This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Category:OWASP WebScarab Project"
From OWASP
(20 intermediate revisions by 9 users not shown) | |||
Line 1: | Line 1: | ||
+ | {{taggedDocument | ||
+ | | type=historical | ||
+ | | link=OWASP Zed Attack Proxy Project | ||
+ | }} | ||
+ | {| | ||
+ | |- | ||
+ | ! width="700" align="center" | <br> | ||
+ | ! width="500" align="center" | <br> | ||
+ | |- | ||
+ | | align="right" | [[Image:OWASP Inactive Banner.jpg|800px| link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Inactive_Projects]] | ||
+ | | align="right" | | ||
+ | |||
+ | |} | ||
{{OWASP Book|1416452}} | {{OWASP Book|1416452}} | ||
− | + | {{OWASP Breakers}} | |
− | + | = Main = | |
'''Welcome to the WebScarab Project''' | '''Welcome to the WebScarab Project''' | ||
Line 22: | Line 35: | ||
==Download== | ==Download== | ||
− | + | The canonical source repository for WebScarab is at [https://github.com/OWASP/OWASP-WebScarab GitHub]. A zip archive of the tip of tree can be downloaded [https://github.com/OWASP/OWASP-WebScarab/archive/master.zip here]. | |
− | |||
− | |||
− | + | Historical Versions: | |
− | + | Alternatively, you can download older builds of WebScarab from the [http://sourceforge.net/project/showfiles.php?group_id=64424&package_id=61823 OWASP Source Code Center at Sourceforge]. Then install them likewise: | |
+ | * Linux: <tt>java -jar ./webscarab-selfcontained-[numbers].jar</tt> | ||
+ | * Windows: double-click the installer jar file [http://www.acsac.org/2007/downloads/t5-webscarab-instructions.pdf (complete installation instructions)]) | ||
==Features== | ==Features== | ||
Line 50: | Line 63: | ||
* Manual request - Allows editing and replay of previous requests, or creation of entirely new requests. | * Manual request - Allows editing and replay of previous requests, or creation of entirely new requests. | ||
− | * SessionID analysis - collects and | + | * SessionID analysis - collects and analyzes a number of cookies to visually determine the degree of randomness and unpredictability. Note that this analysis is rather trivial, and does not do any serious checks, such as FIPS, etc. |
* Scripted - operators can use BeanShell (or any other BSF supported language found on the classpath) to write a script to create requests and fetch them from the server. The script can then perform some analysis on the responses, with all the power of the WebScarab Request and Response object model to simplify things. | * Scripted - operators can use BeanShell (or any other BSF supported language found on the classpath) to write a script to create requests and fetch them from the server. The script can then perform some analysis on the responses, with all the power of the WebScarab Request and Response object model to simplify things. | ||
Line 86: | Line 99: | ||
==Project Contributors== | ==Project Contributors== | ||
− | The WebScarab project is run by Rogan Dawes | + | The WebScarab project is run by Rogan Dawes. He can be contacted at rogan AT dawes.za.net |
+ | |||
+ | = Project About = | ||
+ | |||
+ | {{:Projects/OWASP WebScarab Project | Project About}} | ||
+ | |||
+ | |||
+ | __NOTOC__ <headertabs /> | ||
− | [[Category: | + | [[Category:OWASP_Project|WebScarab Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP Release Quality Tool]] |
− | [[Category: | ||
− | [[Category: | ||
− | [[Category:OWASP Release Quality Tool]] |
Latest revision as of 03:16, 15 August 2014
This historical page is now part of the OWASP archive.
This page contains content that is outdated and is no longer being maintained. It is provided as a courtesy for individuals who are still using these technologies. This page may contain URLs that were once valid but may now link to sites or pages that no longer exist.
Please use the newer Edition(s) like OWASP Zed Attack Proxy Project
This page contains content that is outdated and is no longer being maintained. It is provided as a courtesy for individuals who are still using these technologies. This page may contain URLs that were once valid but may now link to sites or pages that no longer exist.
Please use the newer Edition(s) like OWASP Zed Attack Proxy Project
|
|
---|---|
![]() |
![]() |
This project has produced a book that can be downloaded or purchased. Feel free to browse the full catalog of available OWASP books. |
This project is part of the OWASP Breakers community. Feel free to browse other projects within the Defenders, Builders, and Breakers communities. |
Pages in category "OWASP WebScarab Project"
The following 16 pages are in this category, out of 16 total.