Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Top Posters

Who's Online (0)

Powered by Vanilla. Made with Bootstrap.
OWASP Web Testing LiveCD (2011) | 650 MB
  • mandi
    Posts: 207
    Just find out this while surfing the internet,I hope it would be useful for the learners like me,so tought of sharing with the members


    OWASP LiveCD - contains a selection of programs to test the safety and performance audit of the code of web-applications, acts as an analog of the well-known tool for testing network security BackTrack, but specializes in the web. Last Release OWASP LiveCD was released in 2007, last summer decided to complete processing of the distribution.
    The composition of OWASP LiveCD includes programs such as Httprint to determine the type http-server on circumstantial evidence, vulnerability scanners in web-applications Grendel Scan and w3af, utilities to identify opportunities to introduce SQL code SQLiX and sqlmap, means of brute force, the local proxy WebScarab , Paros Proxy, Rat Proxy and Burp Suite, Firefox c 1925 amendments to debug sites.

    Thus, the very ten most dangerous threats:
    A1 Injection (injection of any kind, including SQL, LDAP, etc.)
    A2 Cross Site Scripting (not lost relevance XSS)
    A3 Broken Authentication and Session Management (errors in the architecture of the authentication and session management)
    A4 Insecure Direct Object References (unprotected resources and facilities, we can recall the case with SVN)
    A5 Cross Site Request Forgery (CSRF)
    A6 Security Misconfiguration (unsafe configuration of the environment, different frameworks, platforms)
    A7 Failure to Restrict URL Access (unauthorized access to functionality that requires special privileges - such as bypassing the validation c using a double slash \"/\" in the URL to gain access to the management of a blog in Wordpress)
    A8 Unvalidated Redirects and Forwards (open redirects, which lead to phishing, HTTP Response Splitting and XSS)
    A9 Insecure Cryptographic Storage (unsafe storage of important data)
    A10 Insufficient Transport Layer Protection (lack of protection for data in transit at the transport level, such as HTTP instead of HTTPS).



    Download link:


    http://appseclive.org/content/downloads

    for lazies:
    http://downall.org/software/96997-owasp-web-testing-livecd-2011.html?newsid=96997




    please post your feed-backs after trying this ...
  • Looking for a fileserve premium account .. then i will try it ..
  • Xin
    Posts: 3,251
    Nice not sure why you needed the fileserve links, download from the official download site,

    http://appseclive.org/content/downloads

    Less likely to be infected.
    Xin
  • mandi
    Posts: 207
    I just see the contents on a site,i am gonna embedd your links on the main thread..
    Thanks for the link xinapse...
  • Sh3llc0d3
    Posts: 1,910
    Nice share, seen it before but still a nice job :)
  • Xin
    Posts: 3,251
    Anyone tried this? Is it worth downloading?
    Xin