Penetration test tool for Web applications...Herramienta de test de penetración de aplicaciones Web.

This is w3af "Web Application Attack and Audit Framework, this tool is a set of plugins grouped by characteristics. The plugins are updated regularly and are listed in the application in the following sections:

Audit: To audit the security of the application. This section highlights plugins such as detecting SQL injection, XSS detection, detection SSI Buffer Overflow detection, detection LDAP Injection ...

Brute force: plugins are mechanisms to attack by brute force authentication.
Discovery: Discovering information on the site as new URLs, users, servers ... Use

plugins like: http Hmap for fingerprinting, fingerGoogle looking for user accounts in the web application google ...

Hobbies: Used to evade IDS.
Grep: analyzes responses from the server to the plugins looking for bugs, cookies ...

The interface has four tabs: Setup, log, results and exploit. These tabs describe the process of penetration testing a web application. The tab shows the log of the scan. At the end of this process we can see its result in the corresponding tab and if there are vulnerabilities to exploit attack that brings the tool.

W3af is multiplatform, as is written in python under the GNU license.

More info and download: w2af
..............................................................................

Se trata de w3af “Web Application Attack and Audit Framework”, esta herramienta es un conjunto de plugins agrupados por características. Los plugins se actualizan de forma periódica y están agrupados en la aplicación, en los siguientes apartados:

Auditoria: para auditar la seguridad de la aplicación. En este apartado destacan plugins como: detección SQL injection, detección XSS, detección SSI, detección Buffer Overflow, detección LDAP Injection…

Fuerza bruta: Son plugins para atacar mecanismos de autentificación por fuerza bruta.
Descubrimiento: Descubrir información sobre el sitio como nuevas URLs, usuarios, servidores… Utiliza plugins como: Hmap para http fingerprinting, fingerGoogle busca cuentas de usuario de la aplicación Web en google…

Evasión: Usados para evadir IDS.
Grep: analiza las respuestas del servidor a los plugins buscando: errores, cookies…

La interfaz tiene cuatro pestañas: configuración, log, resultados y exploit. Estas pestañas describen el proceso de test de penetración a una aplicación web. La pestaña de log muestra el proceso del escaneo. Cuando se acaba este proceso podemos ver su resultado en su correspondiente pestaña y si se encuentran vulnerabilidades, atacarlas con los exploit que trae la herramienta.

W3af es multiplataforma, ya que está escrita en python bajo licencia GNU.

Más información y descarga de:w2af

No hay comentarios:

Protected by Copyscape Original Article Checker