Acunetix Release Web Site Security Pen Testing Tools Free
HTTP editor, fuzzer and sniffer tools help pen testers identify vulnerabilities
London, UK – January 2016 – Hot on the release of Acunetix Version
11, pioneering web application security software Acunetix, now
delivering Manual Pen Testing Tools at no cost. Penetration testers can
make use of an HTTP Editor to modify or craft HTTP requests and analyze
responses; intercept and modify HTTP traffic on the fly using the
integrated HTTP Sniffer; fuzz test HTTP requests using the HTTP Fuzzer
and test Blind SQL Injection vulnerabilities further using the Blind SQL
Injector, among others.
“Acunetix has for the past decade been an excellent resource in the pentester’s tool kit. Prior to Acunetix v11, these Manual Pen Testing Tools were only available to Acunetix Customers. By releasing our manual tools separately, we aim to facilitate veteran testers as well as up and coming security researchers by making it easy to manually test web applications for logical flaws among others,” added Nicholas Sciberras, CTO, Acunetix.
HTTP Editor:
Allows you to create, analyze and edit client HTTP requests; as well as
inspect server responses. It also includes an encoding and decoding
tool to encode/decode text and URL’s to MD5 hashes, UTF-7 and other
formats.
HTTP Sniffer:
A proxy that allows you to analyze HTTP requests and responses, and
edit these while they are in transit. The HTTP sniffer can also be used
to manually crawl a site, and use the manual crawl to seed an Acunetix
scan.
HTTP Fuzzer:
A tool which allows you to automatically send a large number of HTTP
requests including invalid, unexpected and random data to a website, to
test input validation and handling of invalid data by the web
application.
Blind SQL Injector: An automated database data
exfiltration tool. By using Blind SQL injection vulnerabilities
discovered when scanning a website, it is possible to demonstrate the
serious impact a Blind SQL injection vulnerability can have on the
website. Used to enumerate databases, tables, fields and dump data from
the vulnerable web application.
Subdomain Scanner: Scans a top-level domain to
discover subdomains configured in its hierarchy, by using the target
domain’s DNS server, or any other DNS server specified by the user.
While scanning, this tool will also automatically identify and inform
the user if the domain being scanned is using some kind of wildcard
characters, such as *.domain.com.
Target Finder: An IP range / port scanner which can
be used to discover running web servers on a given IP or within a
specified range of IPs. The list of ports on which the web servers are
listening can also be configured. The default ports the scanner will
scan are port 80 for HTTP and port 443 for SSL.
Authentication Tester: Used to test the strength of
both usernames and passwords within HTTP and web forms authentication
environments via a dictionary attack.
Download the FREE Manual Pen Testing Tools
Acunetix Release Web Site Security Pen Testing Tools Free
Reviewed by Zion3R
on
11:28 AM
Rating: