<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; web-application-security-testing</title>
	<atom:link href="http://www.darknet.org.uk/tag/web-application-security-testing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>WebSurgery &#8211; Web Application Security Testing Suite</title>
		<link>http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/</link>
		<comments>http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 09:51:45 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[fuzzer]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[web application security testing suite]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-security-testing]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[websurgery]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3179</guid>
		<description><![CDATA[WebSurgery is a suite of tools for security testing of web applications. It was designed for security auditors to help them with the web application planning and exploitation. Currently, it uses an efficient, fast and stable Web Crawler, File/Dir Brute forcer, Fuzzer for advanced exploitation of known and unusual vulnerabilities such as SQL Injection, Cross [...]]]></description>
			<content:encoded><![CDATA[<p>WebSurgery is a suite of tools for security testing of web applications. It was designed for security auditors to help them with the web application planning and exploitation. Currently, it uses an efficient, fast and stable Web Crawler, File/Dir Brute forcer, <a href="http://www.darknet.org.uk/tag/fuzzer/">Fuzzer</a> for advanced exploitation of known and unusual vulnerabilities such as <a href="http://www.darknet.org.uk/tag/sql-injection/">SQL Injection</a>, <a href="http://www.darknet.org.uk/tag/xss/">Cross site scripting (XSS)</a>, Brute force for login forms, identification of firewall-filtered rules, DOS Attacks and WEB Proxy to analyze, intercept and manipulate the traffic between your browser and the target web application.</p>
<p><strong>WEB Crawler</strong></p>
<p>WEB Crawler was designed to be fast, accurate, stable, completely parametrable and the use of advanced techniques to extract links from Javascript and HTML Tags. It works with parametrable timing settings (Timeout, Threading, Max Data Size, Retries) and a number of rules parameters to prevent infinitive loops and pointless scanning (Case Sensitive, Dir Depth, Process Above/Below, Submit Forms, Fetch Indexes/Sitemaps, Max Requests per File/Script Parameters). It is also possible to apply custom headers (user agent, cookies etc) and Include/Exclude Filters. WEB Crawler come with an embedded File/Dir Brute Forcer which helps to directly brute force for files/dirs in the directories found from crawling.</p>
<p><strong>WEB Bruteforcer</strong></p>
<p>WEB Bruteforcer is a brute forcer for files and directories within the web application which helps to identify the hidden structure. It is also multi-threaded and completely parametrable for timing settings (Timeout, Threading, Max Data Size, Retries) and rules (Headers, Base Dir, Brute force Dirs/Files, Recursive, File’s Extension, Send GET/HEAD, Follow Redirects, Process Cookies and List generator configuration).<br />
By default, it will brute force from root / base dir recursively for both files and directories. It sends both HEAD and GET requests when it needs it (HEAD to identify if the file/dir exists and then GET to retrieve the full response).</p>
<p><strong>WEB Fuzzer</strong></p>
<p>WEB Fuzzer is a more advanced tool to create a number of requests based on one initial request. Fuzzer has no limits and can be used to exploit known vulnerabilities such (blind) SQL Inections and more unsual ways such identifing improper input handling, firewall/filtering rules, DOS Attacks.</p>
<p><strong>WEB Editor</strong></p>
<p>A simple WEB Editor to send individual requests. It also contains a HEX Editor for more advanced requests.</p>
<p><strong>WEB Proxy</strong></p>
<p>WEB Proxy is a proxy server running locally and will allow you to analyze, intercept and manipulate HTTP/HTTPS requests coming from your browser or other application which support proxies.</p>
<p>You can download WebSurgery here:</p>
<p>Setup &#8211; <a href="http://www.surgeonix.com/blog/downloads/websurgery/setup.msi">setup.msi</a><br />
Portable &#8211; <a href="http://www.surgeonix.com/blog/downloads/websurgery/websurgery.zip">websurgery.zip</a></p>
<p>Or read more <a href=" http://www.surgeonix.com/blog/index.php/archives/117">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3179+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;t=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;title=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;title=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;title=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;title=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F08%2Fwebsurgery-web-application-security-testing-suite%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Arachni v0.3 Released &#8211; Web Application Security Scanner Framework</title>
		<link>http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/</link>
		<comments>http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/#comments</comments>
		<pubDate>Mon, 22 Aug 2011 14:04:28 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[arachni]]></category>
		<category><![CDATA[arachni scanner]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[security-scanner]]></category>
		<category><![CDATA[wavsep]]></category>
		<category><![CDATA[web application security scanner]]></category>
		<category><![CDATA[web security scanner]]></category>
		<category><![CDATA[web security scanning tool]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-security-testing]]></category>
		<category><![CDATA[web-hacking-tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3175</guid>
		<description><![CDATA[It&#8217;s been a while since we last mentioned Arachni, it was back in February &#8211; Arachni v0.2.2.1 – Web Application Security Scanner Framework. For those who are not aware, Arachni is a fully automated system which tries to enforce the fire and forget principle. As soon as a scan is started it will not bother [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while since we last mentioned <a href="http://www.darknet.org.uk/tag/arachni/">Arachni</a>, it was back in February &#8211; <a href="http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/" title="Arachni v0.2.2.1 – Web Application Security Scanner Framework">Arachni v0.2.2.1 – Web Application Security Scanner Framework</a>.</p>
<p>For those who are not aware, Arachni is a fully automated system which tries to enforce the fire and forget principle. As soon as a scan is started it will not bother you for anything nor require further user interaction. Upon completion, the scan results will be saved in a file which you can later convert to several different formats (HTML, Plain Text, XML, etc.)</p>
<p>The project was initially started as an educational exercise though it has since evolved into a powerful and modular framework allowing for fast, accurate and flexible security/vulnerability assessments..</p>
<p>More than that, Arachni is highly extend-able allowing for anyone to improve upon it by adding custom components and tailoring most aspects to meet most needs. </p>
<p>The author notified us of a major new release (v0.3) which has some great new features, a few of those being:</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>    A new custom-written, lightweight Spider</li>
<li>    Add-on support for the WebUI
<ul>
<li>  Scan scheduler</li>
<li>       AutoDeploy &#8212; Convert any SSH enabled Linux box into a Dispatcher</li>
</ul>
</li>
<li>    Improved accuracy of differential analysis audits</li>
<li>    Improved accuracy of timing attack audits</li>
<li>    Highly optimized timing attacks</li>
</ul>
<p>If you are interested in the WebUI aspect you can check out some screenshots <a href="http://arachni.segfault.gr/screenshots#v0.3">here</a>, the more comprehensive ChangeLog is also available <a href="http://arachni.segfault.gr/latest">here</a>.</p>
<p>For those of you into benchmarking and testing you might be interested to know that during a recent test Arachni was the only (from a long list of commercial and F/OSS systems) that hit 100% on both XSS and SQLi tests in the WAVSEP benchmark:</p>
<p><a href=" http://sectooladdict.blogspot.com/2011/08/commercial-web-application-scanner.html">Commercial Web Application Scanner Benchmark </a></p>
<p>The author is doing a great job with this tool and rapidly closing the gap between free security scanners and the very expensive commercial options. If you do have any feedback on Arachni v0.3 drop a comment here or hit up the <a href="http://groups.google.com/group/arachni?pli=1">Arachni Google Group</a>.</p>
<p>You can download Arachni v0.3 here:</p>
<p><a href="https://github.com/downloads/Zapotek/arachni/arachni-v0.3-cde.tar.gz">arachni-v0.3-cde.tar.gz</a></p>
<p>Or read more <a href="http://arachni.segfault.gr/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3175+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;t=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;title=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;title=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;title=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;title=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F08%2Farachni-v3-0-released-web-application-security-scanner-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Burp Suite Free Edition v1.4 &#8211; Web Application Security Testing Tool</title>
		<link>http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/</link>
		<comments>http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/#comments</comments>
		<pubDate>Wed, 08 Jun 2011 11:00:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[burp]]></category>
		<category><![CDATA[burp suite download]]></category>
		<category><![CDATA[burp suite free edition]]></category>
		<category><![CDATA[burp v1.4]]></category>
		<category><![CDATA[burp-proxy]]></category>
		<category><![CDATA[burp-suite]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-security-testing]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3127</guid>
		<description><![CDATA[We love Burp Suite and we have since wayyyy back, the last update we posted was around 18 months ago back in January 2010 &#8211; Burp Suite v1.3 Released – Integrated Platform For Attacking Web Applications. For the two people here who don&#8217;t know what this tool does, Burp Suite is an integrated platform for [...]]]></description>
			<content:encoded><![CDATA[<p>We love <a href="http://www.darknet.org.uk/tag/burp-suite/">Burp Suite</a> and we have since wayyyy back, the last update we posted was around 18 months ago back in January 2010 &#8211; <a href="http://www.darknet.org.uk/2010/01/burp-suite-v1-3-released-integrated-platform-for-attacking-web-applications/">Burp Suite v1.3 Released – Integrated Platform For Attacking Web Applications</a>.</p>
<p>For the two people here who don&#8217;t know what this tool does, Burp Suite is an integrated platform for performing security testing of web applications. Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application&#8217;s attack surface, through to finding and exploiting security vulnerabilities.</p>
<p>Burp gives you full control, letting you combine advanced manual techniques with state-of-the-art automation, to make your work faster, more effective, and more fun.</p>
<p>And now, we&#8217;re happy to announce there&#8217;s a new version out and it&#8217;s available for download now!</p>
<p><strong>New Features</strong></p>
<ul>
<li>The ability to compare site maps</li>
<li>Functions to help with testing access controls using your browser</li>
<li>Support for preset request macros</li>
<li>Session handling rules to help you work with difficult situations</li>
<li>In-browser rendering of responses from all Burp tools</li>
<li>Auto recognition and rendering of character sets</li>
<li>Support for upstream SOCKS proxies</li>
<li>Headless mode for unattended scripted usage</li>
<li>Support for more types of redirection</li>
<li>Support for NTLMv2 and IPv6</li>
<li>Numerous enhancements to Burp&#8217;s extensibility</li>
<li>Greater stability on OSX</li>
</ul>
<p>You can download Burp Suite Free Edition v1.4 here:</p>
<p><a href="http://portswigger.net/burp/burpsuite_v1.4.zip">burpsuite_v1.4.zip</a></p>
<p>Or read more <a href="http://portswigger.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3127+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;t=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F06%2Fburp-suite-free-edition-v1-4-web-application-security-testing-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAHI &#8211; Web Automation &amp; Application Security Testing Tool</title>
		<link>http://www.darknet.org.uk/2010/03/sahi-web-automation-application-security-testing-tool/</link>
		<comments>http://www.darknet.org.uk/2010/03/sahi-web-automation-application-security-testing-tool/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 10:48:20 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[hacking-web-applications]]></category>
		<category><![CDATA[javascript security]]></category>
		<category><![CDATA[sahi]]></category>
		<category><![CDATA[web app security]]></category>
		<category><![CDATA[web application security testing tool]]></category>
		<category><![CDATA[web security automated testing tool]]></category>
		<category><![CDATA[web-app-hacking]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-security-testing]]></category>
		<category><![CDATA[web-hacking-tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2574</guid>
		<description><![CDATA[Sahi is an automation tool to test web applications. Sahi injects javascript into web pages using a proxy and the javascript helps automate web applications. Sahi is a tester friendly tool. It abstracts out most difficulties that testers face while automating web applications. Some salient features include excellent recorder, platform and browser independence, no XPaths, [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Sahi is an automation tool to test web applications. Sahi injects javascript into web pages using a proxy and the javascript helps automate web applications.</p>
<p>Sahi is a tester friendly tool. It abstracts out most difficulties that testers face while automating web applications. Some salient features include excellent recorder, platform and browser independence, no XPaths, no waits, multi-threaded playback, excellent Java interaction and inbuilt reporting. </p>
<p><strong>Features</strong></p>
<ul>
<li>Browser and Operating System independent</li>
<li>Powerful recorder which works across browsers</li>
<li>Powerful Object Spy</li>
<li>Intuitive and simple APIs</li>
<li>Javascript based scripts for good programming control</li>
<li>Version Controllable text-based scripts</li>
<li>In-built reports</li>
<li>In-built multi-threaded or parallel playback of tests</li>
<li>Tests do not need the browser window to be in focus</li>
<li>Command line and ant support for integration into build processes</li>
<li>Supports external proxy, HTTPS, 401 &#038; NTLM authentications</li>
<li>Supports browser popups and modal dialogs</li>
<li>Supports AJAX and highly dynamic web applications</li>
<li>Scripts very robust</li>
<li>Works on applications with random auto-generated ids</li>
<li>Very lightweight and scalable</li>
<li>Supports data-driven testing. Can connect to database, Excel or CSV file.</li>
<li>Ability to invoke any Java library from scripts</li>
</ul>
<p><strong>Limitations</strong></p>
<ul>
<li>Framesets/pages with frames/iframes loading pages from multiple domains is not supported. Sahi cannot handle pages which have other pages from different domains embedded in them using iframes or frames. So you cannot have a page from google.com having an iframe with a page from yahoo.com. Note that this is not the same as switching between domains, where you navigate from a google.com page to a yahoo.com page, which will work in Sahi.</li>
<li>File upload field will not be populated on browsers for javascript verification. File upload itself works fine</li>
</ul>
<p>You can download SAHI here:</p>
<p><a href="http://sourceforge.net/projects/sahi/files/sahi-v3/2010-03-02/sahi_20100302.zip/download">sahi_20100302.zip</a></p>
<p></p>
<p>Or read more <a href="http://sahi.co.in/w/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=SAHI+%E2%80%93+Web+Automation+%26+Application+Security+Testing+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2574+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/03/sahi-web-automation-application-security-testing-tool/&amp;t=SAHI+%E2%80%93+Web+Automation+%26+Application+Security+Testing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/03/sahi-web-automation-application-security-testing-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/03/sahi-web-automation-application-security-testing-tool/&amp;title=SAHI+%E2%80%93+Web+Automation+%26+Application+Security+Testing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/03/sahi-web-automation-application-security-testing-tool/&amp;title=SAHI+%E2%80%93+Web+Automation+%26+Application+Security+Testing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/03/sahi-web-automation-application-security-testing-tool/&amp;title=SAHI+%E2%80%93+Web+Automation+%26+Application+Security+Testing+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/03/sahi-web-automation-application-security-testing-tool/&amp;title=SAHI+%E2%80%93+Web+Automation+%26+Application+Security+Testing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F03%2Fsahi-web-automation-application-security-testing-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/03/sahi-web-automation-application-security-testing-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Groundspeed 1.1 &#8211; Web Application Security Add-on For Firefox</title>
		<link>http://www.darknet.org.uk/2010/01/groundspeed-1-1-web-application-security-add-on-for-firefox/</link>
		<comments>http://www.darknet.org.uk/2010/01/groundspeed-1-1-web-application-security-add-on-for-firefox/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 09:24:56 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[firefox security add-on]]></category>
		<category><![CDATA[groundspeed]]></category>
		<category><![CDATA[groundspeed firefox add-on]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[web app security]]></category>
		<category><![CDATA[web-application-hacking]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-security-testing]]></category>
		<category><![CDATA[website security]]></category>
		<category><![CDATA[website security testing]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2430</guid>
		<description><![CDATA[Groundspeed is an open-source Firefox extension for web application security testers presented at the OWASP AppSec DC 2009. It allows you to manipulate the web application’s user interface to eliminate annoying limitations and client-side controls that interfere with the web application penetration test. What can I do with Groundspeed? Groundspeed allows you to modify the [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Groundspeed is an open-source Firefox extension for web application security testers presented at the OWASP AppSec DC 2009. It allows you to manipulate the web application’s user interface to eliminate annoying limitations and client-side controls that interfere with the web application penetration test.</p>
<p><strong>What can I do with Groundspeed?</strong></p>
<p>Groundspeed allows you to modify the forms and form elements loaded in the page. Some practical uses include:</p>
<ul>
<li>Changing the types of form fields, for example you can change hidden fields into text fields so you can easily edit their contents.</li>
<li>Quickly removing size and length limitations on text fields so you have more space to type your attack strings.</li>
<li>Changing form target so the form submits in another tab.</li>
<li>Removing or editing the JavaScript event handlers to bypass client side validation.</li>
</ul>
<p>You can install Groundspeed here:</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/46698/">https://addons.mozilla.org/en-US/firefox/addon/46698/</a></p>
<p></p>
<p>Or read more <a href="http://groundspeed.wobot.org">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Groundspeed+1.1+%E2%80%93+Web+Application+Security+Add-on+For+Firefox+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2430+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/01/groundspeed-1-1-web-application-security-add-on-for-firefox/&amp;t=Groundspeed+1.1+%E2%80%93+Web+Application+Security+Add-on+For+Firefox" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/01/groundspeed-1-1-web-application-security-add-on-for-firefox/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/01/groundspeed-1-1-web-application-security-add-on-for-firefox/&amp;title=Groundspeed+1.1+%E2%80%93+Web+Application+Security+Add-on+For+Firefox" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/01/groundspeed-1-1-web-application-security-add-on-for-firefox/&amp;title=Groundspeed+1.1+%E2%80%93+Web+Application+Security+Add-on+For+Firefox" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/01/groundspeed-1-1-web-application-security-add-on-for-firefox/&amp;title=Groundspeed+1.1+%E2%80%93+Web+Application+Security+Add-on+For+Firefox" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/01/groundspeed-1-1-web-application-security-add-on-for-firefox/&amp;title=Groundspeed+1.1+%E2%80%93+Web+Application+Security+Add-on+For+Firefox" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F01%2Fgroundspeed-1-1-web-application-security-add-on-for-firefox%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/01/groundspeed-1-1-web-application-security-add-on-for-firefox/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>SPIKE Proxy &#8211; Application Level Security Assessment</title>
		<link>http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/</link>
		<comments>http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/#comments</comments>
		<pubDate>Mon, 15 Jan 2007 04:57:20 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[asp-hacking]]></category>
		<category><![CDATA[burp-proxy]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[php-hacking]]></category>
		<category><![CDATA[proxies]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[spike]]></category>
		<category><![CDATA[spike-proxy]]></category>
		<category><![CDATA[web-application-hacking]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-security-testing]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/</guid>
		<description><![CDATA[SPIKE Proxy is part of the SPIKE Application Testing Suite, It functions as an HTTP and HTTPS proxy, and allows the web developer or web application auditor low level access to the entire web application interface, while also providing a bevy of automated tools and techniques for discovering common problems. These automated tools include: Automated [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>SPIKE Proxy is part of the SPIKE Application Testing Suite, It functions as an HTTP and HTTPS proxy, and allows the web developer or web application auditor low level access to the entire web application interface, while also providing a bevy of automated tools and techniques for discovering common problems. These automated tools include:</p>
<ul>
<li>Automated SQL Injection Detection</li>
<li>Web Site Crawling (guaranteed not to crawl sites other than the one being tested)</li>
<li>Login form brute forcing</li>
<li>Automated overflow detection</li>
<li>
Automated directory traversal detection</li>
</ul>
<p>Not all web applications are built in the same ways, and hence, many must be analyzed individually. SPIKE Proxy is a professional-grade tool for looking for application-level vulnerabilities in web applications. SPIKE Proxy covers the basics, such as SQL Injection and cross-site-scripting, but it&#8217;s completely open Python infrastructure allows advanced users to customize it for web applications that other tools fall apart on. SPIKE Proxy is available for Linux and Windows.</p>
<p>Note: that SPIKE Proxy requires a working install of Python and pyOpenSSL on Linux. This is included in the Windows distribution.</p>
<p>SPIKE is a fairly mature tool having been around since about 2003, we at Darknet use Spike Proxy along with the <a href="http://www.darknet.org.uk/2007/01/burp-proxy-burp-suite-attacking-web-applications/">Burp Suite</a> for web application security analysis.</p>
<p>You can download SPIKE here:</p>
<p><a href="http://www.immunitysec.com/downloads/SP148.tgz">Download for Linux</a>    |    <a href="http://www.immunitysec.com/downloads/SP148.zip">Download for Windows</a></p>
<p>Limited information can be found here:</p>
<p></p>
<p><a href="http://www.immunitysec.com/resources-freesoftware.shtml">Immunity Free Software</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D358+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;t=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;title=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;title=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;title=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/&amp;title=SPIKE+Proxy+%E2%80%93+Application+Level+Security+Assessment" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F01%2Fspike-proxy-application-level-security-assessment%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/01/spike-proxy-application-level-security-assessment/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

