Powerfuzzer is a highly automated and fully customizable web fuzzer
(HTTP protocol based application fuzzer) based on many other Open
Source fuzzers available and information gathered from numerous
security resources and websites. It was designed to be user
friendly, modern, effective and working.
Don't have a clue what a Fuzzer/Fuzz testing is ? Not a problem,
read on
here
Currently, it is capable of
identifying these problems:
- Cross Site Scripting (XSS)
- Injections (SQL, LDAP, code, commands, and XPATH)
- CRLF
- HTTP 500 statuses (usually indicative of a possible
misconfiguration/security flaw incl. buffer overflow)
Designed and coded to be modular and extendable. Adding new checks
should simply entail adding new methods.
Source -
0 comments:
Post a Comment