Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Web-App-Sec
[Top] [All Lists]

Re: Beta release of the Oedipus Web Application Scanner is released

Subject: Re: Beta release of the Oedipus Web Application Scanner is released
Date: Sat, 8 Apr 2006 20:17:22 +0100
The link was left off - it is available from http:// oedipus.rubyforge.org

Thanks

On 7 Apr 2006, at 16:53, Justin Clarke wrote:

The Oedipus Web Application Scanner project (disclaimer - I have been
involved in it's development) has just released it's first public beta
release - version 1.8.1. Oedipus is a penetration testing focused tool,
designed for penetration testers and for technical security or web
development folks to test their applications for web application
security issues. It deviates from many of the commercial tools in that:


* Oedipus does not claim to be a one stop testing tool that will
find every type of hole in your applications. It is, however,
pretty good at finding the low hanging fruit so you can spend
your time finding the really nasty problems manually
* Oedipus has some exploitation functionality built in, especially
for SQL injection at this point, for generating working exploits
for web application vulnerabilities. After all, the best way to
show the business impact of an issue is to show it is
exploitable
* It's free, open source, and pretty easy to extend through the
use of it's plugin architecture


From the blurb - "Oedipus is an open source web application security
analysis and testing suite written in Ruby by Pentration Testers for
Penetration Testers. It is capable of parsing different types of log
files off-line and identifying security vulnerabilities. Using the
analyzed information, Oedipus can dynamically test web sites for
application and web server vulnerabilities"


Attachment: smime.p7s
Description: S/MIME cryptographic signature

<Prev in Thread] Current Thread [Next in Thread>