Posts

Showing posts with the label Web Application

Htcap - A Spider Web Application Scanner Able To Crawl Unmarried Page Application (Spa) Inwards A Recursive Mode Past Times Intercepting Ajax Calls Together With Dom Changes

Image
Htcap is a spider web application scanner able to crawl unmarried page application (SPA) inwards a recursive fashion yesteryear intercepting ajax calls as well as DOM changes. Htcap is non merely approximately other vulnerability scanner since it's focused on the crawling procedure as well as it's aimed to discovery as well as intercept ajax/fetch calls, websockets, jsonp ecc. It uses its ain fuzzers addition a laid of external tools to discovery vulnerabilities as well as it's designed to last a tool for both manual as well as automated penetration test of modern spider web applications. It also features a pocket-size but powerful framework to apace educate custom fuzzers amongst less than lx lines of python. The fuzzers tin travel amongst GET/POST data, XML as well as JSON payloads as well as switch betwixt POST as well as GET. Of course, fuzzers run inwards parallel inwards a multi-threaded environment. This is the real outset free that uses headless chrome i...

Php Safety Banking Concern Gibe List

Image
PHP: Hypertext Preprocessor is a web-based, server-side, multi-use, general-purpose, scripting as well as programming linguistic communication that tin endure embedded inward HTML. The PHP development, which was get-go created past times Rasmus Lerdorf inward 1995, is right away beingness run past times the PHP community. The PHP programming linguistic communication is nonetheless used past times a large developer. It is the close known backend programming language. In PHP spider web applications this listing called "php safety banking concern tally list" which safety researchers should know. Full Path Disclosure Arbitrary File Upload Arbitrary File Delete Arbitrary File Download Local File Inclusion Remote File Inclusion Cookie Injection Header Injection SQL Injection XML Injection XXE Injection Email Injection HTML Injection xPath Injection Code Injection Command Injection Object Injection Cross Site Scripting Cross Site Request Forgery Broken ...

Wafw00f V1.0.0 - Bring Out All The Spider Web Application Firewall!

Image
WAFW00F identifies in addition to fingerprints Web Application Firewall (WAF) products. How does it work? To create its magic, WAFW00F does the following: Sends a normal HTTP asking in addition to analyses the response; this identifies a release of WAF solutions. If that is non successful, it sends a release of (potentially malicious) HTTP requests in addition to uses uncomplicated logic to deduce which WAF it is. If that is also non successful, it analyses the responses previously returned in addition to uses roughly other uncomplicated algorithm to gauge if a WAF or safety solution is actively responding to our attacks. What does it detect? It detects a release of WAFs. To sentiment which WAFs it is able to notice run WAFW00F alongside the -l option. At the fourth dimension of writing the output is every bit follows: $ wafw00f -l ______ / \ ( Woof! ) \______/ ) ,, ...