websecurity@lists.webappsec.org

The Web Security Mailing List

View all threads

PROJECT - competition landscape for APPSEC

DD
daryl d
Mon, Apr 29, 2013 8:00 PM

Hi All,

I need detailed information of current application security competition
landscape for one of my university projects. Any pointers to same shall be
helpful. Thanks in advance.

Thanks,
Daryl

Hi All, I need detailed information of current application security competition landscape for one of my university projects. Any pointers to same shall be helpful. Thanks in advance. Thanks, Daryl
AM
Ahmed Masud
Tue, Apr 30, 2013 6:15 PM

My Sincerest apologies for pushing this out on webappsec.org and
securityfocus.com but I thought it would serve as a general guideline
as to what I do and do not expect to receive from a mailing list.  I
don't expect emails like the one sent out by Daryl.

Daryl:

A couple of points on etiquette: Your requirement is rather vague and
sounds very much like homework that you don't wish to do yourself. If
that's not the case you should explain what your project is, so that
someone who may be kind enough to help you can actually understand the
context and give you something useful rather than expecting a
data-dump.  My suggestion would be to set up a simple to answer
questionnaire around your inquiry so someone can answer it easily and
then you can ask more detailed questions around that in follow-ups.
It's a lot better than just saying "what's the current application
security competition landscape" ...A vague question like that would
result in a curt answer like go pay money to www.gartner.com;

A better forum for this would be one of the stackexchange.com venues.
If you formulate your question in a more appropriate way directly to
me; I will be happy to answer it.

Sincerely,

Ahmed Masud ahmed.masud@trustifier.com

Trustifier Inc.
CEO
C: 613-875-0971

On Mon, Apr 29, 2013 at 4:00 PM, daryl d darylcoz@gmail.com wrote:

Hi All,

I need detailed information of current application security competition
landscape for one of my university projects. Any pointers to same shall be
helpful. Thanks in advance.

Thanks,
Daryl


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

My Sincerest apologies for pushing this out on webappsec.org and securityfocus.com but I thought it would serve as a general guideline as to what I do and do not expect to receive from a mailing list. I don't expect emails like the one sent out by Daryl. Daryl: A couple of points on etiquette: Your requirement is rather vague and sounds very much like homework that you don't wish to do yourself. If that's not the case you should explain what your project is, so that someone who may be kind enough to help you can actually understand the context and give you something useful rather than expecting a data-dump. My suggestion would be to set up a simple to answer questionnaire around your inquiry so someone can answer it easily and then you can ask more detailed questions around that in follow-ups. It's a lot better than just saying "what's the current application security competition landscape" ...A vague question like that would result in a curt answer like go pay money to www.gartner.com; A better forum for this would be one of the stackexchange.com venues. If you formulate your question in a more appropriate way directly to me; I will be happy to answer it. Sincerely, Ahmed Masud <ahmed.masud@trustifier.com> Trustifier Inc. CEO C: 613-875-0971 On Mon, Apr 29, 2013 at 4:00 PM, daryl d <darylcoz@gmail.com> wrote: > Hi All, > > I need detailed information of current application security competition > landscape for one of my university projects. Any pointers to same shall be > helpful. Thanks in advance. > > Thanks, > Daryl > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org >
DH
Daniel Herrera
Wed, May 1, 2013 10:00 PM

Really? You have CEO in your title and you have enough time to chastise a college student on his etiquette on a mailing list? Ridiculous. On the whole his question was written in nearly complete english which passes my bar for acceptable submission to this list.

Daryl,

Are you referring more towards CTFs or CCDC competitions?

Thanks,

D

--- On Tue, 4/30/13, Ahmed Masud ahmed.masud@trustifier.com wrote:

From: Ahmed Masud ahmed.masud@trustifier.com
Subject: Re: [WEB SECURITY] PROJECT - competition landscape for APPSEC
To: "daryl d" darylcoz@gmail.com
Cc: webappsec@securityfocus.com, pen-test@securityfocus.com, "web security" websecurity@webappsec.org
Date: Tuesday, April 30, 2013, 11:15 AM

My Sincerest apologies for pushing this out on webappsec.org and
securityfocus.com but I thought it would serve as a general guideline
as to what I do and do not expect to receive from a mailing list.  I
don't expect emails like the one sent out by Daryl.

Daryl:

A couple of points on etiquette: Your requirement is rather vague and
sounds very much like homework that you don't wish to do yourself. If
that's not the case you should explain what your project is, so that
someone who may be kind enough to help you can actually understand the
context and give you something useful rather than expecting a
data-dump.  My suggestion would be to set up a simple to answer
questionnaire around your inquiry so someone can answer it easily and
then you can ask more detailed questions around that in follow-ups.
It's a lot better than just saying "what's the current application
security competition landscape" ...A vague question like that would
result in a curt answer like go pay money to www.gartner.com;

A better forum for this would be one of the stackexchange.com venues.
If you formulate your question in a more appropriate way directly to
me; I will be happy to answer it.

Sincerely,

Ahmed Masud ahmed.masud@trustifier.com

Trustifier Inc.
CEO
C: 613-875-0971

On Mon, Apr 29, 2013 at 4:00 PM, daryl d darylcoz@gmail.com wrote:

Hi All,

I need detailed information of current application security competition
landscape for one of my university projects. Any pointers to same shall be
helpful. Thanks in advance.

Thanks,
Daryl


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

Really? You have CEO in your title and you have enough time to chastise a college student on his etiquette on a mailing list? Ridiculous. On the whole his question was written in nearly complete english which passes my bar for acceptable submission to this list. Daryl, Are you referring more towards CTFs or CCDC competitions? Thanks, D --- On Tue, 4/30/13, Ahmed Masud <ahmed.masud@trustifier.com> wrote: From: Ahmed Masud <ahmed.masud@trustifier.com> Subject: Re: [WEB SECURITY] PROJECT - competition landscape for APPSEC To: "daryl d" <darylcoz@gmail.com> Cc: webappsec@securityfocus.com, pen-test@securityfocus.com, "web security" <websecurity@webappsec.org> Date: Tuesday, April 30, 2013, 11:15 AM My Sincerest apologies for pushing this out on webappsec.org and securityfocus.com but I thought it would serve as a general guideline as to what I do and do not expect to receive from a mailing list.  I don't expect emails like the one sent out by Daryl. Daryl: A couple of points on etiquette: Your requirement is rather vague and sounds very much like homework that you don't wish to do yourself. If that's not the case you should explain what your project is, so that someone who may be kind enough to help you can actually understand the context and give you something useful rather than expecting a data-dump.  My suggestion would be to set up a simple to answer questionnaire around your inquiry so someone can answer it easily and then you can ask more detailed questions around that in follow-ups. It's a lot better than just saying "what's the current application security competition landscape" ...A vague question like that would result in a curt answer like go pay money to www.gartner.com; A better forum for this would be one of the stackexchange.com venues. If you formulate your question in a more appropriate way directly to me; I will be happy to answer it. Sincerely, Ahmed Masud <ahmed.masud@trustifier.com> Trustifier Inc. CEO C: 613-875-0971 On Mon, Apr 29, 2013 at 4:00 PM, daryl d <darylcoz@gmail.com> wrote: > Hi All, > > I need detailed information of current application security competition > landscape for one of my university projects. Any pointers to same shall be > helpful. Thanks in advance. > > Thanks, > Daryl > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org > _______________________________________________ The Web Security Mailing List WebSecurity RSS Feed http://www.webappsec.org/rss/websecurity.rss Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA WASC on Twitter http://twitter.com/wascupdates websecurity@lists.webappsec.org http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org
MC
Muruganandam C
Thu, May 23, 2013 6:35 AM

Hi All,

could you please let me know about application vulnerability scanning tool.

Thanks
Muruganandam

Hi All, could you please let me know about application vulnerability scanning tool. Thanks Muruganandam
S
Seba
Thu, May 23, 2013 6:48 AM

Hi Muruganandam,

OWASP Zed Attack Proxy Project is the perfect tool for you.
It has automated scanners as well as a set of tools that allow you to find
security vulnerabilities manually.

more info & download on
https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project

regards

Seba

On Thu, May 23, 2013 at 8:35 AM, Muruganandam C muruganandam.c@gmail.comwrote:

Hi Muruganandam, OWASP Zed Attack Proxy Project is the perfect tool for you. It has automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. more info & download on https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project regards Seba On Thu, May 23, 2013 at 8:35 AM, Muruganandam C <muruganandam.c@gmail.com>wrote: > Hi All, > > could you please let me know about application vulnerability scanning tool. > > Thanks > Muruganandam > > ______________________________**_________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/**websecurity.rss<http://www.webappsec.org/rss/websecurity.rss> > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/**83336/4B20E4374DBA<http://www.linkedin.com/e/gis/83336/4B20E4374DBA> > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.**org <websecurity@lists.webappsec.org> > http://lists.webappsec.org/**mailman/listinfo/websecurity_** > lists.webappsec.org<http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org> >
TD
The Dead
Thu, May 23, 2013 7:18 PM

Here you can find a benchmark of vulnerabilities scanners, including
commercial and free:

http://sectooladdict.blogspot.com.br/2012/07/2012-web-application-scanner-benchmark.html

TH3D34D

On Thu, May 23, 2013 at 3:48 AM, Seba seba@owasp.org wrote:

Hi Muruganandam,

OWASP Zed Attack Proxy Project is the perfect tool for you.
It has automated scanners as well as a set of tools that allow you to find
security vulnerabilities manually.

more info & download on
https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project

regards

Seba

On Thu, May 23, 2013 at 8:35 AM, Muruganandam C muruganandam.c@gmail.comwrote:

Here you can find a benchmark of vulnerabilities scanners, including commercial and free: http://sectooladdict.blogspot.com.br/2012/07/2012-web-application-scanner-benchmark.html TH3D34D On Thu, May 23, 2013 at 3:48 AM, Seba <seba@owasp.org> wrote: > Hi Muruganandam, > > OWASP Zed Attack Proxy Project is the perfect tool for you. > It has automated scanners as well as a set of tools that allow you to find > security vulnerabilities manually. > > more info & download on > https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project > > regards > > Seba > > > > On Thu, May 23, 2013 at 8:35 AM, Muruganandam C <muruganandam.c@gmail.com>wrote: > >> Hi All, >> >> could you please let me know about application vulnerability scanning >> tool. >> >> Thanks >> Muruganandam >> >> ______________________________**_________________ >> The Web Security Mailing List >> >> WebSecurity RSS Feed >> http://www.webappsec.org/rss/**websecurity.rss<http://www.webappsec.org/rss/websecurity.rss> >> >> Join WASC on LinkedIn http://www.linkedin.com/e/gis/**83336/4B20E4374DBA<http://www.linkedin.com/e/gis/83336/4B20E4374DBA> >> >> WASC on Twitter >> http://twitter.com/wascupdates >> >> websecurity@lists.webappsec.**org <websecurity@lists.webappsec.org> >> http://lists.webappsec.org/**mailman/listinfo/websecurity_** >> lists.webappsec.org<http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org> >> > > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org > >
TD
The Dead
Thu, May 23, 2013 7:51 PM

Here you can find a benchmark of vulnerabilities scanners, including
commercial and free:

http://sectooladdict.blogspot.com.br/2012/07/2012-web-application-scanner-benchmark.html

TH3D34D

On Thu, May 23, 2013 at 3:48 AM, Seba seba@owasp.org wrote:

Hi Muruganandam,

OWASP Zed Attack Proxy Project is the perfect tool for you.
It has automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.

more info & download on https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project

regards

Seba

On Thu, May 23, 2013 at 8:35 AM, Muruganandam C muruganandam.c@gmail.com wrote:

Hi All,

could you please let me know about application vulnerability scanning tool.

Thanks
Muruganandam


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

Here you can find a benchmark of vulnerabilities scanners, including commercial and free: http://sectooladdict.blogspot.com.br/2012/07/2012-web-application-scanner-benchmark.html TH3D34D On Thu, May 23, 2013 at 3:48 AM, Seba <seba@owasp.org> wrote: > > Hi Muruganandam, > > OWASP Zed Attack Proxy Project is the perfect tool for you. > It has automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. > > more info & download on https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project > > regards > > Seba > > > > On Thu, May 23, 2013 at 8:35 AM, Muruganandam C <muruganandam.c@gmail.com> wrote: >> >> Hi All, >> >> could you please let me know about application vulnerability scanning tool. >> >> Thanks >> Muruganandam >> >> _______________________________________________ >> The Web Security Mailing List >> >> WebSecurity RSS Feed >> http://www.webappsec.org/rss/websecurity.rss >> >> Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA >> >> WASC on Twitter >> http://twitter.com/wascupdates >> >> websecurity@lists.webappsec.org >> http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org > > > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org >
MC
Muruganandam C
Fri, May 24, 2013 8:34 AM

Hi,

I would like to know about the certification security+. Has anyone
completed recently. how was the exam and time required for prepration.

Thanks
Muruganandam

Hi, I would like to know about the certification security+. Has anyone completed recently. how was the exam and time required for prepration. Thanks Muruganandam
RP
Rohit Pitke
Fri, May 24, 2013 10:13 PM

Additionally, you can use Ratproxy and skipfish.
If you are concerned about individual vulnerabilities, I would suggest sqlmap (for SQL injection), XSSRay (for XSS), Nikto (Directory Access) 


From: Seba seba@owasp.org
To: Muruganandam C muruganandam.c@gmail.com
Cc: webappsec@securityfocus.com; pen-test@securityfocus.com; web security websecurity@webappsec.org
Sent: Wednesday, May 22, 2013 11:48 PM
Subject: Re: [WEB SECURITY] Need a Opensource tool for application scanning

Hi Muruganandam,
OWASP Zed Attack Proxy Project is the perfect tool for you.
It has automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. 

more info & download on https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project

regards

Seba

On Thu, May 23, 2013 at 8:35 AM, Muruganandam C muruganandam.c@gmail.com wrote:

Hi All,

could you please let me know about application vulnerability scanning tool.

Thanks
Muruganandam


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

Additionally, you can use Ratproxy and skipfish. If you are concerned about individual vulnerabilities, I would suggest sqlmap (for SQL injection), XSSRay (for XSS), Nikto (Directory Access)  ________________________________ From: Seba <seba@owasp.org> To: Muruganandam C <muruganandam.c@gmail.com> Cc: webappsec@securityfocus.com; pen-test@securityfocus.com; web security <websecurity@webappsec.org> Sent: Wednesday, May 22, 2013 11:48 PM Subject: Re: [WEB SECURITY] Need a Opensource tool for application scanning Hi Muruganandam, OWASP Zed Attack Proxy Project is the perfect tool for you. It has automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.  more info & download on https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project regards Seba On Thu, May 23, 2013 at 8:35 AM, Muruganandam C <muruganandam.c@gmail.com> wrote: Hi All, > >could you please let me know about application vulnerability scanning tool. > >Thanks >Muruganandam > >_______________________________________________ >The Web Security Mailing List > >WebSecurity RSS Feed >http://www.webappsec.org/rss/websecurity.rss > >Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > >WASC on Twitter >http://twitter.com/wascupdates > >websecurity@lists.webappsec.org >http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org > _______________________________________________ The Web Security Mailing List WebSecurity RSS Feed http://www.webappsec.org/rss/websecurity.rss Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA WASC on Twitter http://twitter.com/wascupdates websecurity@lists.webappsec.org http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org
SC
Skip Carter
Sat, May 25, 2013 6:11 PM

On Fri, 2013-05-24 at 14:04 +0530, Muruganandam C wrote:

Hi,

I would like to know about the certification security+. Has anyone
completed recently. how was the exam and time required for prepration.

Its a pretty basic network security cert.  It should not be hard for
anybody with a couple of years of experience in the field.  There are
classes you can take, but the practice exams are more efficient
preparation. How long that takes depends upon your prior experience. The
only thing tricky in the exam itself are stupid questions like "which
two things that are not different between java and javascript ?"

Its a good minimum standard for your security people in the sense that
if they do not have the ability to pass it, they should not be doing
network security.

--
Dr Everett (Skip) Carter                        skip@taygeta.net
Taygeta Network Security Services    (v) 831-641-0645
1340 Munras Ave, Suite 314                (f) 831-641-0647
Monterey, CA. 93955

On Fri, 2013-05-24 at 14:04 +0530, Muruganandam C wrote: > Hi, > > I would like to know about the certification security+. Has anyone > completed recently. how was the exam and time required for prepration. > Its a pretty basic network security cert. It should not be hard for anybody with a couple of years of experience in the field. There are classes you can take, but the practice exams are more efficient preparation. How long that takes depends upon your prior experience. The only thing tricky in the exam itself are stupid questions like "which two things that are not different between java and javascript ?" Its a good minimum standard for your security people in the sense that if they do not have the ability to pass it, they should not be doing network security. -- Dr Everett (Skip) Carter skip@taygeta.net Taygeta Network Security Services (v) 831-641-0645 1340 Munras Ave, Suite 314 (f) 831-641-0647 Monterey, CA. 93955
M
maanav
Sun, May 26, 2013 8:22 AM

Hi

My 2 cents:-

  1. Get a confirmation from your company about the this certification (that
    it will add value to your present career in the firm), as usually people go
    for other certs (as this is a very basic one, and probably your money could
    be better invested somewhere else, unless your company is paying for it)
    like C|EH, CISSP, CISA, OSCP, etc.

  2. Also, speak to your manager about the impact of all certifications, and
    then choose whichever one makes bigger impact; IMHO, that's what certs do,
    they elevate your resume;

  3. Technically speaking, I've found that asking questions on forums like
    null, stackoverflow and likes, coupled with lot of homeworks, works better
    than any cert in improving the security knowledge.

Regards
Maanav

-----Original Message-----
From: websecurity [mailto:websecurity-bounces@lists.webappsec.org] On Behalf
Of Muruganandam C
Sent: Friday, May 24, 2013 2:05 PM
To: daryl d
Cc: webappsec@securityfocus.com; pen-test@securityfocus.com; web security
Subject: [WEB SECURITY] Security+ cert info reuired

Hi,

I would like to know about the certification security+. Has anyone completed
recently. how was the exam and time required for prepration.

Thanks
Muruganandam


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

Hi My 2 cents:- 1. Get a confirmation from your company about the this certification (that it will add value to your present career in the firm), as usually people go for other certs (as this is a very basic one, and probably your money could be better invested somewhere else, unless your company is paying for it) like C|EH, CISSP, CISA, OSCP, etc. 2. Also, speak to your manager about the impact of all certifications, and then choose whichever one makes bigger impact; IMHO, that's what certs do, they elevate your resume; 3. Technically speaking, I've found that asking questions on forums like null, stackoverflow and likes, coupled with lot of homeworks, works better than any cert in improving the security knowledge. Regards Maanav -----Original Message----- From: websecurity [mailto:websecurity-bounces@lists.webappsec.org] On Behalf Of Muruganandam C Sent: Friday, May 24, 2013 2:05 PM To: daryl d Cc: webappsec@securityfocus.com; pen-test@securityfocus.com; web security Subject: [WEB SECURITY] Security+ cert info reuired Hi, I would like to know about the certification security+. Has anyone completed recently. how was the exam and time required for prepration. Thanks Muruganandam _______________________________________________ The Web Security Mailing List WebSecurity RSS Feed http://www.webappsec.org/rss/websecurity.rss Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA WASC on Twitter http://twitter.com/wascupdates websecurity@lists.webappsec.org http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org
AS
Andreas Schmidt
Fri, Jun 7, 2013 1:56 PM

Hi,

you may also want to try WATOBO - THE Web Application Toolbox.

WATOBO is a security tool for web applications. It is intended to enable
security professionals to perform efficient (semi-automated) web
application security audits.

Most important features:

  • WATOBO has Session Management capabilities! You can define login
    scripts as well as logout signatures. So you don't have to login
    manually each time you get logged out.
  • WATOB can act as a transparent proxy (requires nfqueue)
  • WATOBO can perform vulnerability checks out of the box
  • WATOBO can perform checks on functions which are protected by
    Anti-CSRF-/One-Time-Tokens
  • WATOBO supports Inline De-/Encoding, so you don't have to copy strings
    to a transcoder and back again. Just do it inside the request/response
    window with a simple mouse click.
  • WATOBO has smart filter functions, so you can find and navigate to the
    most interesting parts of the application easily.
  • WATOBO is written in (FX)Ruby and enables you to easily define your
    own checks
  • WATOBO runs on Windows, Linux, MacOS ... every OS supporting (FX)Ruby
  • WATOBO is free software ( licensed under the GNU General Public
    License Version 2)

Check out the online documentation and video tutorials at
http://watobo.sourceforge.net

regards,

andy (author of watobo ;)

Am 25.05.2013 00:13, schrieb Rohit Pitke:

Additionally, you can use Ratproxy and skipfish.
If you are concerned about individual vulnerabilities, I would suggest
sqlmap (for SQL injection), XSSRay (for XSS), Nikto (Directory Access)


From: Seba seba@owasp.org
To: Muruganandam C muruganandam.c@gmail.com
Cc: webappsec@securityfocus.com; pen-test@securityfocus.com; web
security websecurity@webappsec.org
Sent: Wednesday, May 22, 2013 11:48 PM
Subject: Re: [WEB SECURITY] Need a Opensource tool for application
scanning

Hi Muruganandam,

OWASP Zed Attack Proxy Project is the perfect tool for you.
It has automated scanners as well as a set of tools that allow you to
find security vulnerabilities manually.

more info & download
on https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project

regards

Seba

On Thu, May 23, 2013 at 8:35 AM, Muruganandam C
<muruganandam.c@gmail.com mailto:muruganandam.c@gmail.com> wrote:

 Hi All,

 could you please let me know about application vulnerability
 scanning tool.

 Thanks
 Muruganandam

 _______________________________________________
 The Web Security Mailing List

 WebSecurity RSS Feed
 http://www.webappsec.org/rss/websecurity.rss

 Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

 WASC on Twitter
 http://twitter.com/wascupdates

 websecurity@lists.webappsec.org
 <mailto:websecurity@lists.webappsec.org>
 http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org mailto:websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

Hi, you may also want to try WATOBO - THE Web Application Toolbox. WATOBO is a security tool for web applications. It is intended to enable security professionals to perform efficient (semi-automated) web application security audits. Most important features: * WATOBO has Session Management capabilities! You can define login scripts as well as logout signatures. So you don't have to login manually each time you get logged out. * WATOB can act as a transparent proxy (requires nfqueue) * WATOBO can perform vulnerability checks out of the box * WATOBO can perform checks on functions which are protected by Anti-CSRF-/One-Time-Tokens * WATOBO supports Inline De-/Encoding, so you don't have to copy strings to a transcoder and back again. Just do it inside the request/response window with a simple mouse click. * WATOBO has smart filter functions, so you can find and navigate to the most interesting parts of the application easily. * WATOBO is written in (FX)Ruby and enables you to easily define your own checks * WATOBO runs on Windows, Linux, MacOS ... every OS supporting (FX)Ruby * WATOBO is free software ( licensed under the GNU General Public License Version 2) Check out the online documentation and video tutorials at http://watobo.sourceforge.net regards, andy (author of watobo ;) Am 25.05.2013 00:13, schrieb Rohit Pitke: > Additionally, you can use Ratproxy and skipfish. > If you are concerned about individual vulnerabilities, I would suggest > sqlmap (for SQL injection), XSSRay (for XSS), Nikto (Directory Access) > > ------------------------------------------------------------------------ > *From:* Seba <seba@owasp.org> > *To:* Muruganandam C <muruganandam.c@gmail.com> > *Cc:* webappsec@securityfocus.com; pen-test@securityfocus.com; web > security <websecurity@webappsec.org> > *Sent:* Wednesday, May 22, 2013 11:48 PM > *Subject:* Re: [WEB SECURITY] Need a Opensource tool for application > scanning > > Hi Muruganandam, > > OWASP Zed Attack Proxy Project is the perfect tool for you. > It has automated scanners as well as a set of tools that allow you to > find security vulnerabilities manually. > > more info & download > on https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project > > regards > > Seba > > > > On Thu, May 23, 2013 at 8:35 AM, Muruganandam C > <muruganandam.c@gmail.com <mailto:muruganandam.c@gmail.com>> wrote: > > Hi All, > > could you please let me know about application vulnerability > scanning tool. > > Thanks > Muruganandam > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org > <mailto:websecurity@lists.webappsec.org> > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org > > > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org <mailto:websecurity@lists.webappsec.org> > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org > > > > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org
F
firebits
Fri, Jun 7, 2013 7:21 PM

Hi,

you may also want to try WATOBO - THE Web Application Toolbox.

WATOBO is a security tool for web applications. It is intended to enable
security professionals to perform efficient (semi-automated) web
application security audits.

Most important features:

  • WATOBO has Session Management capabilities! You can define login scripts
    as well as logout signatures. So you don’t have to login manually each time
    you get logged out.
  • WATOB can act as a transparent proxy (requires nfqueue)
  • WATOBO can perform vulnerability checks out of the box
  • WATOBO can perform checks on functions which are protected by
    Anti-CSRF-/One-Time-Tokens
  • WATOBO supports Inline De-/Encoding, so you don’t have to copy strings
    to a transcoder and back again. Just do it inside the request/response
    window with a simple mouse click.
  • WATOBO has smart filter functions, so you can find and navigate to the
    most interesting parts of the application easily.
  • WATOBO is written in (FX)Ruby and enables you to easily define your own
    checks
  • WATOBO runs on Windows, Linux, MacOS ... every OS supporting (FX)Ruby
  • WATOBO is free software ( licensed under the GNU General Public License
    Version 2)

Check out the online documentation and video tutorials at
http://watobo.sourceforge.net

regards,

andy (author of watobo ;)

Am 25.05.2013 00:13, schrieb Rohit Pitke:

Additionally, you can use Ratproxy and skipfish.
If you are concerned about individual vulnerabilities, I would suggest
sqlmap (for SQL injection), XSSRay (for XSS), Nikto (Directory Access)


From: Seba seba@owasp.org seba@owasp.org
To: Muruganandam C muruganandam.c@gmail.com muruganandam.c@gmail.com
Cc: webappsec@securityfocus.com; pen-test@securityfocus.com; web
security websecurity@webappsec.org websecurity@webappsec.org
Sent: Wednesday, May 22, 2013 11:48 PM
Subject: Re: [WEB SECURITY] Need a Opensource tool for application
scanning

Hi Muruganandam,

OWASP Zed Attack Proxy Project is the perfect tool for you.
It has automated scanners as well as a set of tools that allow you to find
security vulnerabilities manually.

more info & download on
https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project

regards

Seba

On Thu, May 23, 2013 at 8:35 AM, Muruganandam C muruganandam.c@gmail.comwrote:

Hi All,

could you please let me know about application vulnerability scanning tool.

Thanks
Muruganandam


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org


The Web Security Mailing List

WebSecurity RSS Feedhttp://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitterhttp://twitter.com/wascupdates
websecurity@lists.webappsec.orghttp://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

My fork skyfallsec https://bitbucket.org/skyfallsec Slides http://www.slideshare.net/firebits/skyfall-b-sidesc00led5sp2013 @firebitsbr 2013/6/7 Andreas Schmidt <webappsec@siberas.de> > Hi, > > you may also want to try WATOBO - THE Web Application Toolbox. > > WATOBO is a security tool for web applications. It is intended to enable > security professionals to perform efficient (semi-automated) web > application security audits. > > Most important features: > * WATOBO has Session Management capabilities! You can define login scripts > as well as logout signatures. So you don’t have to login manually each time > you get logged out. > * WATOB can act as a transparent proxy (requires nfqueue) > * WATOBO can perform vulnerability checks out of the box > * WATOBO can perform checks on functions which are protected by > Anti-CSRF-/One-Time-Tokens > * WATOBO supports Inline De-/Encoding, so you don’t have to copy strings > to a transcoder and back again. Just do it inside the request/response > window with a simple mouse click. > * WATOBO has smart filter functions, so you can find and navigate to the > most interesting parts of the application easily. > * WATOBO is written in (FX)Ruby and enables you to easily define your own > checks > * WATOBO runs on Windows, Linux, MacOS ... every OS supporting (FX)Ruby > * WATOBO is free software ( licensed under the GNU General Public License > Version 2) > > Check out the online documentation and video tutorials at > http://watobo.sourceforge.net > > regards, > > andy (author of watobo ;) > > Am 25.05.2013 00:13, schrieb Rohit Pitke: > > Additionally, you can use Ratproxy and skipfish. > If you are concerned about individual vulnerabilities, I would suggest > sqlmap (for SQL injection), XSSRay (for XSS), Nikto (Directory Access) > > ------------------------------ > *From:* Seba <seba@owasp.org> <seba@owasp.org> > *To:* Muruganandam C <muruganandam.c@gmail.com> <muruganandam.c@gmail.com> > *Cc:* webappsec@securityfocus.com; pen-test@securityfocus.com; web > security <websecurity@webappsec.org> <websecurity@webappsec.org> > *Sent:* Wednesday, May 22, 2013 11:48 PM > *Subject:* Re: [WEB SECURITY] Need a Opensource tool for application > scanning > > Hi Muruganandam, > > OWASP Zed Attack Proxy Project is the perfect tool for you. > It has automated scanners as well as a set of tools that allow you to find > security vulnerabilities manually. > > more info & download on > https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project > > regards > > Seba > > > > On Thu, May 23, 2013 at 8:35 AM, Muruganandam C <muruganandam.c@gmail.com>wrote: > > Hi All, > > could you please let me know about application vulnerability scanning tool. > > Thanks > Muruganandam > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org > > > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org > > > > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feedhttp://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitterhttp://twitter.com/wascupdates > websecurity@lists.webappsec.orghttp://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org > > > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org > >
DM
David Mirza Ahmad
Fri, Jun 7, 2013 11:09 PM

Hi all,

I recommend you try our tool, Vega. It has a fully automated (crawler)
and semi-automated proxy scanning. We've been actively improving it.
Vega is written in Java and runs on OS X, Linux, Windows.

You can download it at http://www.subgraph.com and it is included with
Kali Linux.

The source is on github @ http://github.com/subgraph/Vega. The license
is EPL 1.0.

There is a presentation in this blog post that walks through some of the
features:

http://keystream.subgraph.com/2013/02/22/northsec-confoo-and-the-vega-1-0-release/

On 06/07/2013 03:21 PM, firebits wrote:

--
David Mirza Ahmad
dma@subgraph.com | @attractr
Subgraph | @subgraph
Vega, the Open Source Web Security Platform
http://www.subgraph.com

78A1 CCFD 1C60 4BA7 5E1C C1F2 42D7 08C0 2520 8C7B

Hi all, I recommend you try our tool, Vega. It has a fully automated (crawler) and semi-automated proxy scanning. We've been actively improving it. Vega is written in Java and runs on OS X, Linux, Windows. You can download it at http://www.subgraph.com and it is included with Kali Linux. The source is on github @ http://github.com/subgraph/Vega. The license is EPL 1.0. There is a presentation in this blog post that walks through some of the features: http://keystream.subgraph.com/2013/02/22/northsec-confoo-and-the-vega-1-0-release/ On 06/07/2013 03:21 PM, firebits wrote: > My fork skyfallsec > > https://bitbucket.org/skyfallsec > > Slides > > http://www.slideshare.net/firebits/skyfall-b-sidesc00led5sp2013 > > @firebitsbr > -- David Mirza Ahmad <dma@subgraph.com> | @attractr Subgraph | @subgraph Vega, the Open Source Web Security Platform http://www.subgraph.com 78A1 CCFD 1C60 4BA7 5E1C C1F2 42D7 08C0 2520 8C7B