Rate my Startup: Golem Technologies Web Security
golemtechnologies.com
golemtechnologies.com
To me, that just seems scammy. As in "click here for your free credit report... oh! We've found problems. Pay to see what they are!"
Looking through my web server logs I'm not quite sure what the problems are, or how you determined I had the problem. Did I maybe return an error message with a 200 status code instead of a 403 forbidden? I've got some redirects on my site, did you take the 301 as a bad sign?
Looks like you're using skipfish for the scanning engine?
Who is your target market? I could see companies using something like this to fill the box on PCI compliance, but would need a lot more control over the report (eg "get rid of that low category") and would need a lot more details about how the scan was performed in order to satisfy an auditor. People who just want to display a seal on their signup page will want something a lot more low key, and already have lower cost options.
* I got the same two errors and they were completely benign. The directory traversal problem was just Wordpress returning some data. The "interesting file" was a blog post that had some SQL in it. I'm not sure if they're the same that you found. But if I would have paid for the scan and they turned out to be the same two errors, I would have been pretty angry.
* Skipfish came back with some actual interesting things like embedded scripts and forms without xsrf protection. The embedded scripts were ok (ad/tracking codes), but the forms would have been an interesting thing to note.
Yes, I use skipfish for some tests, though I customized parts of it (it has an amazing web crawler). I also use proprietary scan technology, and plan to add a few more open source tools into the mix (such as port/service and virus scanning) in the not so distant future to create one combined risk/vulnerability report.
interesting file is typically a text file, unsecured htaccess file, or sometimes 500 error messages. If you tell me your site, I will check for you.
target market is small business, medium size business, or individual site owners - mostly those who don't maintain a full time IT security staff but want some visibility into their site risks. Eventually I may add PCI checks, but that is a huge compliance/paper cost which is tough for a one man shop to keep up with.
On your "before you scan page", you might want to mention the possibility of a large number of emails, because it can come as a bit of a surprise.
And you might want to limit the number pages on an initial scan because big sites seem to take a hell of a lot longer to process (an I apologise right now for being a bottleneck). I concur with Marketer the possibility of emailed results would be a real benefit.
Is the monthly plan intended to cater to individual sites, or is it aimed at web designers who might be interested in scanning their creations for vulnerabilities? If web designers do feature at all they might appreciate some sort of test data they could print out and hand to clients as evidence of security.
otherwise, the site looked good.
I just got spammed with like 300 emails from your site.
Is that what its suppose to do?
(at myself)
note to self, add a queue list to scan page..