Web漏洞利用框架和工具

  • BlindElephant - Web application fingerprinter.
  • Browser Exploitation Framework (BeEF) - Command and control server for delivering exploits to commandeered Web browsers.
  • Burp Suite - Integrated platform for performing security testing of web applications.
  • Commix - Automated all-in-one operating system command injection and exploitation tool.
  • DVCS Ripper - Rip web accessible (distributed) version control systems: SVN/GIT/HG/BZR.
  • EyeWitness - Tool to take screenshots of websites, provide some server header info, and identify default credentials if possible.
  • Fiddler - Free cross-platform web debugging proxy with user-friendly companion tools.
  • FuzzDB - Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
  • GitTools - Automatically find and download Web-accessible .git repositories.
  • Kadabra - Automatic LFI exploiter and scanner.
  • Kadimus - LFI scan and exploit tool.
  • NoSQLmap - Automatic NoSQL injection and database takeover tool.
  • OWASP Zed Attack Proxy (ZAP) - Feature-rich, scriptable HTTP intercepting proxy and fuzzer for penetration testing web applications.
  • Offensive Web Testing Framework (OWTF) - Python-based framework for pentesting Web applications based on the OWASP Testing Guide.
  • Raccoon - High performance offensive security tool for reconnaissance and vulnerability scanning.
  • SQLmap - Automatic SQL injection and database takeover tool.
  • VHostScan - Virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, aliases and dynamic default pages.
  • WPSploit - Exploit WordPress-powered websites with Metasploit.
  • Wappalyzer - Wappalyzer uncovers the technologies used on websites.
  • WhatWaf - Detect and bypass web application firewalls and protection systems.
  • WhatWeb - Website fingerprinter.
  • Wordpress Exploit Framework - Ruby framework for developing and using modules which aid in the penetration testing of WordPress powered websites and systems.
  • autochrome - Easy to install a test browser with all the appropriate setting needed for web application testing with native Burp support, from NCCGroup.
  • badtouch - Scriptable network authentication cracker.
  • fimap - Find, prepare, audit, exploit and even Google automatically for LFI/RFI bugs.
  • liffy - LFI exploitation tool.
  • recursebuster - Content discovery tool to perform directory and file bruteforcing.
  • sslstrip2 - SSLStrip version to defeat HSTS.
  • sslstrip - Demonstration of the HTTPS stripping attacks.
  • tplmap - Automatic server-side template injection and Web server takeover tool.
  • wafw00f - Identifies and fingerprints Web Application Firewall (WAF) products.
  • webscreenshot - Simple script to take screenshots of websites from a list of sites.
  • weevely3 - Weaponized PHP-based web shell.
©著作权归作者所有,转载或内容合作请联系作者
【社区内容提示】社区部分内容疑似由AI辅助生成,浏览时请结合常识与多方信息审慎甄别。
平台声明:文章内容(如有图片或视频亦包括在内)由作者上传并发布,文章内容仅代表作者本人观点,简书系信息发布平台,仅提供信息存储服务。

相关阅读更多精彩内容

  • rljs by sennchi Timeline of History Part One The Cognitiv...
    sennchi阅读 8,002评论 0 10
  • # Awesome Python [![Awesome](https://cdn.rawgit.com/sindr...
    emily_007阅读 2,398评论 0 3
  • Java技术版图-awesome-java aewsome-java是github上一个开源项目,搜集Java各领...
    静默虚空阅读 4,713评论 0 44
  • **2014真题Directions:Read the following text. Choose the be...
    又是夜半惊坐起阅读 11,778评论 0 23
  • 感觉班主任还不错。至于学生的话,花枝招展者众也,其中透露着冷漠,以我多年经验来看,恐不值得交,至于男同学,反倒可能...
    Blare_e722阅读 142评论 0 0

友情链接更多精彩内容