iExploder is like a fire hydrant full of bad HTML and CSS code to test the stability and security of web browsers. Available as a standalone webserver or CGI script, it continuously feeds browsers bad data in the hope that they will eventually crash. It is designed to run for hours, or even days until the browser crashes. namebench was initially written as a QA tool for the Mozilla Project to test the Firefox 1.0 release, and is now included and used by Apple's Webkit project.
b4ef8f5c26215580696167fa50ab9b0e33fb7b37c37004c226ce14cf7b13e4fa
iExploder is like a fire hydrant full of bad HTML and CSS code to test the stability and security of web browsers. Available as a standalone webserver or CGI script, it continuously feeds browsers bad data in the hope that they will eventually crash. It is designed to run for hours, or even days until the browser crashes. namebench was initially written as a QA tool for the Mozilla Project to test the Firefox 1.0 release, and is now included and used by Apple's Webkit project.
31614c1344412dbb4611ffdcdc41d272c6411c887e652e52970749008a59e923
RewriteProxy is a small python tool that is based on the twisted library. Its purpose is to serve local files instead of remote files to fool the same-domain policy of modified flash and java-applets.
eca6b434258f98306fbfe4e27f6f2f5a761dd5ee8cf65a55b9e18c282e184890
mod_psldap is an Apache module that performs authentication and authorization against an LDAP server with LDAP based session management. It also provides Web 2.0 based capabilities to add, edit, move, and create new records in the LDAP store, leveraging XSL stylesheets to offload heavy processing to the clients and reduce bandwidth consumption by up to 95% or more.
41e6461d2c3d8d11aae52da0ed3fb1268f990398109b089181f992a02eccefc6
MITMProxy is an interactive, SSL-aware HTTP proxy that allows viewing, modification and replaying of requests.
3c27bce82ee0b9e7856fd7eb86e02050cc1d43711f1f662f02ce1eeb8abda9f6
mod_psldap is an Apache module that performs authentication and authorization against an LDAP server with LDAP based session management. It also provides Web 2.0 based capabilities to add, edit, move, and create new records in the LDAP store, leveraging XSL stylesheets to offload heavy processing to the clients and reduce bandwidth consumption by up to 95% or more.
100bdf5e1d045107171c2afce229a7edc1206398e366c182a682d2435c79eb43
iExploder is like a fire hydrant full of bad HTML and CSS code to test the stability and security of web browsers. Available as a standalone webserver or CGI script, it continuously feeds browsers bad data in the hope that they will eventually crash. It is designed to run for hours, or even days until the browser crashes. namebench was initially written as a QA tool for the Mozilla Project to test the Firefox 1.0 release, and is now included and used by Apple's Webkit project.
073eb39b59a7fa50f9bcd91b589106f80f8fa23aadab7802e7e0294944978450
Cookie Monster is a cookie analysis tool written in Python. Cookie Monster will grab cookies from a host and assign each character a number. This number can be used to perform mathematical calculations on the differences in order to find a pattern and see if cookie prediction is possible.
2ea212371ff52f7cdc5a9a96dc54b6d8e61438beb08855caa82fdf7b84a5f569
dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.
6aa5c7bee5feba563d7a4c7e7153dd36d919758b69278e3d235c5ed61adc7bbb
Pound is a reverse HTTP proxy, load balancer, and SSL wrapper. It proxies client HTTPS requests to HTTP backend servers, distributes the requests among several servers while keeping sessions, supports HTTP/1.1 requests even if the backend server(s) are HTTP/1.0, and sanitizes requests.
ed247a23a4a721231ab601cb13642ba322e0aeee864ee320958bfabf405c7869
Squipy is a proxy server that allows you to capture and modify HTTP traffic.
a9b89ba7b14dd63268ecdafb6173cf172d87074e953088ec884dac7dae401937
phpAV is a script designed to work as antivirus for malicious PHP scripts. It will search a given directory and related files for dangerous functions and provide a report.
68ab3725b4466890a2330c5c5dd11622666a09c408af5bb5c60f44d048036ba0
phpAV is a script designed to work as antivirus for malicious PHP scripts. It will search a given directory and related files for dangerous functions and provide a report.
52ba58c54f23247b703f406196191b4b06961a14a63f73da8e5e630962be128a
dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.
303b1f5e9a3f6d4e4a2dc0c2be86ade9e859fe5050f268725ed11ecbd17e261d
dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.
66b866e356a910a6068f3db98437de71ecd2498a176f2a70a9dfb180147619e4
dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.
56becee9922782acdeeeed9b6cfea60cfef8ff24b8ebb8aada68448d415c2dbe
dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.
9698e24363a7d65cae731214e6a604f6137e86c4f67d24b20706cc5097f13aaa
UrlCrazy is for the study of domainname typos and URL hijacking. It generates domainname typo permutations then tests them to learn if they are in use, estimates their popularity and more. Typo types supported are: Character Omission, Adjacent Character Swap, Adjacent Character Replacement, Adjacent Character Insertion, Missing Dot, Strip Dashes, Singular or Pluralise. Urlcrazy is written in Ruby.
0accacdc470f20231ead2b7d06716604bea1e9f5beeab45ef44e05d06c52df45
dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.
a6f9a40c9bbde3778c9c523f59e469d3dabfeadfc17dc95a8b955cf93d81a15f
dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.
ed8320d7c1b09d109df4958e6a9fde00f7391f39effceb85531ad23b1ea54f37
squid-nufw-helper is an external ACL helper for Squid that provides Single Sign On capabilities. It uses the NuFW firewall suite and supports the NuFW users SQL logging scheme. The module allows for strict SSO identification and authentication of users on any Squid proxy, including transparent proxies.
6984d7dad2acd7450b71ddbbf835596ee118502ab5eca1dd473c04e3701cc2e3
Ruby Script to generate URL encoded Unicode UTF-8 URL.
3716b2b24def26545bf37991157e555c96d9f13dc08744a8b8168ccd6d3bd237
surfjack is a tool that allows you to hijack HTTP connection to steal cookies.
65a1c73679412a460412df6144fbf8de78ac5c5048437c0211b5eee605f5abbd
browserrecon is a framework that performs client-side HTTP fingerprinting. Be sure to hit their site to download the latest fingerprints database.
d37d7efea8951475554a42f5248c7e1de2b4115e3f323ebdd096383e01fbbb38
dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.
2851229d6d96c3f46c369880a065f21a90bc2f811297c7114f9152e9648c7f1d