Our first post regarding OWASP Mantra can be found here. A few days ago, an update – OWASP Mantra Security Toolkit 0.91 Beta Lexicon has been made available to us.
“OWASP Mantra is a collection of free and open source tools integrated into a web browser, which can become handy for students, penetration testers, web application developers,security professionals [...]
Tagged as:
FireFox,
Mantra Security Framework,
owasp,
Penetration Testing,
plugin,
Portable software,
SQL Injection,
sqlinject-finder tutorial,
Web Application Penetration Testing,
web application security,
web security
SQLSentinel is an openSource tool for sql injection security testing for white hats.
SQLSentinel is an opensource tool that automates the process of finding the sql injection on a website. It includes a spider web and sql errors finder. We give in input site name and
It will crawls and try to exploit parameters validation error for you. [...]
Tagged as:
database security,
Penetration Testing,
sqlinjection,
SQLSentinel
Our original post about winAUTOPWN can be found here. Like metasploit winAUTOPWN is regularly updated and winAUTOPWN version 3.0 has been recently released.
“winAUTOPWN and bsdAUTOPWN are minimal Interactive Frameworks which act as a frontend for quick systems vulnerability exploitation. It takes inputs like IP address, Hostname, CMS Path, etc. and does a smart multi-threaded portscan [...]
Tagged as:
bsdAUTOPWN,
Exploit,
Metasploit,
Penetration Testing,
system auditing tool,
welf,
welfexploits,
winAUTOPWN,
Windows
Our first post regarding Intersect, the post exploitation framework can be found here. Recently, an update – Intersect 2.5 – was made available to us!
“Intersect is a post-exploitation framework written in Python. The main goal of this project is to assist penetration testers in the automation of many post exploitation and data exfiltration tasks that [...]
Tagged as:
Exploit,
information gathering,
Intersect,
Penetration Testing
Our first post regarding OWASPBWA or the OWASP Broken Web Applications Project can be found here. About two months ago, an updated version – OWASPBWA version 1.0rc1 was released!
“Open Web Application Security Project (OWASP) Broken Web Applications Project, a collection of vulnerable web applications that is distributed on a Virtual Machine in VMware format compatible with [...]
Tagged as:
BodgeIt,
Damn Vulnerable Web App,
DVWA,
owaspbwa,
Penetration Testing,
WackoPicko
Enema is not autohacking software. This is dynamic tool for people, who knows what to do. Not supported old database versions (e. g. mysql 4.x). Development targeted to modern versions.
We hope in new versions there are some reports and more database version added. With some support for custom plugins and known sql velnerabilities to test with.
Features of Enema:
Multi-platform.
User-friendly [...]
Tagged as:
database security,
Enema,
Penetration Testing,
SQL Injection,
Sql injection dumper
WebSploit Is An Open Source Project For Scan And Analysis Remote System From Vulnerability. A Easy and fast to run tool and find results for further in deep analysis. tool is small less than 1mb.
Features of WebSploit
Autopwn – Used From Metasploit For Scan and Exploit Target Service
wmap – Scan,Crawler Target Used From Metasploit wmap plugin
format [...]
Tagged as:
Metasploit,
Penetration Testing,
Vulnerability Scanner,
WebSploit
Our original post about winAUTOPWN can be found here. Like metasploit winAUTOPWN is regularly updated and versions are released.
“winAUTOPWN and bsdAUTOPWN are minimal Interactive Frameworks which act as a frontend for quick systems vulnerability exploitation. It takes inputs like IP address, Hostname, CMS Path, etc. and does a smart multi-threaded portscan for TCP ports 1 [...]
Tagged as:
Penetration Testing,
system auditing tool,
winAUTOPWN,
Windows