PDA

Просмотр полной версии : Release Exploit-Me


Fugitif
11.12.2007, 21:07
Free Firefox Application Penetration Testing Suite Launch

Security Compass is pleased to announce the release of the free Exploit-Me series of application penetration testing tools at SecTor.

The toolset is made specifically for security consultants, developers and QA staff to facilitate testing of applications. The Exploit-Me series of tools are plug-ins to Firefox that allow for easy "right-click" style parameter fuzzing for web applications.

Included in the Exploit-Me series are:

SQL Inject-Me - Point to any HTML field in your Firefox browser and
try to inject it with an individual SQL injection payload or
multiple-payloads via fuzzing by simply right clicking on the field
and selecting "SQL-Inject Me".

XSS-Me - As with SQL-Inject me, point to any field on an HTML document
and attempt to perform Cross-site scripting by right-clicking and
choosing "XSS-Me".

Web Service Exploit-Me - Enter a valid WSDL location and try fuzzing
various parameters in a simple-to-use HTML interface in Firefox using
Web Service Exploit-Me. The interface will also allow for you to
attempt SQL-Injection and XSS through web services.

XSS-Me

XSS-Me is the Exploit-Me tool used to test for reflected Cross-Site Scripting (XSS) vulnerabilities.

SQL Inject-Me

SQL Inject-Me is the Exploit-Me tool used to test for SQL Injection vulnerabilities.

Download and More Info:

http://www.securitycompass.com/exploitme.shtml

satana8920
15.06.2008, 22:28
how to use it ?
ps:sorry my englesh bad

Americandream
16.06.2008, 11:29
i must say that this tool sux.
i do not recommend the usage of it, but if you want really use it, its easy, instalation is point and click based, you must have firefox and give to that website permissions for install addon, after installation, restart firefox and go to tools menu.

Fata1ex
16.06.2008, 11:40
Also u have to look at the date of first post :(

Americandream
16.06.2008, 12:17
Also u have to look at the date of first post
what date of the post have to do with the content of the post?
in this case that tools are still up-to-date and they suck.