WebSlayer fuzzing tool

2009. 2. 3. 08:45
OWASP WebSlayer라는 fuzzing 툴을 배포했다. 현재 베타 버진이긴 하지만 웹 퍼징 툴이 필요한 사람들한테 매우 유용하게 쓰일거 같다 ^^;

○ WebSlayer fuzzing

It's possible to perform attacks like:
- Predictable resource locator: it can find directories and scripts based on
  well known dictionaries, recursion supported
- Login forms brute force
- Session brute force
- Parameter brute force
- Parameter Injection (XSS, SQL, etc)
- Basic and Ntml Bruteforcing  

Some features are:
- Encodings: 15 encodings supported
- All parameters attack: the tool will inject the payload in every parameter
- Authentication: supports Ntml and Basic
- Multiple payloads: you can use 2 paylods in different parts
- Proxy support (authentication supported)
- For predictable resource location it has: Recursion, common extensions,
   non standard code detection
- Multiple filters for improving the performance and for producing cleaner results
- Live filters
- Threads
- Session export
- Integrated browser (webKit)
- Predefined dictionaries for predictable resource location, based on
  known servers (Thanks to Dark Raver, http://www.open-labs.org/)


공식 사이트 : https://www.owasp.org/index.php/Category:OWASP_Webslayer_Project
툴 다운로드 : http://code.google.com/p/webslayer/downloads/list
참고 사이트 : http://www.edge-security.com/webslayer.php
Posted by n3015m
:
BLOG main image
'네오이즘'의 보안LAB 블로그입니다........... n3oism@gmail.com by n3015m

카테고리

분류 전체보기 (228)
[ HappyDevTool ] (29)
[ HappyToolRelease ] (4)
[Book] (6)
[ Security Studies ] (0)
- CII (2)
- BigData (2)
- Web Hacking (10)
- SQL Injection (25)
- Mobile Security (9)
- Network (6)
- OperatingSystem (4)
- Malware & Reversing (4)
- Phishing (5)
- Compliance (0)
- Programming (13)
- Tools (13)
- IoT (6)
- etc (21)
[Pentration Testing] (3)
[OS X] (4)
[ Security Trends ] (16)
[ Fixing Guideline ] (7)
My Way, My Life (34)
About Me (2)

최근에 올라온 글

최근에 달린 댓글

최근에 받은 트랙백

Total :
Today : Yesterday :