Web Application Scanner

Skipfish has been updated yet again! The latest release is Skipfish-1.62b!

“Skipfish is a fully automated, active web application security reconnaissance tool.”

This version fixes many errors from the previous versions.

Download Skipfish version 1.62b here!

Searches leading to this post:
wep cracker

Be the first to comment!

The complex of programs and the knowledge base for the vulnerability analysis of the implementations and customizations of web-applications and web-servers.
The given complex is intended for inventory and an security estimation of various (heterogeneous) web-applications. The project is developed with usage of WebEngine kernel.

c9940f9c89bbb64eb8053cc97c0e5b62 WebAppTools : Tools for web servers and web applications testing.

On the Inventory stage the following information about the web-application is collected:

- HTML objects
- used scripts and applications/applets
- links with other sites
- the information about a hosting and a server
- time characteristics (response time) and the data about productivity of the web application

Also, the information about the web application received from indirect sources, such as Whois, Ripe.net, DNS, search sites etc is analyzed. On the stage of the Security Estimation of an application the following information is collected:

- the analysis of customizations of a web server
- the analysis of an source code of the application (PHP, ASP, JS etc.)
- search for the vulnerabilities in the Web-server software
- the analysis of the application stability in the case of different types of attacks, such as SQL injection, XSS, CSRF, Script including, OS commanding etc.
- the analysis of the application stability in the case of DoS attacks
- the analysis of the web-application regarding authentication of users.

The main target audience for the given system is the information security experts, system administrators, hosting-providers and the web-application developers.

We good and efficent opensource tool for codes and security code analyst as per our observations this tool can perform much better if fine tuned according to environment.

Download WebAppTools Here

Searches leading to this post:
tutorial WebAppTools

Be the first to comment!

All of you web application penetration testers, check out this release of XSSer version 0.7a, for it now has 26 new injections!

XSSerXSSer is an open source penetration testing tool that automates the process of detecting and exploiting XSS injections against different applications.
It contains several options to try to bypass certain filters, and various special techniques of code injection.

These are the changes:

  • Added attack payloads to fuzzer (26 new injections).
  • Added POST connections: Now you can inject on webforms.
  • Added Statistics: reports with data about efficiency, connections, vectors, etc..
  • Added URL Shorteners: Now, it is possible to have valid results in short links. for the moment support tinyurl and is.gd. your “malicious” code ready to share!!
  • Added IP Octal: Spoofing for fuzzing vectors. Your remote/local IPs encoded in Octal.
  • Added Post-processing payloads: When you see have a valid “hole/payload”, you can say to XSSer to prepare the real code that you want to inject.
  • Added DOM Shadows: For this version, this implementation is a server side anti-logging feature. You can inject code using Document Object Model eval function, to evade some possible server IDS’s.
  • Added Cookie injector: Now is possible to inject code on HTTP Cookie parameters automatically.
  • Added Browser DoS (Denial of Service): Yes!!. If you have a valid payload to inject, XSSer will prepare you a code for share with victims who “collapse” their browsers. DoS of client browser ready for play friend -scripter-!

You can download XSSer version 0.7a here.

Searches leading to this post:
xsser tutorial

Be the first to comment!

Page 1 of 25123456...Last »