{"id":390,"date":"2020-04-11T14:32:11","date_gmt":"2020-04-11T14:32:11","guid":{"rendered":"https:\/\/temp.ashkerala.com\/?p=390"},"modified":"2020-04-11T14:32:11","modified_gmt":"2020-04-11T14:32:11","slug":"tools-vulnerability-assessment-and-penetration-testing","status":"publish","type":"post","link":"https:\/\/temp.ashkerala.com\/?p=390","title":{"rendered":"Tools Vulnerability Assessment And Penetration Testing"},"content":{"rendered":"<p><strong>Acunetix Web Vulnerability Scanner<\/strong><\/p>\n<p> <em><strong>Features:<\/strong><\/em><\/p>\n<p> 1. AcuSensor Technology<br \/> 2. An automatic client script analyzer allowing for security testing of Ajax and Web 2.0 applications.<br \/> 3. Industries&#8217; most advanced and in-depth SQL injection and Cross site scripting testing.<br \/> 4. Advanced penetration testing tools, such as the HTTP Editor and the HTTP Fuzzer.<br \/> 5. Visual macro recorder makes testing web forms and password protected areas easy<br \/> 6. Support for pages with CAPTHCA, single sign-on and Two Factor authentication mechanisms.<br \/> 7. Extensive reporting facilities including VISA PCI compliance reports.<br \/> 8.Multi-threaded and lightning fast scanner crawls hundreds of thousands of pages with ease.<br \/> 9. Intelligent crawler detects web server type and application language.<br \/> 11. Acunetix crawls and analyzes websites including flash content, SOAP and AJAX.<br \/> 12. Port scans a web server and runs security checks against network services running on the server.<\/p>\n<p> <strong>Burp Suite Free Edition v1.4 \u0393\u00c7\u00f4Web Application Security Testing Tool<\/strong><\/p>\n<p> Burp Suite is an integrated platform for performing security testing of web applications. Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application\u0393\u00c7\u00d6s attack surface, through to finding and exploiting security vulnerabilities.<br \/> Burp gives you full control, letting you combine advanced manual techniques with state-of-the-art automation, to make your work faster, more effective, and more fun.<\/p>\n<p> <strong>ZAProxy v1.3.0 \u0393\u00c7\u00f4 Integrated Penetration Testing Tool<\/strong><\/p>\n<p> ZAP is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing.<br \/> ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.<\/p>\n<p><em>Main Features<\/em><\/p>\n<p>Intercepting Proxy, Automated scanner,\u00a0 Passive scanner, Brute Force, scanner, Spider, Fuzzer, Port scanner, Dynamic SSL certificates, API, Beanshell integration.<\/p>\n<p> <strong>FIMAP<\/strong><\/p>\n<p> FIMAP is a Local and Remote file inclusion auditing Tool (LFI\/RFI).<br \/> Fimap is a little python tool which can find, prepare, audit, exploit and even google automatically for local and remote file inclusion bugs in webapps. fimap should be something like sqlmap just for LFI\/RFI bugs instead of sql injection.<\/p>\n<p> <strong>Web Application Attack and Audit Framework<\/strong><\/p>\n<p> W3af is an extremely popular, powerful, and flexible framework for finding and exploiting web application vulnerabilities. It is easy to use and extend and features dozens of web assessment and exploitation plugins<br \/> \u00a0<br \/> <strong>New Features:<\/strong><br \/> -Considerably increased performance by implementing gzip encoding<br \/> -Enhanced embedded bug report system using Trac&#8217;s XMLRPC<br \/> -Fixed hundreds of bugs * Fixed critical bug in auto-update feature<br \/> -Enhanced integration with other tools (bug fixed and added more info to the file)<\/p>\n<p> <strong>WebSploit Toolkit V 1.6<\/strong><\/p>\n<p> WebSploit Is An Open Source Project For Scan And Analysis Remote System From Vulnerability<br \/> Description :<br \/> Autopwn &#8211; Used From Metasploit For Scan and Exploit Target Service<br \/> wmap &#8211; Scan,Crawler Target Used From Metasploit wmap plugin<br \/> format infector &#8211; inject reverse &amp; bind payload into file format<br \/> phpmyadmin &#8211; Search Target phpmyadmin login page<br \/> lfi &#8211; Scan,Bypass local file inclusion Vulnerability &amp; can be bypass some WAF<br \/> apache users &#8211; search server username directory (if use from apache webserver)<br \/> Dir Bruter &#8211; brute target directory with wordlist<br \/> admin finder &#8211; search admin &amp; login page of target<br \/> MLITM Attack &#8211; Man Left In The Middle, XSS Phishing Attacks<br \/> MITM &#8211; Man In The Middle Attack<br \/> Java Applet Attack &#8211; Java Signed Applet Attack<br \/> MFOD Attack Vector &#8211; Middle Finger Of Doom Attack Vector<br \/> USB Infection Attack &#8211; Create Executable Backdoor For Infect USB For Windows<\/p>\n<p> <strong>Penetration Testing Oriented Browser &#8211; Sandcat Browser<\/strong><\/p>\n<p> Sandcat Browser is a freeware portable pen-test oriented multi-tabbed web browser with extensions support developed by the Syhunt team,<br \/> Features<\/p>\n<p> Live HTTP Headers, Request Editor extension,<br \/> Fuzzer extension with multiple modes and support for filters,<br \/> JavaScript Executor extension which allows you to load and run external\u00a0\u00a0\u00a0\u00a0\u00a0 JavaScript files,<br \/> Lua Executor extension &#8212; allows you to load and run external Lua scripts<br \/> Syhunt Gelo, HTTP Brute Force, CGI Scanner scripts and more.<\/p>\n<p> <strong>PHP Vulnerability Hunter v.1.1.4.6 &#8211; Automated fuzz testing tool<\/strong><\/p>\n<p> This is the application that detected almost all of the web application vulnerabilities listed on the advisories page. PHP Vulnerability Hunter is an advanced automated whitebox fuzz testing tool capable of triggering a wide range of exploitable faults in PHP web applications. Minimal configuration is necessary to begin a scan; PHP Vulnerability Hunter doesn\u0393\u00c7\u00d6t even need a user specified starting URI.<br \/> \u00a0 \u00a0<br \/> Updated GUI validation<br \/> Several instrumentation fixes<br \/> Fixed lingering connection issue<br \/> Fixed GUI and report viewer crashes related to working directory<\/p>\n<p> INSECT Pro 2.7 &#8211; Ultimate is here! This penetration security auditing and testing software solutionis designed to allow organizations of all sizes mitigate, monitor and manage the latest security threats vulnerabilities and implement active security policies by performing penetration tests across their infrastructure and applications. This is a partial list of the major changes implanted in version 2.7<\/p>\n<p> &#8211; Available targets now has a sub menu under right-click button<br \/> &#8211; Check update function added in order to verify current version<br \/> &#8211; Threading support for GET request<br \/> &#8211; Module log added and functional<br \/> &#8211; Sniffer support added<br \/> &#8211; 50 Remote exploits added<br \/> &#8211; Project saved on user land &#8211; Application Data special folder<br \/> &#8211; Executed module windows added and functionality for it<br \/> &#8211; Agent Connect now use telnet lib<\/p>\n<p> <strong>OWASP Zed Attack Proxy (ZAP) v.1.3.2 Released<\/strong><\/p>\n<p> The OWASP Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing as well as being a useful addition to an experienced pen testers toolbox.<br \/> Some of ZAP &#8216;s features:<\/p>\n<p> Intercepting Proxy<br \/> Automated scanner<br \/> Passive scanner<br \/> Brute Force scanner<br \/> Spider<br \/> Fuzzer<br \/> Port scanner<br \/> Dynamic SSL certificates<br \/> API<br \/> Beanshell integration<\/p>\n<p> <strong>Uniscan 4.0 vulnerability scanner Released<\/strong><\/p>\n<p> The Uniscan vulnerability scanner is aimed at information security, which aims at<br \/> finding vulnerabilities in Web systems and is licensed under the GNU GENERAL<br \/> PUBLIC LICENSE 3.0 (GPL 3). The Uniscan was developed using the Perl<br \/> programming language to be easier to work with text, has an easy to use regular expressions and is also multi-threaded.<\/p>\n<p> <strong>Uniscan Features<\/strong><\/p>\n<p> \u00a0\u00a0\u00a0 Identification of system pages through a Web Crawler.<br \/> \u00a0\u00a0\u00a0 Use of threads in the crawler.<br \/> \u00a0\u00a0\u00a0 Control the maximum number of requests the crawler.<br \/> \u00a0\u00a0\u00a0 Control of variation of system pages identified by Web Crawler.<br \/> \u00a0\u00a0\u00a0 Control of file extensions that are ignored.<br \/> \u00a0\u00a0\u00a0 Test of pages found via the GET method.<br \/> \u00a0\u00a0\u00a0 Test the forms found via the POST method.<br \/> \u00a0\u00a0\u00a0 Support for SSL requests (HTTPS).<br \/> \u00a0\u00a0\u00a0 Proxy support.<\/p>\n<p> <strong>IBM Rational AppScan<\/strong><\/p>\n<p> IBM Rational AppScan is a family of web security testing and monitoring tools from the Rational Software division of IBM. AppScan is intended to test Web applications for security vulnerabilities during the development process, when it is least expensive to fix such problems. The product learns the behavior of each application, whether an off-the-shelf application or internally developed, and develops a program intended to test all of its functions for both common and application-specific vulnerabilities.<\/p>\n<p> Editions<\/p>\n<p> AppScan Standard Edition &#8211; Desktop software for automated Web application security testing environment for IT Security, auditors, and penetration testers<\/p>\n<p> AppScan Tester Edition &#8211; An edition that integrates with IBM Rational Quality Manager to form a security testing QA environment<\/p>\n<p> AppScan Build Edition &#8211; A version that embeds web application security testing into the build management workflow<\/p>\n<p> AppScan Enterprise Edition &#8211; Client-server version used to scale security testing.<\/p>\n<p> AppScan OnDemand &#8211; Identifies and prioritizes Web Application Security vulnerabilities via SaaS Model<\/p>\n<p> AppScan OnDemand Production Site Monitoring &#8211; Monitors production Web content and sites for security vulnerabilities via SaaS Model<\/p>\n<p> AppScan Source Edition &#8211; Prevent data breaches by locating security flaws in the source code<\/p>\n<p> AppScan Reporting Console &#8211; Reporting add-on<\/p>\n<p><strong>Paros &#8211; for web application security assessment \u00a0\u00a0 \u00a0<\/strong><\/p>\n<p> We wrote a program called &#8220;Paros&#8221; for people who need to evaluate the security of their web applications. It is free of charge and completely written in Java. Through Paros&#8217;s proxy nature, all HTTP and HTTPS data between server and client, including cookies and form fields, can be intercepted and modified.<\/p>\n<p> We hope you can benefit from our work and products.<\/p>\n<p> If you want to support our project or obtain formal support from us, please check out the product MileSCAN ParosPro, which is further developed by our core team member and supported by us as well.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Acunetix Web Vulnerability Scanner Features: 1. AcuSensor Technology 2. An automatic client script analyzer allowing for security testing of Ajax and Web 2.0 applications. 3. Industries&#8217; most advanced and in-depth SQL injection and Cross site scripting testing. 4. Advanced penetration testing tools, such as the HTTP Editor and the HTTP Fuzzer. 5. Visual macro recorder&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"footnotes":""},"categories":[34],"tags":[],"class_list":["post-390","post","type-post","status-publish","format-standard","hentry","category-it-security"],"_links":{"self":[{"href":"https:\/\/temp.ashkerala.com\/index.php?rest_route=\/wp\/v2\/posts\/390","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/temp.ashkerala.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/temp.ashkerala.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/temp.ashkerala.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/temp.ashkerala.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=390"}],"version-history":[{"count":0,"href":"https:\/\/temp.ashkerala.com\/index.php?rest_route=\/wp\/v2\/posts\/390\/revisions"}],"wp:attachment":[{"href":"https:\/\/temp.ashkerala.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=390"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/temp.ashkerala.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=390"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/temp.ashkerala.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=390"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}