Penetration Testing mailing list archives

Re: Required Help on Automated Tools


From: Christian Martorella <cmartorella () edge-security com>
Date: Wed, 15 Oct 2008 19:49:57 +0200

Hi Noxious, you can try ProxyStrike, an active http proxy that will test for XSS and SQL Injection for all the traffic passing through it.

You can check it here:  http://www.edge-security.com/proxystrike.php

And maybe it will be useful the for the URL Access vuln, Wfuzz:

http://www.edge-security.com/wfuzz.php

Hope it helps

Christian Martorella
http://laramies.blogspot.com



On Oct 14, 2008, at 8:32 PM, Vin Oxious wrote:

Hello Everyone,

                              Greetings !! ..Can you please list me
some tools that would allow automated testing of the below ...  (
while I have already got a few tools .. just wanted to know if there
are some good ones ) ..

SQL Injection -

XSS -

Improper Session Management -

URL Access -

Direct Object Reference -


regards,
Noxious

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Security Trends Report from Cenzic
Stay Ahead of the Hacker Curve!
Get the latest Q2 2008 Trends Report now

www.cenzic.com/landing/trends-report
------------------------------------------------------------------------




------------------------------------------------------------------------
This list is sponsored by: Cenzic

Security Trends Report from Cenzic
Stay Ahead of the Hacker Curve!
Get the latest Q2 2008 Trends Report now

www.cenzic.com/landing/trends-report
------------------------------------------------------------------------


Current thread: