Showing posts with label Vulnerability. Show all posts
Showing posts with label Vulnerability. Show all posts
ZAproxy 1.4.1 Weekly updates
Labels:
Tools Download,
Vulnerability
The OWASP Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.
It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing as well as being a useful addition to an experienced pen testers toolbox.
Some of Zap's Features
Intercepting Proxy
Active Scanner
Passive Scanner
Bruteforce Scanner
Spider
Fuzzer
Port Scanner
Dynamic SSL Certificates
API
Beanshell Integration
Download Zaproxy 1.4.1
Arachni Version 0.4.1.1
Labels:
Hacking News,
Tools Download,
Vulnerability
Arachni scanner updated to version 0.4.1.1 Arachni is an Open Source, feature-full, modular, high-performance Ruby framework aimed towards helping penetration testers and administrators evaluate the security of web applications. Arachni is smart, it trains itself by learning from the HTTP responses it receives during the audit process and is able to perform meta-analysis using a number of factors in order to correctly assess the trustworthiness of results and intelligently identify false-positives.
Unlike other scanners, it takes into account the dynamic nature of web applications, can detect changes caused while travelling through the paths of a web application's cyclomatic complexity and is able to adjust itself accordingly. This way attack/input vectors that would otherwise be undetectable by non-humans are seamlessly handled by Arachni.
Change log:
Auditor#log and Auditor#log_remote_file bugfixed to pass a Hash of the response headers instead of a String — also solving another bug causing response bodies not to be logged in the Issues. [Issue #294]
Issue — Response headers are now always Hash.
Reports
HTML — Removed response headers handling code and added the option to not include HTTP response bodies. [Issue #296]
XML — Removed response headers handling code and added the option to not include HTTP response bodies. [Issue #296]
HTTP debugging output now includes Response data. [Issue #297]
Executables
arachni_rpcd_monitor — Laxed standards enforced on the Dispatcher URL argument. [Issue #293]
Path extractors
Added path extractor for the area HTML tag (href attribute). [Issue #300]
Download Arachni version 0.4.1.1
Download Arachni Version 0.4.1.1
Subscribe to:
Posts (Atom)

