Showing posts with label web. Show all posts

[IronWASP v0.9.6.5] Open Source Advanced Web Security Testing Platform

IronWASP (Iron Web application Advanced Security testing Platform) is an open source system for web application vulnerability testing. It i...

IronWASP (Iron Web application Advanced Security testing Platform) is an open source system for web application vulnerability testing. It is designed to be customizable to the extent where users can create their own custom security scanners using it. Though an advanced user with Python/Ruby scripting expertise would be able to make full use of the platform, a lot of the tool’s features are simple enough to be used by absolute beginners.

What’s new in IronWASP v0.9.6.5


IronWASP v0.9.6.5 is now available for download. Users of older versions should get an update prompt when using IronWASP. This is what you get with the new version.

  • Completely redesigned awesome new Results section
  • Support for editing, scanning and fuzzing SOAP messages
  • New active checks for Server Side Includes, Sever Side Request Forgery and Expression Language Injection
  • New passive check for JSON messages that are vulnerable to JSON hijacking
  • Significantly faster and robust parsers for XML, JSON and Multi-part messages with auto-detection support
  • Enhancements to the Payload Effect Analysis feature
  • Enhancements to the Scan Trace Viewer feature
  • Ability to create Request in Manual Testing section from clipboards
  • New Network address parsing APIs
  • Update to FiddlerCore v2.4.4.8


LOIC :Dos Attacking tool

What is LOIC LOIC basically turns your computer’s network connection into a firehose of garbage requests, directed towards a target web se...

What is LOIC
LOIC basically turns your computer’s network connection into a firehose of garbage requests, directed towards a target web server. On its own, one computer rarely generates enough TCP, UDP, or HTTP requests at once to overwhelm a web server—garbage requests can easily ignored while legit requests for web pages are responded to as normal.
But when thousands of users run LOIC at once, the wave of requests become overwhelming, often shutting a web server (or one of its connected machines, like a database server) down completely, or preventing legitimate requests from being answered.

LOIC is more focued on web applications we can also call it applicaton based DOS attack. LOIC can be used on a target site by flooding the server with TCP packets, UDP packets, or HTTP requests with the intention of disrupting the service of a particular host. People have used LOIC to join voluntary botnets.
LOIC is a nice tool to perform dos or ddos attack but try it on your own risk. It does no have an ability to hide your IP addressSource code is also available .
Download LOIC 1.0.4 here

Free Web Application Security for Dummies

Qualys announced that it has published a new comprehensive free guide on Web Application Scanning (WAS) to help readers understand web appl...

Qualys announced that it has published a new comprehensive free guide on Web Application Scanning (WAS) to help readers understand web application security – including how to quickly find and fix vulnerabilities in web applications
Web applications are an attractive target for hackers and vulnerabilities are now among the most prevalent of all server vulnerability disclosures. The new “WAS for Dummies” book provides information on how to scan for vulnerabilities to proactively keep data in web applications secure.

IRONBEE: The Open Source Next Generation WAF!

IronBee is a new open source project to build a universal web application security sensor. Its like building a universal web application ...

IronBee IRONBEE: The Open Source Next Generation WAF!IronBee is a new open source project to build a universal web application security sensor. Its like building a universal web application firewall in the cloud Open Source Next Generation WAF for the Community! It is a new open source project from Qualys to build a universal web application firewall sensor in the cloud through collective efforts of the community.
There are two projects included in this one:
Projects:


Get your .com domain for free...

Yes, you can now get any.com domains for free if it is available. If not you can choose a different domain name from the available list. ...

Yes, you can now get any.com domains for free if it is available. If not you can choose a different domain name from the available list.


HyperWebEnable is a free web hosting service with as many as 400 websites and blogs provided till date. But you will have limited control on your HyperWebEnable hosted site. You can even get multiple websites freely with unlimited bandwidth and email ids and many more services that the paid services provide.

You can see domain comparison in their site


Last but not the least…you can even refer your friends to get a website from HyperWebEnable through referrals and earn money.