Samurai Web测试框架是一个LiveCD,专注于web应用程序测试。Samurai中收集了最好的Web测试工具并将它们预先安装在系统中。Samurai是一个强大的web应用程序测试工具集,收集了最好的开源和免费的工具,用于Web程序的测试与攻击。SamuraiIn中的工具是开发者基于他们渗透测试实践选择的,他们将安全测试分为信息刺探阶段,工具包括:Fierce domain scanner和Maltego;网络映射,工具包括:WebScarab和ratproxy;漏洞发现,工具包括: w3af和burp;最后阶段,漏洞利用,工具包括:BeEF, AJAXShell等等更多。
工具更多信息及下载地址:http://sourceforge.net/projects/samurai/
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    SamuraiIn developing this environment, we have based our tool selection on the tools we use in our security practice. We have included the tools used in all four steps of a web pen-test.Starting with reconnaissance, we have included tools such as the Fierce domain scanner and Maltego. For mapping, we have included tools such WebScarab and ratproxy. We then chose tools for discovery. These would include w3af and burp. For exploitation, the final stage, we included BeEF, AJAXShell and much more. This CD also includes a pre-configured wiki, set up to be the central information store during your pen-test.