|
|||||||||||
|
Proof of Concept Tool on Web Application Security
From: Indian Tiger <indiantiger(at)mailandnews.com>
Date: Tue Apr 15 2003 - 14:05:34 EDT
I have tried a lot to find any Proof of Concept Tool on Web Application Security but still I am not able to find a single one. Let me give some specific details.
Session ID
Cookie Manipulation
This manipulation can also be achieved if an Attacker can put his Proxy (Web Sleuth) on intermediate Router/Proxy. One Example is I am accessing Hotmail and on my ISP Router/Proxy, An attacker installs tool like Web Sleuth. But again question comes Router works on OSI layer 3 so attacker can't put tool like Web Sleuth. If intermediate hop is Proxy which is on Application level, there should be some tool which can be placed here. XSS
Please also tell any other Proof of Concept Tool on Web Application Security. I read OWASP guides, WebGoat and some more to understand three things deeply and develop Proof of Concept Tool but no successes accept Hidden field manipulation. Please recommend some good guides on this. Any help on this would be highly appreciated.
Thanking You.
Indian Tiger, CISSP Costs are climbing and complaints are rising as SPAM overloads your e-mail servers and Inboxes SurfControl E-mail Filter puts the brakes on spam & viruses and gives you the reports to prove it. http://www.securityfocus.com/SurfControl-pen-test2 Download a free trial and see just what's going in and out of your organization. Received on Thu Apr 10 17:38:50 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:35 EDT |
||||||||||
|
|||||||||||