHell, skip competent for a moment. There's no information to judge whether this service isn't just a way to gain access to website backends in the guise of scanning.
- boie0025 9y agoI'd say there's not anything to even judge if it's not just a way to charge a credit card. Picking a plan asks for a web address (which isn't validated in any way, you can type a single letter), and then it shows what looks like a Stripe CC popup (which probably signs a user up for recurring billing on stripe). Nothing about a login, email or password (I can ASSUME that's after a card is entered, but who knows..). I would never use something like this in its current state.
- sboselli 9y agoNo info whatsoever. What kind of scans are you running? What kind of data can I expect from the report? Is it port scanning or CVE based stuff?
- LarkaUZ_ 9y agoHi. I'm the founder of ScannerSec. We run Vunlerabilty scanners : Infrastructure and Web applications. It starts with a port scan, and then it tries to detect vunlerabilities ( CVE and others). It is like as a simplified version of Nessus or OpenVAS.
- GordonS 9y ago> It is like as a simplified version of Nessus or OpenVAS Do you mean you've written your own scanners (a rather large task), or that you're using Nessus and OpenVAS and your service provides simplified access to these?
- LarkaUZ_ 9y agoWe aggregate data from multiple web vulnerability scanners, and provide a unified and simplified report about the vulnerabilities detected.
- jvehent 9y agoI doubt you rewrote a vulnerability scanner from scratch, since it takes years and a lot of efforts to do, so why don't you tell us a bit more about the technology behind it. Does it use ZAP? Arachni? W3AF? OpenVAS? SQLMap? All of them? Also, I'd be careful about such claims: > Our scans are secure and non-intrusive. Because you never know what will happen in the backend when you hit that "GET /article/delete/1" endpoint while spidering the home page. Tons of poorly coded webapps have that kind of trap, and you should scan staging/test instances whenever possible to avoid dropping a production DB whenever you hit one of those.
- codingdave 9y agoTo be fair, if a scanning tool running anonymously can muck up your webapp by hitting "GET /article/delete/1" then they did successfully find a problem with your SaaS app.
- ifoundthetao 9y agoYou're missing the "non-intrusive" point that he was bringing up. While they did find a vulnerability, they went beyond the scope the had agreed to, which is the issue he's describing.
- LarkaUZ_ 9y agoHi. Indeed we did not write a vulnerability scanner from scratch. We run a few major vulnerability scanners like OpenVAS on the target website, configured in a way to be non-intrusive. We do not communicate on the exact tools that we launch and how we compile the results since this is our secret sauce ... Fair point about the "GET /article/delete/1" issue, unfortunately a lot of SMB do not have staging/test instances ...
- jvehent 9y agoYour secret sauce is purely based on the hard work of open source developers. Pardon me if I don't support your obscurantism.
- epalm 9y agoFront page <h1> typo: "Find out if your website is protected again Hackers" You probably mean "against".
- LarkaUZ_ 9y agoThanks! I fixed it.
- peterwwillis 9y agoInitial thoughts: 1. First heading text past the title bar has a typo. Yes, this matters. If you can't even get a second look at your website copy, did you get a second look at your product? 2. The domain was registered a month ago. 3. Like others mentioned, absolutely zero product information, and no information about whether they support the many industry standards that small businesses might actually need a security scanner for (are they wasting their money?). 4. The root domain only hosts http and not https, and the www site hosts both http and https, and none seem to advertise HTTP security headers. Considering this is a security product that takes your money: wtf? 5. The IPs used to host the site do not have reverse records. Again, wtf. 6. Leaks version and OS information of their DigitalOcean droplet. Honestly, just paying a kid in high school the $20 to run Nmap and a webapp vuln scanner on your site might be a better investment.
- kc10 9y agoIMO, just saying vulnerability scanner is not enough. A sample report would help understand the service better.
- LarkaUZ_ 9y agoThanks for the suggestion. We will try to fix that soon...
- GordonS 9y agoThis is a really crowded space - there are a lot of small business offering 'managed' vulnerability scans, so you will struggle to differentiate yourself. Having said that, you seem to be a good job of differentiating yourself in a rather bad way from those other businesses: Most other businesses tell you what vulnerability scanner(s) they use. Most other businesses offer a free scan (or partial scan), so you can get an idea of what is provided. Most other businesss show sample reports, so you can get an idea of what is provided. Dammit, every other business tells you something useful about the product being offered, and absolutely tell you who is offering it. I'm sorry if this is all negative, but... come on?! This honestly looks like some chancer has thrown this up in their lunch break. There isn't even anything to tell me who 'ScannerSec' is - I seriously can't even tell if this is some kind of scam to extort HN users.
- LarkaUZ_ 9y ago> Most other businesses offer a free scan (or partial scan), so you can get an idea of what is provided. >Most other businesss show sample reports, so you can get an idea of what is provided. This is clearly something that we will add. Thanks for the suggestions. As for the rest of your comment, you raise valid criticism from a technical point a view. This is our launch and we did it on hacker news to collect feedbacks. However the website is designed to target small business or mom-and-pop shops that do not have the technical shops to understand the nitty-gritty security details. We will try to find a way to give more information about how we do our scans whithout overwhelming a non-techincal reader.
- desdiv 9y ago>there are a lot of small business offering 'managed' vulnerability scans Which managed vulnerability scanners would HNer recommend? When I Google for them I can't tell who's good at security and who's simply good at SEO and snake-oil-selling. I would love to hear what HNers have used/would recommend.
- gremlinsinc 9y agoWanna make more money? -- Drastically lower the cost, or even have a freemium model maybe the 1 post per month plan. Then have solutions for FIXING the vulnerabilities--esp for low-tech users like Wordpress users who don't know how to fix things themselves. -- Also having plugins for wordpress, etc... that scans from inside out could help as well.
- newsat13 9y agoI would love to see a sample vulnerability report. Also, why is this flagged?
- LarkaUZ_ 9y agoThanks. I really have no idea why it was flagged ... I will try to add an anonymized report.
- dang 9y agoIt looks to me like it violates the Show HN rules by being just a sign-up instead of something people can try out. https://news.ycombinator.com/showhn.html https://news.ycombinator.com/showhn.html
- LarkaUZ_ 9y agoIt is not. Users subscribe and they receive a mail informing them that the Scan will be launched shortly. Once the scan is over the user receive the scan report on his mailbox. This is the service we provide...
- GordonS 9y agoFrom the guidelines: "Blog posts, sign-up pages, and fundraisers can't be tried out, so they can't be Show HNs" The only way to try out your service is to hand over card details.
- kapauldo 9y agoIts not clear where all the negativity is coming from. This is a great idea. Open source tools are hard to work with but powerful. If you can bottle it and automate it and sell it, good for you. It's absolutley worth something, not sure that's 20 bucks a month but i would keep tweaking til you get there. Good luck.