Website vulnerability scanner

DamFinger: Finding Security Problems Before Somebody Else Does

A website can work perfectly and still be unsafe. It might contain vulnerable code, an outdated configuration, an exposed file, or a password stored somewhere it should not be.

That’s where DamFinger comes in.

I’ve been working on another project called DamFinger, a website security scanner that helps find problems in websites and web applications before someone with bad intentions discovers them.

What DamFinger Does

DamFinger is designed to check for several common security problems:

  • SAST (Static Application Security Testing): Reads source code without running the application and looks for dangerous patterns, such as potential SQL injection risks.
  • DAST (Dynamic Application Security Testing): Tests a running website to see how it responds, checking for exposed areas, missing protections, and unsafe input handling.
  • Secret detection: Looks for passwords, API keys, and database credentials accidentally left in files.
  • Configuration checks: Finds missing security headers, exposed files, and other server or application settings that may create weaknesses.
  • IOC checks: Looks for indicators of compromise, such as suspicious IP addresses, domains, or files associated with known threats.

The goal is not to break a website. It is to identify weaknesses so they can be investigated and fixed. Testing should only be performed on websites you own or have permission to assess.

When DamFinger finds something, it should explain what happened, why it matters, and what can be done about it. Findings are organized by severity, making it easier to focus on the most important issues first. The project also follows guidance from OWASP, the Open Worldwide Application Security Project.

Why Build Another Scanner?

There are already excellent security tools, but many are designed for security professionals or larger organizations. I wanted something I could run on my own server, point at my own projects, and understand without needing a cybersecurity degree.

I build many PHP and MySQL projects, so having a tool that fits that workflow is useful. DamFinger is primarily for personal use and development; it is not a replacement for professional security testing.

Building Websites Faster With AI

I’m also building more websites with help from AI, which makes development much faster. I use ChatGPT to help plan sprints, break features into tasks, think through architecture, and suggest technical approaches. Most of the actual coding happens on my local distributed-AI box, where I can keep the work and project data under my control.

That speed is useful, but it also creates a problem: faster development can introduce mistakes more quickly. AI can produce working code without guaranteeing that the code is secure. A scanner like DamFinger acts as a watchdog during the process, checking the result instead of assuming it is safe.

DamFinger does not rely on AI tokens to discover vulnerabilities. Its scanning engine examines code, files, configurations, and running applications programmatically, using defined checks and security rules. AI may eventually help explain findings or suggest fixes, but the actual detection should remain repeatable and independent of any AI response.

Keeping Everything Local

DamFinger is designed to run on my own server. I don’t want to upload source code, database information, or sensitive configuration files to an unknown service just to scan them.

The application uses PHP and MySQL for the interface and data storage, along with Python for parts of the scanning engine. Keeping the system local gives me more control over the data and the development process.

Where I’m Going With This

My goal is to make security testing a normal part of building a website:

Build the project, test the features, run DamFinger, fix what it finds, and test again.

No scanner catches everything. False positives happen, and real vulnerabilities can be missed. DamFinger is simply another tool in my development process, alongside code review, updates, backups, testing, and other good security practices.

The more software I build, especially with AI helping accelerate the work, the more important this extra layer of checking becomes. Making something work is only half the job. Making sure it does not expose somebody’s information or leave an easy opening for an attacker matters just as much.

I’d rather have DamFinger point out my mistakes than have somebody on the internet find them for me.

Leave a Reply

Your email address will not be published. Required fields are marked *