Archive for the 'Web Applications' Category
Thursday, August 16th, 2007
SideJacking is about sniffing HTTP traffic and cloning whatever cookies are exchanged between the browser and the server. In this way, the attacker can clone your session IDs and eventualy they can hijack your account.
Share This
4 Comments » | Posted in Penetration Testing, Web Applications, Tools
Tuesday, August 14th, 2007
This publication discusses the fundamental technologies and features of SSL VPNs.
It describes SSL and how it fits within the context of layered network security.
It presents a phased approach to SSL VPN planning and implementation that can help in achieving successful SSL VPN deployments.
It also compares the SSL VPN technology with IPsec VPNs and other VPN solutions.
This information is particularly valuable for helping organizations to determine how best to deploy SSL VPNs within their specific network environments.
Share This
Leave Comment » | Posted in Web Applications, Guidelines
Monday, August 6th, 2007
Today I discovered an impressive collection of security tools developed and offered for free by iSEC Partners and because I really appreciate any open source effort, I thought at least I could present them.
Share This
Leave Comment » | Posted in Web Applications, Tools
Friday, July 20th, 2007
Watir is an automated test tool which uses the Ruby scripting language to drive the Internet Explorer web browser. Watir is a toolkit for automated tests to be developed and run against a web browser.
Share This
Leave Comment » | Posted in Web Applications, Brute Force, Tools
Thursday, July 19th, 2007
Srinath Anantharaju, a member of Google’s Security Team posted in Google’s Security Blog the availability of “Lemon” , a new web application security fuzzerdeveloped by Google.
Share This
Leave Comment » | Posted in Web Applications, Brute Force, Tools
Thursday, June 28th, 2007
another web testing tool called FunkLoad. This python application can be used for functional and regression testing of web applications.
Share This
Leave Comment » | Posted in Web Applications, Brute Force, Tools
Tuesday, June 26th, 2007
WebLOAD stress and load testing tool has been released by Radware as open source. The Commercial-Grade Open Source Load Testing Solution from RadView. Load-test any Internet Application, including applications that use Web 2.0 & AJAX.
Share This
1 Comment » | Posted in Web Applications, Brute Force, Tools
Thursday, June 21st, 2007
Acunetix Web Vulnerability Scanner 5 is definitely a most valuable ally in the battle against web security risks. This versatile software has successfully tackled the 80 / 20 problem of advanced software applications. It delivers good value for the money even if you use just 20 percent of it’s features, whereas in the hands of an web application security professional it reveals the 80 percent reserve of raw power.
Share This
3 Comments » | Posted in Reviews, Vuln. Scanner, Web Applications, Tools
Friday, June 15th, 2007
Andres Riancho has released w3af 1.0 - the Web Application Attack and Audit Framework.This framework is written in python and resembles a bit to metasploit having an architecture based on plugins
Share This
Leave Comment » | Posted in Framework, Web Applications, Tools
Thursday, June 14th, 2007
I read today about a new tool for web brute forcing : DirBuster. It is a multi threaded java application designed to brute force directories and files names on web/application servers.
Share This
1 Comment » | Posted in Web Applications, Brute Force, Tools
Pages (7): « 1 [2] 3 4 5 » ... Last »