This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP/Training/OWASP Webslayer Project"
From OWASP
Cmartorella (talk | contribs) |
Sandra Paiva (talk | contribs) |
||
Line 25: | Line 25: | ||
The training will show how to use the tool and will cover the following topics: | The training will show how to use the tool and will cover the following topics: | ||
− | + | *Interface overview | |
− | + | *Basic Payloads overview | |
− | + | *Basic directory discovery setup | |
− | + | *Advance directory and file discovery | |
− | + | *Login form brute force attack | |
− | + | *Basic authentication attack | |
− | + | *Custom payload generation | |
− | + | *Advanced uses | |
Line 41: | Line 41: | ||
The latest version of Webslayer can be downloaded from: | The latest version of Webslayer can be downloaded from: | ||
− | [http://code.google.com/p/webslayer/downloads/list Webslayer] | + | *[http://code.google.com/p/webslayer/downloads/list Webslayer] |
}} | }} |
Revision as of 18:40, 7 December 2010
MODULE | |
' | |
Overview & Goal | |
WebSlayer is a tool designed for bruteforcing Web Applications, it can be used for finding not linked resources (directories, servlets, scripts, etc), bruteforce GET and POST parameters, bruteforce Forms parameters (User/Password), Fuzzing, etc.
The tools have a payload generator and a easy and powerful results analyzer.
Some features are:
| |
Contents | Materials |
The training will show how to use the tool and will cover the following topics:
|
The training is a hands on course, so it is recommended to bring your own laptop.
The latest version of Webslayer can be downloaded from: |