Интересный компактный набор (всего 460 KB) хакерских ключей содержит BURP (отрыжка?). В BURP suite входят следующие plugins: proxy, spider, intruder, repeater, а вскоре будет представлен ещё и scanner. Burp suite is an integrated platform for attacking web applications. It contains all of the burp tools (proxy, spider, intruder and repeater) with numerous interfaces between them designed to facilitate and speed up the process of attacking an application. All plugins share the same robust framework for handling HTTP requests, authentication, downstream proxies, logging, alerting and extensibility. Plugins можно скачать бесплатно и отдельно, кроме burp intruder. Здесь общее описание BURP suite и софт для Windows и Linux http://portswigger.net/suite/help.html http://portswigger.net/suite/burpsuite_v1.01.zip http://portswigger.net/suite/burpsuite_v1.01.tar.gz burp proxy - an intercepting HTTP/S proxy server which operates as a man-in-the-middle between the end browser and the target web application, allowing the user to intercept, inspect and modify the raw traffic passing in both directions. Здесь описание burp proxy и софт для Windows и Linux http://portswigger.net/proxy/help.html http://portswigger.net/proxy/burpproxy_v1.3.zip http://portswigger.net/proxy/burpproxy_v1.3.tar.gz burp spider - an intelligent application-aware web spider which allows complete enumeration of an application's content and functionality. Burp spider is a tool for enumerating web-enabled applications. It uses various intelligent techniques to generate a comprehensive inventory of an application's content and functionality. Здесь описание burp spider и софт для Windows и Linux http://portswigger.net/spider/help.html http://portswigger.net/spider/burpspider_v1.2.zip http://portswigger.net/spider/burpspider_v1.2.tar.gz burp intruder - a highly configurable tool to automate attacks against web applications. Burp intruder is a tool to facilitate automated attacks against web-enabled applications. It is not a point-and-click tool: using burp intruder effectively requires a detailed knowledge of the target application, and an understanding of the HTTP protocol. The free version of burp suite includes a demo version of burp intruder. Burp intruder is sold on a per-user basis, and each license costs 99 Pounds Sterling Здесь описание burp intruder http://portswigger.net/intruder/help.html burp repeater - a tool for manually manipulating and re-issuing individual HTTP requests, and rendering the application's responses. Before burp repeater can be used, the attacker needs to investigate the functionality and structure of the target application, and in particular the various HTTP messages which the application uses to communicate with the user's browser. This investigation can be performed using a standard browser and an interactive proxy tool, such as burp proxy. Each element of the application's functionality will typically use a number of HTTP requests which communicate information from the user's browser to the application server. Burp repeater is free. Здесь описание burp repeater и софт для Windows и Linux http://portswigger.net/repeater/help.html http://portswigger.net/repeater/burprepeater_v1.12.zip http://portswigger.net/repeater/burprepeater_v1.12.tar.gz burp scanner - a tool for performing automated vulnerability assessments of web-enabled applications. It can help to identify common vulnerabilities such as SQL injection, cross-site scripting and directory traversal. Хочу обратить Ваше внимание, что Burp suite это прекрасный набор ключей для тестирования Ваших сайтов и поиска слабых мест в Ваших разработках. Разработчик BURP suite скрывает своё имя, но поскольку он намерен продавать burp intruder, то можно провести небольшое исследование и установить что это английская компания-провайдер UK2 Group Ltd, director Bo Bendtsen.
|