19.08.2015 Views

4.0

1IZ1TDd

1IZ1TDd

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

215Appendixkajfghlhfkcocafkcjlajldicbikpgnp?hl=en-US• Request Maker is a tool for penetration testing. With it you can easilycapture requests made by web pages, tamper with the URL, headersand POST data and, of course, make new requestsCookie Editor - https:/chrome.google.com/webstore/detail/fngmhnnpilhplaeedifhccceomclgfbg?hl=en-US• Edit This Cookie is a cookie manager. You can add, delete, edit, search,protect and block cookiesCookie swap - https:/chrome.google.com/webstore/detail/dffhipnliikkblkhpjapbecpmoilcama?hl=en-US• Swap My Cookies is a session manager, it manages cookies, lettingyou login on any website with several different accounts.Firebug lite for Chrome”” - https:/chrome.google.com/webstore/detail/bmagokdooijbeehmkpknfglimnifench• Firebug Lite is not a substitute for Firebug, or Chrome DeveloperTools. It is a tool to be used in conjunction with these tools. FirebugLite provides the rich visual representation we are used to see in Firebugwhen it comes to HTML elements, DOM elements, and Box Modelshading. It provides also some cool features like inspecting HTML elementswith your mouse, and live editing CSS propertiesSession Manager”” - https:/chrome.google.com/webstore/detail/bbcnbpafconjjigibnhbfmmgdbbkcjfi• With Session Manager you can quickly save your current browserstate and reload it whenever necessary. You can manage multiplesessions, rename or remove them from the session library. Each sessionremembers the state of the browser at its creation time, i.e theopened tabs and windows.Subgraph Vega - http:/www.subgraph.com/products.html• Vega is a free and open source scanner and testing platform to testthe security of web applications. Vega can help you find and validateSQL Injection, Cross-Site Scripting (XSS), inadvertently disclosed sensitiveinformation, and other vulnerabilities. It is written in Java, GUIbased, and runs on Linux, OS X, and Windows.Testing for specific vulnerabilitiesTesting for DOM XSS• DOMinator Pro - https:/dominator.mindedsecurity.comTesting AJAX• OWASP Sprajax ProjectTesting for SQL Injection• OWASP SQLiX• Sqlninja: a SQL Server Injection & Takeover Tool - http:/sqlninja.sourceforge.net• Bernardo Damele A. G.: sqlmap, automatic SQL injection tool - http:/sqlmap.org/• Absinthe 1.1 (formerly SQLSqueal) - http:/sourceforge.net/projects/absinthe/• SQLInjector - Uses inference techniques to extract data anddetermine the backend database server. http:/www.databasesecurity.com/sql-injector.htm• Bsqlbf-v2: A perl script allows extraction of data from Blind SQLInjections - http:/code.google.com/p/bsqlbf-v2/• Pangolin: An automatic SQL injection penetration testing tool - http:/www.darknet.org.uk/2009/05/pangolin-automatic-sql-injectiontool/• Antonio Parata: Dump Files by sql inference on Mysql - SqlDumper -http:/www.ruizata.com/• Multiple DBMS Sql Injection tool - SQL Power Injector - http:/www.sqlpowerinjector.com/• MySql Blind Injection Bruteforcing, Reversing.org - sqlbftools - http:/packetstormsecurity.org/files/43795/sqlbftools-1.2.tar.gz.htmlTesting Oracle• TNS Listener tool (Perl) - http:/www.jammed.com/%7Ejwa/hacks/security/tnscmd/tnscmd-doc.html• Toad for Oracle - http:/www.quest.com/toadTesting SSL• Foundstone SSL Digger - http:/www.mcafee.com/us/downloads/free-tools/ssldigger.aspxTesting for Brute Force Password• THC Hydra - http:/www.thc.org/thc-hydra/• John the Ripper - http:/www.openwall.com/john/• Brutus - http:/www.hoobie.net/brutus/• Medusa - http:/www.foofus.net/~jmk/medusa/medusa.html• Ncat - http:/nmap.org/ncat/Testing Buffer OverflowOllyDbg - http:/www.ollydbg.de• “A windows based debugger used for analyzing buffer overflowvulnerabilities”Spike - http:/www.immunitysec.com/downloads/SPIKE2.9.tgz• A fuzzer framework that can be used to explore vulnerabilities andperform length testingBrute Force Binary Tester (BFB) - http:/bfbtester.sourceforge.net• A proactive binary checkerMetasploit - http:/www.metasploit.com/• A rapid exploit development and Testing frame workFuzzer• OWASP WSFuzzer• Wfuzz - http:/www.darknet.org.uk/2007/07/wfuzz-a-tool-forbruteforcingfuzzing-web-applications/Googling• Stach & Liu’s Google Hacking Diggity Project - http:/www.stachliu.com/resources/tools/google-hacking-diggity-project/• Foundstone Sitedigger (Google cached fault-finding) - http:/www.mcafee.com/us/downloads/free-tools/sitedigger.aspxCommercial Black Box Testing tools• NGS Typhon III - http:/www.nccgroup.com/en/our-services/security-testing-audit-compliance/information-security-software/ngs-typhon-iii/• NGSSQuirreL - http:/www.nccgroup.com/en/our-services/securitytesting-audit-compliance/information-security-software/ngssquirrel-vulnerability-scanners/• IBM AppScan - http:/www-01.ibm.com/software/awdtools/appscan/• Cenzic Hailstorm - http:/www.cenzic.com/products_services/cenzic_hailstorm.php• Burp Intruder - http:/www.portswigger.net/burp/intruder.html• Acunetix Web Vulnerability Scanner - http:/www.acunetix.com• Sleuth - http:/www.sandsprite.com• NT Objectives NTOSpider - http:/www.ntobjectives.com/products/ntospider.php• MaxPatrol Security Scanner - http:/www.maxpatrol.com• Ecyware GreenBlue Inspector - http:/www.ecyware.com• Parasoft SOAtest (more QA-type tool) - http:/www.parasoft.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!