Web Application Analysis refers to all applications that are accessed through a browser. Security testing for your application is very important if data leaks or modifications are unacceptable and intolerable. For example, if a e-commerce applications, which sometimes involve banking transactions, security testing is critical. It should also ensure that sufficient authentication and authorization mechanisms are in place.
Security testing can be static or dynamic.
- Static testing involves doing a static code analysis to check for any vulnerabilities. The goal is to understand the code flow and check for security threats by walking through the code.
- Dynamic testing entails running the application to see if the response is as expected for the associated request. It is very similar to black box testing.
WEB APPLICATION ANALYSIS - SOFTWARE'S / TOOLS / UTILITIES
- Web Proxies
- Web Scanners
- Web Testing Frameworks
- Web Browser Assessment
- Web Browser For Penetration Testing
- Fuzzers
- Database Assessment
- Burpsuite
- Fiddler
- OWASP ZAP
- Paros Proxy
- ProxyStrike
- Ratproxy
- Webscarab
- SPIKE Proxy
- ModSecurity
- ASProxy
- stunnel
- Assh
- iodine
- Tor
- UltraSurf
- ProxMon
- CSRFTester
- Curl
- DFF Scanner
- DirBuster
- Grabber
- Grendel Scan
- Httprint
- xSQL Scanner
- WebVulScan
- Jmeter
- Lbd
- Mini Mysqlat0r
- Netsparker Community Edition
- Nikto
- OpenAcunetix
- OWASP ZAP
- SecuBat
- Skipfish
- SoapUI
- Swfintruder
- W3AF
- Wapiti
- WebRaider
- Webshag
- x5s
- Xsss
- xssrays
- Yokoso!
- Arachni v0.4
- wavsep
- watcher
- Cenzic Hailstrom
- OWASP Joomla
- SSL Audit
- httpsScanner
- Metoscan
- cewl
- wstool
- Conficker Detection
- Asp-Audit
- XSSer
- xssed
- Bizploit
- Sahi
- Websecurify
- Mutillidae
- BeFF
- zaproxy
- FunkLoad
- Beef
- Browser Fuzzer 3 (bf3)
- Browser Rider
WEB BROWSER FOR PENETRATION TESTING
- OWASP Mantra
- Sandcat Browser
- Hcon
- twill
- FuzzDb
- OWASP ZAP
- PowerFuzzer
- Wfuzz
- DotDotPwn
- MS-SQL
- MYSQL
- DBPwAudit
- Metacoretex
- MYSQLAudit
- MySploit
- Pblind
- SQLCheck
- SQLData
- SQLiX
- SQLMap
- Sqlsus
- UDF
- MYSQL 5 ENUMERATOR
- ORACLE
- DBPwAudit
- Metacoretex
- Opquery
- Opwg
- Oscanner
- Ose
- Otnsctl
- Pblind
- SQLbrute
- SQLiX
- SQLMap
- Encryption Wizard
- BSQL Hacker
- Sqlninja
- Havij
- Pangolin
- The Mole
- Safe3SI
- Darkjumper
- GreenSQL
- xpath blind explorer