Who's Online
There are currently, 187 guest(s) and 0 member(s) that are online.
You are Anonymous user. You can register for free by clicking here
|  |
The Professional Security Testers Warehouse for the CEH V7 GPEN CPTS CREST GCIH GREM OPST: Web Applications Security
[ Go to Home | Select a New Topic ] |
|
The Open Web Application Security Project (OWASP) is a 501c3 not-for-profit worldwide charitable organization focused on improving the security of application software. Our mission is to make application security visible, so that people and organizations can make informed decisions about true application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.
All Long Island chapter meetings are free. Please water our calendar for up coming events.
For more info contact: Helen Gao (helen.gao@wasp.org)
https://www.owasp.org/index.php/Long_Island
Hi guys, This is just to let you know that there's a new version of Arachni. Arachni is a high-performance (Open Source) Web Application Security Scanner Framework written in Ruby. This version includes lots of goodies, including: * A new light-weight RPC implementation (No more XMLRPC) * High Performance Grid (HPG) -- Combines the resources of multiple nodes for lightning-fast scans * Updated WebUI to provide access to HPG features and context-sensitive help * New plugins * ReScan — It uses the AFR report of a previous scan to extract the sitemap in order to avoid a redundant crawl. * BeepNotify — Beeps when the scan finishes. * LibNotify — Uses the libnotify library to send notifications for each discovered issue and a summary at the end of the scan. * EmailNotify — Sends a notification (and optionally a report) over SMTP at the end of the scan. * Manual verification — Flags issues that require manual verification as untrusted in order to reduce the signal-to-noise ratio. * Resolver — Resolves vulnerable hostnames to IP addresses. * Accuracy improvements and bugfixes for the XSS, SQL Injection and Path Traversal modules * New report formats (JSON, Marshal, YAML) * Cygwin package for Windows For a more detailed walk-through of what's new check-out: http://trainofthought.segfault.gr/2012/01/07/arachni-v0-4-is-out/ Details at: http://arachni.segfault.gr/latest ChangeLog: http://arachni.segfault.gr/latest#v0.4 Homepage: http://arachni.segfault.gr Github page: http://github.com/zapotek/arachni Documentation: http://github.com/Zapotek/arachni/wiki Google Group: http://groups.google.com/group/arachni Author: Tasos "Zapotek" Laskos Twitter: http://twitter.com/Zap0tek Copyright: 2010-2012 License: GNU General Public License v2 All available installation options and usage instructions can be found in the homepage and the GitHub page. I hope that you find it useful. If you run into any problems or want to make a suggestion or feature request the following pages will allow you to do so: https://github.com/Zapotek/arachni/issues http://groups.google.com/group/arachni Cheers, Tasos "Zapotek" Laskos.
iSEC Partners Releases SSLyze to test your TLS and/or SSL setup Posted by cdupuis on Saturday, 05 November 2011 @ 17:52:47 EDT (619 reads) Topic Web Applications Security
Anonymous writes "Transport Layer Security (TLS) and the Secure Socket Layer commonly called SSL, is one of the most widely used protocols to secure network communications. As costs fall and user security and privacy expectations rise companies are deploying it more widely every year. Attacks against the CA system, SSL implementation flaws and aging protocol versions have grabbed news headlines, bringing attention to weak configurations, and the need to avoid them. Additionally, server misconfigurations have always greatly increased the overhead caused by SSL, slowing the transition to improved communications security.
To help improve system configurations, iSEC is releasing the free software “SSLyze” tool. We have found this tool helpful for analyzing the configuration of SSL servers and for identifying misconfigurations such as the use of outdated protocol versions, weak hash algorithms in trust chains, insecure renegotiation, and session resumption settings.
SSLyze is a stand-alone python application that looks for classic SSL misconfigurations, while providing the advanced user with the opportunity to customize the application via a simple plugin interface. Right now it supports the following features:
- Insecure renegotiation testing
- Scanning for weak strength ciphers
- Checking for SSLv2, SSLv3 and TLSv1 versions
- Server certificate information dump and basic validation
- Session resumption capabilities and actual resumption rate measurement
- Support for client certificate authentication
- Simultaneous scanning of multiple servers, versions and ciphers
For example, SSLyze can help user’s identify server configurations vulnerable to THC’s recently released SSL DOS attack (http://www.thc.org/thc-ssl-dos/) by checking the server’s support for client-initiated renegotiations. For more information on testing for client-initiated renegotiations, see: http://code.google.com/p/sslyze/wiki/ThcSslDOS
The project is hosted on Google Code at the following URL: http://code.google.com/p/sslyze/
Thanks and we hope our tool helps you quickly discover SSL issues in your environment!
- Alban Diquet
- Aaron Grattafiori
Note: for questions or comments about the tool, please email sslyze@isecpartners.com.
"
Anonymous writes "Hi, I've released an update to Agnitio which I hope will help people to carry out security focused code reviews and find vulnerabilities in the source code they are reviewing. The major changes in v2.1 are listed below: 1) Windows x64 support 2) Automatically decompile Android .apk application to easily analyse the apps source code 3) Application profiles now have an application type of either web or mobile which allows only relevant checklist items to be displayed during the security code review 4) Create new checklist questions and mark them as web or mobile 5) C# and Java rules from the OWASP Code Crawler project have been imported into the Agnitio database and linked to relevant checklist questions Plus lots of small user requested changes. For more information on the changes in this release please visit this page: https://www.securityninja.co.uk/application-security/agnitio-security-code-review-tool-v2-1-released/ You can download Agnitio v2.1 here: https://sourceforge.net/projects/agnitiotool/files/v2.1/ Let me know what you think of it! Dave "
Anonymous writes "Hi everyone, I'm receiving good feedback, bugs reports and suggestions. Keep going...
I did a new version of xTSCrack Some new features: + Supported clients: Windows 2000, XP, Vista, 2003 and 7 + Supported servers: Windows 2000, Windows XP, Windows 2003 and Windows 2008 + Port field added; + Stop bug fixed. Now you can audit rdp servers running on different port. Stay updated at my blog because always new releases come out: http://atrixteam.blogspot.com/2011/10/xtscrack-06-released.html Published applications: - xSQLScanner - xSHA1 Crack - xMD5 Crack - xTSCrack Coming soon: - xGHDB - Google Hacking Database Tool - xAuditor - Tool to audit hosts based on CIS & NIST checklists - xSQLScanner 1.4 (Exploit section added. I'm building the modules) - xWin Crack - NT & LM Hash password recovery tool and more. Cya folks. "
St. Cloud State University wins OWASP AppSec USA 2011 University Challenge Posted by cdupuis on Wednesday, 19 October 2011 @ 09:09:10 EDT (675 reads) Topic Web Applications Security
Students win prestigious challenge
Monday, October 17, 2011
Seven St. Cloud State students won the Open Web Application Security Project AppSec USA 2011 University Challenge held at the Minneapolis Convention Center Sep. 21-22. The winners are majoring in Network Information Security at the Computer Networking and Applications (IT) program.
"This is another great achievement by students in the CNA (IT) program after winning the Minnesota Cyber Defense competition in March," said Tirthankar Ghosh, associate professor at the Department of Computer Science and Information Technology. "This is a moment of pride for all of us, a moment of pride for SCSU."
The St. Cloud State team not only won the overall competition but also scored the highest on the "attack portion" of this application security university challenge. The competition was divided into two challenges – security penetration and security defense. In the first challenge, the students had to break into a number of websites provided to them, identify their security vulnerabilities and suggest solutions to fix them. In the second challenge, the teams had to set up a virtual store, identify any weaknesses in the code and resolve them by providing new programming changes to the code.
"These challenges gave us a well-rounded experience of a security professional, both with being able to attack as well as to defend web applications," said junior Joshua Platz, St. Cloud.
The other members of the winning team were senior Jake Soenneker, Clear Lake, senior Derek Winter, Champlin, senior Eric Kluthe, Apple Valley, junior Ryan McDougall, Monticello, junior Matthew Sitko, Mahtomedi and junior George Massawe, Mason City, Iowa
http://www.stcloudstate.edu/news/newsrelease/default.asp?pubID=3&issueID=31494&storyID=36589
BackBox Linux 2 penetration testing distribution released Posted by cdupuis on Monday, 12 September 2011 @ 02:56:02 EDT (1014 reads) Topic Web Applications Security
Anonymous writes "As seen on the H Security News mailing list:
BackBox Linux 2 in action
The BackBox development team has released version 2.0 of its penetration testing distribution. According to the developers, the latest release has a new look and feel, as well as a significant performance boost over previous versions.

Based on Ubuntu 11.04 "Natty Narwhal", BackBox 2 includes the 2.6.38 Linux kernel and version 4.8.0 of the Xfce desktop environment. The release adds three new security audit sections: Vulnerability Assessment, Forensic Analysis and VoIP Analysis.
Other changes include new and updated hacking tools, an improved system menu and various bug fixes. Firefox 6.0.1, Thunderbird 3.1.13, version 2.7.11 of the Pidgin IM client, AbiWord and version 2.13 of the Transmission BitTorrent client are among the included packages.
More details about the release, including system requirements, can be found in the official release announcement. BackBox 2 is available to download for 32- and 64-bit systems from the project's mirrors. "
Anonymous writes "What is the Purpose of spotthevuln.com
Spotthevuln.com was designed to give developers more insight into designing code with security in mind.
When developers write source code they rarely think about security.
After insecure code is deployed,one of two things can happen.
- The bug can be found,in which case the developers have to waste development time in order to rewrite their solutions.
- The vulnerability is exploited,and the organization loses money,consumer trust,and can gain a negative reputation to their brand.
These problems can be avoided if the developers wrote the code correctly (securely) the first time.
Spotthevuln.com can aid developers,development managers,and QA staff by helping them sharpen their skills in spotting vulnerabilities in source code.
Spotthevuln.com use actual code snippets from open source applications to demonstrate how often vulnerable pieces of code get deployed into the real world.
The purpose is simple:
- Every Monday a vulnerable piece of code is posted.
- Every Friday the solution is posted.
On Monday,look at the piece of the code to see if you can identify what the security vulnerability is. Like everything else being able to spot vulnerable code takes practice.
Doing this exercise should take between 5 and 10 minutes out of your day. Do it while you drink your morning coffee and you will already be on your way to being able to write more secure applications.
The more secure code is,the better off we will all be.
Visit the website at: http://spotthevuln.com/ "
Version 1.3.0 of the OWASP Zed Attack Proxy (ZAP) has now been released Posted by cdupuis on Wednesday, 15 June 2011 @ 01:00:00 EDT (1687 reads) Topic Web Applications Security
Anonymous writes "Hi folks, Version 1.3.0 of the OWASP Zed Attack Proxy (ZAP) has now been released. ZAP is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. This release adds the following main features: Fuzzing, using the JBroFuzz library Dynamic SSL Certificates Daemon mode and API BeanShell integration Full internationalization Out of the box support for 10 languages For more information and to download this release please visit the ZAP homepage at:
http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project I will also be presenting "An Introduction to the OWASP Zed Attack Proxy" at OWASP AppSec EU on Friday 10th June. Many thanks to everyone who contributed code, language files, enhancement requests, bug reports and general feedback.
Psiinon "
Anonymous writes "Burp Suite Free Edition v1.4 is now available to download from http://portswigger.net/ This is a major upgrade with numerous new features, including: - The ability to compare site maps - Functions to help with testing access controls using your browser - Support for preset request macros - Session handling rules to help you work with difficult situations - In-browser rendering of responses from all Burp tools - Auto recognition and rendering of character sets - Support for upstream SOCKS proxies - Headless mode for unattended scripted usage - Support for more types of redirection - Support for NTLMv2 and IPv6 - Numerous enhancements to Burp's extensibility - Greater stability on OSX Read more details here: http://blog.portswigger.net/2011/06/burp-suite-free-edition-v14-released.html Cheers
PortSwigger "
Since our latest w3af release in mid January, and our new windows installer release a couple of months ago, we've got lots of encouraging words telling us we are going in the right direction. The objective was near and we could almost taste it. Having a stable code-base is no joke, it requires countless hours of writing unit-tests, running w3af scripts and most importantly: fixing bugs.
Now, finally we're here! In this latest release, we bring you a couple of the most important improvements of our framework: * Stable code base, an improvement that will reduce your w3af crashes to a minimum. We've been working on fixing all of our long-standing bugs, wrote thousands of lines of doctests and various types of automation to make sure we can also keep improving without breaking other sections of the code. * Auto-Update, which will allow you to keep your w3af installation updated without any effort. Always get the latest and greatest from our contributors! * Web Application Payloads, for people that enjoy exploitation techniques, this is one of the most interesting things you'll see in web application security! We created various layers of abstraction around an exploited vulnerability in order to be able to write payloads that use emulated syscalls to read, write and execute files on the compromised web server. Keep an eye on the rapid7 community blog an entry completely dedicated to this subject! * PHP static code analyzer, as part of a couple of experiments and research projects, Javier Andalia created a PHP static code analyzer that performs tainted mode analysis of PHP code in order to identify SQL injections, OS Commanding and Remote File Includes. At this time you can use this very interesting feature as a web application payload. After exploiting a vulnerability try: "payload php_sca", that will download the remote PHP code to your box and analyze it to find more vulnerabilities! And many others, such as:
* Refactoring of HTTP cache and GTK user interface code to store HTTP requests only once on disk (5% performance improvement)
* Performance improvement in sqlite database by using indexes (1% performance improvement)
* Huge w3af code-base refactoring on how URLs are handled. Moved away from handling URLs as strings into a url_object model. This reduces the number of times a URL is parsed into its component pieces (protocol, domain, path, query string, etc.) and put back together into a string, which clarifies the code and makes it run faster. We have a stable release, w0000t! Hmmmm.... have we finished? Should we go home? No! We still have work to do; there are still features and capabilities we'd like to add. For example,as you read this, we're working on integrating the multiprocessing module into w3af's code, with the objective of using more than one CPU core at the same time and substantially improve our scanning speed. We're also working on handling of encodings by the use of unicode strings across the whole framework, and making the user experience more intuitive in the UI. As usual, you can get our latest installable packages from the w3af.com website! Just download and enjoy our latest improvements! http://w3af.sourceforge.net/#download Regards, -- Andrés Riancho Director of Web Security at Rapid7 LLC Founder at Bonsai Information Security Project Leader at w3af
Arachni v0.2.3 has been released (Open Source Web Application Security Scanner) Posted by cdupuis on Monday, 23 May 2011 @ 07:54:01 EDT (1332 reads) Topic Web Applications Security
Anonymous writes "Pen Testing Perfect Storm VI: "We Love Cisco!" with Ed Skoudis, Joshua Wright, and Kevin Johnson
• Date: Tuesday, March 22, 2010
• Time: 2pm EDT/ 11am PDT (GMT -4:00, New York)
• Click here to register http://ws.coresecurity.com/PerfectStormPartVIC.html
*** A recording of the webcast will be sent to everyone who registers, so be sure to sign up even if you can't make the live session. ***
Networking equipment is a key IT security concern because of its strategic role in isolating systems and data from unauthorized access. An attacker with control over router configuration could gain access to networks that otherwise would be undetectable, while command of a switch could allow them to quietly steal, manipulate and inject data.
During this webcast, security swashbucklers Ed Skoudis, Joshua Wright and Kevin Johnson will return with more penetration testing madness and demonstrate techniques that you can use to proactively assess the security of Cisco networking equipment throughout your organization.
Click here to register http://ws.coresecurity.com/PerfectStormPartVIC.html
You'll learn how to ...
- Use XSS vulns and Project Yokoso to discover Cisco-centric management interfaces
- Abuse web interfaces for infrastructure control
- Leverage SNMP-to-telnet access escalation for switch pwnage
- Conduct privilege escalation with switch mirror ports
- Engage in VLAN hopping for fun and profit
- Set up your own virtual routing lab for practice and testing
Like all Perfect Storm webcasts, part VI will go beyond simple vulnerability exploitation and show you how to replicate multiple stages of an attack - from identifying and profiling exposed systems to gaining root and gathering data for reporting and remediation.
Click here to register http://ws.coresecurity.com/PerfectStormPartVIC.html "
Anonymous writes "Hi everybody, we want to announce that we just released version 0.9.6 of WATOBO - The Web Application Toolbox (http://watobo.sourceforge.net).
WATOBO is intended to enable security professionals to perform highly efficient (semi-automated) web application security audits. -- NEW -- * General: Supports One-Time-Tokens (e.g. Anti-CSRF-Tokens) * General: NTLM Authentication (Server and Proxy) * New Plugin: FileFinder * GUI: switch the icon and text size for lower screen resolution * Manual Request Editor: Table-View for easier parameter manipulation -- CONTRIBUTIONS -- :)) Many thanks to Hans-Martin Muench who contributed two active-check modules! * modstatus.rb: Check for status page created by mod_status * crossdomain.rb: Check for crossdomain.xml weaknesses !! NOTE !! Due to the import fix you can't import older WATOBO sessions! -- Documentation -- Watch the video tutorials on our project page for further information < http://sourceforge.net/apps/mediawiki/watobo/index.php?title=Videos>. There's an almost complete documentation with also very good lessons on aldeid < http://www.aldeid.com/index.php/Watobo> - thanks Sebastien! We hope you find WATOBO useful! If you find a bug, have a feature request or simply want to tell some success stories please send a mail to watobo@siberas.de. Regards, Andy "
|
 |
Login
Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.
Big Story of Today
There isn't a Biggest Story for Today, yet.
Old Articles
| Friday, February 18 | | · | Arachni Version 0-2-2-1 Web Security Scanner is out |
| Wednesday, January 12 | | · | Version 1.2.0 of the OWASP Zed Attack Proxy (ZAP) has now been released |
| Thursday, December 09 | | · | HTTP Parameter Pollution Attacks -- A Detection tool has been released |
| Monday, December 06 | | · | The Zed Attack Proxy (ZAP) has been released |
| Friday, December 03 | | · | SSA v2.0 Beta 002 - Making Open Standard Assessment Easy !!! |
| Tuesday, October 26 | | · | WATOBO - The Web Application Toolbox Version 0.9.5 released |
| Wednesday, October 20 | | · | Web Security Dojo 1.1 is released |
| Sunday, October 17 | | · | SamuraiWTF Version 0.9 released |
| Sunday, September 05 | | · | Arachni - Web Application Vulnerability Scanning Framework V0.1 is released |
| Monday, August 23 | | · | Air Force Lt. Gen. says: The enemy is banging away at our applications |
| · | HP To Acquire Code Security Software Maker Fortify |
| Sunday, August 22 | | · | WhatWeb -- The next generation web scanner |
| Friday, August 20 | | · | BinPack: Las Vegas Edition Release |
| · | Better Security Through Sacrificing Maidens |
| Friday, July 23 | | · | WebCruiser - Web Vulnerability Scanner V2.4.1 |
Older Articles
|