Show HN: SaaS Vulnerability Scanner for Small Businesses
scannersec.com
scannersec.com
Most other businesses tell you what vulnerability scanner(s) they use.
Most other businesses offer a free scan (or partial scan), so you can get an idea of what is provided.
Most other businesss show sample reports, so you can get an idea of what is provided.
Dammit, every other business tells you something useful about the product being offered, and absolutely tell you who is offering it.
I'm sorry if this is all negative, but... come on?! This honestly looks like some chancer has thrown this up in their lunch break. There isn't even anything to tell me who 'ScannerSec' is - I seriously can't even tell if this is some kind of scam to extort HN users.
This is clearly something that we will add. Thanks for the suggestions.
As for the rest of your comment, you raise valid criticism from a technical point a view. This is our launch and we did it on hacker news to collect feedbacks. However the website is designed to target small business or mom-and-pop shops that do not have the technical shops to understand the nitty-gritty security details.
We will try to find a way to give more information about how we do our scans whithout overwhelming a non-techincal reader.
Which managed vulnerability scanners would HNer recommend?
When I Google for them I can't tell who's good at security and who's simply good at SEO and snake-oil-selling. I would love to hear what HNers have used/would recommend.
Also, I'd be careful about such claims:
> Our scans are secure and non-intrusive.
Because you never know what will happen in the backend when you hit that "GET /article/delete/1" endpoint while spidering the home page. Tons of poorly coded webapps have that kind of trap, and you should scan staging/test instances whenever possible to avoid dropping a production DB whenever you hit one of those.
Fair point about the "GET /article/delete/1" issue, unfortunately a lot of SMB do not have staging/test instances ...
Honestly, you're not communicating much. Serious question: why would anyone give you their card details for a complete unknown? Your site doesn't provide free scans, sample reports (or even partial ones), or even say anything about who 'ScannerSec' is.
I'd echo the other comments about being very careful with language like "non-intrusive", I've taken systems down with a single ' character in a login box before or by carrying out basic port scans.
Now obviously you could say that a system that fragile has bigger problems, but customers tend not to feel that way if something bad has happened to their site on the day you're scanning them...
As a security expert myself, I mostly have recommended tinfoilsecurity.com and tenable.io to the small businesses I consult with. In cases where you want more than simple web application scanning, CyberGRX.com tries to accumulate a more holistic picture of the security practices of your company.
1. First heading text past the title bar has a typo. Yes, this matters. If you can't even get a second look at your website copy, did you get a second look at your product? 2. The domain was registered a month ago. 3. Like others mentioned, absolutely zero product information, and no information about whether they support the many industry standards that small businesses might actually need a security scanner for (are they wasting their money?). 4. The root domain only hosts http and not https, and the www site hosts both http and https, and none seem to advertise HTTP security headers. Considering this is a security product that takes your money: wtf? 5. The IPs used to host the site do not have reverse records. Again, wtf. 6. Leaks version and OS information of their DigitalOcean droplet.
Honestly, just paying a kid in high school the $20 to run Nmap and a webapp vuln scanner on your site might be a better investment.
What kind of scans are you running? What kind of data can I expect from the report? Is it port scanning or CVE based stuff?
Do you mean you've written your own scanners (a rather large task), or that you're using Nessus and OpenVAS and your service provides simplified access to these?
You probably mean "against".
Also, why is this flagged?
"Blog posts, sign-up pages, and fundraisers can't be tried out, so they can't be Show HNs"
The only way to try out your service is to hand over card details.
It's quite common when someone posts something to 'Show HN' for some of the more affluent member of this community to sign up just to see if it works; perhaps the flaggers feel this website has been set up to take advantage of this.