As security testers we tend to always be on the lookout for new or updated tools to test the security of web based applications. Some of these are of course commercial, but most of us also make extensive use of the free and/or open source offerings. In no particular order here are the ones I am currently making use of: firebug - http://getfirebug.com/ Cheers, |
Adrien de Beaupre 353 Posts ISC Handler Apr 13th 2010 |
Thread locked Subscribe |
Apr 13th 2010 1 decade ago |
How about some more browser plugins to assist with the testing. E.g. MultiProxy to quickly switch between local proxies, and developer toolbar to inspect and modify pages. Also SSLScan or something similar to rate certificate strength.
I would be interested to know how people go about documenting their testing. Something like the Leo Editor, or do you just use Open Office with templates and macros? |
Anonymous |
Quote |
Apr 13th 2010 1 decade ago |
Netsparker + Watcher
Netsparker + Ratproxy Skipfish Burp Suite Pro + Buby + Gotham Digital Science tools fuzzdb.googlecode.com I do not like Grendel-Scan. I do not like W3AF. Wikto and Nikto are old, perhaps replaced by Skipfish or Burp Intruder with the fuzzdb list. Firefox add-ons are unstable and annoying -- Burp Suite Pro is better. My current favorite distro is the Web Security Dojo (much better than Samurai-WTF). SSLScan.sf.net is pretty neat, but so is ssllabs.com |
Anonymous |
Quote |
Apr 14th 2010 1 decade ago |
The Codeburner plugin for Firebug is handy as a side-reference.
|
AndrewB 24 Posts |
Quote |
Apr 14th 2010 1 decade ago |
Sign Up for Free or Log In to start participating in the conversation!