Firefox Extensions For Penetration Testing
This year at the SecTor security conference in Toronto, Canada, Security Compass introduced a series of open source firefox extensions aiding in penetration testing exercises.
Illuminating the Black Art of Security. SecTor brings the world’s brightest (and darkest) minds together to identify, discuss, dissect and debate the latest digital threats facing corporations today. Unique to central Canada, SecTor provides an unmatched opportunity for IT Professionals to collaborate with their peers and learn from their mentors. Held at the Metro Toronto Convention Centre in downtown Toronto, SecTor runs two full days, October 7th and 8th. The event features Keynotes from North America’s most respected and trusted experts. Speakers are true security professionals with depth of understanding on topics that matter. SecTor is a must attend event for every IT Professional.
This suite of web application security testing tools is named Exploit-Me and its designed to be lightweight and easy to use.
The suite is compromised of XSS-Me allowing Cross-Site Scripting, which is a common flaw found in web applications, SQL Inject-Me used to check for SQL Injection vulnerabilities which would allow malicious users to view, delete and modify records and finally Access-Me which test for access vulnerabilities by trying to access resources without being authenticated.
XSS-Me
Cross-Site Scripting (XSS) is a common flaw found in today’s web applications. XSS flaws can cause serious damage to a web application. Detecting XSS vulnerabilities early in the development process will help protect a web application from unnecessary flaws. XSS-Me is the Exploit-Me tool used to test for reflected XSS vulnerabilities.
- Download XSS-Me Now!
- XSS-Me 0.4 release notes
- Get the source
- Read the FAQ to find out more
- Extended XSS string set
- Known issues
SQL Inject-Me
SQL Injection vulnerabilities can cause a lot of damage to a web application. A malicious user can possibly view records, delete records, drop tables or gain access to your server. SQL Inject-Me is the Exploit-Me tool used to test for SQL Injection vulnerabilities.
- Download SQL Inject-Me Now!
- SQL Inject-Me 0.4 release notes
- Get the source
- Read the FAQ to find out more
- Known issues
Access-Me
Access vulnerabilities in an application can allow an attacker to access resources without being authenticated. Access-Me is the Exploit-Me tool used to test for Access vulnerabilities.
- Download Access-Me Now!
- Access-Me 0.2 release notes
- Get the source
- Learn to Hack Access Me to add evaluation code
- Read the FAQ to find out more
- Known issues
My Twitts
- RT @slashdot: A5 Mystery Solved (Why Siri Won't Run On iPhone 4) http://t.co/IX0A91op 10 hours ago
- RT @patriciaaraque: Super Bowl 2012 Commercials: Watch Them All Here http://t.co/3hUrLfwu 2012/02/06
- Demasiado bueno --> RT @susana_rorra: #Madonna genial. Me hizo recordar la adolescencia #TodoUnPerformance 2012/02/06
- Awesome commercial with Clint Eastwood. #superbowl 2012/02/06
- @diegosatx conoceras a alguien en Univision Dallas.? Queremos informar sobre primarias en Dallas el proximo Domingo! 2012/02/04
- @rodolfovargas congrats 2012/02/04
Blogroll
- Blog de Economía y Finanzas
- Dameon D. Welch-Abernathy – Phoneboy
- Drew’s Marketing Minute
- Duct Tape Marketing
- Geek Dad
- Guy Kawasaki – How to Change the World
- Jeff Pulver Blog
- Kevin Kelly’s LifeStream
- Malcolm Gladwell
- Mark Cuban
- Nerd Vittles
- NovaSphere Blog
- OCS Team Blog
- Robert X. Cringely
- Seth Godin
- Small Business Trends
- The Eco-Capitalist – Tom Szaky
- UC – Joachim Farla
- WorkHappy
Sites I Visit
Spam Blocked








