RSS Feed for This Post

addons for Hacker : Sql Inject-me and Xss-me Plugin

Security Compass announces the release of the open source addons mozilla firefox for web application penetration testing at the SecTor conference in Toronto.this is include addons mozilla firefox XSS-me and addons mozilla firefox Exploit-me
exploit mE is A suite of Firefox web application security testing tools. Exploit-Me tools are designed to be lightweight and easy to use. Instead of using proxy tools like many web application testing tools, Exploit-Me integrates directly with Firefox.

XSS-mE

The tool works by submitting your HTML forms and substituting the form value with strings that are representative of an XSS attack.

If the resulting HTML page sets a specific JavaScript value (document.vulnerable=true) then the tool marks the page as vulnerable to the given XSS string.

The tool does not attempting to compromise the security of the given system. It looks for possible entry points for an attack against the system. There is no port scanning, packet sniffing, password hacking or firewall attacks done by the tool.

You can think of the work done by the tool as the same as the QA testers for the site manually entering all of these strings into the form fields.

The Cross-Site Script Me (XSS-Me) tool allows the user to test their web applications against common XSS vulnerabilities. The Beta2 release corrects an issue with the plugin failing to work with Firefox 2.0.0.10.

XSS-Me 0.2 is available here.

SQL INJECT-mE

SQL Inject Me is the Exploit-Me tool used to test for SQL Injection vulnerabilities.

The tool work by submitting your HTML forms and substituting the form value with strings that are representative of an SQL Injection attack.

The tool works by sending database escape strings through the form fields. It then looks for database error messages that are output into the rendered HTML of the page.

The tool does not attempting to compromise the security of the given system. It looks for possible entry points for an attack against the system. There is no port scanning, packet sniffing, password hacking or firewall attacks done by the tool.

You can think of the work done by the tool as the same as the QA testers for the site manually entering all of these strings into the form fields.

SQL Inject-Me 0.2 is available here.

Looking for similar article like this? Try with this search terms, You will automatically go to search page with the term: SQL Inject Me strings, sql inject me tutorial, sql inject me dork, sql injection backtrack tutorial, SQL Inject-Me, , SQL Inject-Me, mozilla addons sql inject me,

Trackback URL

RSS Feed for This Post2 Comment(s)

  1. Bronzefury | May 27, 2008 | Reply

    I want tolearn XSS now please

  2. admin | May 28, 2008 | Reply

    so please learn it

RSS Feed for This PostPost a Comment

  • Meta

  • Partner links