A popular open-source Web application attack and audit framework is now under the umbrella of Rapid7, the vulnerability management company that purchased the Metasploit Project last year. The w3af project ultimately will bring more Web security features and functions to both the Metasploit tool and Rapid7's commercial NeXpose product. . The open-source Metasploit penetration-testing tool currently has exploits for a handful of Web application bugs, as well as a few for generic Web flaws that affect multiple applications, says HD Moore, chief architect of Metasploit and chief security officer at Rapid7. But the goal is to expand Metasploit with more integrated Web flaw detection and attack features. "Where we are moving to is toward dynamic detection and exploitation of vulnerabilities in custom applications and in known-vulnerable applications installed in nonstandard directories," Moore says. "So [we're] combining [Web] crawling with scanning to find vulnerable applications and then apply 'generic' Web application exploit modules against those to get access. The link for this article located at Dark Reading is no longer available. . Metasploit is upgrading its capabilities for web application attacks, focusing on real-time identification and exploitation through fresh integrations.. Metasploit Framework, Web Application Security, Rapid7 Features. . LinuxSecurity.com Team
w3af, is a Web Application Attack and Audit Framework. It is extended using plugins; the framework and the plugins are fully written in python. Each plugin will add a functionality like xss detection or sql injection exploitation. . The link for this article located at SourceForge is no longer available. . w3af serves as a robust Framework for Web Application Attacks and Audits, utilizing various plugins to augment its security assessment capabilities.. Web Application Security, w3af, Security Testing Framework, Penetration Testing Tools. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.