




已阅读5页,还剩8页未读, 继续免费阅读
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
Test sites / testing groundsSPI Dynamics (live) /Cenzic (live) /Watchfire (live) /Acunetix (live) / WebMaven / Buggy Bank /webmavenFoundstone SASS tools /us/resources-free-tools.aspUpdated HackmeBank /technical-info/2008/12/8/updated-version-of-hacmebank.htmlOWASP WebGoat /index.php/OWASP_WebGoat_ProjectOWASP SiteGenerator /index.php/Owasp_SiteGeneratorStanford SecuriBench /livshits/securibench/SecuriBench Micro /livshits/work/securibench-micro/HTTP proxying / editingWebScarab /index.php/Category:OWASP_WebScarab_ProjectBurp /Paros /Fiddler /Web Proxy Editor /mspress/companion/0-7356-2187-X/Pantera /index.php/Category:OWASP_Pantera_Web_Assessment_Studio_ProjectSuru /research/suru/httpedit (curses-based) /en/rd/httpedit/Charles /charles/Odysseus /tools/odysseusBurp, Paros, and WebScarab for Mac OS X /downloads/Web-application scanning tool from Network Security Tools/OReilly /networkst/JS Commander /Ratproxy /p/ratproxy/RSnakes XSS cheat sheet based-tools, webapp fuzzing, and encoding toolsWfuzz /wfuzz.phpProxMon /proxmon.htmlWapiti /Grabber /beta/grabber/XSSScan http:/darkcode.ath.cx/scanners/XSSscan.pyCAL9000 /index.php/Category:OWASP_CAL9000_ProjectHTMangLe /Tools/HTMangLe/publish.htmJBroFuzz /projects/jbrofuzzXSSFuzz /blog/20060921/xssfuzz-released/WhiteAcids XSS Assistant /greasemonkey/Overlong UTF /mspress/companion/0-7356-2187-X/TGZ MielieTool (SensePost Research) /UNIX/utilities/mielietools-v1.0.tgzRegFuzzer: test your regular expression filter /b/index.php/post/2007/05/26/RegFuzzer%3A-Test-your-regular-expression-filterscreamingCobra /projects/screamingcobra.htmlSPIKE and SPIKE Proxy /resources-freesoftware.shtmlRFuzz /WebFuzz /index.php?option=com_content&task=view&id=112&Itemid=99999999TestMaker /Docs/downloads/features.htmlASP Auditor /projects/asp-auditor-v2/WSTool /Web Hack Control Center (WHCC) /whcc/Web Text Converter /mspress/companion/0-7356-2187-X/HackBar (Firefox Add-on) /firefox/3899/Net-Force Tools (NF-Tools, Firefox Add-on) -force.nl/library/downloads/PostIntercepter (Greasemonkey script) /scripts/show/743HTTP general testing / fingerprintingWbox: HTTP testing tool /wbox/ht:/Check /Mumsie /tools/mumsie.htmlWebInject /Torture.pl Home Page /lstein/torture/JoeDogs Seige /JoeDog/Siege/OPEN-LABS: metoscan (http method testing) /Load-balancing detector http:/ge.mine.nu/lbd.htmlHMAP /hmap/Net-Square: httprint /httprint/Wpoison: http stress testing /Net-square: MSNPawn /msnpawn/index.shtmlhcraft: HTTP Vuln Request Crafter /projects/hcraft/rfp.labs: LibWhisker /rfp/lw.aspNikto /code/nikto.shtmltwill /DirBuster /index.php/Category:OWASP_DirBuster_ProjectZIP DFF Scanner /files/dff/DFF.zipZIP The Elza project /web/elza-1.4.7-beta.zip /elza.htmlHackerFox and Hacking Addons Bundled: Portable Firefox with web hacking addons bundled /projects/hackfoxBrowser-based HTTP tampering / editing / replayingTamperIE /Other/isr-form .ar/developments.htmlModify Headers (Firefox Add-on) /Tamper Data (Firefox Add-on) /UrlParams (Firefox Add-on) /en-US/firefox/addon/1290/TestGen4Web (Firefox Add-on) /en-US/firefox/addon/1385/DOM Inspector / Inspect This (Firefox Add-on) /en-US/firefox/addon/1806/ /en-US/firefox/addon/1913/LiveHTTPHeaders / Header Monitor (Firefox Add-on) / /en-US/firefox/addon/575/Cookie editing / poisoningTGZ stompy: session id tool http:/lcamtuf.coredump.cx/stompy.tgzAddN Edit Cookies (AnEC, Firefox Add-on) /CookieCuller (Firefox Add-on) /CookiePie (Firefox Add-on) /oss/firefox/extensions/cookiepie/CookieSpy /shell/cookiespy.aspCookies Explorer /Features/Cookies.aspxAjax and XHR scanningSahi http:/sahi.co.in/scRUBYt /jQuery /jquery-include /projects/jquery-includeSprajax /sprajax.htmlWatir /Watij /Watin /RBNarcissus http:/idontsmoke.co.uk/2005/rbnarcissus/SpiderTest (Spider Fuzz plugin) http:/blog.caboo.se/articles/2007/2/21/the-fabulous-spider-fuzz-pluginJavascript Inline Debugger (jasildbg) /Firebug Lite /lite.htmlfirewaitr /p/firewatir/RSS extensions and cachingLiveLines (Firefox Add-on) /en-US/firefox/addon/324/rss-cache /chris/projects/rss-cache/SQL injection : home of Absinthe, Mezcal, etc http:/090.org/releases.phpSQLiX /index.php/Category:OWASP_SQLiX_Projectsqlninja: a SQL Server injection and takover tool /JustinClarkes SQL Brute /archives/2006/03/sqlbrute.htmlBobCat http:/www.northern-monkee.co.uk/projects/bobcat/bobcat.htmlsqlmap /Scully: SQL Server DB Front-End and Brute-Forcer /research/scully/FG-Injector /?lang=en&seccion=herramientasPRIAMOS /Web application security malware, backdoors, and evil codeW3AF: Web Application Attack and Audit Framework /Jikto /jikto-in-the-wild/XSS Shell /article/?1338XSS-Proxy AttackAPI /projects/attackapi/FFsniFF http:/azurit.elbiahosting.sk/ffsniff/HoneyBlogs web-based junkyard /junkyard/web-based/BeEF /tools/beef/Firefox Extension Scanner (FEX) /projects/fex/What is my IP address? http:/reglos.de/myaddress/xRumer: blogspam automation tool /movies/XFull.htmSpyJax /makebeta/tools/spyjax/Greasecarnaval /projects/greasecarnavalTechnika /projects/technika/Load-AttackAPI bookmarklet /projects/load-attackapi-bookmarkletMDs Projects: JS port scanner, pinger, backdoors, etc /my-projects/Web application services that aid in web application security assessmentNetcraft AboutURL /The Scrutinizer /net.toolkit /ServerSniff /Online Microsoft script decoder /security/tools/decoder/Webmaster-Toolkit /myIPNeighbbors, et al /security/MyIPNeighbors_Find_Out_Who_Else_is_Hosted_on_Your_Site_s_IP_AddressPHP charset encoding http:/h4k.in/encodingdata: URL testcases http:/h4k.in/dataurlBrowser-based security fuzzing / checkingZalewskis MangleMe http:/lcamtuf.coredump.cx/mangleme/mangle.cgihdms tools: Hamachi, CSSDIE, DOM-Hanoi, AxMan /users/hdm/tools/Peach Fuzzer Framework /TagBruteForcer /html/tools/RT20060801-3.htmlPROTOS Test-Suite: c05-http-reply http:/www.ee.oulu.fi/research/ouspg/protos/testing/c05/http-reply/index.htmlCOMRaider bcheck http:/bcheck.scanit.be/bcheck/Stop-Phishing: Projects page /phishing/?projectsLinkScanner /linkscanner/default.aspBrowserCheck http:/www.heise-security.co.uk/services/browsercheck/Cross-browser Exploit Tests /cool.phpStealing information using DNS pinning demo /index.php?i=2&a=1&b=7Javascript Website Login Checker /weird/javascript-website-login-checker.htmlMozilla Activex http:/www.iol.ie/locka/mozilla/mozilla.htmJungsonns Black Dragon Project /Mr. T (Master Recon Tool, includes Read Firefox Settings PoC) /mr-t/Vulnerable Adobe Plugin Detection For UXSS PoC /?i=324About Flash: is your flash up-to-date? /software/flash/about/Test your installation of Java software /en/download/installed.jsp?detect=jre&try=1WebPageFingerprint Light-weight Greasemonkey Fuzzer /scripts/show/30285PHP static analysis and file inclusion scanningPHP-SAT.org: Static analysis for PHP /PHP/Unl0ck Research Team: tool for searching in google for include bugs /tools.phpFIS: File Inclusion Scanner http:/www.segfault.gr/index.php?cat_id=3&cont_id=25PHPSecAudit /projects/phpsecauditPHP Defensive ToolsPHPInfoSec Check phpinfo configuration for security /projects/phpsecinfo/A Greasemonkey Replacement can be found at /lab/#tools.greasemonkeyPhp-Brute-Force-Attack Detector Detect your web servers being scanned by brute force tools such as WFuzz, OWASP DirBuster and vulnerability scanners such as Nessus, Nikto, Acunetix .etc. /lab/pr0js/files.php/php_brute_force_detect.zipPHP-Login-Info-Checker Strictly enforce admins/users to select stronger passwords. It tests cracking passwords against 4 rules. It has also built-in smoke test page via url loginfo_checker.php?testlic/lab/pr0js/files.php/loginfo_checkerv0.1.zip/lab/pr0js/files.php/phploginfo_checker_demo.zipphp-DDOS-Shield A tricky script to prevent idiot distributed bots which discontinue their flooding attacks by identifying HTTP 503 header code. /p/ddos-shield/PHPMySpamFIGHTER /lab/pr0js/files.php/phpmyspamfighter.zip /lab/pr0js/files.php/phpMySpamFighter_demo.rarWeb Application Firewall (WAF) and Intrusion Detection (APIDS) rules and resourcesAPIDS on Wikipedia /wiki/APIDSPHP Intrusion Detection System (PHP-IDS) / /p/phpids/dotnetids /p/dotnetids/Secure Science InterScout /home/newsandevents/news/interscout1.0.htmlRemo: whitelist rule editor for mod_security /GotRoot: ModSecuirty rules /tiki-index.php?page=mod_security+rulesThe Web Security Gateway (WSGW) /mod_security rules generator /tools/modsecurity/Mod_Anti_Tamper http:/www.wisec.it/projects.php?id=3TGZ Automatic Rules Generation for Mod_Security http:/www.wisec.it/rdr.php?fn=/Projects/Rule-o-matic.tgzAQTRONIX WebKnight /?PageID=99Akismet: blog spam defense /Samoa: Formal tools for securing web services /projects/samoa/Web services enumeration / scanning / fuzzingWebServiceStudio2.0 /WebserviceStudioNet-square: wsChess /wschess/index.shtmlWSFuzzer /index.php/Category:OWASP_WSFuzzer_ProjectSIFT: web method search tool .au/73/171/sift-web-method-search-tool.htmiSecPartners: WSMap, WSBang, etc /tools.htmlWeb application non-specific static source-code analysisPixy: a static analysis tool for detecting XSS vulnerabilities http:/www.seclab.tuwien.ac.at/projects/pixy/Brixoft.Net: Source Edit /prodinfo.asp?id=1Security compass web application auditing tools (SWAAT) /index.php/Category:OWASP_SWAAT_ProjectAn even more complete list here /aldrich/courses/654/tools/A nice list that claims some demos available /aldrich/courses/413/tools.htmlA smaller, but also good list /static/Yasca: A highly extensible source code analysis framework; incorporates several analysis tools into one package. /Static analysis for C/C+ (CGI, ISAPI, etc) in web applicationsRATS /resources/download_rats.htmlITS4 /its4/FlawFinder /flawfinder/Splint /Uno /uno/BOON (Buffer Overrun detectiON) /daw/boon/ Valgrind /Java static analysis, security frameworks, and web application security toolsLAPSE /livshits/work/lapse/HDIV Struts /Orizon /projects/orizon/FindBugs: Find bugs in Java programs /PMD /CUTE: A Concolic Unit Testing Engine for C and Java /ksen/cute/EMMA /JLint /Java PathFinder /Fujaba: Move between UML and Java source code http:/wwwcs.uni-paderborn.de/cs/fujaba/Checkstyle /Cookie Revolver Security Framework /projects/cookie-revolvertinapoc /projects/tinapocjarsigner /j2se/1.5.0/docs/tooldocs/solaris/jarsigner.htmlSolex /Java Explorer /jexplore/HTTPClient http:/www.innovation.ch/java/HTTPClient/another HttpClient /commons/httpclient/a list of code coverage and analysis tools for Java /2007/06/java-foss-freeopen-source-software.htmlMicrosoft .NET static analysis and security framework tools, mostly for ASP.NET and ASP.NET AJAX, but also C# and VB.NET Visual Studio 2008 Code Analysis, available in: o VSTS 2008 Development Edition (/vsts2008/products/bb933752.aspx) and o VSTS 2008 Team Suite (/vsts2008/products/bb933735.aspx) Visual Studio 2005 Code Analyzer, available in: o Visual Studio 2005 Team Edition for Software Developers (/en-us/vstudio/aa718806.aspx) o Visual Studio 2005 Team Suite (/en-us/vstudio/aa718806.aspx) Web Development Helper /Project.WebDevHelper.aspx FxCop: o (blog) /fxcop/ o (download) /codeanalysis Microsoft internal tools you cant have yet: o /windows/cse/pa_projects.mspx o /Pex/ o /images/5/5b/OWASP_IL_7_FuzzGuru.pdf Threat modelingMicrosoft Threat Analysis and Modeling Tool v2.1 (TAM) /downloads/details.aspx?FamilyID=59888078-9daf-4e96-b7d1-944703479451&displaylang=enAmenaza: Attack Tree Modeling (SecurITree) /software.phpOctotrike /Add-ons for Firefox that help with general web application securityWeb Developer Toolbar /firefox/60/Plain Old Webserver (POW) /firefox/3002/XML Developer Toolbar /firefox/2897/Public Fox /firefox/3911/XForms Buddy http:/beaufour.dk/index.php?sec=misc&pagename=xformsMR Tech Local Install /extensions/local_install
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 临床复试题目大全图片高清及答案2025年版
- 抗药物临床应用考试试题及答案2025年版
- 康复临床试题答案解析pdf2025年版
- 2025年文创产品线下体验店项目可持续发展可行性分析报告
- 火锅市场消费者需求洞察与创新营销:2025年竞争格局与创新实践研究报告
- 2025健身房转让合同标准版范本
- 2025个人中介房屋租赁合同范本(合同样本)
- 激光雷达固态化技术在智能仓储2025年成本控制与物流效率分析报告
- 镜片防雨知识培训内容课件
- 2025年3D食物打印技术的口感研究
- 下半年中小学教师资格笔试考试题库带答案2025
- 酒吧店长聘用协议书
- 2024年全国职业院校技能大赛高职组(环境检测与监测赛项)考试题库(含答案)
- 贵州省高品质住宅设计导则(试行)2025
- 2025-2030中国钽电解电容器市场营运格局分析与全景深度解析报告
- 晋副主任护师的述职报告
- 广西田林八渡金矿 资源储量核实报告
- 《消化性溃疡诊疗》课件
- GB/T 44927-2024知识管理体系要求
- CISA国际注册信息系统审计师认证备考试题库(600题)
- 《混凝土质量通病》课件
评论
0/150
提交评论