No account yet?
Home » Downloads » Tools » Web App Security
Downloads
Web App Security
Categories
 
Documents
Order by : Name | Date | Hits [ Descendent ]
AttackAPI
AttackAPI Tooltip
Hits: 28
Date added: 12/02/2006
AttackAPI provides simple and intuitive web programmable interface for composing attack vectors with JavaScript and other client and server related technologies. This is the 2.x branch which among other improvements introduces better interaction with the attack subroutines. AttackAPI is standard part of many public and private security related projects hosted in GNUCITIZEN and other organizations. This library may be treated as open source (GPLv2) project although all visual elements are published under the Creative Commons Attribution-NonCommercial-NoDerivs 2.5 License. This library may only be used for experimental and demonstration purposes. GNUCITIZEN disclaims any responsibility for your own actions. This is JavaScript Web Pen testing tool. Visit the home page for more info.
Details
 
sqlmap
sqlmap Tooltip
Hits: 17
Date added: 12/25/2006
Sqlmap is an automatic blind SQL injection tool capable to enumerate entire remote database, perform an active database fingerprint and much more. The aim of this project is to implement a fully functional database mapper tool which takes advantages of web application security flaws.
Details
 
FPD
FPD Tooltip
Hits: 10
Date added: 01/18/2007
This tool retrieves and decrypts the Mozilla firefox passwords. Comes with Delphi Source Code.
Details
 
mod_evasive
mod_evasive Tooltip
Hits: 28
Date added: 02/09/2007
mod_evasive is an evasive maneuvers module for Apache to provide evasive action in the event of an HTTP DoS or DDoS attack or brute force attack. It is also designed to be a detection and network management tool, and can be easily configured to talk to ipchains, firewalls, routers, and etcetera. mod_evasive presently reports abuses via email and syslog facilities. Detection is performed by creating an internal dynamic hash table of IP Addresses and URIs, and denying any single IP address from any of the following: * Requesting the same page more than a few times per second * Making more than 50 concurrent requests on the same child per second * Making any requests while temporarily blacklisted (on a blocking list) This method has worked well in both single-server script attacks as well as distributed attacks, but just like other evasive tools, is only as useful to the point of bandwidth and processor consumption (e.g. the amount of bandwidth and processor required to receive/process/respond to invalid requests), which is why it's a good idea to integrate this with your firewalls and routers for maximum protection. This module instantiates for each listener individually, and therefore has a built-in cleanup mechanism and scaling capabilities. Because of this per-child design, legitimate requests are never compromised (even from proxies and NAT addresses) but only scripted attacks. Even a user repeatedly clicking on 'reload' should not be affected unless they do it maliciously. mod_evasive is fully tweakable through the Apache configuration file, easy to incorporate into your web server, and easy to use.
Details
 
ZmbScap
ZmbScap Tooltip
Hits: 19
Date added: 02/21/2007
The zombie scapper is an automated perl tool for detecting and stopping distributed denial of service programs. The tool automatically searches and scans the desired target for programs by looking for the ports that are used by the zombie masters. It stops the zombie masters by sending a kill/stop trigger. Detects/Kills the following programs 1. Stacheldhart Version 1 2. Stacheldhart Version 2 3. Wintrinoo 4. Mstream 5. Tribal Flood Network 6. Trinoo 7. Shaft 8. Trinitinty 9. Entitee Requires Net::RawIP and Net::Ping (optional) perl modules.
Details
 
<< Start < Prev 11 12 13 Next > End >>
Page 11 of 13

Downloads Home
Downloads Home
Search Document
Search Document

Get Archive RSS

The latest tools and texts wherever you are


Do you own a website?
Add these feeds to your site and get a link on our home page!

Newsletter


Every week our tools in your inbox?


Enter your Email


Preview

Security Services by HSC