<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; web-hacking-tool</title>
	<atom:link href="http://www.darknet.org.uk/tag/web-hacking-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>WebSurgery &#8211; Web Application Security Testing Suite</title>
		<link>http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/</link>
		<comments>http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 09:51:45 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[fuzzer]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[web application security testing suite]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-security-testing]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[websurgery]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3179</guid>
		<description><![CDATA[WebSurgery is a suite of tools for security testing of web applications. It was designed for security auditors to help them with the web application planning and exploitation. Currently, it uses an efficient, fast and stable Web Crawler, File/Dir Brute forcer, Fuzzer for advanced exploitation of known and unusual vulnerabilities such as SQL Injection, Cross [...]]]></description>
			<content:encoded><![CDATA[<p>WebSurgery is a suite of tools for security testing of web applications. It was designed for security auditors to help them with the web application planning and exploitation. Currently, it uses an efficient, fast and stable Web Crawler, File/Dir Brute forcer, <a href="http://www.darknet.org.uk/tag/fuzzer/">Fuzzer</a> for advanced exploitation of known and unusual vulnerabilities such as <a href="http://www.darknet.org.uk/tag/sql-injection/">SQL Injection</a>, <a href="http://www.darknet.org.uk/tag/xss/">Cross site scripting (XSS)</a>, Brute force for login forms, identification of firewall-filtered rules, DOS Attacks and WEB Proxy to analyze, intercept and manipulate the traffic between your browser and the target web application.</p>
<p><strong>WEB Crawler</strong></p>
<p>WEB Crawler was designed to be fast, accurate, stable, completely parametrable and the use of advanced techniques to extract links from Javascript and HTML Tags. It works with parametrable timing settings (Timeout, Threading, Max Data Size, Retries) and a number of rules parameters to prevent infinitive loops and pointless scanning (Case Sensitive, Dir Depth, Process Above/Below, Submit Forms, Fetch Indexes/Sitemaps, Max Requests per File/Script Parameters). It is also possible to apply custom headers (user agent, cookies etc) and Include/Exclude Filters. WEB Crawler come with an embedded File/Dir Brute Forcer which helps to directly brute force for files/dirs in the directories found from crawling.</p>
<p><strong>WEB Bruteforcer</strong></p>
<p>WEB Bruteforcer is a brute forcer for files and directories within the web application which helps to identify the hidden structure. It is also multi-threaded and completely parametrable for timing settings (Timeout, Threading, Max Data Size, Retries) and rules (Headers, Base Dir, Brute force Dirs/Files, Recursive, File’s Extension, Send GET/HEAD, Follow Redirects, Process Cookies and List generator configuration).<br />
By default, it will brute force from root / base dir recursively for both files and directories. It sends both HEAD and GET requests when it needs it (HEAD to identify if the file/dir exists and then GET to retrieve the full response).</p>
<p><strong>WEB Fuzzer</strong></p>
<p>WEB Fuzzer is a more advanced tool to create a number of requests based on one initial request. Fuzzer has no limits and can be used to exploit known vulnerabilities such (blind) SQL Inections and more unsual ways such identifing improper input handling, firewall/filtering rules, DOS Attacks.</p>
<p><strong>WEB Editor</strong></p>
<p>A simple WEB Editor to send individual requests. It also contains a HEX Editor for more advanced requests.</p>
<p><strong>WEB Proxy</strong></p>
<p>WEB Proxy is a proxy server running locally and will allow you to analyze, intercept and manipulate HTTP/HTTPS requests coming from your browser or other application which support proxies.</p>
<p>You can download WebSurgery here:</p>
<p>Setup &#8211; <a href="http://www.surgeonix.com/blog/downloads/websurgery/setup.msi">setup.msi</a><br />
Portable &#8211; <a href="http://www.surgeonix.com/blog/downloads/websurgery/websurgery.zip">websurgery.zip</a></p>
<p>Or read more <a href=" http://www.surgeonix.com/blog/index.php/archives/117">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3179+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;t=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;title=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;title=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;title=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/&amp;title=WebSurgery+%E2%80%93+Web+Application+Security+Testing+Suite" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F08%2Fwebsurgery-web-application-security-testing-suite%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/08/websurgery-web-application-security-testing-suite/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Arachni v0.3 Released &#8211; Web Application Security Scanner Framework</title>
		<link>http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/</link>
		<comments>http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/#comments</comments>
		<pubDate>Mon, 22 Aug 2011 14:04:28 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[arachni]]></category>
		<category><![CDATA[arachni scanner]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[security-scanner]]></category>
		<category><![CDATA[wavsep]]></category>
		<category><![CDATA[web application security scanner]]></category>
		<category><![CDATA[web security scanner]]></category>
		<category><![CDATA[web security scanning tool]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-security-testing]]></category>
		<category><![CDATA[web-hacking-tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3175</guid>
		<description><![CDATA[It&#8217;s been a while since we last mentioned Arachni, it was back in February &#8211; Arachni v0.2.2.1 – Web Application Security Scanner Framework. For those who are not aware, Arachni is a fully automated system which tries to enforce the fire and forget principle. As soon as a scan is started it will not bother [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while since we last mentioned <a href="http://www.darknet.org.uk/tag/arachni/">Arachni</a>, it was back in February &#8211; <a href="http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/" title="Arachni v0.2.2.1 – Web Application Security Scanner Framework">Arachni v0.2.2.1 – Web Application Security Scanner Framework</a>.</p>
<p>For those who are not aware, Arachni is a fully automated system which tries to enforce the fire and forget principle. As soon as a scan is started it will not bother you for anything nor require further user interaction. Upon completion, the scan results will be saved in a file which you can later convert to several different formats (HTML, Plain Text, XML, etc.)</p>
<p>The project was initially started as an educational exercise though it has since evolved into a powerful and modular framework allowing for fast, accurate and flexible security/vulnerability assessments..</p>
<p>More than that, Arachni is highly extend-able allowing for anyone to improve upon it by adding custom components and tailoring most aspects to meet most needs. </p>
<p>The author notified us of a major new release (v0.3) which has some great new features, a few of those being:</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>    A new custom-written, lightweight Spider</li>
<li>    Add-on support for the WebUI
<ul>
<li>  Scan scheduler</li>
<li>       AutoDeploy &#8212; Convert any SSH enabled Linux box into a Dispatcher</li>
</ul>
</li>
<li>    Improved accuracy of differential analysis audits</li>
<li>    Improved accuracy of timing attack audits</li>
<li>    Highly optimized timing attacks</li>
</ul>
<p>If you are interested in the WebUI aspect you can check out some screenshots <a href="http://arachni.segfault.gr/screenshots#v0.3">here</a>, the more comprehensive ChangeLog is also available <a href="http://arachni.segfault.gr/latest">here</a>.</p>
<p>For those of you into benchmarking and testing you might be interested to know that during a recent test Arachni was the only (from a long list of commercial and F/OSS systems) that hit 100% on both XSS and SQLi tests in the WAVSEP benchmark:</p>
<p><a href=" http://sectooladdict.blogspot.com/2011/08/commercial-web-application-scanner.html">Commercial Web Application Scanner Benchmark </a></p>
<p>The author is doing a great job with this tool and rapidly closing the gap between free security scanners and the very expensive commercial options. If you do have any feedback on Arachni v0.3 drop a comment here or hit up the <a href="http://groups.google.com/group/arachni?pli=1">Arachni Google Group</a>.</p>
<p>You can download Arachni v0.3 here:</p>
<p><a href="https://github.com/downloads/Zapotek/arachni/arachni-v0.3-cde.tar.gz">arachni-v0.3-cde.tar.gz</a></p>
<p>Or read more <a href="http://arachni.segfault.gr/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3175+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;t=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;title=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;title=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;title=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/&amp;title=Arachni+v0.3+Released+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F08%2Farachni-v3-0-released-web-application-security-scanner-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/08/arachni-v3-0-released-web-application-security-scanner-framework/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Websecurify &#8211; Integrated Web Security Testing Environment</title>
		<link>http://www.darknet.org.uk/2011/08/websecurify-integrated-web-security-testing-environment/</link>
		<comments>http://www.darknet.org.uk/2011/08/websecurify-integrated-web-security-testing-environment/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 09:41:28 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[web security testing]]></category>
		<category><![CDATA[web security testing framework]]></category>
		<category><![CDATA[web security testing tool]]></category>
		<category><![CDATA[web-application-hacking]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[web-security]]></category>
		<category><![CDATA[websecurify]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3160</guid>
		<description><![CDATA[Websecurify is an integrated web security testing environment, which can be used to identify web vulnerabilities by using advanced browser automation, discovery and fuzzing technologies. The platform is designed to perform automated as well as manual vulnerability tests and it is constantly improved and fine-tuned by a team of world class web application security penetration [...]]]></description>
			<content:encoded><![CDATA[<p>Websecurify is an integrated web security testing environment, which can be used to identify web vulnerabilities by using advanced browser automation, discovery and fuzzing technologies. The platform is designed to perform automated as well as manual vulnerability tests and it is constantly improved and fine-tuned by a team of world class web application security penetration testers and the feedback from an active open source community.</p>
<p>The penetration testing platform is the only one of its kind. Websecurify is in effect built on the top of a browser and can understand all modern web technologies including upcoming web standards and current technologies such as HTML5.</p>
<p><strong>Main Features</strong></p>
<ul>
<li>    Available for all major platforms (Windows, Mac OS, Linux)</li>
<li>    Simple to use user interface</li>
<li>    Builtin internationalization support</li>
<li>    Easily extensible with the help of add-ons and plugins</li>
<li>    Exportable and customisable reports with any level of detail</li>
<li>    Moduler and reusable design</li>
<li>    Powerful manual testing tools and helper facilities</li>
<li>    Team sharing support</li>
<li>    Powerful analytical and scanning technology</li>
<li>    Built-in service and support integration</li>
<li>    Scriptable support for JavaScript and Python</li>
<li>    Extensible via many languages including JavaScript, Python, C, C++ and Java</li>
</ul>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>Websecurify uses several key technologies combined together to achieve the best possible result when performing automatic and manual tests. At the core of the platform sits a Web Browser. This allows Websecurify to gain a fine-grained control over the targeted web application and as such detect vulnerabilities that are difficult to find with other tools.</p>
<p>The carefully engineered user interface is simple to use but powerful. All tools and platform features are integrated with each other. This allows smooth transition from one type of task to another and it also makes it easier to work with the complex flow of data, gathered during the penetration test.</p>
<p>You can download Websecurify here:</p>
<p>Windows: <a href="http://websecurify.googlecode.com/files/Websecurify%200.8.exe">Websecurify%200.8.exe</a><br />
Mac: <a href="http://websecurify.googlecode.com/files/Websecurify%200.8.dmg">Websecurify%200.8.dmg</a><br />
Linux: <a href="http://websecurify.googlecode.com/files/Websecurify%200.8.tgz">Websecurify%200.8.tgz</a></p>
<p>Or you can read more <a href="http://www.websecurify.com/overview">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Websecurify+%E2%80%93+Integrated+Web+Security+Testing+Environment+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3160+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/08/websecurify-integrated-web-security-testing-environment/&amp;t=Websecurify+%E2%80%93+Integrated+Web+Security+Testing+Environment" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/08/websecurify-integrated-web-security-testing-environment/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/08/websecurify-integrated-web-security-testing-environment/&amp;title=Websecurify+%E2%80%93+Integrated+Web+Security+Testing+Environment" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/08/websecurify-integrated-web-security-testing-environment/&amp;title=Websecurify+%E2%80%93+Integrated+Web+Security+Testing+Environment" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/08/websecurify-integrated-web-security-testing-environment/&amp;title=Websecurify+%E2%80%93+Integrated+Web+Security+Testing+Environment" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/08/websecurify-integrated-web-security-testing-environment/&amp;title=Websecurify+%E2%80%93+Integrated+Web+Security+Testing+Environment" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F08%2Fwebsecurify-integrated-web-security-testing-environment%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/08/websecurify-integrated-web-security-testing-environment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zed Attack Proxy &#8211; ZAProxy v1.3.0 Released &#8211; Integrated Penetration Testing Tool</title>
		<link>http://www.darknet.org.uk/2011/06/zed-attack-proxy-zaproxy-v1-3-0-released-integrated-penetration-testing-tool/</link>
		<comments>http://www.darknet.org.uk/2011/06/zed-attack-proxy-zaproxy-v1-3-0-released-integrated-penetration-testing-tool/#comments</comments>
		<pubDate>Mon, 20 Jun 2011 17:46:11 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[intercepting proxy]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owasp zap]]></category>
		<category><![CDATA[owasp zed attack proxy]]></category>
		<category><![CDATA[proxy-tool]]></category>
		<category><![CDATA[web application security tool]]></category>
		<category><![CDATA[web-application-scanner]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[windows proxy tool]]></category>
		<category><![CDATA[zap]]></category>
		<category><![CDATA[zaproxy]]></category>
		<category><![CDATA[zed attack proxy]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3125</guid>
		<description><![CDATA[It&#8217;s been a while since the last time we wrote about the OWASP ZAP – Zed Attack Proxy for Web Application Penetration Testing, back in October 2010. ZAP is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while since the last time we wrote about the <a href="http://www.darknet.org.uk/2010/10/owasp-zap-zed-attack-proxy-web-application-penetration-testing/">OWASP ZAP – Zed Attack Proxy for Web Application Penetration Testing</a>, back in October 2010.</p>
<p>ZAP is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing.</p>
<p>ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. </p>
<p><strong>Main Features</strong></p>
<ul>
<li>Intercepting Proxy</li>
<li>Automated scanner</li>
<li>Passive scanner</li>
<li>Brute Force scanner</li>
<li>Spider</li>
<li>Fuzzer</li>
<li>Port scanner</li>
<li>Dynamic SSL certificates</li>
<li>API</li>
<li>Beanshell integration </li>
</ul>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p><strong>What&#8217;s New?</strong></p>
<p>A new version has been released, v1.3.0, the release adds the following main features:</p>
<ul>
<li>Fuzzing, using the JBroFuzz library</li>
<li>Dynamic SSL Certificates</li>
<li>Daemon mode and API</li>
<li>BeanShell integration</li>
<li>Full internationalization</li>
<li>Out of the box support for 10 languages</li>
</ul>
<p>You can download ZAP v1.3.0 here:</p>
<p>Windows Installer &#8211; <a href="http://zaproxy.googlecode.com/files/ZAP_1.3.0_Windows.exe">ZAP_1.3.0_Windows.exe</a><br />
Linux Installer &#8211; <a href="http://zaproxy.googlecode.com/files/ZAP_1.3.0_Linux.tar.gz">ZAP_1.3.0_Linux.tar.gz</a><br />
Mac OSX Installer &#8211; <a href="http://zaproxy.googlecode.com/files/ZAP_1.3.0_Mac_OS_X.zip">ZAP_1.3.0_Mac_OS_X.zip</a></p>
<p>Or read more <a href="http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Zed+Attack+Proxy+%E2%80%93+ZAProxy+v1.3.0+Released+%E2%80%93+Integrated+Penetration+Testing+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3125+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/06/zed-attack-proxy-zaproxy-v1-3-0-released-integrated-penetration-testing-tool/&amp;t=Zed+Attack+Proxy+%E2%80%93+ZAProxy+v1.3.0+Released+%E2%80%93+Integrated+Penetration+Testing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/06/zed-attack-proxy-zaproxy-v1-3-0-released-integrated-penetration-testing-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/06/zed-attack-proxy-zaproxy-v1-3-0-released-integrated-penetration-testing-tool/&amp;title=Zed+Attack+Proxy+%E2%80%93+ZAProxy+v1.3.0+Released+%E2%80%93+Integrated+Penetration+Testing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/06/zed-attack-proxy-zaproxy-v1-3-0-released-integrated-penetration-testing-tool/&amp;title=Zed+Attack+Proxy+%E2%80%93+ZAProxy+v1.3.0+Released+%E2%80%93+Integrated+Penetration+Testing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/06/zed-attack-proxy-zaproxy-v1-3-0-released-integrated-penetration-testing-tool/&amp;title=Zed+Attack+Proxy+%E2%80%93+ZAProxy+v1.3.0+Released+%E2%80%93+Integrated+Penetration+Testing+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/06/zed-attack-proxy-zaproxy-v1-3-0-released-integrated-penetration-testing-tool/&amp;title=Zed+Attack+Proxy+%E2%80%93+ZAProxy+v1.3.0+Released+%E2%80%93+Integrated+Penetration+Testing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F06%2Fzed-attack-proxy-zaproxy-v1-3-0-released-integrated-penetration-testing-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/06/zed-attack-proxy-zaproxy-v1-3-0-released-integrated-penetration-testing-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Skipfish 1.94b Released &#8211; Active Web Application Security Reconnaissance Tool</title>
		<link>http://www.darknet.org.uk/2011/06/skipfish-1-94b-released-active-web-application-security-reconnaissance-tool/</link>
		<comments>http://www.darknet.org.uk/2011/06/skipfish-1-94b-released-active-web-application-security-reconnaissance-tool/#comments</comments>
		<pubDate>Wed, 15 Jun 2011 08:54:47 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[google code]]></category>
		<category><![CDATA[google skipfish]]></category>
		<category><![CDATA[google tools]]></category>
		<category><![CDATA[skipfish]]></category>
		<category><![CDATA[web application security scanner]]></category>
		<category><![CDATA[web application security tool]]></category>
		<category><![CDATA[web reconnaissance tool]]></category>
		<category><![CDATA[web scanning tool]]></category>
		<category><![CDATA[web security scanning tool]]></category>
		<category><![CDATA[web security tools]]></category>
		<category><![CDATA[web-application-hacking]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[web-security]]></category>
		<category><![CDATA[web-security-tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3129</guid>
		<description><![CDATA[It&#8217;s been a while since we last mentioned Skipfish, it was back in March 2010 when they first came out. Skipfish is an active web application security reconnaissance tool. It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated with the [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while since we last mentioned Skipfish, <a href="http://www.darknet.org.uk/2010/03/skipfish-automated-web-application-security-reconnaissance-tool/">it was back in March 2010</a> when they first came out.</p>
<p>Skipfish is an active web application security reconnaissance tool. It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated with the output from a number of active (but hopefully non-disruptive) security checks. The final report generated by the tool is meant to serve as a foundation for professional web application security assessments.</p>
<p>A number of commercial and open source tools with analogous functionality is readily available (e.g., <a href="http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/">Nikto</a>, <a href="http://www.darknet.org.uk/2009/09/websecurify-web-security-testing-framework/">Websecurify</a>, <a href="http://www.darknet.org.uk/2010/04/netsparker-community-edition-web-application-security-scanner/">Netsparker</a>, <a href="http://www.darknet.org.uk/2010/06/w3af-1-0-rc3-available-for-download-web-application-attack-audit-framework/">w3af</a>, <a href="http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/">Arachni</a>); stick to the one that suits you best. That said, skipfish tries to address some of the common problems associated with web security scanners.</p>
<p>Specific advantages include: </p>
<ul>
<li>    <strong>High speed:</strong> pure C code, highly optimized HTTP handling, minimal CPU footprint &#8211; easily achieving 2000 requests per second with responsive targets. </li>
<li>    <strong>Ease of use:</strong> heuristics to support a variety of quirky web frameworks and mixed-technology sites, with automatic learning capabilities, on-the-fly wordlist creation, and form autocompletion. </li>
<li>    <strong>Cutting-edge security logic:</strong> high quality, low false positive, differential security checks, capable of spotting a range of subtle flaws, including blind injection vectors. </li>
</ul>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>Some users had a problem getting it running, it does have a dependency &#8211; assuming you are on a Debian based distro, all you need to do is:</p>
<pre><code>apt-get install libidn11</code></pre>
<p>The minum syntax required to run the tool would be:</p>
<pre><code>./skipfish -o /home/youruser -W dictionaries/standard.wl http://yoursite.com</code></pre>
<p>That should be enough to get you started!</p>
<p>It&#8217;s a pretty powerful tool and likely to pick up issues that <a href="http://www.darknet.org.uk/2008/08/openvas-open-vulnerability-assessment-system-nessus-is-back/">Nessus</a> or <a href="http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/">Nikto</a> might miss.</p>
<p>You can download Skipfish 1.94b here:</p>
<p><a href="http://skipfish.googlecode.com/files/skipfish-1.94b.tgz">skipfish-1.94b.tgz</a></p>
<p>Or read more <a href="http://code.google.com/p/skipfish/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Skipfish+1.94b+Released+%E2%80%93+Active+Web+Application+Security+Reconnaissance+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3129+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/06/skipfish-1-94b-released-active-web-application-security-reconnaissance-tool/&amp;t=Skipfish+1.94b+Released+%E2%80%93+Active+Web+Application+Security+Reconnaissance+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/06/skipfish-1-94b-released-active-web-application-security-reconnaissance-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/06/skipfish-1-94b-released-active-web-application-security-reconnaissance-tool/&amp;title=Skipfish+1.94b+Released+%E2%80%93+Active+Web+Application+Security+Reconnaissance+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/06/skipfish-1-94b-released-active-web-application-security-reconnaissance-tool/&amp;title=Skipfish+1.94b+Released+%E2%80%93+Active+Web+Application+Security+Reconnaissance+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/06/skipfish-1-94b-released-active-web-application-security-reconnaissance-tool/&amp;title=Skipfish+1.94b+Released+%E2%80%93+Active+Web+Application+Security+Reconnaissance+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/06/skipfish-1-94b-released-active-web-application-security-reconnaissance-tool/&amp;title=Skipfish+1.94b+Released+%E2%80%93+Active+Web+Application+Security+Reconnaissance+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F06%2Fskipfish-1-94b-released-active-web-application-security-reconnaissance-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/06/skipfish-1-94b-released-active-web-application-security-reconnaissance-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Burp Suite Free Edition v1.4 &#8211; Web Application Security Testing Tool</title>
		<link>http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/</link>
		<comments>http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/#comments</comments>
		<pubDate>Wed, 08 Jun 2011 11:00:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[burp]]></category>
		<category><![CDATA[burp suite download]]></category>
		<category><![CDATA[burp suite free edition]]></category>
		<category><![CDATA[burp v1.4]]></category>
		<category><![CDATA[burp-proxy]]></category>
		<category><![CDATA[burp-suite]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-security-testing]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3127</guid>
		<description><![CDATA[We love Burp Suite and we have since wayyyy back, the last update we posted was around 18 months ago back in January 2010 &#8211; Burp Suite v1.3 Released – Integrated Platform For Attacking Web Applications. For the two people here who don&#8217;t know what this tool does, Burp Suite is an integrated platform for [...]]]></description>
			<content:encoded><![CDATA[<p>We love <a href="http://www.darknet.org.uk/tag/burp-suite/">Burp Suite</a> and we have since wayyyy back, the last update we posted was around 18 months ago back in January 2010 &#8211; <a href="http://www.darknet.org.uk/2010/01/burp-suite-v1-3-released-integrated-platform-for-attacking-web-applications/">Burp Suite v1.3 Released – Integrated Platform For Attacking Web Applications</a>.</p>
<p>For the two people here who don&#8217;t know what this tool does, Burp Suite is an integrated platform for performing security testing of web applications. Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application&#8217;s attack surface, through to finding and exploiting security vulnerabilities.</p>
<p>Burp gives you full control, letting you combine advanced manual techniques with state-of-the-art automation, to make your work faster, more effective, and more fun.</p>
<p>And now, we&#8217;re happy to announce there&#8217;s a new version out and it&#8217;s available for download now!</p>
<p><strong>New Features</strong></p>
<ul>
<li>The ability to compare site maps</li>
<li>Functions to help with testing access controls using your browser</li>
<li>Support for preset request macros</li>
<li>Session handling rules to help you work with difficult situations</li>
<li>In-browser rendering of responses from all Burp tools</li>
<li>Auto recognition and rendering of character sets</li>
<li>Support for upstream SOCKS proxies</li>
<li>Headless mode for unattended scripted usage</li>
<li>Support for more types of redirection</li>
<li>Support for NTLMv2 and IPv6</li>
<li>Numerous enhancements to Burp&#8217;s extensibility</li>
<li>Greater stability on OSX</li>
</ul>
<p>You can download Burp Suite Free Edition v1.4 here:</p>
<p><a href="http://portswigger.net/burp/burpsuite_v1.4.zip">burpsuite_v1.4.zip</a></p>
<p>Or read more <a href="http://portswigger.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3127+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;t=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F06%2Fburp-suite-free-edition-v1-4-web-application-security-testing-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CAT &#8211; Web Application Security Test &amp; Assessment Tool</title>
		<link>http://www.darknet.org.uk/2011/03/cat-web-application-security-test-assessment-tool/</link>
		<comments>http://www.darknet.org.uk/2011/03/cat-web-application-security-test-assessment-tool/#comments</comments>
		<pubDate>Thu, 24 Mar 2011 09:05:18 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[application test tool]]></category>
		<category><![CDATA[application testing]]></category>
		<category><![CDATA[cat]]></category>
		<category><![CDATA[context]]></category>
		<category><![CDATA[context application test tool]]></category>
		<category><![CDATA[fuzzer]]></category>
		<category><![CDATA[fuzzing]]></category>
		<category><![CDATA[local proxy tool]]></category>
		<category><![CDATA[security testing tool]]></category>
		<category><![CDATA[web application security tool]]></category>
		<category><![CDATA[web proxy tool]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[web-proxy]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3075</guid>
		<description><![CDATA[CAT is designed to facilitate manual web application penetration testing for more complex, demanding application testing tasks. It removes some of the more repetitive elements of the testing process, allowing the tester to focus on individual applications, thus enabling them to conduct a much more thorough test. Conceptually it is similar to other proxies available [...]]]></description>
			<content:encoded><![CDATA[<p>CAT is designed to facilitate manual web application penetration testing for more complex, demanding application testing tasks. It removes some of the more repetitive elements of the testing process, allowing the tester to focus on individual applications, thus enabling them to conduct a much more thorough test. Conceptually it is similar to other proxies available both commercially and open source, but CAT provides a richer feature set and greater performance, combined with a more intuitive user interface.</p>
<p>There are a number of differences between CAT and currently available web proxies. They include:</p>
<ul>
<li>CAT uses Internet Explorer&#8217;s rendering engine for accurate HTML representation</li>
<li> It supports many different types of text conversions including: URL, Base64, Hex, Unicode, HTML/XML, SQL and JavaScript no quotes</li>
<li>  It offers integrated SQL Injection and XSS Detection</li>
<li> Synchronised Proxies for Authentication and Authorisation checking</li>
<li> Faster performance due to HTTP connection caching</li>
<li> SSL Version and Cipher checker using OpenSSL</li>
<li> Greater flexibility for importing/exporting logs and saving projects</li>
<li> Tabbed Interface allows for multiple tools at once e.g. multiple repeaters &#038; different logs</li>
<li>The ability to repeat and modify a sequence of requests (particularly useful in SSO testing)</li>
<li>    It’s free!</li>
</ul>
<p>Do bear in mind that this is a free tool, but it is NOT Open Source. Also take a good look at the EULA before using it (especially Section 6).</p>
<p>You can download CAT Beta 4 here:</p>
<p><a href="http://cat.contextis.co.uk/cat/CAT_Beta_4.msi">CAT_Beta_4.msi</a></p>
<p>Or read more <a href="http://www.contextis.co.uk/resources/tools/cat/">here</a>. (<em>Thanks to reader Simon for the heads-up on this.</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=CAT+%E2%80%93+Web+Application+Security+Test+%26+Assessment+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3075+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/03/cat-web-application-security-test-assessment-tool/&amp;t=CAT+%E2%80%93+Web+Application+Security+Test+%26+Assessment+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/03/cat-web-application-security-test-assessment-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/03/cat-web-application-security-test-assessment-tool/&amp;title=CAT+%E2%80%93+Web+Application+Security+Test+%26+Assessment+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/03/cat-web-application-security-test-assessment-tool/&amp;title=CAT+%E2%80%93+Web+Application+Security+Test+%26+Assessment+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/03/cat-web-application-security-test-assessment-tool/&amp;title=CAT+%E2%80%93+Web+Application+Security+Test+%26+Assessment+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/03/cat-web-application-security-test-assessment-tool/&amp;title=CAT+%E2%80%93+Web+Application+Security+Test+%26+Assessment+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F03%2Fcat-web-application-security-test-assessment-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/03/cat-web-application-security-test-assessment-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Arachni v0.2.2.1 &#8211; Web Application Security Scanner Framework</title>
		<link>http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/</link>
		<comments>http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/#comments</comments>
		<pubDate>Thu, 17 Feb 2011 10:33:45 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[arachni]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[hacking-web-applications]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[security-scanner]]></category>
		<category><![CDATA[web app security]]></category>
		<category><![CDATA[web application security scanner]]></category>
		<category><![CDATA[web security scanner]]></category>
		<category><![CDATA[web-application-hacking]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3001</guid>
		<description><![CDATA[Arachni is a feature-full, modular, high-performance Ruby framework aimed towards helping penetration testers and administrators evaluate the security of web applications. Arachni is smart, it trains itself by learning from the HTTP responses it receives during the audit process. Unlike other scanners, Arachni takes into account the dynamic nature of web applications and can detect [...]]]></description>
			<content:encoded><![CDATA[<p>Arachni is a feature-full, modular, high-performance Ruby framework aimed towards helping penetration testers and administrators evaluate the security of web applications.</p>
<p>Arachni is smart, it trains itself by learning from the HTTP responses it receives during the audit process. Unlike other scanners, Arachni takes into account the dynamic nature of web applications and can detect changes caused while traveling through the paths of a web application&#8217;s cyclomatic complexity. This way attack/input vectors that would otherwise be undetectable by non-humans are seamlessly handled by Arachni.</p>
<p>Finally, Arachni yields great performance due to its asynchronous HTTP model (courtesy of Typhoeus). Thus, you&#8217;ll only be limited by the responsiveness of the server under audit and your available bandwidth.</p>
<p><strong>Note:</strong> Despite the fact that Arachni is mostly targeted towards web application security, it can easily be used for general purpose scraping, data-mining, etc with the addition of custom modules.</p>
<p>Module, report and plugin writers are allowed to easily and quickly create and deploy their components with the minimum amount of restrictions imposed upon them, while provided with the necessary infrastructure to accomplish their goals. Furthermore, they are encouraged to take full advantage of the Ruby language under a unified framework that will increase their productivity without stifling them or complicating their tasks.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>Although some parts of the Framework are fairly complex you will never have to deal them directly. From a user&#8217;s or a component developer&#8217;s point of view everything appears simple and straight-forward all the while providing power, performance and flexibility.</p>
<p>There is a new version of Arachni which features numerous optimizations, new modules, new plug-ins and a brand new, although experimental, Web user interface (adding support for distributed deployment, parallel scans and basic report management).</p>
<p>The changelog for this version is extremely long and you can view the full list of changes on the authors blog here &#8211; <a href="http://trainofthought.segfault.gr/2011/02/13/arachni-v0-2-2-1-is-out/">Arachni v0.2.2.1 is out!</a>. You can also view the <a href="http://zapotek.github.com/arachni/file.CHANGELOG.html">release changelog here</a>.</p>
<p>All available installation options and usage instructions can be found in the homepage and the GitHub page.</p>
<p>You can watch a screencast of the new WebUI here:</p>
<p align="center"><iframe src="http://player.vimeo.com/video/19928281?color=ff9933" width="500" height="275" frameborder="0"></iframe></p>
<p>With the new release, there is also the new Arachni Google Group, if you’re hacking or using Arachni and have a related questions you can contact the author and the community <a href="http://groups.google.com/group/arachni">here</a>.</p>
<p>You can download Arachni v0.2.2.1 here:</p>
<p><a href="https://github.com/Zapotek/arachni/zipball/v0.2.2.1">Zapotek-arachni-v0.2.2.1.zip</a></p>
<p>Or read more <a href="https://github.com/Zapotek/arachni/#readme">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Arachni+v0.2.2.1+%E2%80%93+Web+Application+Security+Scanner+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3001+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/&amp;t=Arachni+v0.2.2.1+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/&amp;title=Arachni+v0.2.2.1+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/&amp;title=Arachni+v0.2.2.1+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/&amp;title=Arachni+v0.2.2.1+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/&amp;title=Arachni+v0.2.2.1+%E2%80%93+Web+Application+Security+Scanner+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F02%2Farachni-v0-2-2-1-web-application-security-scanner-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/02/arachni-v0-2-2-1-web-application-security-scanner-framework/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>WATOBO &#8211; The Web Application Toolbox</title>
		<link>http://www.darknet.org.uk/2010/11/watobo-the-web-application-toolbox/</link>
		<comments>http://www.darknet.org.uk/2010/11/watobo-the-web-application-toolbox/#comments</comments>
		<pubDate>Mon, 01 Nov 2010 10:36:00 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[hacking web apps]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[watabo]]></category>
		<category><![CDATA[web app security]]></category>
		<category><![CDATA[web application audit]]></category>
		<category><![CDATA[web application toolbox]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2980</guid>
		<description><![CDATA[WATOBO is intended to enable security professionals to perform highly efficient (semi-automated ) web application security audits. We are convinced that the semi-automated approach is the best way to perform an accurate audit and to identify most of the vulnerabilities. WATOBO has no attack capabilities and is provided for legal vulnerability audit purposes only. How [...]]]></description>
			<content:encoded><![CDATA[<p>WATOBO is intended to enable security professionals to perform highly efficient (semi-automated ) web application security audits. We are convinced that the semi-automated approach is the best way to perform an accurate audit and to identify most of the vulnerabilities. WATOBO has no attack capabilities and is provided for legal vulnerability audit purposes only. </p>
<p><strong>How Does It Work?</strong></p>
<p>WATOBO works like a local proxy, similar to <a href="http://www.darknet.org.uk/2006/07/webscarab-web-application-analysis-new-version/">Webscarab</a>, <a href="http://www.darknet.org.uk/2006/05/paros-proxy-3212-released-mitm-http-and-https-proxy/">Paros</a> or <a href="http://www.darknet.org.uk/2010/01/burp-suite-v1-3-released-integrated-platform-for-attacking-web-applications/">BurpSuite</a>.</p>
<p>Additionally, WATOBO supports passive and active checks. Passive checks are more like filter functions. They are used to collect useful information, e.g. email or IP addresses. Passive checks will be performed during normal browsing activities. No additional requests are sent to the (web) application.</p>
<p>Active checks instead will produce a high number of requests (depending on the check module) because they do the automatic part of vulnerability identification, e.g. during a scan.</p>
<p><strong>WATOBO Advantages</strong></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>Session Management capabilities! You can define login scripts as well as logout signatures. So you don’t have to login manually each time you get logged out.</li>
<li>Can perform vulnerability checks out of the box.</li>
<li>Supports Inline De-/Encoding, so you don’t have to copy strings to a transcoder and back again. Just do it inside the request/response window with a simple mouse click.</li>
<li>Smart filter functions, so you can find and navigate to the most interesting parts of the application easily.</li>
<li>Written in (FX)Ruby and enables you to define your own checks</li>
<li>Free software ( licensed under the GNU General Public License Version 2) </li>
</ul>
<p>There is an &#8216;unofficial&#8217; manual here:</p>
<p><a href="http://www.corelan.be:8800/index.php/2010/07/23/watobo-the-unofficial-manual/">WATOBO – the unofficial manual</a></p>
<p>And some video tutorials to get you started <a href="http://sourceforge.net/apps/mediawiki/watobo/index.php?title=Videos">here</a>.</p>
<p>You can download WATOBO 0.9.5 here:</p>
<p><a href="http://sourceforge.net/projects/watobo/files/watobo_0.9.5rev226.zip/download">watobo_0.9.5rev226.zip</a></p>
<p>Or read more <a href="http://sourceforge.net/apps/mediawiki/watobo/index.php?title=Main_Page">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=WATOBO+%E2%80%93+The+Web+Application+Toolbox+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2980+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/11/watobo-the-web-application-toolbox/&amp;t=WATOBO+%E2%80%93+The+Web+Application+Toolbox" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/11/watobo-the-web-application-toolbox/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/11/watobo-the-web-application-toolbox/&amp;title=WATOBO+%E2%80%93+The+Web+Application+Toolbox" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/11/watobo-the-web-application-toolbox/&amp;title=WATOBO+%E2%80%93+The+Web+Application+Toolbox" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/11/watobo-the-web-application-toolbox/&amp;title=WATOBO+%E2%80%93+The+Web+Application+Toolbox" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/11/watobo-the-web-application-toolbox/&amp;title=WATOBO+%E2%80%93+The+Web+Application+Toolbox" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F11%2Fwatobo-the-web-application-toolbox%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/11/watobo-the-web-application-toolbox/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP ZAP &#8211; Zed Attack Proxy &#8211; Web Application Penetration Testing</title>
		<link>http://www.darknet.org.uk/2010/10/owasp-zap-zed-attack-proxy-web-application-penetration-testing/</link>
		<comments>http://www.darknet.org.uk/2010/10/owasp-zap-zed-attack-proxy-web-application-penetration-testing/#comments</comments>
		<pubDate>Thu, 07 Oct 2010 08:51:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owasp proxy]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[web application hacking tool]]></category>
		<category><![CDATA[web application penetration testing]]></category>
		<category><![CDATA[web-application-hacking]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[zap. zed attack proxy]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2963</guid>
		<description><![CDATA[The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who a new to penetration testing. ZAP provides automated scanners [...]]]></description>
			<content:encoded><![CDATA[<p>The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who a new to penetration testing. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.</p>
<p><strong>Features</strong></p>
<ul>
<li>Intercepting proxy</li>
<li>
Automated scanner</li>
<li>
Passive scanner</li>
<li>
Spider </li>
</ul>
<p><strong>Next Release</strong></p>
<p>The next release of <a href="http://www.darknet.org.uk/tag/owasp/">OWASP</a> ZAP, planned for later this year, is expected to include:</p>
<ul>
<li>
OWASP rebranding</li>
<li>Improvements to the passive and active automated scanners</li>
<li>Improvements the Spider</li>
<li>The addition a basic port scanner</li>
<li>The ability to brute force files and directories (using components from <a href="http://www.darknet.org.uk/2011/11/dirbuster-brute-force-directories-files-names/">DirBuster</a>)</li>
</ul>
<p>ZAP is actually a fork from <a href="http://www.darknet.org.uk/tag/paros-proxy/">Paros Proxy</a>.</p>
<p>You can download ZAP v1.0 here:</p>
<p>Cross Platform &#8211; <a href="http://code.google.com/p/zaproxy/downloads/detail?name=ZAP_1.0.0b_installation.tar.gz">ZAP_1.0.0b_installation.tar.gz</a><br />
Windows Installer &#8211; <a href="http://code.google.com/p/zaproxy/downloads/detail?name=ZAP_1.0.0_installer.exe">ZAP_1.0.0_installer.exe</a></p>
<p>Or read more <a href="http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=OWASP+ZAP+%E2%80%93+Zed+Attack+Proxy+%E2%80%93+Web+Application+Penetration+Testing+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2963+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/10/owasp-zap-zed-attack-proxy-web-application-penetration-testing/&amp;t=OWASP+ZAP+%E2%80%93+Zed+Attack+Proxy+%E2%80%93+Web+Application+Penetration+Testing" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/10/owasp-zap-zed-attack-proxy-web-application-penetration-testing/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/10/owasp-zap-zed-attack-proxy-web-application-penetration-testing/&amp;title=OWASP+ZAP+%E2%80%93+Zed+Attack+Proxy+%E2%80%93+Web+Application+Penetration+Testing" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/10/owasp-zap-zed-attack-proxy-web-application-penetration-testing/&amp;title=OWASP+ZAP+%E2%80%93+Zed+Attack+Proxy+%E2%80%93+Web+Application+Penetration+Testing" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/10/owasp-zap-zed-attack-proxy-web-application-penetration-testing/&amp;title=OWASP+ZAP+%E2%80%93+Zed+Attack+Proxy+%E2%80%93+Web+Application+Penetration+Testing" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/10/owasp-zap-zed-attack-proxy-web-application-penetration-testing/&amp;title=OWASP+ZAP+%E2%80%93+Zed+Attack+Proxy+%E2%80%93+Web+Application+Penetration+Testing" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F10%2Fowasp-zap-zed-attack-proxy-web-application-penetration-testing%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/10/owasp-zap-zed-attack-proxy-web-application-penetration-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

