Kali Linux includes multiple tools for automated vulnerability scanning of web applications. We have examined some of these already, particularly the ones focused on specific vulnerabilities such as sqlmap for SQL injection or XSSer for Cross-Site Scripting (XSS).
Next, we will cover the basic usage of some of the more general web vulnerability scanners listed here:
- Nikto
- Skipfish
- Wapiti
- OWASP-ZAP