OWASP Mantra

OWASP Mantra

offline
  • Pridružio: 17 Jun 2012
  • Poruke: 727

Citat:Free and Open Source Browser based Security Framework, is a collection of free and open source tools integrated into a web browser, which can become handy for penetration testers, web application developers, security professionals etc.

Slika 1


Slika2


Slika3



Arrow Tools

Information Gathering

Flagfox Displays a flag icon indicating the current webserver's physical location with many additional features.

JSView Get straight access to scripts and stylesheets included in the current web page.

PassiveRecon Perform passive discovery of target resources utilizing publicly available information.

Wappalyzer Uncovers underlying technologies used on websites like CMS, e-commerce systems, JavaScript frameworks, analytics tools etc..

View Dependencies Shows you all the files which were loaded to show the current page.

Link Sidebar View, search and test hyperlinks in a web page.


Application Auditing

Hackbar Simple security audit / Penetration test tool.

RESTClient Visit and test RESTful/WebDav services.

Tamper Data Use tamperdata to view and modify HTTP/HTTPS headers and post parameters.

Live HTTP Headers View HTTP headers of a page and while browsing.

RefControl Control what gets sent as the HTTP Referer on a per-site basis.

User Agent Switcher Various web developer tools on browser.

Web Developer Various web developer tools on browser.

DOM Inspector Inspect and edit the live DOM of any web document or XUL application.

Inspect This Inspect the current element with the DOM Inspector.

Form Fox Displays the form action, the site to which the information you've entered is being sent.

SQL Inject Me Test for SQL injection vulnerabilities which can cause a lot of damage to a web application.

XSS Me Test for XSS vulnerabilities which can cause a lot of damage to a web application.

Cookies Manager+ View, edit and create cookies.

Firecookie View and manage cookies.

Autofill Forms Autofill Forms enables you to fill out web forms with one click or a keyboard shortcut.

Cookie Monster Cookie Monster provides proactive cookie management on a site or domain level basis, including 3rd party cookies.

Fireforce Brute-force attacks on GET or POST forms.

Groundspeed Groundspeed is an add-on that allows security testers to manipulate the application user interface to eliminate annoying limitations and client-side controls that interfere with the web application penetration tests.

Http Requester A tool for easily making HTTP requests (GET/PUT/POST/DELETE), viewing the responses, and keeping a history of transactions.

Modify Headers Add, modify and filter the HTTP request headers sent to web servers. This addon is particularly useful for Mobile web development, HTTP testing and privacy.

Poster A developer tool for interacting with web services and other web resources that lets you make HTTP requests, set the entity body, and content type.


Editors

JSView Get straight access to scripts and stylesheets included in the current web page. View the source code external stylesheets and javascripts.

Firebug Edit, debug, and monitor CSS, HTML, and JavaScript live in any web page.


Proxy

HTTP Fox A built in local proxy for analyzing traffic.

FoxyProxy A proxy management tool with ability to switch between multiple proxies with few clicks.

Proxy Tool A proxy management tool with lots of additional features to enahnce the privacy.


Network Utilities

FireFTP FTP/SFTP Client which provides intuitive access to FTP/SFTP servers.

SQLite Manager Manage any SQLite database on your computer.

FireSSH SSH Client.

DNS Cache Allows you to disable and enable the DNS Cache of Firefox.

HTTP Fox Monitors and analyzes all incoming and outgoing HTTP traffic between the browser and the web servers.


Misc

Greasemonkey Customize the way webpages look and function. A userscript manager for Firefox.

Greasefire Automatically finds Greasemonkey scripts on Userscripts.org.

CacheToggle Disable and optionally clear the browser cache with the flick of a switch.

URL Flipper Easily increment or decrement a portion of a URL without having to manually edit the text in the Location Bar.

Event Spy DOM Event spy addon. Lets you watch JavaScript events as they occur.

Stacked Inspector Switch DOM Inspector to an over/under vertical layout instead of the usual side-by-side panel layout.

Scriptish The greatest user script engine on the Internet (a fork of Greasemonkey).

Session Manager Session Manager saves and restores the state of all windows. It can also automatically save the state of open windows individually.

Fire Encrypter Encrypt, decrypt and hashing functions utility.

DownThemAll An easy to use and fucntional download manager.


Application Auditing

Websecurify Websecurify is a powerful, cross-platform web security testing technology designed from the ground up with simplicity in mind.

Ra.2 Blackbox DOM-based XSS Scanner.

Ref Spoof Easy spoofing of the URL referer (referrer) featuring a toolbar.

NoRedirect Take control of web page redirects for fun and profit.


Arrow Bookmarks

Hackery

A collection of penetration testing links.

*Hacker media
* Blogs worth it
* Forums
* Magazines
* Video
*Methodologies
*OSINT
*Presentations
*People and Orginizational
*Infastructure
*Exploits and Advisories
*Cheat Sheets and Syntax
*Cheat Sheets and Syntax
*Agile Hacking
*OS & Scripts
*Tools
*Security and Penetration Testing Distributions
*Labs
*Vulnerable Software
*ISO's/ VMs
*Test Sites
*Exploitation Introductions and guides
*Reverse Engineering and Malware
*Password and Hashes
*Wordlists
*Pass the Hash
*Passwords and Hashes
*MitM
*Tools
*OSINT
*OSINT > Metadata
*Google Hacking
*Web
*Attack Strings
*Shells
*Proxies
*Scanners
*Proxies > Burp
*Password
*Social Engineering
*NSE
*Metasploit > MSF Exploits or Easy
*Net Scanners and Scripts
*Metasploit
*Netcat
*Post Exploitation
*Source Inspection
*Tool Listings
*Firefox Addons
*Training / Classes
*Metasploit
*Programming > Python
*Sec / Hacking
*Programming > Ruby
*Other/Misc
*Web Vectors
*SQLi
*Upload tricks
*LFI/RFI
*Coldfusion
*XSS
*SharePoint
*SAP
*Lotus
*Jboss
*Oracle Appserver
*Vmware web
*Misc/ Unsorted
*Wireless
*CTF / Wargames
*Conferences

Galley

A collection of links to online tools.

*Information Gathering
*Whois
*DNS
*Location Info
*Enumeration and Fingerprint
*Data Mining
*Search Engines
*Editors
*Online Text Editors
*Share text snippets
*Network Utilities
*Ping
*HTTP
*HTTPS
*VNC
*Remote Desktop
*SSH
*DNS
*Sniffers
*Misc
*Forensics
*Frameworks
*E-mail
*Password (zabranjeno)ing
*URL Cloaking
*Encoders and Decoders
*Encoders
*Decoders
*Malware
*Malware Analysis
*Identify Malicious Websites
*Suspected Malicious IPs and URLs
*Application Auditing
*SQL Injection
*Cross Site Scripting
*File Inclusion
*Anonymity
*Proxy
*Others

Support:
Windows
Linux 32 bit
Linux 64 bit
Macintosh

Video http://www.youtube.com/user/Getmantra/videos?view=0

Arrow Official Website & Download http://www.getmantra.com/index.html



Registruj se da bi učestvovao u diskusiji. Registrovanim korisnicima se NE prikazuju reklame unutar poruka.
Ko je trenutno na forumu
 

Ukupno su 929 korisnika na forumu :: 46 registrovanih, 8 sakrivenih i 875 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., amaterSRB, anta, Apok, Boris BM, CikaKURE, cinoeye, djboj, dushan, Excalibur13, Georgius, grenadir, hatman, ILGromovnik, jackreacher011011, JOntra, Još malo pa deda, kobaja77, Komentator, Krvava Devetka, kunktator, ljuba, loon123, Lošmi, mercedesamg, Mi lao shu, milutin134, nikoladim, ozzy, Petar35, raptorsi, Romibrat, rovac, slonic_tonic, Srle993, stegonosa, Stoilkovic, Sumadija34, TITAN DUDIN JARAN, Toper, Trpe Grozni, Vatreni Zmaj, vladaa012, yrraf, zeo, ZetaMan