Skip to content

HTTP Sniffer for iPhone and iPad

2011 August 6
Posted by zhyale

App Store:  http://itunes.apple.com/us/app/http-sniffer/id451037645?ls=1&mt=8

HTTP Sniffer is a manual web security testing tool which can capture HTTP requests, include request headers, post data, and you can modify the request and then resend them.
You can get the response headers and source code only, or load the response in web browser.
Notice:
1. Using HTTP Sniffer requires network connection, and Wi-Fi network is preferred.
2. HTTP Sniffer will not capture the requests of other applications, it capture the requests of its own only.
3. HTTP Sniffer is designed for web security professionals only, used for web security penetration testing, such as SQL Injection, Cross-site Scripting(XSS) etc.
Key features:
1. HTTP (Get, Post etc.) Sniffer;
2. HTTP request replay (resend);

SQL Injection Tutorial

2010 December 25
Posted by zhyale

SQL Injection Tutorial describes how to use SQL Injection manually.

http://sec4app.com/download/SQL_Injection_Tutorial.pdf

Zebra Blog

2010 November 19
Posted by zhyale

 Zebra Blog , Zebra Blog supplies reviews of books, magazines, software, sporting goods etc.

http://www.zebrablog.org/

Janus File StrongBox (File Encryption Software)

2010 November 9
Posted by zhyale

File StrongBox, is a file encryption software that offers protection for your important files, pictures and private data. File StrongBox creates encrypted storages named StrongBox, You can keep your private files in the Strongbox and protect it with a password.

File StrongBox Key Features:
* AES-256 bit encryption (Military level);
* Multiple-Strongbox support;
* Password protection for strongbox;
* Encrypted files edit;
* Import or export Strongbox;
* Drag and drop for files and folders;

System Requirement:
.Net Framework 2.0 or higher;

FAQ
1. How to open StrongBox?
Simply, double click it;
2. How to add files into the StrongBox?
Drag files and drop it into the StrongBox;
3. If I forgot my password, is there any way to open my StrongBox?
No way. You should keep the password in mind, nobody can open it if you forgot it; But you can set a prompt sentence when you create the strongbox.

Support WebSite:
http://www.janusec.com

Janus PowerPoint Countdown Timer

2010 October 24
Posted by zhyale

Janus Countdown Timer, is a perfect PowerPoint countdown timer designed for PowerPoint slideshow countdown or other countdown purpose. Janus Countdown Timer integrated with PowerPoint, it can automatically countdown when slideshow begin and stop when slideshow end.

Janus PowerPoint Countdown Timer Key Features:
* Integrated with PowerPoint;
* Auto countdown start when slideshow begin;
* Auto countdown stop when slideshow end;
* Auto or manually start;
* Full screen support;
* Insufficient time reminder;

System Requirement:
.Net Framework 2.0 or higher;

WebCruiser – Web Vulnerability Scanner V2.4.2

2010 July 20
Posted by zhyale

WebCruiser – Web Vulnerability Scanner V2.4.2 Released.

WebCruiser – Web Vulnerability Scanner, a compact but powerful web security scanning tool that will aid you in auditing your site! It has a Vulnerability Scanner and a series of security tools.It can support scanning website as well as POC (Proof of concept) for web vulnerabilities: SQL Injection, Cross Site Scripting, XPath Injection etc. So, WebCruiser is also an automatic SQL injection tool, an XPath injection tool, and a Cross Site Scripting tool!

Key Features:
* Crawler(Site Directories And Files);
* Vulnerability Scanner: SQL Injection, Cross Site Scripting, XPath Injection etc.;
* SQL Injection Scanner;
* SQL Injection Tool: GET/Post/Cookie Injection POC(Proof of Concept);
* SQL Injection for SQL Server: PlainText/Union/Blind Injection;
* SQL Injection for MySQL: PlainText/Union/Blind Injection;
* SQL Injection for Oracle: PlainText/Union/Blind/CrossSite Injection;
* SQL Injection for DB2: Union/Blind Injection;
* SQL Injection for Access: Union/Blind Injection;
* Post Data Resend;
* Cross Site Scripting Scanner and POC;
* XPath Injection Scanner and POC;
* Auto Get Cookie From Web Browser For Authentication;
* Report Output.

System Requirement: Windows with .Net Framework 2.0 or higher
Download WebCruiser – Web Vulnerability Scanner

Which is the most effective Web Vulnerability Scanner?

2010 July 9
Posted by zhyale

Hackers can get plenty of sensitive data such as the whole database which include customer’s details and corporate data through web application vulnerabilities.

Any defense at network layer will guarantee no protection against web attacks since they are launched on usual port 80 or 443– which has to remain open. In addition, web application security auditing is often done from the developer’s perspective – checking the source code for possible security issues, which is called “White-Box Testing”, that can leave gaps in the application security.

To create a secure web application, you need to combine developer’s approach and hacker’s approach – checking security issues after the code leaves the development environment, which is called “Black-Box Testing”. To provide continues protection to your web application, this task needs to be done automatically and regularly – such as is provided by WebCruiserWeb Vulnerability Scanner.

WebCruiserWeb Vulnerability Scanner lets you view your web application security problems from the hacker’s perspective – it doesn’t check the code, but can tell how one could circumvent your application’s security by SQL Injection, Cross Site Scripting, XPath Injection etc.

To perform a scan, you simply input the URL and click “Scan Site” to start a whole web site scanning or click “Scan URL” to start a single page scanning. WebCruiser can also launch a multi-site scan based on entries in a file.

The scanner comes with many built-in scanning test tools such as SQL Injection, Cross Site Scripting, XPath Injection and more. The default option performs all tests. However, to speed the scanning process, you can perform particular tests.

WebCruiserWeb Vulnerability Scanner, is the most effective tool to audit your web application. WebCruiser focuses its attention on the web application and provides you with information on security issues that hackers can exploit. So, whether you are a web application developer or a security auditor, WebCruiserWeb Vulnerability Scanner is an essential tool to ensure the security of your web application. Click here to download a copy of WebCruiserWeb Vulnerability Scanner.

WebCruiser – Web Vulnerability Scanner V2.3.3

2010 June 26
Posted by zhyale

WebCruiserWeb Vulnerability Scanner, a compact but powerful web security scanning tool that will aid you in auditing your site! It has a Vulnerability Scanner and a series of security tools.

It can support scanning website as well as POC (Proof of concept) for web vulnerabilities: SQL Injection, Cross Site Scripting, XPath Injection etc. So, WebCruiser is also an automatic SQL injection tool, an XPath injection tool, and a Cross Site Scripting tool!

Key Features:
* Crawler(Site Directories And Files);
* Vulnerability Scanner: SQL Injection, Cross Site Scripting, XPath Injection etc.;
* SQL Injection Scanner;
* SQL Injection Tool: GET/Post/Cookie Injection POC(Proof of Concept);
* SQL Injection for SQL Server: PlainText/Union/Blind Injection;
* SQL Injection for MySQL: PlainText/Union/Blind Injection;
* SQL Injection for Oracle: PlainText/Union/Blind/CrossSite Injection;
* SQL Injection for DB2: Union/Blind Injection;
* SQL Injection for Access: Union/Blind Injection;
* Post Data Resend;
* Cross Site Scripting Scanner and POC;
* XPath Injection Scanner and POC;
* Auto Get Cookie From Web Browser For Authentication;
* Report Output.

System Requirement: Windows with .Net Framework 2.0 or higher

WebCruiser Web Vulnerability Scanner Download

Janus Security Software

2010 June 23
Posted by zhyale

Janus Security Software

Janus Security Software

In Roman mythology, Janus was the god of gates, doors, doorways, beginnings and endings. His most prominent remnant in modern culture is his namesake, the month of January, which begins the new year. He is most often depicted as having two faces or heads, facing in opposite directions. These heads were rumored to look both into the future and the past.

http://www.janusec.com/

Order WebCruiser – Web Vulnerability Scanner

2010 June 18
Posted by zhyale

WebCruiserWeb Vulnerability Scanner, a compact but powerful web security scanning tool that will aid you in auditing your site! It has a Vulnerability Scanner and a series of security tools.

It can support scanning website as well as POC (Proof of concept) for web vulnerabilities: SQL Injection, Cross Site Scripting, XPath Injection etc. So, WebCruiser is also an automatic SQL injection tool, an XPath injection tool, and a Cross Site Scripting tool!

Key Features:
* Crawler(Site Directories And Files);
* Vulnerability Scanner(SQL Injection, Cross Site Scripting, XPath Injection etc.);
* POC(Proof of Concept): SQL Injection, Cross Site Scripting, XPath Injection etc.;
* SQL Injection Tool for GET/Post/Cookie Injection;
* SQL Injection for SQL Server: PlainText/Union/Blind Injection;
* SQL Injection for MySQL: PlainText/Union/Blind Injection;
* SQL Injection for Oracle: PlainText/Union/Blind/CrossSite Injection;
* SQL Injection for DB2: Union/Blind Injection;
* SQL Injection for Access: Union/Blind Injection;
* Post Data Resend;
* Administration Entrance Search;
* Time Delay For Search Injection;
* Auto Get Cookie From Web Browser For Authentication;
* Report Output.

System Requirement: Windows with .Net Framework 2.0 or higher

1.WebCruiserWeb Vulnerability Scanner Professional Edition (Non-Commercial License) US$49.00 Buy Now

2.WebCruiserWeb Vulnerability Scanner Enterprise Edition (Commercial License) US$890.00 Buy Now

3.WebCruiserWeb Vulnerability Scanner Free Edition

The Free Edition is for security amateurs, no support service, some function such as scanning government or military web site, multi-site scanning is disabled. The Professional Edition is for security professionals, masters of individual websites etc., non-commercial purpose, 12-month update and support service, No function limit. The Enterprise Edition is for enterprises, institution, or commercial organizations, 12-month update and support service with top priority. No function limit.

Function      \     Edition Free Professional Enterprise
Commercial License No No Yes
Directories Crawler Yes Yes Yes
Vulnerabilities Scanning Yes Yes Yes
SQL Server Injection Yes Yes Yes
MySQL Injection Yes Yes Yes
Oracle Injection Yes Yes Yes
DB2 Injection Yes Yes Yes
Advanced Injection Yes Yes Yes
Access Injection Yes Yes Yes
Access Dictionary Edit Yes Yes Yes
Cross-Site Scripting Yes Yes Yes
XPath Injection Yes Yes Yes
Post Resend Yes Yes Yes
Multi-Site Scanning No Yes Yes
Sensitive WebSites Scanning No Yes Yes
Cookie Tool Yes Yes Yes
Report No Yes Yes
Technical Support No 12-month 12-month

Thank you for choosing WebCruiser.