<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>a4apphack &#187; appsec</title>
	<atom:link href="http://a4apphack.com/index.php/tag/appsec/feed" rel="self" type="application/rss+xml" />
	<link>http://a4apphack.com</link>
	<description>Get more out of the Apps!</description>
	<lastBuildDate>Wed, 11 Jan 2012 20:25:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<image>
<link>http://a4apphack.com</link>
<url>http://a4apphack.com/blog/wp-content/themes/primus/favicon.ico</url>
<title>a4apphack</title>
</image>
		<item>
		<title>HTML5 CheatSheet Project</title>
		<link>http://a4apphack.com/security/sec-browser/html5-cheatsheet-project</link>
		<comments>http://a4apphack.com/security/sec-browser/html5-cheatsheet-project#comments</comments>
		<pubDate>Thu, 13 May 2010 21:49:50 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Code]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[html5]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1962</guid>
		<description><![CDATA[HTML5 is a new and upcoming technology which has enough features to introduce potential security issues if not properly implemented. A new project has been initiated in Google Code to keep developers updated on the security concerns to be kept in mind while developing their apps with HTML5. Description of Project in Authors Terms, This [...]]]></description>
			<content:encoded><![CDATA[<p>HTML5 is a new and upcoming technology which has enough features to introduce potential security issues if not properly implemented. A new project has been initiated in Google Code to keep developers updated on the security concerns to be kept in mind while developing their apps with <a title="HTML5" href="http://en.wikipedia.org/wiki/HTML5">HTML5</a>.</p>
<p>Description of Project in Authors Terms,</p>
<blockquote><p><em>This project is an attempt to create a well maintained, informative and categorized cheat sheet to highlight HTML5 as well as other client side and related security issues and ways to avoid them.  The project is meant to target web developers as well as security researchers and especially browser vendors since many of the problems we found are based on faulty or quirky implementations. Focus is on completeness, comprehensibility and timeliness as well as continuity &#8211; benefits many other related cheat sheets don&#8217;t exactly provide.</em></p>
<p></em></p>
</blockquote>
<p><span id="more-1962"></span></p>
<p><a href="http://img.a4apphack.com/html5sec-main.jpg" rel="lightbox[1962]" title="HTML5 Security Cheatsheet"><img class="alignnone" title="HTML5 Security Cheatsheet" src="http://img.a4apphack.com/html5sec-main.jpg" alt="HTML5 Security Cheatsheet" width="600" height="493" /></a></p>
<p>Time to this site if are a developer or security analyst.</p>
<p><a title="HTML5 Cheatsheet" href="http://heideri.ch/jso/">HTML5 CheatSheet</a></p>
<table id="cft">
  <thead>
  <tr>
    <th colspan="2">HTML5 CheatSheet Info</th>
  </tr>
  </thead>
  <tbody>
    <tr>
      <td  width="40%">App Name</td>
      <td>HTML5 CheatSheet</td>
    </tr>
    <tr>
      <td>License</td>
      <td>free</td>
    </tr>
    <tr>
      <td>Type</td>
      <td>online</td>
    </tr>
    <tr>
      <td>App URL</td>
      <td>
      <a target="_blank" href="http://heideri.ch/jso/"><img
 style="" alt="Download"
 src="http://img.a4apphack.com/site/a4apphack-download.png"
 title="Download" witdh="30" height="30"></a></td>
    </tr>
    <tr>
      <td>More Info</td>
      <td> <a href="http://code.google.com/p/html5security/">link</a></td>
    </tr>
  </tbody>
</table>

<p><br class="spacer_" /></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1962&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/security/sec-browser/html5-cheatsheet-project/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Websecurify &#8211;  Free Web Application Vulnerability Scanner</title>
		<link>http://a4apphack.com/featured/websecurify-free-web-application-vulnerability-scanner</link>
		<comments>http://a4apphack.com/featured/websecurify-free-web-application-vulnerability-scanner#comments</comments>
		<pubDate>Thu, 01 Apr 2010 22:06:20 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[va]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1768</guid>
		<description><![CDATA[Websecurify is a powerful web application security testing environment designed from the ground up to provide the best combination of automatic and manual vulnerability testing technologies. This tool automatically identifies web application vulnerabilities by using advanced discovery and fuzzing technologies. WebSecurify is available in major OS platforms &#8211; Windows, Mac and Linux. Its even available [...]]]></description>
			<content:encoded><![CDATA[<p>Websecurify is a powerful web  application security testing environment  designed from the ground up to  provide the best combination of  automatic and manual vulnerability  testing technologies. This tool  automatically identifies web application vulnerabilities by using   advanced discovery and fuzzing technologies.</p>
<p>WebSecurify is available in major OS platforms &#8211; Windows, Mac and Linux. Its even available as a Chrome extension.</p>
<p><strong>Post Updated:</strong></p>
<ul>
<li>Target site that requires authentication</li>
<li>Info on Chrome Plugin</li>
</ul>
<p><a title="Websecurify Scan in Progress" href="http://img.a4apphack.com/websecurify-testprogress.jpg" rel="lightbox[1768]"><img class="alignnone" title="Websecurify Scan in Progress" src="http://img.a4apphack.com/websecurify-scanning.jpg" alt="Wensecurify Scan in Progress" width="600" height="330" /></a></p>
<p><span id="more-1768"></span></p>
<p><strong>Running the Scanner</strong></p>
<p>Initiating a scan with Websecurify is simple and is achieved in 2-3 steps.</p>
<p style="padding-left: 30px;">1. Select &#8216;Start new automated test&#8217;, Enter Workspace Name and the Target application URL.</p>
<p style="padding-left: 30px;"><a href="http://img.a4apphack.com/websecurify-startscan.jpg" rel="lightbox[1768]" title="Start Scan"><img class="alignnone" title="Start Scan" src="http://img.a4apphack.com/websecurify-startscan.jpg" alt="Start Scan" width="550" height="406" /></a></p>
<p style="padding-left: 30px;">2. If application requires login, select &#8216;login or initialize target&#8217;. This opens the browser and asks you to enter the credentials. Close the browser window after login. (This step is optional).</p>
<p style="padding-left: 30px;"><a href="http://img.a4apphack.com/websecurify-authenticate.jpg" rel="lightbox[1768]" title="Authenticate"><img class="alignnone" title="Authenticate" src="http://img.a4apphack.com/websecurify-authenticate.jpg" alt="Authenticate" width="550" height="331" /></a></p>
<p style="padding-left: 30px;">You should new be authenticated to the application. After post login pages are displayed, close websecurify browser window.</p>
<p style="padding-left: 30px;"><a href="http://img.a4apphack.com/websecurify-postlogin.jpg" rel="lightbox[1768]" title="Post Login Page"><img class="alignnone" title="Post Login Page" src="http://img.a4apphack.com/websecurify-postlogin.jpg" alt="Post Login Page" width="550" height="420" /></a></p>
<p style="padding-left: 30px;">3. Click on &#8216;Ok&#8217; to start the scan <img src='http://a4apphack.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p style="padding-left: 30px;"><a href="http://img.a4apphack.com/websecurify-startscan.jpg" rel="lightbox[1768]" title="Scan in Progress"><img class="alignnone" title="Scan in Progress" src="http://img.a4apphack.com/websecurify-startscan.jpg" alt="Scan in Progress" width="550" height="406" /></a></p>
<ol></ol>
<p><strong>Once the Scan is Complete</strong></p>
<p>Once the scan is complete, scan results are displayed, sorted based on the severity of the vulnerabilities discovered. Clicking on each of the category will further display the instances found and the technical details of analysis.</p>
<p><a href="http://img.a4apphack.com/websecurify-issuestab.jpg" rel="lightbox[1768]" title="Issues List"><img class="alignnone" title="Issues List" src="http://img.a4apphack.com/websecurify-issuestab.jpg" alt="Issues List" width="542" height="446" /></a></p>
<p>Scan results can be rendered in a report format by clicking on the Report Tab and can be exported in CSV, HTM, XML and JSON formats.</p>
<p><a title="Websecurify Report" href="http://img.a4apphack.com/websecurify-reporttab.jpg" rel="lightbox[1768]"><img class="alignnone" title="Websecurify Report" src="http://img.a4apphack.com/websecurify-reporttab.jpg" alt="Websecurify Report" width="600" height="413" /></a></p>
<p><strong>Comments/Observations</strong></p>
<ol>
<li>A scan was initiated for an average sized application during evaluation of websecurify and following were identified</li>
<li>Memory consumption was increasing with time but its far better than many other free/commercial scanners</li>
<li>Progress of scan was normal till it reached almost 97% (in around 2   hrs), then it stayed in 97-98 and back to 97 for a loooong time. So I had it running and checked it the next day.</li>
<li>This tool doesn&#8217;t provide the statistics of the scan, like pages crawled, time consumed, etc.</li>
<li>This tool has the simplest interface of all the other tools available in the market.</li>
</ol>
<p><strong>Chrome Extension</strong></p>
<p>WebSecurify has a chrome extension too. Once installed, we can initiate the scan from within Chrome.</p>
<p><img class="alignnone" title="Scan from Chrome" src="http://img.a4apphack.com/websecurify-chrometest.jpg" alt="Scan from Chrome" width="445" height="266" /></p>
<p>Test Report can be displayed on a new page once the scan is complete.</p>
<p><a href="http://img.a4apphack.com/websecurify-chromereport.jpg" rel="lightbox[1768]" title="Chrome Test Report"><img class="alignnone" title="Chrome Test Report" src="http://img.a4apphack.com/websecurify-chromereport.jpg" alt="Chrome Test Report" width="600" height="599" /></a></p>
<p><a href="https://chrome.google.com/webstore/detail/emclbdbpcnhmopfkidjhlinikkohlkpn#">https://chrome.google.com/webstore/detail/emclbdbpcnhmopfkidjhlinikkohlkpn#</a></p>
<div id="sidebar">
<h3>Features</h3>
<ul>
<li>Scans major web vulnerabilities like, XSS, SQL injection, CRLFI, LFI, Directory Listing, System Path disclosure vulnerabilities etc</li>
<li>Available for all major platforms (Mac, Win, Linux)</li>
<li>Easily extensible with add-ons</li>
<li>Detailed reports which can be exported in CSV, HTM, XML and JSON.</li>
<li>Configurable proxy setting.</li>
<li>Simple to use</li>
</ul>
</div>
<div style="padding-left: 30px;"><strong><a href="http://www.websecurify.com/"><img class="alignnone" title="Websecurify Logo" src="http://img.a4apphack.com/websecurify-logo.jpg" alt="Websecurify Logo" width="292" height="73" /></a><br />
</strong></div>
<table id="cft">
  <thead>
  <tr>
    <th colspan="2">Websecurify Info</th>
  </tr>
  </thead>
  <tbody>
    <tr>
      <td  width="40%">App Name</td>
      <td>Websecurify</td>
    </tr>
    <tr>
      <td>License</td>
      <td>free</td>
    </tr>
    <tr>
      <td>Type</td>
      <td></td>
    </tr>
    <tr>
      <td>App URL</td>
      <td>
      <a target="_blank" href="http://www.websecurify.com/"><img
 style="" alt="Download"
 src="http://img.a4apphack.com/site/a4apphack-download.png"
 title="Download" witdh="30" height="30"></a></td>
    </tr>
    <tr>
      <td>More Info</td>
      <td> <a href="http://www.websecurify.com/">link</a></td>
    </tr>
  </tbody>
</table>

<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1768&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/featured/websecurify-free-web-application-vulnerability-scanner/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Tool to View the Cookies Created by Flash Component</title>
		<link>http://a4apphack.com/security/tool-to-view-the-cookies-created-by-flash-component</link>
		<comments>http://a4apphack.com/security/tool-to-view-the-cookies-created-by-flash-component#comments</comments>
		<pubDate>Tue, 30 Mar 2010 18:48:50 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Portable]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[systools]]></category>
		<category><![CDATA[va]]></category>
		<category><![CDATA[viewer]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1760</guid>
		<description><![CDATA[FlashCookiesView is a small utility that displays the list of cookie files created by Flash component (Local Shared Object) in your Web browser. For each cookie file, the lower pane of FlashCookiesView displays the content of the file in readable format or as Hex dump. If you are a security tester, this can help you [...]]]></description>
			<content:encoded><![CDATA[<p>FlashCookiesView is a small utility that displays the list of cookie files created by Flash component (Local Shared Object) in your Web browser. For each cookie file, the lower pane of FlashCookiesView displays the content of the file in readable format or as Hex dump. If you are a security tester, this can help you while testing for flash applications &#8211; to analyse the sensitive content in the flash generated cookies.</p>
<p>You can also select one or more cookie files, and then copy them to the clipboard, save them to text/html/xml file or delete them.</p>
<div class="wp-caption alignnone" style="width: 610px"><a title="Flash Cookie Viewer" href="http://img.a4apphack.com/flashcookiesview-main.gif" rel="lightbox[1760]"><img class="" title="Flash Cookie Viewer" src="http://img.a4apphack.com/flashcookiesview-main.gif" alt="Flash Cookie Viewer" width="600" height="329" /></a><p class="wp-caption-text">Flash Cookie Viewer</p></div>
<p><span id="more-1760"></span></p>
<p><strong>System Requirements</strong></p>
<p>This utility works on any version of Windows, starting from Windows 2000 and up to Windows 7. Also, FlashCookiesView can work with any Web browser, because the Flash component always save flash cookies in the same place and in the same format, regardless the Web browser that you use.</p>
<h4>Using FlashCookiesView</h4>
<p>FlashCookiesView doesn&#8217;t require any installation process or additional DLL files. In order to start using it, simply copy the files to any folder you like, and run the executable file &#8211; FlashCookiesView.exe <br />
 The main window of FlashCookiesView contains 2 panes: The upper pane displays the list of all cookies files found in your flash cookies folder. When you select a cookies file in the upper pane, the lower pane displays the content of the cookie. By default, FlashCookiesView parse the cookie file and display it in name/value format, but you can also view the content of the cookie file as Hex Dump, by choosing &#8216;Hex Dump&#8217; view from Options-&gt;Display Mode (or simply by pressing F3).</p>
<p>You can also select one or more cookie files in the upper pane, and then use &#8216;Save Selected Items&#8217; option to export the cookies list to text/html/xml/csv file, or &#8216;Delete Selected Cookies Files&#8217; to delete unneeded flash cookies.</p>
<p>If you want to view the Flash cookies of another computer/operating system/user profile, simply press F9 and select the right base cookies folder.</p>
<p><br class="spacer_" /></p>
<p><strong>Download FlashCookieViewer:</strong> <a target="_blank" href="http://www.nirsoft.net/utils/flashcookiesview.zip"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a></p>
<p><br class="spacer_" /></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1760&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/security/tool-to-view-the-cookies-created-by-flash-component/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ZeroDay Scanner Scans Web App Vulnerabilities Online For Free</title>
		<link>http://a4apphack.com/featured/zeroday-scanner-scans-web-app-vulnerabilities-online-for-free</link>
		<comments>http://a4apphack.com/featured/zeroday-scanner-scans-web-app-vulnerabilities-online-for-free#comments</comments>
		<pubDate>Sun, 28 Mar 2010 23:59:14 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[online]]></category>
		<category><![CDATA[va]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1728</guid>
		<description><![CDATA[ZeroDayScan is an online web application scanner which crawls through the app and discovers the vulnerabilities in the application. It attempts to find out the common web vulnerabilities like XSS, SQL Injection and all the way down to web app fingerprinting. As per their FAQ it takes around half an hour to scan normal sized [...]]]></description>
			<content:encoded><![CDATA[<p>ZeroDayScan is an online web application scanner which crawls through the app and discovers the vulnerabilities in the application. It attempts to find out the common web vulnerabilities like XSS, SQL Injection and all the way down to web app fingerprinting.</p>
<p>As per their FAQ it takes around half an hour to scan normal sized websites, but as soon as I initiated scan for my website, I got a notification mail saying that it takes around 72 hours to complete the scan but I got the results emailed in about 5 hours.</p>
<p><span id="more-1728"></span><strong> </strong></p>
<p><strong>Start the Scan</strong></p>
<ol>
<li>Create a text file with the name &#8216;zerodayscan.txt&#8217; which contains the unique random key generated at zerodayscan.com site.</li>
<li>Submit the  Site URL and Email Id to which the scan results are to be mailed.</li>
<li>Start the scan. (Scan results will be emailed once its complete)</li>
</ol>
<p><strong>Scan Results</strong></p>
<p>Output of the scan result is a pdf document which will be emailed to the user and contains the following information</p>
<ol>
<li>Summary of the Scan (check the above pic) </li>
<li>Details of the Critical, High, Medium and Low Vulnerabilities </li>
<li>Whois information of the website. </li>
</ol>
<p><strong>Sample Summary Table in the Report</strong></p>
<p><br class="spacer_" /></p>
<div class="wp-caption alignnone" style="width: 510px"><a title="ZeroDay Scan Summary Table" href="http://img.a4apphack.com/zerodayscan-summary.jpg" rel="lightbox[1728]"><img title="ZeroDay Scan Summary Table" src="http://img.a4apphack.com/zerodayscan-summary.jpg" alt="" width="500" height="284" /></a><p class="wp-caption-text">ZeroDay Scan Summary Table</p></div>
<p><br class="spacer_" /></p>
<p>The results gives us an approximate idea on the vulnerabilities of the target though it obviously does not have as much capabilities as a commercial webapp scanner.</p>
<p><strong>Features</strong></p>
<ul>
<li>No installation is required. It is an online service </li>
<li>Detects Cross Site Scripting attacks (XSS) </li>
<li>Detects Hidden Directories and Backup Files </li>
<li>Looks for Known Security Vulnerabilities </li>
<li>Searches for SQL Injection Vulnerabilities </li>
<li>Automatically detects zero day bugs </li>
<li>Performs Website Fingerprinting </li>
<li>Generates free reports </li>
</ul>
<p><a href="http://www.zerodayscan.com/"><img class="alignnone" title="Zerodayscan Logo" src="http://img.a4apphack.com/zerodayscan-logo.jpg" alt="Zerodayscan Logo" width="200" height="49" /></a></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1728&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/featured/zeroday-scanner-scans-web-app-vulnerabilities-online-for-free/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Free Web Vulnerability Assessment Tool &#8211; CAT</title>
		<link>http://a4apphack.com/featured/free-web-vulnerability-assessment-tool-cat</link>
		<comments>http://a4apphack.com/featured/free-web-vulnerability-assessment-tool-cat#comments</comments>
		<pubDate>Wed, 27 Jan 2010 07:07:43 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[automate]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1638</guid>
		<description><![CDATA[Its very rare to find out a good n effective web application security assessment tool and would make it almost impossible if you want it for free. After a long time of hunt, I found one; CAT &#8211; Context App Tool. Although its free, it offers a good GUI and powerful features along with the [...]]]></description>
			<content:encoded><![CDATA[<p>Its very rare to find out a good n effective web application security assessment tool and would make it almost impossible if you want it for free. After a long time of hunt, I found one; CAT &#8211; Context App Tool. Although its free, it offers a good GUI and powerful features along with the basic ones which comes with a every proxy available.</p>
<h3>Features</h3>
<p>There are a number of features which CAT has to enable a wide variety of testing to be conducted:</p>
<ul>
<li><strong>Request Repeater</strong> – Used for repeating a single request</li>
<li><strong>Proxy</strong> – Classic Inline proxy</li>
<li><strong>Fuzzer</strong> – Allows for batch of tests to be sent to a server for brute forcing, parameter fuzzing, forced browsing etc.</li>
<li><strong>Log</strong> – View a list of requests to sort, search repeat etc. Allows for a sequence of requests to be repeated and modified.</li>
<li><strong>Authentication Checker</strong> – Two synchronised proxies which can be used to check authentication and authorisation controls.</li>
<li><strong>SSL Checker</strong> – Request a specific page with various SSL ciphers and versions.</li>
<li><strong>Notepad</strong> – A text/RTF editor which can be used as a scratch pad for conversions etc.</li>
<li><strong>Web Browser</strong> – An integrated web browser with proxy pre-configured based on the Internet Explorer&#8217;s rendering engine.</li>
</ul>
<h3>Reasons to use CAT</h3>
<p>There are a number of differences between CAT and currently available web proxies.  Some key differences are:</p>
<ul>
<li>Uses Internet Explorer&#8217;s rendering engine for accurate HTML representation</li>
<li>Supports many different types of text conversions including: URL, Base64, Hex, Unicode, HTML/XML, SQL and JavaScript no Quotes</li>
<li>Integrated SQL Injection and XSS Detection</li>
<li>Synchronised Proxies for Authentication and Authorisation checking</li>
<li>Faster due to HTTP connection caching</li>
<li>SSL Version and Cipher checker using OpenSSL</li>
<li>Greater flexibility for importing/exporting logs and saving projects</li>
<li>Tabbed Interface allowing for multiple tools at once e.g. multiple repeaters and different logs</li>
<li>The ability to repeat and modify a sequence of requests (particularly useful in SSO testing)</li>
<li>Free!</li>
</ul>
<p><span id="more-1638"></span></p>
<p><strong>Proxy &amp; Authentication Checker<br />
 </strong></p>
<p>I generally use multiple browsers during web app assessments. This helps me to analyze the difference in the responses received from the server for same requests sent with different login credentials. This can also help me during the tests performed for horizontal/vertical privilege escalations. CAT listens to multiple ports at the same time, which means that you can use 2 browsers (or <a href="http://a4apphack.com/index.php/featured/secfox-turn-firefox-into-an-ultimate-hacking-tool-part-1" title="SecFox – Turn Firefox Into an Ultimate Hacking tool" >browser profiles</a>) and direct the traffic to one proxy &#8211; CAT. CAT displays the traffic from different sources in different tabs.</p>
<p><br class="spacer_" /></p>
<div class="wp-caption alignnone" style="width: 610px"><a href="http://img.a4apphack.com/catvulnscan-browserproxy.jpg" rel="lightbox[1638]" title="Multiple Browsers Via Proxies"><img title="Multiple Browsers Via Proxies" src="http://img.a4apphack.com/catvulnscan-browserproxy.jpg" alt="Multiple Browsers Via Proxies" width="600" height="407" /></a><p class="wp-caption-text">Multiple Browsers Via Proxies</p></div>
<p><br class="spacer_" /></p>
<div class="wp-caption alignnone" style="width: 610px"><a href="http://img.a4apphack.com/catvulnscan-appproxy.jpg" rel="lightbox[1638]" title="CAT Listening Via Multiple Proxies"><img title="CAT Listening Via Multiple Proxies" src="http://img.a4apphack.com/catvulnscan-appproxy.jpg" alt="CAT Listening Via Multiple Proxies" width="600" height="383" /></a><p class="wp-caption-text">CAT Listening Via Multiple Proxies</p></div>
<p><br class="spacer_" /></p>
<p>While doing the authentication testing, we can login with the user having higher privilege in browser 1 and user with lower privilege in browser 2. Access various pages in browser 1 and identical requests are sent using the cookies stored in browser 2. CAT leaves us the response pairs behind for manual analysis.</p>
<p><br class="spacer_" /></p>
<div class="wp-caption alignnone" style="width: 610px"><a href="http://img.a4apphack.com/catvulnscan-authchecker.png" rel="lightbox[1638]" title="Auth Checker"><img title="Auth Checker" src="http://img.a4apphack.com/catvulnscan-authchecker.png" alt="Auth Checker" width="600" height="474" /></a><p class="wp-caption-text">Auth Checker</p></div>
<h3>SSL Strength Check</h3>
<p>Why use SSLDigger/Open SSL if your proxy has built-in SSL strength checking feature.</p>
<p><br class="spacer_" /></p>
<div class="wp-caption alignnone" style="width: 610px"><a href="http://img.a4apphack.com/catvulnscan-sslchecker.jpg" rel="lightbox[1638]" title="SSL Strength Checker"><img title="SSL Strength Checker" src="http://img.a4apphack.com/catvulnscan-sslchecker.jpg" alt="SSL Strength Checker" width="600" height="398" /></a><p class="wp-caption-text">SSL Strength Checker</p></div>
<p><br class="spacer_" /></p>
<p><strong>Download:</strong> <a target="_blank" href="http://cat.contextis.com/cat/cat.msi"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a>  (More Info <a title="CAT Details" href="http://cat.contextis.com/cat/explanation.htm">here </a>)</p>
<p><br class="spacer_" /></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1638&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/featured/free-web-vulnerability-assessment-tool-cat/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HTML Purifier &#8211; Malicious Input Filtering (XSS Protection)</title>
		<link>http://a4apphack.com/security/html-purifier-malicious-input-filtering</link>
		<comments>http://a4apphack.com/security/html-purifier-malicious-input-filtering#comments</comments>
		<pubDate>Wed, 27 Jan 2010 06:45:14 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[scripts]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1639</guid>
		<description><![CDATA[HTML Purifier is a standards-compliant HTML filter library written in PHP. HTML Purifier will remove all malicious code (efficient filtering of XSS scripts) with a thoroughly audited, secure yet permissive whitelist. Quick Install 1 2 3 4 5 6 &#60;?php require_once '/path/to/htmlpurifier/library/HTMLPurifier.auto.php'; &#160; $purifier = new HTMLPurifier&#40;&#41;; $clean_html = $purifier-&#62;purify&#40;$dirty_html&#41;; ?&#62; View Before-After XSS Filtering [...]]]></description>
			<content:encoded><![CDATA[<p>HTML Purifier is a standards-compliant HTML filter library written in PHP. HTML Purifier will remove all malicious code (efficient filtering of XSS scripts) with a thoroughly audited, secure yet permissive whitelist.</p>
<div class="wp-caption alignnone" style="width: 610px"><a title="HTML Comparison Chart" href="http://img.a4apphack.com/htmlpurify-compare.jpg" rel="lightbox[1639]"><img class="" title="HTML Comparison Chart" src="http://img.a4apphack.com/htmlpurify-compare.jpg" alt="HTML Comparison Chart" width="600" height="107" /></a><p class="wp-caption-text">HTML Comparison Chart</p></div>
<p><strong>Quick Install</strong></p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
</pre></td><td class="code"><pre class="php" style="font-family:monospace;"><span style="color: #000000; font-weight: bold;">&lt;?php</span>
    <span style="color: #b1b100;">require_once</span> <span style="color: #0000ff;">'/path/to/htmlpurifier/library/HTMLPurifier.auto.php'</span><span style="color: #339933;">;</span>
&nbsp;
    <span style="color: #000088;">$purifier</span> <span style="color: #339933;">=</span> <span style="color: #000000; font-weight: bold;">new</span> HTMLPurifier<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
    <span style="color: #000088;">$clean_html</span> <span style="color: #339933;">=</span> <span style="color: #000088;">$purifier</span><span style="color: #339933;">-&gt;</span><span style="color: #004000;">purify</span><span style="color: #009900;">&#40;</span><span style="color: #000088;">$dirty_html</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
<span style="color: #000000; font-weight: bold;">?&gt;</span></pre></td></tr></table></div>

<p><a title="XSS Attacks" href="http://htmlpurifier.org/live/smoketests/xssAttacks.php">View Before-After XSS Filtering</a></p>
<p><a title="View Demo: HTML Purifier" href="http://htmlpurifier.org/demo.php">View Demo: HTML Purifier</a></p>
<p><strong>Download HTML Purfier : </strong><a target="_blank" href="http://htmlpurifier.org/releases/htmlpurifier-4.0.0.zip"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a> (More Info at: <a title="HTML Purifier" href="http://htmlpurifier.org/">http://htmlpurifier.org/</a>)</p>
<p><br class="spacer_" /></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1639&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/security/html-purifier-malicious-input-filtering/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Subscribe to SecFox &#8211; Firefox Addon Collections</title>
		<link>http://a4apphack.com/featured/subscribe-to-secfox-firefox-addon-collections</link>
		<comments>http://a4apphack.com/featured/subscribe-to-secfox-firefox-addon-collections#comments</comments>
		<pubDate>Wed, 13 Jan 2010 19:29:34 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[addons]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[Secfox]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1630</guid>
		<description><![CDATA[Stay updated with addons discussed in the SecFox series, the most popular section of this blog. For that you need to subscribe to the SecFox addon collection available in the mozilla addons site. SecFox is collection of addons which can be used to customize any firefox to a security assessment tool. At the time of [...]]]></description>
			<content:encoded><![CDATA[<p>Stay updated with addons discussed in the <a title="SecFox Series" href="http://a4apphack.com/index.php/tag/secfox">SecFox series</a>, the most popular section of this blog. For that you need to subscribe to the SecFox addon collection available in the mozilla addons site.</p>
<p>SecFox is collection of addons which can be used to customize any firefox to a security assessment tool. At the time of writing this collection has 40+ addons which can help the web app sec testers during their assessments.</p>
<p><span id="more-1630"></span>An &#8216;<a title="Add-on Collector" href="https://addons.mozilla.org/en-US/firefox/pages/collector">addon collector</a>&#8216; addon is to be installed to get the SecFox updates. So if any new addon added to SecFox collection gives an alert to the subscriber.</p>
<p>Check the video below which explains how.</p>
<p><object type="application/x-shockwave-flash" style="width:600px;height:440px" data="http://www.youtube.com/v/mzryNGYmvjg&amp;hl=en&amp;fs=1"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="quality" value="best" /><param name="wmode" value="transparent" /><param name="movie" value="http://www.youtube.com/v/mzryNGYmvjg&amp;hl=en&amp;fs=1" /><param name="pluginspage" value="http://www.macromedia.com/go/getflashplayer" />If you can see this, then you might need a Flash Player upgrade or you need to install Flash Player if it's missing. Get <a href="http://get.adobe.com/flashplayer/" target="_blank">Flash Player</a> from Adobe.</object><br/>
		<!-- Valid XHTML flash object delivered by XHTML Video Embed. Get it at: http://saltwaterc.net/xhtml-video-embed -->
		</p>
<p><strong>Download Secfox Collection :</strong> <a target="_blank" href="https://addons.mozilla.org/en-US/firefox/collection/secfox"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1630&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/featured/subscribe-to-secfox-firefox-addon-collections/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<series:name><![CDATA[Secfox]]></series:name>
	</item>
		<item>
		<title>Web AppSec Testing Checklist (OWASP Based)</title>
		<link>http://a4apphack.com/featured/web-appsec-testing-checklist</link>
		<comments>http://a4apphack.com/featured/web-appsec-testing-checklist#comments</comments>
		<pubDate>Fri, 16 Oct 2009 05:06:38 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[excel]]></category>
		<category><![CDATA[organize]]></category>
		<category><![CDATA[webapp]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1574</guid>
		<description><![CDATA[Web AppSec Testing Checklist is an Excel based checklist which helps you to track the status of completed and pending test cases. This helps you to organize the flow of your testing process and also to ensure that none of the test cases are missed out. This checklist is completely based on OWASP Testing Guide [...]]]></description>
			<content:encoded><![CDATA[<p>Web AppSec Testing Checklist is an Excel based checklist which helps you to track the status of completed and pending test cases. This helps you to organize the flow of your testing process and also to ensure that none of the test cases are missed out.</p>
<div class="wp-caption alignnone" style="width: 610px"><a href="http://img.a4apphack.com/appsecchck-main.jpg" rel="lightbox[1574]" title="WebApp Sec Checklist"><img title="WebApp Sec Checklist" src="http://img.a4apphack.com/appsecchck-main.jpg" alt="WebApp Sec Checklist" width="600" height="415" /></a><p class="wp-caption-text">WebApp Sec Checklist</p></div>
<p>This checklist is completely based on OWASP Testing Guide v 3. The <a title="OWASP Testing Guide v 3.0" href="http://www.owasp.org/index.php/Category:OWASP_Testing_Project">OWASP Testing Guide</a> includes a &#8220;best practice&#8221; penetration testing framework which users can implement in their own organizations and a &#8220;low level&#8221; penetration testing guide that describes techniques for testing most common web application and web service security issues.</p>
<p><span id="more-1574"></span></p>
<p>The main intention of creating this checklist is to minimize our effort we would have put if we had to go through the 350 page OWASP Testing guide everytime during our testing.</p>
<p>I&#8217;ve added 66 test cases falling under different categories and you can add your own test by inserting a row in the Checklist and then changing the Overall status formulas.</p>
<h3>Quick Completion Status</h3>
<p>This section gives the details on the total checks completed, vulnerabilities noticed so far, and overall status in percentage.</p>
<div class="wp-caption alignnone" style="width: 276px"><a href="http://img.a4apphack.com/appsecchck-status.jpg" rel="lightbox[1574]" title="Overall Status"><img title="Overall Status" src="http://img.a4apphack.com/appsecchck-status.jpg" alt="Overall Status" width="266" height="156" /></a><p class="wp-caption-text">Overall Status</p></div>
<h3>Risk Metric Chart</h3>
<p>Displays the number of High, Medium, Low and Info risk items. This can help us to give a quick glance on the ratio of High risk items.</p>
<div class="wp-caption alignnone" style="width: 288px"><a href="http://img.a4apphack.com/appsecchck-riskmetric.jpg" rel="lightbox[1574]" title="Risk Metric Chart"><img title="Risk Metric Chart" src="http://img.a4apphack.com/appsecchck-riskmetric.jpg" alt="Risk Metric Chart" width="278" height="235" /></a><p class="wp-caption-text">Risk Metric Chart</p></div>
<p><strong>Note:</strong> The Security Tester has to decide upon the rating of risk for each vulnerability. Check the OWASP Guide for more details</p>
<h3>Alerts Displayed</h3>
<p>Alerts are displayed whenever there is some inconsistency with the task completion marked and the risk value updated.</p>
<p><br class="spacer_" /></p>
<div class="wp-caption alignnone" style="width: 313px"><a href="http://img.a4apphack.com/appsecchck-alerts.jpg" rel="lightbox[1574]" title="Alerts Displayed"><img title="Alerts Displayed" src="http://img.a4apphack.com/appsecchck-alerts.jpg" alt="Alerts Displayed" width="303" height="82" /></a><p class="wp-caption-text">Alerts Displayed </p></div>
<p>Alert symbol (<span style="color: #3366ff;"><strong>!!</strong></span>) is displayed when.</p>
<ul>
<li>Status is marked as &#8216;Done&#8217; but Risk rating is not updated</li>
<li>Risk is marked but Status still shows &#8216;Not Done&#8217;</li>
</ul>
<h3>Features</h3>
<ul>
<li>Quick Status on completion of the tasks</li>
<li>Reference Sheet which contains short info on each test case</li>
<li>Risk Metric Chart displays the distribution of vulnerabilities based on the risk rating</li>
<li>Tiny alerts displayed if task is marked complete, but risk level is not mentioned (and vice versa)</li>
<li>List of tools to be used for various test cases (not completely updated)</li>
</ul>
<p><strong>Download Web AppSec Checklist Excel Sheet:</strong> <a target="_blank" href="http://img.a4apphack.com/dl/appsecchck-checklist.zip"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a><strong> Mirror</strong> : <a target="_blank" href="http://www.box.net/shared/5cauqbnqal"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a></p>
<p><br class="spacer_" /></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1574&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/featured/web-appsec-testing-checklist/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>XSS Made Simple- Flash Animation</title>
		<link>http://a4apphack.com/security/xss-made-simple-flash-animation</link>
		<comments>http://a4apphack.com/security/xss-made-simple-flash-animation#comments</comments>
		<pubDate>Thu, 26 Mar 2009 07:57:09 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[xsrf]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://a4apphack.com/blog/?p=1010</guid>
		<description><![CDATA[&#8220;CrossSite Scripting (XSS) attacks are a type of injection problem, in which malicious scripts are injected into the otherwise benign and trusted web sites. Cross-site scripting (XSS) attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>&#8220;<a title="XSS Wikipedia" href="http://en.wikipedia.org/wiki/Cross-site_scripting">CrossSite Scripting</a> (XSS) attacks are a type of injection problem, in which malicious scripts are injected into the otherwise benign and trusted web sites. Cross-site scripting (XSS) attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user in the output it generates without validating or encoding it.</p>
<p>An attacker can use XSS to send a malicious script to an unsuspecting user. The end user&#8217;s browser has no way to know that the script should not be trusted, and will execute the script. Because it thinks the script came from a trusted source, the malicious script can access any cookies, session tokens, or other sensitive information retained by your browser and used with that site. These scripts can even rewrite the content of the HTML page.&#8221; &#8211; OWASP</p>
</blockquote>
<p>Understanding XSS or to make one understand it ain&#8217;t easy. Too much of theory will confuse the person rather than helping him out. The best way of explaining it!; through flash animations and that is how <a title="Virtual Forge" href="http://www.virtualforge.de/">virtualforge</a> guys have done. This animation is intended for both a layman and a security analyst.</p>
<p>They have published two set of flash applications which demonstrates XSS. Here cookie theft and file access are demonstrated.</p>
<p><strong>Screenshot</strong><br />
 <img class="alignnone size-full wp-image-1017" title="XSS Animation Screenshot" src="http://a4apphack.com/blog/wp-content/uploads/2009/03/xssmadesimplemain.jpg" alt="XSS Animation Screenshot" width="358" height="260" /></p>
<p>Check the following links</p>
<h3>Example 1 : Car Auction</h3>
<p><a href="http://www.virtualforge.de/vmovie/xss_lesson_1/xss_selling_platform_v1.0.swf">http://www.virtualforge.de/vmovie/xss_lesson_1/xss_selling_platform_v1.0.swf</a></p>
<h3>Example 2 : Online Application</h3>
<p><a href="http://www.virtualforge.de/vmovie/xss_lesson_2/xss_selling_platform_v2.0.swf">http://www.virtualforge.de/vmovie/xss_lesson_2/xss_selling_platform_v2.0.swf</a></p>
<p><em>Read More about XSS at </em><a title="XSS Wikipedia" href="http://en.wikipedia.org/wiki/Cross-site_scripting"><em>Wiki</em></a><em> and </em><a title="XSS OWASP" href="http://www.owasp.org/index.php/XSS"><em>OWASP</em></a></p>
<p>See CrossSiteRequestForgery (XSRF) in action, <a title="XSRF Demo" href="http://a4apphack.com/security/cross-site-request-forgery-demo">here</a>.</p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1010&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/security/xss-made-simple-flash-animation/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secfox &#8211; Hackbar, Audit / Penetration Test Tool in Firefox</title>
		<link>http://a4apphack.com/security/hackbar-audit-penetration-test-tool</link>
		<comments>http://a4apphack.com/security/hackbar-audit-penetration-test-tool#comments</comments>
		<pubDate>Thu, 19 Feb 2009 06:59:00 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[addons]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[automate]]></category>
		<category><![CDATA[Secfox]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://a4apphack.com/blog/?p=686</guid>
		<description><![CDATA[Hackbar is a tiny toolbar in Firefox with features to aid in application pen-testing. This can be used to perform our security tests quickly and effectively. 1. Manipulate integer values: Click on Load URL and then Split URL. Now select the Integer under interest and click on the INT +1 or INT -1 as required. [...]]]></description>
			<content:encoded><![CDATA[<p>Hackbar is a tiny toolbar in Firefox with features to aid in application pen-testing. This can be used to perform our security tests quickly and effectively.</p>
<p><img class="alignnone" title="Hackbar" src="http://img.a4apphack.com/hackbar-featured.jpg" alt="" width="349" height="199" /></p>
<p><span id="more-686"></span></p>
<h3>1. Manipulate integer values:</h3>
<p>Click on Load URL and then Split URL. Now select the Integer under interest and click on the INT +1 or INT -1 as required. This will automatically load the page with the new modified param value. This can help us while checking for &#8216;forceful browsing&#8217; or &#8216;revealing hidden pages&#8217; kind of tests.</p>
<div class="wp-caption alignnone" style="width: 610px"><a title="Change Integer Value" href="http://img.a4apphack.com/hackbar-changeintegervalue.jpg" rel="lightbox[686]"><img title="Change Integer Value" src="http://img.a4apphack.com/hackbar-changeintegervalue.jpg" alt="Change Integer Value" width="600" height="513" /></a><p class="wp-caption-text">Change Integer Value</p></div>
<h3>2. Calculate MD5 of selected string</h3>
<p>Some of the sites amateur developers might do poor encoding for the sensitive data which is communicated between server and the client. But with Hackbar the values can be easily decoded with a single click.</p>
<div class="wp-caption alignnone" style="width: 610px"><a title="Hash Selected Value" href="http://img.a4apphack.com/hackbar-hashselectedvalue.jpg" rel="lightbox[686]"><img class="" title="Hash Selected Value" src="http://img.a4apphack.com/hackbar-hashselectedvalue.jpg" alt="Hash Selected Value" width="600" height="513" /></a><p class="wp-caption-text">Hash Selected Value</p></div>
<h3>3. Calculate MySQL Char code of selected string.</h3>
<p>MySQL CHAR() button can help us in calculating the charcode of the selected string. This can help in injecting the char code value during some tests which usually are not stripped of while performing server side validation.</p>
<div class="wp-caption alignnone" style="width: 610px"><a title="Calculate Char Code" href="http://img.a4apphack.com/hackbar-calculatecharcode.jpg" rel="lightbox[686]"><img title="Calculate Char Code" src="http://img.a4apphack.com/hackbar-calculatecharcode.jpg" alt="Calculate Char Code" width="600" height="513" /></a><p class="wp-caption-text">Calculate Char Code</p></div>
<h2>Features</h2>
<ul>
<li>Increment/Decrement the numeric value of the params (e.g. change pageid to reveal hidden page, session ids etc)</li>
<li>Above operation on HEX values</li>
<li>SQL and XSS vectors string construction</li>
<li>Built-In string encryption options (MD5, SHA-1, SHA-256)</li>
<li>Encode and Decode URL (Base 64, URL Encoding)</li>
<li>Strings for performing BoF attacks.</li>
</ul>
<p><strong>Download Hackbar :</strong> <a href="https://addons.mozilla.org/en-US/firefox/addon/hackbar/"><img style="vertical-align: middle;" title="Hackbar Logo" src="http://img.a4apphack.com/hackbar-logo.png" alt="Hackbar Logo" /></a></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=686&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/security/hackbar-audit-penetration-test-tool/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (Requested URI is rejected)
Object Caching 1446/1554 objects using disk: basic

Served from: a4apphack.com @ 2012-02-05 09:51:29 -->
