what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 76 - 100 of 253 RSS Feed

Files

iExploder 1.7
Posted Sep 8, 2010
Authored by Thomas Stromberg | Site code.google.com

iExploder is like a fire hydrant full of bad HTML and CSS code to test the stability and security of web browsers. Available as a standalone webserver or CGI script, it continuously feeds browsers bad data in the hope that they will eventually crash. It is designed to run for hours, or even days until the browser crashes. namebench was initially written as a QA tool for the Mozilla Project to test the Firefox 1.0 release, and is now included and used by Apple's Webkit project.

Changes: A new browser-harness mode was added to stop and start browsers, replicate crash scenarios, and save minimized testcases. CSS selector fuzzing and support for Ruby 1.9.x were added. The tag dictionary was updated from Webkit and Mozilla source trees.
tags | web, cgi
systems | apple
SHA-256 | 31614c1344412dbb4611ffdcdc41d272c6411c887e652e52970749008a59e923
RewriteProxy Same-Domain Policy Bypass
Posted Jul 26, 2010
Authored by Noen | Site noen.svartboks.com

RewriteProxy is a small python tool that is based on the twisted library. Its purpose is to serve local files instead of remote files to fool the same-domain policy of modified flash and java-applets.

tags | java, remote, web, local, python
SHA-256 | eca6b434258f98306fbfe4e27f6f2f5a761dd5ee8cf65a55b9e18c282e184890
Apache mod_psldap Module 0.93
Posted Apr 21, 2010
Site sourceforge.net

mod_psldap is an Apache module that performs authentication and authorization against an LDAP server with LDAP based session management. It also provides Web 2.0 based capabilities to add, edit, move, and create new records in the LDAP store, leveraging XSL stylesheets to offload heavy processing to the clients and reduce bandwidth consumption by up to 95% or more.

Changes: This release provides new core capabilities to support new actions to register users. It also adds LDAP attributes and client side drag and drop editing of the LDAP records to reassign records to superiors, people to managers, and members to groups. A client side form validation framework was introduced, which simplifies validation through leverage of custom attributes on the input elements.
tags | web
SHA-256 | 41e6461d2c3d8d11aae52da0ed3fb1268f990398109b089181f992a02eccefc6
Man-In-The-Middle Proxy 0.2
Posted Apr 9, 2010
Site corte.si

MITMProxy is an interactive, SSL-aware HTTP proxy that allows viewing, modification and replaying of requests.

tags | web
SHA-256 | 3c27bce82ee0b9e7856fd7eb86e02050cc1d43711f1f662f02ce1eeb8abda9f6
Apache mod_psldap Module 0.92
Posted Apr 6, 2010
Site sourceforge.net

mod_psldap is an Apache module that performs authentication and authorization against an LDAP server with LDAP based session management. It also provides Web 2.0 based capabilities to add, edit, move, and create new records in the LDAP store, leveraging XSL stylesheets to offload heavy processing to the clients and reduce bandwidth consumption by up to 95% or more.

Changes: This is a bug fix release to address variations on the initially tested configurations. It also restores isolation of site specific configurations to simplify an upgrade.
tags | web
SHA-256 | 100bdf5e1d045107171c2afce229a7edc1206398e366c182a682d2435c79eb43
iExploder 1.5
Posted Mar 16, 2010
Authored by Thomas Stromberg | Site code.google.com

iExploder is like a fire hydrant full of bad HTML and CSS code to test the stability and security of web browsers. Available as a standalone webserver or CGI script, it continuously feeds browsers bad data in the hope that they will eventually crash. It is designed to run for hours, or even days until the browser crashes. namebench was initially written as a QA tool for the Mozilla Project to test the Firefox 1.0 release, and is now included and used by Apple's Webkit project.

tags | web, cgi
systems | apple
SHA-256 | 073eb39b59a7fa50f9bcd91b589106f80f8fa23aadab7802e7e0294944978450
Cookie Monster 1.6
Posted Mar 11, 2010
Authored by Tom Neaves | Site tomneaves.com

Cookie Monster is a cookie analysis tool written in Python. Cookie Monster will grab cookies from a host and assign each character a number. This number can be used to perform mathematical calculations on the differences in order to find a pattern and see if cookie prediction is possible.

tags | web, python
SHA-256 | 2ea212371ff52f7cdc5a9a96dc54b6d8e61438beb08855caa82fdf7b84a5f569
Dradis Information Sharing Tool 2.5.0
Posted Feb 6, 2010
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

Changes: The Note editor (Textile) was improved. An HTML export plugin was added for producing reports in HTML format. A Nikto Upload plugin was added. A Burp Upload plugin was added. The "First Time User Wizard" introduction was improved. You can keep track of all the activity with the built-in RSS feed. A new Rake task was added: dradis:backup. Rake dradis:reset now creates a backup of the project by default. Rake dradis:reset now clears the old log files. The structure of the Nmap Upload plugin data was improved. The ExtJS 3.0 and Rails 2.3.5 libraries were upgraded. Bugs were fixed.
tags | web
SHA-256 | 6aa5c7bee5feba563d7a4c7e7153dd36d919758b69278e3d235c5ed61adc7bbb
Pound-2.5.tgz
Posted Feb 4, 2010
Authored by roseg | Site apsis.ch

Pound is a reverse HTTP proxy, load balancer, and SSL wrapper. It proxies client HTTPS requests to HTTP backend servers, distributes the requests among several servers while keeping sessions, supports HTTP/1.1 requests even if the backend server(s) are HTTP/1.0, and sanitizes requests.

Changes: New features include support for HTTPS back-end servers, full support for DH key exchange, an "include" directive in configuration files, support for separate connection time-out, much improved auto-configuration and Make, and flags to enable or disable optional libraries. A bunch of minor bugs were fixed. Performance was improved.
tags | web
SHA-256 | ed247a23a4a721231ab601cb13642ba322e0aeee864ee320958bfabf405c7869
Squipy Proxy Server 1.2
Posted Feb 2, 2010
Authored by Pepelux | Site pepelux.org

Squipy is a proxy server that allows you to capture and modify HTTP traffic.

tags | web
SHA-256 | a9b89ba7b14dd63268ecdafb6173cf172d87074e953088ec884dac7dae401937
phpAV Code Auditing Tool 1.1
Posted Jan 7, 2010
Authored by Milos Zivanovic

phpAV is a script designed to work as antivirus for malicious PHP scripts. It will search a given directory and related files for dangerous functions and provide a report.

tags | web, php
SHA-256 | 68ab3725b4466890a2330c5c5dd11622666a09c408af5bb5c60f44d048036ba0
phpAV Code Auditing Tool 1.0
Posted Jan 5, 2010
Authored by Milos Zivanovic

phpAV is a script designed to work as antivirus for malicious PHP scripts. It will search a given directory and related files for dangerous functions and provide a report.

tags | web, php
SHA-256 | 52ba58c54f23247b703f406196191b4b06961a14a63f73da8e5e630962be128a
Dradis Information Sharing Tool 2.4.1
Posted Nov 3, 2009
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

Changes: This release fixes several bugs in the client and server components.
tags | web
SHA-256 | 303b1f5e9a3f6d4e4a2dc0c2be86ade9e859fe5050f268725ed11ecbd17e261d
Dradis Information Sharing Tool 2.4.0
Posted Sep 11, 2009
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

Changes: In the server component, you can drag\'n\'drop your notes. New Rake tasks were added to backup the project, reset the environment, etc. The upload plugin gives better feedback in case of an exception. Nmap Upload now uses the Nmap::Parser library. A plugin was added to import data from the OSVDB. Bugs were fixed in the client component.
tags | web
SHA-256 | 66b866e356a910a6068f3db98437de71ecd2498a176f2a70a9dfb180147619e4
Dradis Information Sharing Tool 2.2.0
Posted Jun 12, 2009
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

Changes: The following changes were made to the server component: Attachments can be added to nodes. "Refresh" buttons were added to the tree and the notes list. The use of "webrick" is forced even if mongrel is installed, since there is no SSL support in mongrel. The framework version information was centralized. autoExpandColumn now works on IE. Rails runs in "production" mode. The following changes were made to the client component: dradis can be used with wxRuby 2.0.0. Error handling was improved for REST Web service communication errors. REST credentials configuration in ./conf/dradis.xml was made easier.
tags | web
SHA-256 | 56becee9922782acdeeeed9b6cfea60cfef8ff24b8ebb8aada68448d415c2dbe
Dradis Information Sharing Tool 2.1.0
Posted Apr 17, 2009
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

Changes: The server component now features an import/export plugin architecture, import/export plugin generators, a sample WordXML export plugin, and a sample WikiMedia import plugin. The client component now features an import extension that allows nmap output to be imported, the ability to import a note from a plain text file, and more a powerful add extension that can add a note from the console.
tags | web
SHA-256 | 9698e24363a7d65cae731214e6a604f6137e86c4f67d24b20706cc5097f13aaa
URLCrazy Domain Name Typo Tool 0.2
Posted Apr 1, 2009
Authored by Andrew Horton | Site morningstarsecurity.com

UrlCrazy is for the study of domainname typos and URL hijacking. It generates domainname typo permutations then tests them to learn if they are in use, estimates their popularity and more. Typo types supported are: Character Omission, Adjacent Character Swap, Adjacent Character Replacement, Adjacent Character Insertion, Missing Dot, Strip Dashes, Singular or Pluralise. Urlcrazy is written in Ruby.

tags | tool, web, ruby
SHA-256 | 0accacdc470f20231ead2b7d06716604bea1e9f5beeab45ef44e05d06c52df45
Dradis Information Sharing Tool 2.0.1
Posted Feb 25, 2009
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

Changes: First security patch. Minor bug fixes. Some additions.
tags | web
SHA-256 | a6f9a40c9bbde3778c9c523f59e469d3dabfeadfc17dc95a8b955cf93d81a15f
Dradis Information Sharing Tool 2.0.0
Posted Jan 30, 2009
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

tags | web
SHA-256 | ed8320d7c1b09d109df4958e6a9fde00f7391f39effceb85531ad23b1ea54f37
squid-nufw-helper-1.1.3.tar.gz
Posted Nov 24, 2008
Authored by Vincent Deffontaines

squid-nufw-helper is an external ACL helper for Squid that provides Single Sign On capabilities. It uses the NuFW firewall suite and supports the NuFW users SQL logging scheme. The module allows for strict SSO identification and authentication of users on any Squid proxy, including transparent proxies.

Changes: -a switch now useless. Handles automatic reconnection to MySQL sever.
tags | web
SHA-256 | 6984d7dad2acd7450b71ddbbf835596ee118502ab5eca1dd473c04e3701cc2e3
unicode-fun.txt
Posted Sep 11, 2008
Authored by Gary O'Leary-Steele | Site sec-1.com

Ruby Script to generate URL encoded Unicode UTF-8 URL.

tags | web, ruby
SHA-256 | 3716b2b24def26545bf37991157e555c96d9f13dc08744a8b8168ccd6d3bd237
surfjack-0.1b.zip
Posted Aug 13, 2008
Authored by Sandro Gauci | Site enablesecurity.com

surfjack is a tool that allows you to hijack HTTP connection to steal cookies.

tags | web
SHA-256 | 65a1c73679412a460412df6144fbf8de78ac5c5048437c0211b5eee605f5abbd
browserrecon-1.0-php.tar.gz
Posted May 9, 2008
Authored by Marc Ruef | Site computec.ch

browserrecon is a framework that performs client-side HTTP fingerprinting. Be sure to hit their site to download the latest fingerprints database.

tags | web
SHA-256 | d37d7efea8951475554a42f5248c7e1de2b4115e3f323ebdd096383e01fbbb38
Dradis Information Sharing Tool 1.2
Posted May 7, 2008
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

tags | web
SHA-256 | 2851229d6d96c3f46c369880a065f21a90bc2f811297c7114f9152e9648c7f1d
Pound-2.4.tgz
Posted Feb 11, 2008
Authored by roseg | Site apsis.ch

Pound is a reverse HTTP proxy, load balancer, and SSL wrapper. It proxies client HTTPS requests to HTTP backend servers, distributes the requests among several servers while keeping sessions, supports HTTP/1.1 requests even if the backend server(s) are HTTP/1.0, and sanitizes requests.

Changes: Various bug fixes and enhancements.
tags | web
SHA-256 | 3fdb9f6a2e4f4646412d216fe0fcb346a9be274fb9908dd7dc186b6361ba7fd5
Page 4 of 11
Back23456Next

Top Authors In Last 30 Days

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close