[Full-disclosure] wfuzz v1.4 - The web bruteforcer

Christian Martorella laramies2k at yahoo.com.ar
Thu Jan 24 22:41:44 GMT 2008


A new version of Wfuzz is available, many improvements and fixes since  
first release.

http://www.edge-security.com/wfuzz.php

Wfuzz is a tool designed for bruteforcing Web Applications, it can be  
used for finding resources not linked (directories, files), bruteforce  
HEADERS, GET and POST parameters for checking different kind of  
injections (SQL, XSS, LDAP,etc), bruteforce Forms parameters (User/ 
Password), Fuzzing,etc.

It's very flexible, here are some functionalities:

    *-Recursion (When doing directory bruteforce)
    *-Post, headers and authentication data bruteforcing
    *-Output to HTML (easy for just clicking the links and checking  
the page, even with postdata!!)
    *-Colored output on all systems ;)
    *-Hide results by return code, word numbers, line numbers, etc.
    *-Encodings: (Random_upper, Urlencode, SHA1, MD5,  
Bin_ascii,Base64, UTF8, many more..)
    *- Cookies bruteforcing
    *- Multithreading
    *- Proxy support
    *- Multiple bruteforce points capability with different dictionaries
    *- Authentication support (Ntlm, Digest,Basic)
    *- Authentication bruteforcing.
    *- All parameters bruteforcing (POST,GET)
    *- Worldlist tailored for known applications  
(Weblogic,Iplanet,Tomcat, Domino, Oracle) and common applications file  
names.
    *- Speed :)

Regards,

Christian Martorella
www.edge-security.com
laramies.blogspot.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20080124/068fa142/attachment.html 


Full-Disclosure is hosted and sponsored by Secunia.