Tools to exploit websites

Status
Not open for further replies.

Osiris

Golden Master
Messages
36,817
Location
Kentucky
Lynx is a text browser for the World Wide Web. Lynx 2.8.5 runs on Un*x, VMS, Windows 95/98/NT, DOS386+ but not 3.1, 3.11, or OS/2 EMX. The current developmental version is also available for testing. Ports to Mac are in beta test.​

  • Many user questions are answered in the online help provided with Lynx. Press the '?' key to find this help.
  • If you are encountering difficulty with Lynx you may write to lynx-dev@nongnu.org. Be as detailed as you can about the URL where you were on the Web when you had trouble, what you did, what Lynx version you have (try '=' key), and what OS you have. If you are using an older version, you may well need to upgrade.
Logo.png


Internet scanning and downloading tool for the expert and the novice. Use it to scan a site and create a complete profile of the site's structure, files, external links and even link errors. BlackWidow will download all file types such as pictures and images, audio and MP3, videos, documents, ZIP, programs, CSS, Macromedia Flash, .pdf , PHP, CGI, HTM to MIME types from any web sites. Pull links from Java Scripts and Java Scripts files, scan Adobe Acrobat (.pdf) and Flash files for links + more from any web site. Write your own "Plugins" for impossible to scan sites.

Download websites using BlackWidow


Our flagship product, Sleuth is a Web Application Assessment Tool. It can be used to great effect by both auditors and developers alike to debug/analyze Web Applications for function & security.

The 1.4 Installer comes with both the free 1.36 version as well as the new enhanced commercial version.
</B>
113687233.jpg
Sleuth allows you the tools and framework to examine/ test/ probe anywhere you need. It was built around the precept that manual skills, know-how and exploration are a necessary commodity and an invaluable training tool.


The next version of Burp is on the way! Please submit your feature requests here.

Burp spider is a tool for enumerating web-enabled applications. It uses various intelligent techniques to generate a comprehensive inventory of an application's content and functionality.
Burp spider enables the user to obtain a detailed understanding of how a web application works, avoiding the time-consuming and unreliable task of manually following links, submitting forms and scouring HTML source code. Potentially vulnerable application functions can be quickly identified, allowing the user to check for specific vulnerabilities such as SQL injection and directory traversal.
Key features include:
  • Accurate HTML and JavaScript parsers to effectively enumerate the application's content and functionality.
  • Presentation of findings in tree and table formats, with detailed information about all results.
  • Handling of HTML forms, with automatic or user-guided form submission.
  • Full integration with other burp suite plugins.
  • Authentication to protected areas of the application using supplied credentials.
  • Processing of cookies.
  • Detection of custom "not found" responses.
  • Fine-grained scope control.
  • SSL support.
  • Identification of dynamic "application" pages which use data parameters or are session-dependent.
  • IDS evasion techniques.
  • Support for downstream proxy server.
  • Authentication to downstream proxy and web servers, using basic, NTLM or digest authentication types.
  • Optimised memory and disk usage to allow efficient spidering of very large sites.
  • Runs in both Linux and Windows.
New features in version 1.2 include:
  • ability to "passively" spider web applications, with all requests originating from the user's browser.
  • regex-based search and highlight in all text panes.
  • HTML rendering of server responses.
  • full integration with other burp suite tools.
  • ability to specify spider scope using both URL regex and IP ranges.
  • optional persistent preferences across program launches.
  • correct handling of "HTTP 100 Continue" responses.
  • logging of all X509 certificates encountered.
Burp spider is a Java application, and runs on any platform for which a Java Runtime Environment is available. It requires version 1.4 or later. The JRE can be obtained for free from java.sun.com.
For examples of burp spider in action, see the screenshots, or for detailed information about the configuration and use of burp spider, see the help file.
Download burp spider.
 
Status
Not open for further replies.
Back
Top Bottom