plan for the worst
Showing 1 - 25 of 196 RSS Feed

Files

Dradis Information Sharing Tool 2.9.0
Posted Feb 3, 2012
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

Changes: This release added a Retina Network Security Scanner upload plugin and a Zed Attack Proxy upload plugin. The Nessus, Nikto, and Nmap upload plugins are now orders of magnitude faster. A VulnDB import plugin was added to support VulnDB HQ integration. The First Time User's Wizard was updated. Rails was upgraded to version 3.2.
tags | tool, web
systems | unix
MD5 | e8fe9b4cd524c1549a109ff5e66d828a
OWASP Mantra Armada 0.81 Beta
Posted Dec 31, 2011
Site getmantra.com

OWASP Mantra is a collection of free and open source tools integrated into a web browser, which can become handy for students, penetration testers, web application developers,security professionals etc. It is portable, ready-to-run, compact and follows the true spirit of free and open source software. This is the platform independent release.

Changes: New add-ons have been added. The base itself has been upgraded. Galley integration has been added along with a better look and feel.
tags | tool, web
MD5 | af9a3b960b56a94a7c6227d62d674bea
Pound Reverse HTTP Proxy 2.6
Posted Dec 29, 2011
Authored by roseg | Site apsis.ch

Pound is a reverse HTTP proxy, load balancer, and SSL wrapper. It proxies client HTTPS requests to HTTP backend servers, distributes the requests among several servers while keeping sessions, supports HTTP/1.1 requests even if the backend server(s) are HTTP/1.0, and sanitizes requests.

Changes: Support for SNI via multiple Cert directives. A pre-defined number of threads for better performance on small hardware. Translation of hexadecimal characters in the URL for pattern matching. Support for a "Disabled" directive in the configuration. More detailed error logging. Allows multiple AddHeader directives.
tags | tool, web
systems | linux
MD5 | 8c913b527332694943c4c67c8f152071
WordPress AES-Edition 0.0.2
Posted Nov 25, 2011
Authored by Skraps | Site code.google.com

WordPress AES-Edition is a modified version of WordPress that implements use of AES.

tags | web
MD5 | b3fd765d90474e7082ce47c257e96ee1
w3af Web Application Attack and Audit Framework 1.1
Posted Nov 10, 2011
Authored by Andres Riancho | Site w3af.sourceforge.net

w3af, is a Web Application Attack and Audit Framework. The w3af core and it's plugins are fully written in python. The project has more than 130 plugins, which check for SQL injection, cross site scripting (xss), local and remote file inclusion and much more.

Changes: Increased performance using gzip encoding, hundreds of bugs fixed, enhanced embedded bug report system added and more.
tags | tool, remote, web, local, xss, sql injection, python, file inclusion
MD5 | b67ba4ac19a5bcd7dc1e43cdf59c5688
OWASP Mantra c0c0n 11 / AppSecLatam 11 0.71 Beta
Posted Oct 27, 2011
Site getmantra.com

OWASP Mantra is a collection of free and open source tools integrated into a web browser, which can become handy for students, penetration testers, web application developers,security professionals etc. It is portable, ready-to-run, compact and follows the true spirit of free and open source software. This is the platform independent release.

tags | tool, web
MD5 | 6fdb5e9408261d741f24cb83df4b4066
Dradis Information Sharing Tool 2.8.0
Posted Oct 11, 2011
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

Changes: This release has a cleaner three-column layout, smarter AJAX polling and auto-updating, a new version of the Nmap upload plugin, and a new version of the Nessus upload plugin. ./verify.sh now checks that libxml2 is installed.
tags | tool, web
systems | unix
MD5 | b3025a81b505f1a773031a940911d749
Zed Attack Proxy (ZAP) 1.3.2
Posted Sep 28, 2011
Authored by Psiinon | Site owasp.org

The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. Mac OS X, Windows and Linux releases are all included in this file.

Changes: Various updates and enhancements.
tags | web, vulnerability
systems | linux, windows, apple, osx
MD5 | 0a4595ead06485cac1af873adc88930b
Lanuguage Pack For ZAP 1.3.2
Posted Sep 27, 2011
Authored by Psiinon | Site owasp.org

This is the language pack for Zed Attack Proxy (ZAP). Languages supported include English, Brazilian Portuguese, Chinese, Danish, French, German, Greek, Indonesian, Japanese, Polish, and Spanish.

tags | web
MD5 | c576bd54403eb0735c29828257752df5
Zed Attack Proxy (ZAP) Client API 0.1 Alpha
Posted Sep 27, 2011
Authored by Psiinon | Site owasp.org

This is the client API for the Zed Attack Proxy (ZAP).

tags | web
MD5 | 8d976d2ea09ea7bc8fcceba3450361e3
URLCrazy Domain Name Typo Tool 0.4
Posted Sep 15, 2011
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

URLCrazy enables the study of domainname typos and URL hijacking. URLCrazy is a domainname typo generator that generates 13 types of typos, knows over 8000 common misspellings, supports multiple keyboard layouts, can check if a typo is a valid domain, tests if domain typos are in use, and estimates the popularity of a typo.

Changes: It now also supports bit flipped domains. Urlcrazy is written in Ruby.
tags | tool, web
systems | unix
MD5 | 3393672839100e9ba0d1c3ee6f039cf0
w3af Web Application Attack and Audit Framework 1.0
Posted May 25, 2011
Authored by Andres Riancho | Site w3af.sourceforge.net

w3af, is a Web Application Attack and Audit Framework. The w3af core and it's plugins are fully written in python. The project has more than 130 plugins, which check for SQL injection, cross site scripting (xss), local and remote file inclusion and much more.

Changes: Code base has been stabilized. Additions include an auto-update feature, web application payloads, PHP static code analyzer, and more.
tags | remote, web, local, xss, sql injection, python, file inclusion
MD5 | 4ac1fb2cfcbbefb8c0caa813dd822723
Dradis Information Sharing Tool 2.7.0
Posted Apr 20, 2011
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

Changes: This release has an improved command line API with Thor. A new Configuration Manager to handle all plugin config settings. A new Upload Manager that runs uploads in the background and updates the interface through AJAX. New plugins: Metasploit import; NeXpose (.xml) upload; OpenVAS (.xml) upload; SureCheck (.sc) upload; w3af (.xml) upload; and Web Exploitation Framework (wXf) upload. The Nessus plugin supports .nessus v2. Vuln::DB import has been updated to support the latest release. Bugs fixed: #2888332 and #2973256. Rails has been updated to 3.0.6.
tags | web
systems | unix
MD5 | 32b028f69797fac4ce197eb773ac02d9
w3af Web Application Attack and Audit Framework 1.0 RC5
Posted Jan 19, 2011
Authored by Andres Riancho | Site w3af.sourceforge.net

w3af, is a Web Application Attack and Audit Framework. The w3af core and it's plugins are fully written in python. The project has more than 130 plugins, which check for SQL injection, cross site scripting (xss), local and remote file inclusion and much more.

Changes: Improvements include new vulnerability checks, more stable code and an approximate 15% performance boost in the overall speed of your scan.
tags | tool, remote, web, local, xss, sql injection, python, file inclusion
MD5 | a5c30f4643150b6586a94b38f33d7f2a
Zed Attack Proxy (ZAP) 1.1.0
Posted Dec 6, 2010
Authored by Psiinon | Site owasp.org

The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. Mac OS X, Windows and Cross Platform releases are all included in this file.

Changes: OWASP rebranding, Brute Force scanner c/o the OWASP DirBuster project, Port scanner, Active scan tab, and more.
tags | web, vulnerability
systems | linux, windows, apple, osx
MD5 | 2715972dc19561924d64d7a30cc3e544
w3af Web Application Attack and Audit Framework 1.0 RC4
Posted Nov 3, 2010
Authored by Andres Riancho | Site w3af.sourceforge.net

w3af, is a Web Application Attack and Audit Framework. The w3af core and it's plugins are fully written in python. The project has more than 130 plugins, which check for SQL injection, cross site scripting (xss), local and remote file inclusion and much more.

Changes: Improvements of the GUI and more.
tags | remote, web, local, xss, sql injection, python, file inclusion
MD5 | 105504ceba3554ee45c1c9bab1c9709c
Zed Attack Proxy (ZAP) 1.0.0
Posted Oct 5, 2010
Authored by Psiinon | Site owasp.org

The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. Mac OS X, Windows and Cross Platform releases are all included in this file.

tags | web, vulnerability
systems | windows, apple, osx
MD5 | 078f1884cb2f0b456c6f295ecd4dbcae
iExploder 1.7.2
Posted Sep 21, 2010
Authored by Thomas Stromberg | Site code.google.com

iExploder is like a fire hydrant full of bad HTML and CSS code to test the stability and security of web browsers. Available as a standalone webserver or CGI script, it continuously feeds browsers bad data in the hope that they will eventually crash. It is designed to run for hours, or even days until the browser crashes. namebench was initially written as a QA tool for the Mozilla Project to test the Firefox 1.0 release, and is now included and used by Apple's Webkit project.

Changes: This release adds a second redirect for confirming crash conditions in order to duplicate page transition crashes. It fixes a bug that broke subtest isolation when running tests in random order.
tags | web, cgi
systems | apple
MD5 | 59d392f6d376119c017195ce8fb447a5
iExploder 1.7
Posted Sep 8, 2010
Authored by Thomas Stromberg | Site code.google.com

iExploder is like a fire hydrant full of bad HTML and CSS code to test the stability and security of web browsers. Available as a standalone webserver or CGI script, it continuously feeds browsers bad data in the hope that they will eventually crash. It is designed to run for hours, or even days until the browser crashes. namebench was initially written as a QA tool for the Mozilla Project to test the Firefox 1.0 release, and is now included and used by Apple's Webkit project.

Changes: A new browser-harness mode was added to stop and start browsers, replicate crash scenarios, and save minimized testcases. CSS selector fuzzing and support for Ruby 1.9.x were added. The tag dictionary was updated from Webkit and Mozilla source trees.
tags | web, cgi
systems | apple
MD5 | 5c53e50c2c085e605d1fd4086de39612
RewriteProxy Same-Domain Policy Bypass
Posted Jul 26, 2010
Authored by Noen | Site noen.svartboks.com

RewriteProxy is a small python tool that is based on the twisted library. Its purpose is to serve local files instead of remote files to fool the same-domain policy of modified flash and java-applets.

tags | java, remote, web, local, python
MD5 | a08c950a24eed7173d10eedf262b18f9
Apache mod_psldap Module 0.93
Posted Apr 21, 2010
Site sourceforge.net

mod_psldap is an Apache module that performs authentication and authorization against an LDAP server with LDAP based session management. It also provides Web 2.0 based capabilities to add, edit, move, and create new records in the LDAP store, leveraging XSL stylesheets to offload heavy processing to the clients and reduce bandwidth consumption by up to 95% or more.

Changes: This release provides new core capabilities to support new actions to register users. It also adds LDAP attributes and client side drag and drop editing of the LDAP records to reassign records to superiors, people to managers, and members to groups. A client side form validation framework was introduced, which simplifies validation through leverage of custom attributes on the input elements.
tags | web
MD5 | b70448db24ace891bf9a181736163968
Man-In-The-Middle Proxy 0.2
Posted Apr 9, 2010
Site corte.si

MITMProxy is an interactive, SSL-aware HTTP proxy that allows viewing, modification and replaying of requests.

tags | web
MD5 | 14e856ae95434947be1bd7e51cd0c9b1
Apache mod_psldap Module 0.92
Posted Apr 6, 2010
Site sourceforge.net

mod_psldap is an Apache module that performs authentication and authorization against an LDAP server with LDAP based session management. It also provides Web 2.0 based capabilities to add, edit, move, and create new records in the LDAP store, leveraging XSL stylesheets to offload heavy processing to the clients and reduce bandwidth consumption by up to 95% or more.

Changes: This is a bug fix release to address variations on the initially tested configurations. It also restores isolation of site specific configurations to simplify an upgrade.
tags | web
MD5 | f95255035a62dabd6bd3a49cca975a3f
iExploder 1.5
Posted Mar 16, 2010
Authored by Thomas Stromberg | Site code.google.com

iExploder is like a fire hydrant full of bad HTML and CSS code to test the stability and security of web browsers. Available as a standalone webserver or CGI script, it continuously feeds browsers bad data in the hope that they will eventually crash. It is designed to run for hours, or even days until the browser crashes. namebench was initially written as a QA tool for the Mozilla Project to test the Firefox 1.0 release, and is now included and used by Apple's Webkit project.

tags | web, cgi
systems | apple
MD5 | a9f13caef6e05e60c287cb32bf4e5084
Cookie Monster 1.6
Posted Mar 11, 2010
Authored by Tom Neaves | Site tomneaves.com

Cookie Monster is a cookie analysis tool written in Python. Cookie Monster will grab cookies from a host and assign each character a number. This number can be used to perform mathematical calculations on the differences in order to find a pattern and see if cookie prediction is possible.

tags | web, python
MD5 | c8965e9b954a6b7684b304c5e80a7dda
Page 1 of 8
Back12345Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close