PaulDotCom mailing list archives

Re: Code scanner


From: Kembolle Amilkar <haxorcoding () gmail com>
Date: Mon, 30 Jul 2012 11:25:01 -0400

hy glen!

- Depende muito da linguagem de programação que o senhor deseja! Vamos aos
exemplos:
ISO: http://www.iso27001security.com/html/site_map.html

# Owasp
ela possui bibliotecas seguras de desenvolvimento das aplicações seja movel
ou desktop.
https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API

já para realizar analise de vulnerabilidade depois da aplicação pronta o
senhor pode utilizar as aplicações de teste da owasp ( recomendo live-CD )
que foi desenvolvido exatamente para esta finalidade!
http://appseclive.org/content/downloads segue a lista de ferramentas para
utilização do código .

We _think_ this is the current tool list. We are in the process of
verifitying it.
Also, check here: http://appseclive.org/content/upcoming-livecd-changes to
see upcoming tool additions and changes.


   - 1 OWASP WebScarab<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#OWASP_WebScarab>
   - 2 OWASP WebGoat<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#OWASP_WebGoat>
   - 3 OWASP CAL9000<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#OWASP_CAL9000>
   - 4 OWASP JBroFuzz<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#OWASP_JBroFuzz>
   - 5 Paros Proxy<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Paros_Proxy>
   - 6 nmap & Zenmap<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#nmap_.26_Zenmap>
   - 7 Wireshark<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Wireshark>
   - 8 tcpdump<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#tcpdump>
   - 9 Firefox 3<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Firefox_3>
   - 10 Burp Suite<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Burp_Suite>
   - 11 Grenedel-Scan<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Grenedel-Scan>
   - 12 OWASP DirBuster<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#OWASP_DirBuster>
   - 13 OWASP SQLiX<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#OWASP_SQLiX>
   - 14 OWASP WSFuzzer<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#OWASP_WSFuzzer>
   - 15 Metasploit
3<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Metasploit_3>
   - 16 w3af & GTK GUI for
w3af<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#w3af_.26_GTK_GUI_for_w3af>
   - 17 Netcats
collection<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Netcats_collection>
   - 18 OWASP Wapiti<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#OWASP_Wapiti>
   - 19 Nikto<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Nikto>
   - 20 Fierce Domain
Scaner<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Fierce_Domain_Scaner>
   - 21 Maltego
CE<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Maltego_CE>
   - 22 Httprint<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Httprint>
   - 23 SQLBrute<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#SQLBrute>
   - 24 Spike Proxy<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Spike_Proxy>
   - 25 Rat Proxy<http://mtesauro.com/livecd/index.php?title=Current_Tool_List#Rat_Proxy>

*
*
*Espero que ajude! **Saudações. *
*
*
*Att. Kembolle Amilkar *
#/[ kembolle.com.br <http://www.kembolle.com.br> ] - Consultoria Segurança
da Informação.
#/ [ samurayconsultoria.com.br ] - Chief Security Officer - Samuray
Consultoria.
#/ Systems Analyst | Esp. Information Security | Computer Forensic Expert |
#/ Owasp Chapter Lider Cuiabá - https://www.owasp.org/index.php/Cuiaba
#/ Mobile: [65] 9979-2925  && contato[at]kembolle.com.br.
**
_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

Current thread: