Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Web-App-Sec
[Top] [All Lists]

Re: Any special tool for testing a web chat application?

Subject: Re: Any special tool for testing a web chat application?
Date: Thu, 05 Feb 2009 10:56:59 +0200
Barry Archer wrote:
I need to test a web chat application.

I was wondering if there's any recommendations on a special tool
and/or approach that might be the best.

Right now I'm looking at:
  Nessus
  A full web application scanner (HP/SPI,AppsScan,or Cenzic)
  A proxy for manual testing (WebScarab, Paros, etc)

 Sorry if this is a silly question, but chat seems like it's smaller
in scope but harder for that initial automated scan.

Thanks

   Ba

For what it is worth, when testing AJAXy web apps, you probably want to
use a scriptable proxy, as you would otherwise be hammered with
intercepts every time the script polls for an update.

WebScarab supports using BeanShell (or, with a bit of work, your
BSF-supported language of choice) to automatically make whatever
modifications you choose.

Regards,

Rogan

-------------------------------------------------------------------------
Sponsored by: Watchfire 
Methodologies & Tools for Web Application Security Assessment 
With the rapid rise in the number and types of security threats, web 
application security assessments should be considered a crucial phase in the 
development of any web application. What methodology should be followed? What 
tools can accelerate the assessment process? Download this Whitepaper today! 

https://www.watchfire.com/securearea/whitepapers.aspx?id=70170000000940F
-------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>