<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; w3af</title>
	<atom:link href="http://www.darknet.org.uk/tag/w3af/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>w3af v1.1 Released For Download &#8211; Web Application Attack &amp; Audit Framework</title>
		<link>http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/</link>
		<comments>http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/#comments</comments>
		<pubDate>Mon, 14 Nov 2011 17:37:57 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[auditing-framework]]></category>
		<category><![CDATA[cross site scriping]]></category>
		<category><![CDATA[hacking-web-application]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[w3af]]></category>
		<category><![CDATA[web-applicaton-security]]></category>
		<category><![CDATA[web-auditing]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3225</guid>
		<description><![CDATA[w3af is a Web Application Attack and Audit Framework. The project&#8217;s goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend. The w3af core and it&#8217;s plugins are fully written in python. The project has more than 130 plugins, which check for SQL injection, cross [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.darknet.org.uk/tag/w3af/">w3af</a> is a Web Application Attack and Audit Framework. The project&#8217;s goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend.</p>
<p>The w3af core and it&#8217;s plugins are fully written in python. The project has more than 130 plugins, which check for <a href="http://www.darknet.org.uk/tag/sql-injection/">SQL injection</a>, cross site scripting (<a href="http://www.darknet.org.uk/tag/xss/">xss</a>), local and remote file inclusion and much </p>
<p>Finally it&#8217;s out of BETA and RC and there&#8217;s now a stable core for the codebase.</p>
<p><strong>New in v1.1</strong></p>
<ul>
<li>Considerably increased performance by implementing gzip encoding</li>
<li>Enhanced embedded bug report system using Trac&#8217;s XMLRPC</li>
<li>Fixed hundreds of bugs</li>
<li>Fixed critical bug in auto-update feature</li>
<li>Enhanced integration with other tools (bug fixed and addedmore info to the file)</li>
</ul>
<p>You can download w3af v1.1 here:</p>
<p><a href="http://downloads.sourceforge.net/project/w3af/w3af/w3af%201.1/w3af-1.1.tar.bz2?r=http%3A%2F%2Fsourceforge.net%2Fprojects%2Fw3af%2Ffiles%2Fw3af%2Fw3af%25201.1%2F&#038;ts=1321290325&#038;use_mirror=cdnetworks-kr-1">w3af-1.1.tar.bz2</a></p>
<p>Or you can read more <a href="http://www.w3af.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3225+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;t=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fw3af-v1-1-released-for-download-web-application-attack-audit-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>w3af 1.0-rc3 Available For Download &#8211; Web Application Attack &amp; Audit Framework</title>
		<link>http://www.darknet.org.uk/2010/06/w3af-1-0-rc3-available-for-download-web-application-attack-audit-framework/</link>
		<comments>http://www.darknet.org.uk/2010/06/w3af-1-0-rc3-available-for-download-web-application-attack-audit-framework/#comments</comments>
		<pubDate>Fri, 25 Jun 2010 09:30:17 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[hacking-web-applications]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[w3af]]></category>
		<category><![CDATA[web app security framework]]></category>
		<category><![CDATA[web application audit]]></category>
		<category><![CDATA[web application exploitation]]></category>
		<category><![CDATA[web-application-scanner]]></category>
		<category><![CDATA[web-applications-security]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2632</guid>
		<description><![CDATA[Our last mention of w3af was back in 2008 when the fifth BETA was released, the team have recently released a new version 1.0 &#8211; Release Candidate 3. w3af is a Web Application Attack and Audit Framework. The project&#8217;s goal is to create a framework to find and exploit web application vulnerabilities that is easy [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Our last mention of <a href="http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/">w3af was back in 2008 when the fifth BETA was released</a>, the team have recently released a new version 1.0 &#8211; Release Candidate 3.</p>
<p>w3af is a Web Application Attack and Audit Framework. The project&#8217;s goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend.</p>
<p><strong>New Features</strong></p>
<ul>
<li>Enhanced GUI, including huge changes in the MITM proxy and the Fuzzy Request Editor</li>
<li>Increased speed by rewriting parts of the thread management code</li>
<li>Fixed tons of bugs</li>
<li>Reduced memory usage</li>
<li>Many plugins were rewritten using different techniques that use less HTTP requests to identify the same vulnerabilities</li>
<li>Reduced false positives</li>
</ul>
<p>You can download w3af 1.0-rc3 here:</p>
<p>Windows &#8211; <a href="http://sourceforge.net/projects/w3af/files/w3af/w3af%201.0-rc3%20%5Bmoyogui%5D/w3af-1.0-rc3.exe/download">w3af-1.0-rc3.exe</a><br />
Linux/BSD/Mac &#8211; <a href="http://sourceforge.net/projects/w3af/files/w3af/w3af%201.0-rc3%20%5Bmoyogui%5D/w3af-1.0-rc3.tar.bz2/download">w3af-1.0-rc3.tar.bz2</a></p>
<p></p>
<p>Or read more <a href="http://w3af.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=w3af+1.0-rc3+Available+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2632+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/06/w3af-1-0-rc3-available-for-download-web-application-attack-audit-framework/&amp;t=w3af+1.0-rc3+Available+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/06/w3af-1-0-rc3-available-for-download-web-application-attack-audit-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/06/w3af-1-0-rc3-available-for-download-web-application-attack-audit-framework/&amp;title=w3af+1.0-rc3+Available+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/06/w3af-1-0-rc3-available-for-download-web-application-attack-audit-framework/&amp;title=w3af+1.0-rc3+Available+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/06/w3af-1-0-rc3-available-for-download-web-application-attack-audit-framework/&amp;title=w3af+1.0-rc3+Available+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/06/w3af-1-0-rc3-available-for-download-web-application-attack-audit-framework/&amp;title=w3af+1.0-rc3+Available+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F06%2Fw3af-1-0-rc3-available-for-download-web-application-attack-audit-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/06/w3af-1-0-rc3-available-for-download-web-application-attack-audit-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>w3af Fifth BETA for Download &#8211; Automated Web Auditing and Exploitation Framework</title>
		<link>http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/</link>
		<comments>http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/#comments</comments>
		<pubDate>Wed, 16 Jan 2008 07:22:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[auditing-framework]]></category>
		<category><![CDATA[hacking-web-application]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[w3af]]></category>
		<category><![CDATA[web-applicaton-security]]></category>
		<category><![CDATA[web-auditing]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/</guid>
		<description><![CDATA[As you all seem to pretty interested in Inguma, there&#8217;s something else similar called w3af &#8211; the fifth BETA was released a while back and the team are now working on the sixth. w3af is a Web application attack and Audit Framework. The project goal is to create a framework to find and exploit web [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>As you all seem to pretty interested in <a href="http://www.darknet.org.uk/tag/inguma/">Inguma</a>, there&#8217;s something else similar called w3af &#8211; the fifth BETA was released a while back and the team are now working on the sixth.</p>
<p>w3af is a Web application attack and Audit Framework. The project goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and</p>
<p>We did mention when it was first released &#8211; <a href="http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/">w3af &#8211; Web Application Attack and Audit Framework</a>.</p>
<p>There are a lot of small changes, but the basic and bigger ones are:</p>
<ul>
<li>Virtual daemon, a way to use Metasploit framework payloads/shellcodes while exploiting web applications.</li>
<li>w3afAgent, a reverse VPN that allows you to route packets through the compromised server</li>
<li>Good samaritan, a module that allows you to exploit blind sql injections much faster</li>
<li>20+ new plugins</li>
<li>A lot of bug fixes</li>
<li>A much more stable core.</li>
</ul>
<p>A full plugin list is here:</p>
<p><a href="http://w3af.sourceforge.net/pluginDesc.php">w3af &#8211; Plugins</a></p>
<p>The users guide can be found here:</p>
<p><a href="http://w3af.sourceforge.net/documentation/user/w3afUsersGuide.pdf">w3afUsersGuide.pdf</a></p>
<p>The author has also uploaded the presentation material he made for the T2 conference in Finland &#8211; this can serve as a good introduction. </p>
<p><a href="http://w3af.sourceforge.net/documentation/user/w3af-T2.pdf">w3af-T2.pdf</a></p>
<p>You can download w3af here:</p>
<p><a href="http://sourceforge.net/project/showfiles.php?group_id=170274&#038;package_id=194268&#038;release_id=548053">w3af BETA5</a></p>
<p></p>
<p>Or read more <a href="http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D712+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;t=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;title=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;title=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;title=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/&amp;title=w3af+Fifth+BETA+for+Download+%E2%80%93+Automated+Web+Auditing+and+Exploitation+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F01%2Fw3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/01/w3af-fifth-beta-for-download-automated-web-auditing-and-exploitation-framework/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>w3af &#8211; Web Application Attack and Audit Framework</title>
		<link>http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/</link>
		<comments>http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/#comments</comments>
		<pubDate>Wed, 22 Aug 2007 09:00:37 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[auditing-framework]]></category>
		<category><![CDATA[hacking-web-application]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[w3af]]></category>
		<category><![CDATA[web-applicaton-security]]></category>
		<category><![CDATA[web-auditing]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/</guid>
		<description><![CDATA[A pretty cool tool was released a while back called w3af ( Web Application Attack and Audit Framework ), a fully automated auditing and exploiting framework for the web. This framework has been in development for almost a year and has the following features: Audit SQL injection detection XSS detection SSI detection Local file include [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>A pretty cool tool was released a while back called w3af ( Web Application Attack and Audit Framework ), a fully automated auditing and exploiting framework for the web. This framework has been in development for almost a year and has the following features:</p>
<p><strong>Audit</strong></p>
<ul>
<li>SQL injection detection</li>
<li>XSS detection</li>
<li>SSI detection</li>
<li>Local file include detection</li>
<li>Remote file include detection</li>
<li>Buffer Overflow detection</li>
<li>Format String bugs detection</li>
<li>OS Commanding detection</li>
<li>Response Splitting detection</li>
<li>LDAP Injection detection</li>
<li>Basic Authentication bruteforce</li>
<li>File upload inside webroot</li>
<li>htaccess LIMIT misconfiguration</li>
<li>SSL certificate validation</li>
<li>XPATH injection detection</li>
<li>unSSL (HTTPS documents can be fetched using HTTP)</li>
</ul>
<p><strong>Discovery</strong></p>
<ul>
<li>Pykto, a nikto port to python</li>
<li>Hmap, http fingerprinting.</li>
<li>fingerGoogle, finds valid user accounts in google.</li>
<li>googleSpider, a spider that uses google.</li>
<li>webSpider, a classic web spider.</li>
<li>robotsReader</li>
<li>urlFuzzer</li>
<li>serverHeader, fetches server header</li>
<li>allowedMethods, gets a list of allowed HTTP methods.</li>
<li>crossDomain, get and parse the flash file crossdomain.xml</li>
<li>error404page, generate a regular expression to match 404 pages.</li>
<li>sitemapReader, read googles sitemap.xml and parse it.</li>
<li>spiderMan, using a localproxy and a human, find new URLs for auditing.</li>
<li>webDiff, find differences between a local and a remote directory.</li>
<li>wsdlFinder, find and parse WSDL and DISCO files.</li>
</ul>
<p>The framework is extended using plug-ins and is completely written in Python.</p>
<p>You can download w3af here:</p>
<p><a href="http://sourceforge.net/project/showfiles.php?group_id=170274">w3af BETA 4</a></p>
<p></p>
<p>Or read more <a href="http://w3af.sf.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D600+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;t=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;title=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;title=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;title=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/&amp;title=w3af+%E2%80%93+Web+Application+Attack+and+Audit+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F08%2Fw3af-web-application-attack-and-audit-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/08/w3af-web-application-attack-and-audit-framework/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

