Powerfuzzer 's

admin 2017年4月22日14:39:32评论335 views字数 2287阅读7分37秒阅读模式
摘要

软件主页:http://powerfuzzer.sourceforge.net/ (via tr4c3)Powerfuzzer is a highly automated web fuzzer based on many other Open Source fuzzers available (incl. cfuzzer, fuzzled, fuzzer.pl, jbrofuzz, webscarab, wapiti, Socket Fuzzer) and information gathered from numerous security resources and websites. It is capable of spidering website and identifying inputs.

软件主页:http://powerfuzzer.sourceforge.net/ (via tr4c3)

Powerfuzzer is a highly automated web fuzzer based on many other Open Source fuzzers available (incl. cfuzzer, fuzzled, fuzzer.pl, jbrofuzz, webscarab, wapiti, Socket Fuzzer) and information gathered from numerous security resources and websites. It is capable of spidering website and identifying inputs.

Don’t have a clue what a Fuzzer/Fuzz testing is ? Not a problem, read on here

Currently, it is capable of identifying these problems:
– Cross Site Scripting (XSS)
– Injections (SQL, LDAP, code, commands, and XPATH)
– CRLF
– HTTP 500 statuses (usually indicative of a possible misconfiguration/security flaw incl. buffer overflow)

Designed and coded to be modular and extendable. Adding new checks should simply entail adding new methods.

Screenshots made during demo tests against ACUNETIX test website testphp.acunetix.com. Myself, as well as this project/website is not in affiliation with ACUNETIX in any shape and form.

Powerfuzzer  's
Main Screen

Powerfuzzer  's
Scanning

Powerfuzzer  's
Scanning with finding

Powerfuzzer  's
HTTP POST form scanning

Powerfuzzer  's
Final report with findings

Project news
06/21/2008 – Powerfuzzer v1 BETA available. Several bugfixes (see CHANGES.txt). Improved BASIC AUTH and Cookie support.

02/22/2008 – Yay … webbsite is ready. Feel free to dl the ALPHA version, some features don’t work quite well yet. Need volunteers to help. Please contact me if you’re intersted.

TODO
IMHO, In order of importance:

-add NTLM support

-add custom check field to GUI (you can specify parameters that should be passed to fuzzer module in the GUI interface)

-modularize checks perfomed by the scanning engine, so that users can add their customized checks/modules/plugins

-add threading to scanning engine (for super fast scanning)

-improve GUI/reporting

-documentation/tutorials

Talks
Yapa … Yapa …. Yapa

FAQ

Documentation
We are actively working on the documentation.

Prerequisites and Installation
It is platform independent, hence powerfuzzer should run on Windows/Linux/Unix (Tested on Windows XP SP2 and Linux). Install Python (Testted with Python 2.5), wxPython (Tested with wxPython 2.8), HTML Tidy Library, ctypes, TidyLib Python wrapper and you’re ready to go.

To start using the application unzip the package and double click, execute powerfuzzer.py

Mailing List
None yet

License
powerfuzzer is an Open Source software package. It is licensed under the GNU General Public License Version 2.

Download
You can download a release package with source code:

Here
Author(s)
The project leader is Marcin Kozlowski (marcinguy ‘@’ yahoo.com). He is an active contributor and researcher to Open Source projects and information security arena (tools, modules, exploits, research)

免责声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由读者承担全部法律及连带责任,本站不承担任何法律及连带责任;如有问题可邮件联系(建议使用企业邮箱或有效邮箱,避免邮件被拦截,联系方式见首页),望知悉。
  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2017年4月22日14:39:32
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   Powerfuzzer 'shttps://cn-sec.com/archives/45399.html
                  免责声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由读者承担全部法律及连带责任,本站不承担任何法律及连带责任;如有问题可邮件联系(建议使用企业邮箱或有效邮箱,避免邮件被拦截,联系方式见首页),望知悉.

发表评论

匿名网友 填写信息