w3af
Tr4c3推荐
w3af is a Web Application Attack and Audit Framework. The project goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend. This project is currently hosted at SourceForge . For further information, you may also want to visit w3af SourceForge project page .
If you are here just to “take a look” these screenshots and videos will show you what w3af can do:
- OS commanding detection and exploit (console user interface) – Screenshot
- OS commanding and DAV misconfiguration detection and exploit (console user interface) – Screenshot
- Blind SQL Injection exploit (console user interface) – Screenshot
- OS commanding detection and exploit (pyGTK user interface) – Video
DNS漏洞续—-为什么我们需要全面披露
Bruce Schneier大师说,DNS漏洞的细节还是被提前披露了,人们开始撰写利用这一漏洞的攻击程序,等等。这里摘录一些比较精彩的内容,推荐您阅读原文。
然而,因此而对 Kaminsky 展开口诛笔伐显然是不对的。在圈外人士看来,也许如果他在这个事情上缄口不语,我们便不会有这许多的麻烦。这显然是不对的, Kaminsky 偶然发现了这个问题,他没有理由相信自己是第一个,更没有理由相信自己是最后一个发现这些问题的。问题出在 DNS 协议本身,而不是 Kaminsky。
阅读全文 »