<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; hacking-web-application</title>
	<atom:link href="http://www.darknet.org.uk/tag/hacking-web-application/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>w3af v1.1 Released For Download &#8211; Web Application Attack &amp; Audit Framework</title>
		<link>http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/</link>
		<comments>http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/#comments</comments>
		<pubDate>Mon, 14 Nov 2011 17:37:57 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[auditing-framework]]></category>
		<category><![CDATA[cross site scriping]]></category>
		<category><![CDATA[hacking-web-application]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[w3af]]></category>
		<category><![CDATA[web-applicaton-security]]></category>
		<category><![CDATA[web-auditing]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3225</guid>
		<description><![CDATA[w3af is a Web Application Attack and Audit Framework. The project&#8217;s goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend. The w3af core and it&#8217;s plugins are fully written in python. The project has more than 130 plugins, which check for SQL injection, cross [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.darknet.org.uk/tag/w3af/">w3af</a> is a Web Application Attack and Audit Framework. The project&#8217;s goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend.</p>
<p>The w3af core and it&#8217;s plugins are fully written in python. The project has more than 130 plugins, which check for <a href="http://www.darknet.org.uk/tag/sql-injection/">SQL injection</a>, cross site scripting (<a href="http://www.darknet.org.uk/tag/xss/">xss</a>), local and remote file inclusion and much </p>
<p>Finally it&#8217;s out of BETA and RC and there&#8217;s now a stable core for the codebase.</p>
<p><strong>New in v1.1</strong></p>
<ul>
<li>Considerably increased performance by implementing gzip encoding</li>
<li>Enhanced embedded bug report system using Trac&#8217;s XMLRPC</li>
<li>Fixed hundreds of bugs</li>
<li>Fixed critical bug in auto-update feature</li>
<li>Enhanced integration with other tools (bug fixed and addedmore info to the file)</li>
</ul>
<p>You can download w3af v1.1 here:</p>
<p><a href="http://downloads.sourceforge.net/project/w3af/w3af/w3af%201.1/w3af-1.1.tar.bz2?r=http%3A%2F%2Fsourceforge.net%2Fprojects%2Fw3af%2Ffiles%2Fw3af%2Fw3af%25201.1%2F&#038;ts=1321290325&#038;use_mirror=cdnetworks-kr-1">w3af-1.1.tar.bz2</a></p>
<p>Or you can read more <a href="http://www.w3af.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3225+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;t=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fw3af-v1-1-released-for-download-web-application-attack-audit-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netsparker Community Edition &#8211; Web Application Security Scanner</title>
		<link>http://www.darknet.org.uk/2010/04/netsparker-community-edition-web-application-security-scanner/</link>
		<comments>http://www.darknet.org.uk/2010/04/netsparker-community-edition-web-application-security-scanner/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 10:00:42 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[free web application security scanner]]></category>
		<category><![CDATA[hacking web apps]]></category>
		<category><![CDATA[hacking-databases]]></category>
		<category><![CDATA[hacking-web-application]]></category>
		<category><![CDATA[mavituna]]></category>
		<category><![CDATA[mavituna security]]></category>
		<category><![CDATA[netsparker]]></category>
		<category><![CDATA[netsparker community edition]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[web app security]]></category>
		<category><![CDATA[web application security scanner]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2662</guid>
		<description><![CDATA[Netsparker is a Web Application Security Scanner that claims to be False-Positive Free. The developers thought that if you need to investigate every single identified issue manually what&#8217;s the point of having an automated scanner? So they developed a new technology which can confirm vulnerabilities on demand which allowed us to develop the first false [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Netsparker is a Web Application Security Scanner that claims to be False-Positive Free. The developers thought that if you need to investigate every single identified issue manually what&#8217;s the point of having an automated scanner? So they developed a new technology which can confirm vulnerabilities on demand which allowed us to develop the first false positive free web application security scanner.</p>
<p>When Netsparker identifies an SQL Injection, it can identify how to exploit it automatically and extract the version information from the application. When the version is successfully extracted Netsparker will report the issue as confirmed so that you can make sure that the issue is not a false-positive.</p>
<p>Same applies to other vulnerabilities such as XSS (Cross-site Scripting) where Netsparker loads the injection in an actual browser and observes the execution of JavaScript to confirm that the injection will actually get executed in the browser.</p>
<p>Thanks to its comprehensive and powerful JavaScript engine it&#8217;s possible to simulate a real attacker successfully. This means it can successfully analyse websites that rely on AJAX and JavaScript.</p>
<p>You don&#8217;t need to be a security expert, get training or read a long manual to start. Since the user interface is easy to use and can confirm and show you the impact, you can just fire it up and start using it.</p>
<p align="center"><img src="http://farm5.static.flickr.com/4036/4534428226_9c666cf62b.jpg" alt="Netsparker - Community Edition" /></p>
<p>You can download Netsparker &#8211; Community Edition here:</p>
<p><a href="http://www.mavitunasecurity.com/communityedition/">NetSparkerCommunityEditionSetup.exe</a></p>
<p></p>
<p>Or read more <a href="http://www.mavitunasecurity.com/netsparker/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Netsparker+Community+Edition+%E2%80%93+Web+Application+Security+Scanner+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2662+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/04/netsparker-community-edition-web-application-security-scanner/&amp;t=Netsparker+Community+Edition+%E2%80%93+Web+Application+Security+Scanner" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/04/netsparker-community-edition-web-application-security-scanner/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/04/netsparker-community-edition-web-application-security-scanner/&amp;title=Netsparker+Community+Edition+%E2%80%93+Web+Application+Security+Scanner" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/04/netsparker-community-edition-web-application-security-scanner/&amp;title=Netsparker+Community+Edition+%E2%80%93+Web+Application+Security+Scanner" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/04/netsparker-community-edition-web-application-security-scanner/&amp;title=Netsparker+Community+Edition+%E2%80%93+Web+Application+Security+Scanner" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/04/netsparker-community-edition-web-application-security-scanner/&amp;title=Netsparker+Community+Edition+%E2%80%93+Web+Application+Security+Scanner" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F04%2Fnetsparker-community-edition-web-application-security-scanner%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/04/netsparker-community-edition-web-application-security-scanner/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>w3af Fifth BETA for Download &#8211; Automated Web Auditing and Exploitation Framework</title>
		<link>http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/</link>
		<comments>http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/#comments</comments>
		<pubDate>Wed, 16 Jan 2008 07:22:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[auditing-framework]]></category>
		<category><![CDATA[hacking-web-application]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[w3af]]></category>
		<category><![CDATA[web-applicaton-security]]></category>
		<category><![CDATA[web-auditing]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/</guid>
		<description><![CDATA[As you all seem to pretty interested in Inguma, there&#8217;s something else similar called w3af &#8211; the fifth BETA was released a while back and the team are now working on the sixth. w3af is a Web application attack and Audit Framework. The project goal is to create a framework to find and exploit web [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>As you all seem to pretty interested in <a href="http://www.darknet.org.uk/tag/inguma/">Inguma</a>, there&#8217;s something else similar called w3af &#8211; the fifth BETA was released a while back and the team are now working on the sixth.</p>
<p>w3af is a Web application attack and Audit Framework. The project goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and</p>
<p>We did mention when it was first released &#8211; <a href="http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/">w3af &#8211; Web Application Attack and Audit Framework</a>.</p>
<p>There are a lot of small changes, but the basic and bigger ones are:</p>
<ul>
<li>Virtual daemon, a way to use Metasploit framework payloads/shellcodes while exploiting web applications.</li>
<li>w3afAgent, a reverse VPN that allows you to route packets through the compromised server</li>
<li>Good samaritan, a module that allows you to exploit blind sql injections much faster</li>
<li>20+ new plugins</li>
<li>A lot of bug fixes</li>
<li>A much more stable core.</li>
</ul>
<p>A full plugin list is here:</p>
<p><a href="http://w3af.sourceforge.net/pluginDesc.php">w3af &#8211; Plugins</a></p>
<p>The users guide can be found here:</p>
<p><a href="http://w3af.sourceforge.net/documentation/user/w3afUsersGuide.pdf">w3afUsersGuide.pdf</a></p>
<p>The author has also uploaded the presentation material he made for the T2 conference in Finland &#8211; this can serve as a good introduction. </p>
<p><a href="http://w3af.sourceforge.net/documentation/user/w3af-T2.pdf">w3af-T2.pdf</a></p>
<p>You can download w3af here:</p>
<p><a href="http://sourceforge.net/project/showfiles.php?group_id=170274&#038;package_id=194268&#038;release_id=548053">w3af BETA5</a></p>
<p></p>
<p>Or read more <a href="http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D712+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;t=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;title=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;title=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;title=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;title=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F01%2Fw3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>w3af &#8211; Web Application Attack and Audit Framework</title>
		<link>http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/</link>
		<comments>http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/#comments</comments>
		<pubDate>Wed, 22 Aug 2007 09:00:37 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[auditing-framework]]></category>
		<category><![CDATA[hacking-web-application]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[w3af]]></category>
		<category><![CDATA[web-applicaton-security]]></category>
		<category><![CDATA[web-auditing]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/</guid>
		<description><![CDATA[A pretty cool tool was released a while back called w3af ( Web Application Attack and Audit Framework ), a fully automated auditing and exploiting framework for the web. This framework has been in development for almost a year and has the following features: Audit SQL injection detection XSS detection SSI detection Local file include [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>A pretty cool tool was released a while back called w3af ( Web Application Attack and Audit Framework ), a fully automated auditing and exploiting framework for the web. This framework has been in development for almost a year and has the following features:</p>
<p><strong>Audit</strong></p>
<ul>
<li>SQL injection detection</li>
<li>XSS detection</li>
<li>SSI detection</li>
<li>Local file include detection</li>
<li>Remote file include detection</li>
<li>Buffer Overflow detection</li>
<li>Format String bugs detection</li>
<li>OS Commanding detection</li>
<li>Response Splitting detection</li>
<li>LDAP Injection detection</li>
<li>Basic Authentication bruteforce</li>
<li>File upload inside webroot</li>
<li>htaccess LIMIT misconfiguration</li>
<li>SSL certificate validation</li>
<li>XPATH injection detection</li>
<li>unSSL (HTTPS documents can be fetched using HTTP)</li>
</ul>
<p><strong>Discovery</strong></p>
<ul>
<li>Pykto, a nikto port to python</li>
<li>Hmap, http fingerprinting.</li>
<li>fingerGoogle, finds valid user accounts in google.</li>
<li>googleSpider, a spider that uses google.</li>
<li>webSpider, a classic web spider.</li>
<li>robotsReader</li>
<li>urlFuzzer</li>
<li>serverHeader, fetches server header</li>
<li>allowedMethods, gets a list of allowed HTTP methods.</li>
<li>crossDomain, get and parse the flash file crossdomain.xml</li>
<li>error404page, generate a regular expression to match 404 pages.</li>
<li>sitemapReader, read googles sitemap.xml and parse it.</li>
<li>spiderMan, using a localproxy and a human, find new URLs for auditing.</li>
<li>webDiff, find differences between a local and a remote directory.</li>
<li>wsdlFinder, find and parse WSDL and DISCO files.</li>
</ul>
<p>The framework is extended using plug-ins and is completely written in Python.</p>
<p>You can download w3af here:</p>
<p><a href="http://sourceforge.net/project/showfiles.php?group_id=170274">w3af BETA 4</a></p>
<p></p>
<p>Or read more <a href="http://w3af.sf.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D600+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;t=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;title=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;title=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;title=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;title=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F08%2Fw3af-web-application-attack-and-audit-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

