header image
Home arrow Blog
New Web Application Scanner: Netsparker
Blog
Dec 12, 2009 at 01:22 PM

I've been involved in the beta testing of Netsparker for some time now.  Now that it's publicly available, I wanted to write a brief blog post to recommend that you try it out...

If you can't be bothered reading this post, make sure you at least check out the videos of Netsparker in action (particularly the bit where it gets a reverse shell from a SQL injection!).

Last Updated ( Dec 12, 2009 at 01:33 PM )
Read more...
Cross-Site Request Forgery For POST Requests With An XML Body
Blog
Dec 06, 2009 at 01:55 PM

I recently had cause to create a proof-of-concept for a site that seemed to be vulnerable to Cross-Site Request Forgery (CSRF).  I say "seemed" because there was no CSRF protection, but I was finding the XML POST body really hard to forge (It was a SOAP / XMLRPC type request).

Eventually Sid from notsosecure.com pointed me in the right direction.  The solution is not new, but it's interesting if you've never come across this problem before.

Last Updated ( Dec 06, 2009 at 02:33 PM )
Read more...
exploit-suggester Update: v0.3
Blog
Dec 20, 2008 at 11:27 PM
Minor update to exploit suggester.  It now suggests the raptor sploits for Netscape Portable Runtime vulnerability.  Download it here.
Last Updated ( Dec 20, 2008 at 11:29 PM )
YaptestFE Update: v1.1
Blog
Nov 26, 2008 at 09:40 PM

Version 1.1 of the Yaptest Frontend is now available.  Download it here.

 There are three main improvements to the interface:

  • The "Ports" page now displays Nmap version and service information when it's available.
  • The "Windows Info" page displays a list of Windows hosts along with various information about each: Domain name, whether the host is a domain controller, whether it's in a workgroup or a domain, its SID, password complexity setting and account lockout policy.
  • The "Nessus" page simply display the nessus HTML report for the corresponding host.

 

Last Updated ( Nov 26, 2008 at 09:51 PM )
Yaptest Update: v0.2.1
Blog
Nov 26, 2008 at 09:06 PM

Version 0.2.1 of yaptest is now available.  Download it here.

This is quite a major update.  The most notable improvements are support for running Nessus and/or OpenVAS.  At present Nessus and OpenVAS are automatically run against  any open ports with Safe Checks enabled.

As with any major update one or two bugs might have crept in.  Please mail pentestmonkey at pentestmonkey dot net if you find anything's broken.

The complete changelog is included below:

 

Last Updated ( Nov 26, 2008 at 09:09 PM )
Read more...
<< Start < Previous 1 2 3 Next > End >>

Results 1 - 25 of 73