Free Web Security Scanning Tools
Nikto
N-Stalker NStealth Free Edition
Burp Suite
Paros Proxy
OWASP Webscarab
SQL Injection
SQL Power Injector by Francois Larouche
Bobcat (based on "Data Thief" by Application Security, Inc.).
Absinthe - free blind SQL injection tool
SQLInjector by David Litchfield
NGS Software database tools
Cross-Site Scripting (XSS)
RSnake's XSS Cheat Sheet
XSS-Proxy
IE Extensions for HTTP Analysis
TamperIE
IEWatch
IE Headers
IE Developer Toolbar
IE 5 Powertoys for WebDevs
Firefox Extensions for HTTP Analysis
LiveHTTP Headers
Tamper Data
Modify Headers
HTTP/S Proxy Tools
Paros Proxy
WebScarab
Fiddler HTTP Debugging Proxy
Burp Intruder
WatchFire PowerTools
Command-line HTTP/S Tools
cURL
Netcat
Sslproxy
Openssl
Stunnel
Sample Applications
Bayden Systems' "sandbox" online shopping application
Foundstone Hacme Bank and Hacme Books
Web Site Crawling/Mirroring Tools
Lynx
Wget
Teleport Pro
Black Widow
Offline Explorer Pro
Profiling
HTTPrint for fingerprinting web servers
Jad, the Java Dissasembler
Google search using "+www.victim.+com"
Google search using 뱎arent directory? robots.txt
Web Platform Attacks and Countermeasures
Microsoft IIS Security Bulletins and Advisories
Apache Security Bulletins
Metasploit Framework
Microsoft URLScan
Apache ModSecurity
Commercial Web App Vulnerability Scanners
Acunetix Enterprise Web Vulnerability Scanner
Cenzic Hailstorm
Ecyware GreenBlue Inspector
Syhunt Sandcat Suite
SPI Dynamics WebInspect
Watchfire AppScan
NTObjectives NTOSpider
Compuware DevPartner SecurityChecker
WhiteHat Security
Web Authentication Attack Tools
Brutus AET2
Hydra
WebCracker
NTLM Authentication Proxy Server (APS)
XML Web Services (SOAP)
WebService Studio
WSDigger
SoapClient.com
XML eXternal Entity (XXE) Attack
XPath Injection
"Blind XPath Injection" by Amit Klein
출처:하나두리
'[IT 알아보기] > 보안 이슈' 카테고리의 다른 글
[이호스트IDC] Cisco IOS XR 소프트웨어 IP패킷 취약점 보안업데이트 권고 (0) | 2011.05.27 |
---|---|
그린IDC, 국내 공개 웹 게시판(그누보드) 보안 업데이트 권고 (0) | 2011.05.18 |
이호스트IDC , 패킷캡쳐 WireShark으로 로그인 비밀번호 정보 알아내는 방법 (0) | 2011.05.17 |
Adobe Flash Player 다중 취약점 업데이트 권고 (0) | 2011.05.17 |
BIND 원격 서비스거부 취약점 보안 업데이트 권고 (0) | 2011.05.13 |