WebApp Sec mailing list archives

Paros 3.2.9 release


From: contact () parosproxy org
Date: 14 Jan 2006 16:11:54 -0000

Paros 3.2.9 is released.  This version contains bug fix with several minor enhancements.  All users are recommended to 
upgrade to this version.

The new verison is available at http://www.parosproxy.org.

Bug reports and comments on Paros can be sent to [contact at parosproxy org].

[Installation]

If you have installed the old version on or after 3.2.4, you can directly install this new version.

If you are using version prior to 3.2.4, you should uninstall the old version first.

Default installation will use a maximum VM size of 64M. For large application testing, you may adjust it depending on 
your need
and the memory you have (eg 128M)


[introduction]

Paros is a man-in-the-middle proxy and application vulnerability scanner. It allows
users to intercept, modify and debug HTTP and HTTPS data on-the-fly between web
server and client browser. It also supports spidering, proxy-chaining, filtering
and application vulnerability scanning.


[License] - Clarified Artistic License (open source and GPL-compatible license)


[Details/new features]

3.2.9
=====
New
-       Continuous browser display when selecting in History panel.
-       Use final stable version of external library.
-       Record working directory for all subsequent file access within the same Paros instance.

Thanks to Christophe for the following:
-       Improved spider capability to crawl forms with textarea and handle links with "&"
-       Improved check for cross-site script without bracket.
-       Improved check for PHP error and MySQL.
-       Improved blind sql check on double quotes.

Fix
-       if request body contain certain binary bytes it may cause unnecessary encoding.  Fixed to always submit contain 
binary bytes.
-       better handling of accepted-encoding.

-------------------------------------------------------------------------
This List Sponsored by: Watchfire

Watchfire's AppScan is the industry's first and leading web application 
security testing suite, and the only solution to provide comprehensive 
remediation tasks at every level of the application. See for yourself. 
Download AppScan 6.0 today.

https://www.watchfire.com/securearea/appscansix.aspx?id=701300000003Ssh
--------------------------------------------------------------------------


Current thread: