<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; ferruh mavituna</title>
	<atom:link href="http://www.darknet.org.uk/tag/ferruh-mavituna/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>WebRaider &#8211; Automated Web Application Exploitation Tool</title>
		<link>http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/</link>
		<comments>http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 09:41:24 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[automated web application exploitation tool]]></category>
		<category><![CDATA[automated web application security testing]]></category>
		<category><![CDATA[automated web hacking]]></category>
		<category><![CDATA[ferruh mavituna]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[mesut timur]]></category>
		<category><![CDATA[one click ownage]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[reverse shell]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[web exploitation]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[webraider]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2587</guid>
		<description><![CDATA[WebRaider is a plugin based automated web application exploitation tool which focuses to get a shell from multiple targets or injection point Idea of this attack is very simple. Getting a reverse shell from an SQL Injection with one request without using an extra channel such as TFTP, FTP to upload the initial payload. It&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>WebRaider is a plugin based automated web application exploitation tool which focuses to get a shell from multiple targets or injection point</p>
<p>Idea of this attack is very simple. Getting a reverse shell from an SQL Injection with one request without using an extra channel such as TFTP, FTP to upload the initial payload.</p>
<ul>
<li>It&#8217;s only one request therefore faster,</li>
<li>Simple, you don&#8217;t need a tool you can do it manually by using your browser or a simple MITM proxy,</li>
<li>Just copy paste the payload,</li>
<li>CSRF(able), It&#8217;s possible to craft a link and carry out a CSRF attack that will give you a reverse shell,</li>
<li>It&#8217;s not fixed, you can change the payload,</li>
<li>It&#8217;s short, Generally not more than 3.500 characters,</li>
<li>Doesn&#8217;t require any application on the target system like FTP, TFTP or debug.exe,</li>
<li>Easy to automate.</li>
</ul>
<p><strong>Dependencies</strong></p>
<p>Internally WebRaider uses <a href="http://www.darknet.org.uk/tag/metasploit/">Metasploit</a>. The authors use a specific version of Metasploit, they trimmed the fat from Metasploit to launch it faster and make it smaller. You can change the paths and make it work with the latest Metasploit of your own setup. </p>
<p>Also note due to the reverse shells and Metasploit components this software will be detected a virus by AV software.</p>
<p>You can download WebRaider here:</p>
<p><a href="http://webraider.googlecode.com/files/WebRaider-0.2.3.8.zip">WebRaider-0.2.3.8.zip</a></p>
<p></p>
<p>Or read more <a href="http://code.google.com/p/webraider/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2587+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;t=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;title=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;title=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;title=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;title=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F03%2Fwebraider-automated-web-application-exploitation-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>fm-fsf &#8211; Freakin&#8217; Simple Fuzzer &#8211; Cross Platform Fuzzing Tool</title>
		<link>http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/</link>
		<comments>http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 09:39:42 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[.NET]]></category>
		<category><![CDATA[application hacking]]></category>
		<category><![CDATA[application-security]]></category>
		<category><![CDATA[data scraper]]></category>
		<category><![CDATA[ferruh mavituna]]></category>
		<category><![CDATA[fm-fsf]]></category>
		<category><![CDATA[freakin simple fuzzer]]></category>
		<category><![CDATA[fuzzer]]></category>
		<category><![CDATA[fuzzing tools]]></category>
		<category><![CDATA[fuzzing-tool]]></category>
		<category><![CDATA[hacking-software]]></category>
		<category><![CDATA[mono]]></category>
		<category><![CDATA[personal software security]]></category>
		<category><![CDATA[software-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1855</guid>
		<description><![CDATA[fm-fsf is a new fuzzer/data scraper that works under OSX, Linux (with Mono) and Windows (.NET Framework). Fuzzing tools are always useful if you are looking at discovering some new flaws in a software or web service. Quick Info FSF is a plug-in based freakin&#8217; simple fuzzer for fuzzing web applications and scraping data. It [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>fm-fsf is a new fuzzer/data scraper that works under OSX, Linux (with Mono) and Windows (.NET Framework). <a href="http://www.darknet.org.uk/tag/fuzzing-tool/">Fuzzing tools</a> are always useful if you are looking at discovering some new flaws in a software or web service.</p>
<p><strong>Quick Info</strong></p>
<p>FSF is a plug-in based freakin&#8217; simple fuzzer for fuzzing web applications and scraping data. </p>
<p>It supports some basic stuff and is missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.</p>
<p>It&#8217;s still in early stage of development so don&#8217;t expect too much.</p>
<p><strong>Why bring yet another fuzzer into this cruel world?</strong></p>
<p>The author was trying to fuzz something and after spending about 2-3 hours about 3-4 different terribly designed fuzzers he thought knocking up his own would be better.</p>
<p><strong>Don&#8217;t use if you&#8230;.</strong></p>
<ul>
<li>Want a fuzzer where you can control the raw HTTP request</li>
<li>Need some crazy features such as fuzzing multiple locations at a time </li>
</ul>
<p><strong>Use if you need a fuzzer&#8230;</strong></p>
<ul>
<li>That allows to take advantage of RegEx with the full power for scraping data (this is quite useful while exploiting SQL Injections, gathering data, looking for some hidden resource or trying to enumerate all valid &#8220;user id&#8221;s)</li>
<li>Simple to run and easy to use</li>
<li>Which makes it easy to write your own fuzzing modules</li>
<li>With simple and compact .NET code </li>
</ul>
<p>You can download fm-fsf here:</p>
<p><a href="http://fm-fsf.googlecode.com/files/FSF-7.1.0.0.tar.gz">FSF-7.1.0.0.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://code.google.com/p/fm-fsf/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1855+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;t=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;title=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;title=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;title=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;title=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F06%2Ffm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

