NOWASP (Mutillidae) has been tested/attacked with Cenzic Hailstorm ARC, W3AF, SQLMAP, Samurai WTF, Backtrack, HP Web Inspect, Burp-Suite, NetSparker Community Edition, and oth
Features :
- Mutillidae can be installed on Linux, Windows XP, and Windows 7 using XAMMP making it easy for users who do not want to install or administrate their own webserver.
- Installs easily by dropping project files into the "htdocs" folder of XAMPP.
- Preinstalled on Rapid7 Metasploitable 2
- Preinstalled on Samurai Web Testing Framework (WTF)
- Has dozen of vulnerablities and challenges. Contains at least one vulnearbility for each of the OWASP Top Ten 2007 and 2010
- System can be restored to default with single-click of "Setup" button
- Switches between secure and insecure mode
- Secure and insecure source code for each page stored in the same PHP file for easy comparison
- Used in graduate security courses, in corporate web sec training courses, and as an "assess the assessor" target for vulnerability software
- Contains 2 levels of hints to help users get started
- Instructional Videos: http://www.youtube.com/user/webpwnized
- Updates tweeted to @webpwnized
- Mutillidae has been tested/attacked with Cenzic Hailstorm ARC, W3AF, SQLMAP, Samurai WTF, Backtrack, HP Web Inspect, Burp-Suite, NetSparker Community Edition, and other tools
Change Log for NOWASP 2.3.2 (Codename: Mutillidae):
- Added large amount of code to help users who have database issues of some type or users unfamiliar with MySQL
- Made change to bubble hint hanlder to return error message if hint retrieval fails rather than allow page to fail
- Added new page database-offline.php to handle database error
- Added database error detection to setup scripts
- Changed how the database connection occurs. The MySQLHandler splits the connection to the database server and OWASP10 database into separate steps to help the user have a better chance of detecting issues. This allows the index.php page to connect later in the process as well.
- Improved database connection in log handler
- Changed database configuration to static properties
- Added method connectToDefaultDatabase() to SQL Handler class
Download :
LATEST-mutillidae-2.3.2.zip (7.2 MB)
For more information on existing Version
Visit Website :
For more information on existing Version
Visit Website :
0 comments:
Post a Comment