- Security Testing - Automation Tools
- Testing Malicious File Execution
- Security Testing - Denial of Service
- Security Testing - Buffer Overflows
- Testing Security - Web Service
- Security Testing - Ajax Security
- Unvalidated Redirects and Forwards
- Components with Vulnerabilities
- Cross Site Request Forgery
- Missing Function Level Access Control
- Testing Sensitive Data Exposure
- Testing Security Misconfiguration
- Insecure Direct Object Reference
- Testing Cross Site Scripting
- Testing Broken Authentication
- Security Testing - Injection
- Hacking Web Applications
- Security Testing - Cookies
- Security Testing - Same Origin Policy
- Security Testing - Cryptography
- Encoding and Decoding
- HTTPS Protocol Basics
- HTTP Protocol Basics
- Security Testing - Malicious Software
- Security Testing - Process
- Security Testing - Overview
- Security Testing - Home
Security Testing Useful Resources
Selected Reading
- Who is Who
- Computer Glossary
- HR Interview Questions
- Effective Resume Writing
- Questions and Answers
- UPSC IAS Exams Notes
Security Testing - Automation Tools
现有各种工具对申请进行安全测试。 几乎没有能够进行终端到终端安全测试的工具,而有些工具则专门发现该系统中的一种特殊缺陷。
Open Source Tools
提供了一些开放源安全检测工具——
S.No. | Tool Name |
---|---|
1 | Zed Attack Proxy 为发现安全缺陷提供自动扫描仪和其他工具。 |
2 | 编写于 Java,分析Http和Https的要求。 |
3 | 支持多语文安全测试框架 |
4 | Burp Proxy 工具 Intercepting & Modyfying trafficking and work with practices SSL documents. http://www.portswigger.net/Burp/>。 |
5 | 利用篡改数据观测和修改吉大港山区/吉大港山区头目和员额参数 https://addons.mozilla.org/en-US/firefox/addon/tamper-data/>。 |
6 | 网络开发者向浏览器增加了各种网络开发工具。 |
7 | 让用户添加、删除、编辑、搜索、保护和 block |
Specific Tool Sets
以下工具可帮助我们在系统中发现某种特定的脆弱性:
S.No. | Link | |
---|---|---|
1 | DOMinator Pro——OMXSS检测 |
|
3 | <Sqlninja>-Q. Injection |
|
4 | https://sourceforge.net/projects/safe3si/> |
|
5 | qlpowerinjector - 文 件 |
|
6 | ||
7 | THC-Hydra - 部队通行证 http://www.thc.org/thc-hydra/>。 |
|
8 | Brutus - Brute Force Password |
|
9 | Ncat - Brute Force Password |
|
10 | ||
11 | ||
12 |
Commercial Black Box Testing tools
这里有一些商业黑箱检测工具,帮助我们在开发的应用中发现安全问题。
S.No | Tool | |
---|---|---|
1 | https://www.nccgroup.com/en/our-services/security-consulting/information-security-software/squirrel-vulnerabipty-scanner/> |
|
2 | IBM AppScan |
|
3 | ||
4 | NTOSpider https://www.ntobjectives.com/products/ntospider.php。 |
|
5 | SOAP UI |
|
7 |
Commercial Source Code Analyzers
这些分析器检查、发现和报告容易发生脆弱性的源代码中的弱点:
S.No | Tool |
---|---|
1 | Parasoft C/C++ test http://www.parasoft.com/cpptest/testing_malacious_file_execution.htm>。 |
2 | |
3 | |
4 | http://www.veracode.com。 |
5 | |
6 | http://www.grammatech.com/>。 |