Skip to content

luanjampa/webfight

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

webfight

Webfigh is a tool for manual analysis of web application security.

The tool performs a log parser of Burp (http://portswigger.net/burp/download.html), and performs a series of tests and show notes to an expert analyze:

  1. All requests and parameters to fuzz and data validation tests;
  2. Show all files and javascriopt perform syntax analysis;
  3. Show all flash files, disassembled and grep potential vulnerabilities;
  4. Analyze all headers and do a fingerprint;
  5. Validate security headers (CSP; HSTS, X-Frame-Options)
  6. Create the CSRF PoC for all requests;
  7. And much more ... Make your module ...

Watch Demo:

http://www.youtube.com/watch?v=-xXdoWilR6M&feature=player_embedded

About

Webfigh is a tool for manual analysis of web application security.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published