<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; spike</title>
	<atom:link href="http://www.darknet.org.uk/tag/spike/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>SPIKE Proxy &#8211; Application Level Security Assessment</title>
		<link>http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/</link>
		<comments>http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/#comments</comments>
		<pubDate>Mon, 15 Jan 2007 04:57:20 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[asp-hacking]]></category>
		<category><![CDATA[burp-proxy]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[php-hacking]]></category>
		<category><![CDATA[proxies]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[spike]]></category>
		<category><![CDATA[spike-proxy]]></category>
		<category><![CDATA[web-application-hacking]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-security-testing]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/</guid>
		<description><![CDATA[SPIKE Proxy is part of the SPIKE Application Testing Suite, It functions as an HTTP and HTTPS proxy, and allows the web developer or web application auditor low level access to the entire web application interface, while also providing a bevy of automated tools and techniques for discovering common problems. These automated tools include: Automated [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>SPIKE Proxy is part of the SPIKE Application Testing Suite, It functions as an HTTP and HTTPS proxy, and allows the web developer or web application auditor low level access to the entire web application interface, while also providing a bevy of automated tools and techniques for discovering common problems. These automated tools include:</p>
<ul>
<li>Automated SQL Injection Detection</li>
<li>Web Site Crawling (guaranteed not to crawl sites other than the one being tested)</li>
<li>Login form brute forcing</li>
<li>Automated overflow detection</li>
<li>
Automated directory traversal detection</li>
</ul>
<p>Not all web applications are built in the same ways, and hence, many must be analyzed individually. SPIKE Proxy is a professional-grade tool for looking for application-level vulnerabilities in web applications. SPIKE Proxy covers the basics, such as SQL Injection and cross-site-scripting, but it&#8217;s completely open Python infrastructure allows advanced users to customize it for web applications that other tools fall apart on. SPIKE Proxy is available for Linux and Windows.</p>
<p>Note: that SPIKE Proxy requires a working install of Python and pyOpenSSL on Linux. This is included in the Windows distribution.</p>
<p>SPIKE is a fairly mature tool having been around since about 2003, we at Darknet use Spike Proxy along with the <a href="http://www.darknet.org.uk/2007/01/burp-proxy-burp-suite-attacking-web-applications/">Burp Suite</a> for web application security analysis.</p>
<p>You can download SPIKE here:</p>
<p><a href="http://www.immunitysec.com/downloads/SP148.tgz">Download for Linux</a>    |    <a href="http://www.immunitysec.com/downloads/SP148.zip">Download for Windows</a></p>
<p>Limited information can be found here:</p>
<p></p>
<p><a href="http://www.immunitysec.com/resources-freesoftware.shtml">Immunity Free Software</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D358+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;t=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;title=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;title=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;title=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;title=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F01%2Fspike-proxy-application-level-security-assessment%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SpikeSource Spike PHP Security Audit Tool</title>
		<link>http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/</link>
		<comments>http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/#comments</comments>
		<pubDate>Tue, 01 Aug 2006 03:13:49 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[code auditing tool]]></category>
		<category><![CDATA[code-audit]]></category>
		<category><![CDATA[code-auditing]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[php-audit-tool]]></category>
		<category><![CDATA[php-security]]></category>
		<category><![CDATA[source code auditing]]></category>
		<category><![CDATA[spike]]></category>
		<category><![CDATA[spikesource]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/</guid>
		<description><![CDATA[Spike is an Open Source tool based on the popular RATS C based auditing tool implemented for PHP. The tool Spike basically does static analysis of php code for security exploits, PHP5 and call-time pass-by-reference are currently required, but a PHP4 version is coming out this week. This tool is especially welcomed by Darknet as [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Spike is an Open Source tool based on the popular <a href="http://www.darknet.org.uk/2009/11/rats-rough-auditing-tool-for-security/">RATS</a> C based auditing tool implemented for PHP.</p>
<p>The tool Spike basically does static analysis of php code for security exploits, PHP5 and call-time pass-by-reference are currently required, but a PHP4 version is coming out this week.</p>
<p>This tool is especially welcomed by Darknet as there aren&#8217;t many static analysis tools out there that are free, and there are very few tools for auditing PHP code..which as we all known tends to be coded quite insecurely at times (just look at phpBB and PhpNUKE).</p>
<p>You can find the latest version here:</p>
<p></p>
<p><a href="http://developer.spikesource.com/projects/phpsecaudit">Spike PHP Audit Tool</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=SpikeSource+Spike+PHP+Security+Audit+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D307+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;t=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F08%2Fspikesource-spike-php-security-audit-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

