更新:skipfish 1.92b
发布:wpulog | 发布时间: 2011年6月8日skipfish是Google推出的一款免费、开源、Web应用程序安全检测工具。skipfish主要特点:
High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint – easily achieving 2000 requests per second with responsive targets.
Ease of use: heuristics to support a variety of quirky web frameworks and mixed-technology sites, with automatic learning capabilities, on-the-fly wordlist creation, and form autocompletion.
Cutting-edge security logic: high quality, low false positive, differential security checks, capable of spotting a range of subtle flaws, including blind injection vectors.
目前skipfish已经更新至1.9.2b版,新版主要改变如下:
- Reading starting URLs from file is now supported (@ prefix).
工具下载:http://code.google.com/p/skipfish/downloads/detail?name=skipfish-1.92b.tgz&can=2&q=
发表评论
◎欢迎参与讨论,请在这里发表您的看法、交流您的观点。



