Web应用程序测试框架(LiveCD) - Samurai
发布:wpulog | 发布时间: 2010年12月27日 Samurai Web测试框架是一个LiveCD,专注于web应用程序测试。Samurai中收集了最好的Web测试工具并将它们预先安装在系统中。Samurai是一个强大的web应用程序测试工具集,收集了最好的开源和免费的工具,用于Web程序的测试与攻击。SamuraiIn中的工具是开发者基于他们渗透测试实践选择的,他们将安全测试分为信息刺探阶段,工具包括:Fierce domain scanner和Maltego;网络映射,工具包括:WebScarab和ratproxy;漏洞发现,工具包括: w3af和burp;最后阶段,漏洞利用,工具包括:BeEF, AJAXShell等等更多。
工具更多信息及下载地址:http://sourceforge.net/projects/samurai/
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
SamuraiIn developing this environment, we have based our tool selection on the tools we use in our security practice. We have included the tools used in all four steps of a web pen-test.Starting with reconnaissance, we have included tools such as the Fierce domain scanner and Maltego. For mapping, we have included tools such WebScarab and ratproxy. We then chose tools for discovery. These would include w3af and burp. For exploitation, the final stage, we included BeEF, AJAXShell and much more. This CD also includes a pre-configured wiki, set up to be the central information store during your pen-test.
发表评论
◎欢迎参与讨论,请在这里发表您的看法、交流您的观点。



