Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Paros 3.2.0 beta release |
|---|---|
| Date: | 23 Jan 2005 15:02:58 -0000 |
Paros 3.2.0beta version is available. The new verison is available at http://www.parosproxy.org. A particular note is that JRE 1.5 is required. Queries, bug reports and comments on Paros can be sent to [contact at parosproxy org]. Please feel free to send any comments to us! [Installation] Note the Windows installer will overwrite the old version if the directory is unchanged. Please rename the installation directory if you need to keep the old version for use. The default installation used 128M VM. You may adjust it depending on your need. [Brief introduction] Paros is a man-in-the-middle proxy and application vulnerability scanner. It allows users to intercept, modify and debug HTTP and HTTPS data on-the-fly between web server and client browser. It also supports spidering, proxy-chaining, filtering and application vulnerability scanning. [License] - Clarified Artistic License (open source and GPL-compatible license) [Details/new features] 3.2.0 beta ========== New - support charset encoding display in response/trap panels for HTMLs. Various language characters eg Chinese, Russian, Japanese, Korean, etc can be displayed. - Dropping request/response in trap panel. - Improved checking for redirected response in all plugins. - Improved spider performance, crawling capability and memory utilization. - Malicious content filter for suspicious IE ActiveX Control Cross-Site Scripting - Allow delete/purge site hierarchy or history. Delete = delete from view. Purge means remove from db as well. - Some user interface streamlining. - Resend request in history and scanned alerts. - Replaced Java methods deprecated in Java 1.5. Now the program must be run under Java 1.5.0 or above. - Include links not crawled (due to out of scope) in spider display. New (in previous 3.1.3 but new in 3.2.0 beta)) - Log cookie filter in request - Detect set-cookie filter - Manual request editor - client certificate support in Options->certificate - Some more test is ported. However, a couples of checks is not migrated yet. Fix (with special thanks to users reporting them) - URL in header text input if not properly encoded may fail. Now automatically encode for improper characters. - File dialog does not allow directory browsing. - spider on individual node does not work. - window title does not change after setting properties. - Frameless splash window cannot be displayed under Debian Linux. - Error was always encountered when saving a session under Debian Linux. - Fix some NIO problem in Debian OS platforms. - Host progress dialog may frozen when stopping all hosts. - Improved CRLF check with more cases to avoid incorrect HTTP response hanging up scanner. - SQL check to to look for error server response as well. - Large scans terminate early problem.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Proposal to anti-phishing, Jimi Thompson |
|---|---|
| Next by Date: | RE: Proposal to anti-phishing, Sam Koh |
| Previous by Thread: | OWASP Meeting Tues 1/25 (6PM in Columbia MD), Jeff Williams |
| Next by Thread: | Anti-Phishing, why it doesn't work, Joseph Miller |
| Indexes: | [Date] [Thread] [Top] [All Lists] |