Penetration Testing mailing list archives

ProxyStrike v2.0 released


From: Christian Martorella <cmartorella () edge-security com>
Date: Tue, 17 Mar 2009 23:42:46 +0100

Im please to announce a new version of ProxyStrike, an active Web Application Proxy, is a tool designed to find vulnerabilities while browsing an application. It was created because the problems we faced in the pentests of web applications that heavily depends on Javascript, not many web scanners did it good at this stage, so we came with this proxy.

Right now it has available Sql injection, XSS and Server side includes.

Features:

        • Plugin engine (Create your own plugins!)
        • Request interceptor
        • Request diffing
        • Request repeater
        • Automatic crawl process
        • Save/restore session
        • Http request/response history
        • Request parameter stats
        • Request parameter values stats
        • Request url parameter signing and header field signing
        • Use of an alternate proxy (tor for example ;D )
        • Attack logs
        • Export results to HTML or XML
        * Sql attacks (plugin)
        • Server Side Includes (plugin)
        • Xss attacks (plugin)

Check it at:  http://www.edge-security.com/proxystrike.php

Thanks to  Carlos del Ojo for this new release

Regards,

Christian Martorella
------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Learn all of the latest penetration testing techniques in InfoSec Institute's Ethical Hacking class.
Totally hands-on course with evening Capture The Flag (CTF) exercises, Certified Ethical Hacker and Certified 
Penetration Tester exams, taught by an expert with years of real pen testing experience.

http://www.infosecinstitute.com/courses/ethical_hacking_training.html
------------------------------------------------------------------------


Current thread: