martes, 25 de agosto de 2020

Web-fu - The Ultimate Web Hacking Chrome Extension

Web-fu Is a web hacking tool focused on discovering and exploiting web vulnerabilitites.

 BROWSER INTEGRATION 

This tool has many advantages, as a browser-embedded webhacking tool, is very useful for scanning browser-authenticated applications, if browser can authenticate and access to the web application, the tool also can. Note that some other tools do not support neither certificate authentication nor web vpn accesses.
The integration with chrome, provides a more comfortable and agile way of web-hacking, and you have all the application data loaded on the hacking tool, you don't need to copy the url, cookies, etc. to the tool, just right click and hack.
The browser rendering engine is also used in this tool, to draw the html of the responses.


 FALSES POSITIVES 

When I coded this tool, I was obsessed with false positives, which is the main problem in all detection tools.  I have implemented a gauss algorithm, to reduce the faslse positives automatically which works very very well, and save a lot of time to the pentester.


 VIDEO 

 Here is a video, with some of the web-fu functionalitites:

 VISUAL FEATURES 

This tool has a visual crawler. Normal crawlers doesn't parse the ajvascript, this tool does. The visual crawler loads each link of the web site, rendering the html and executing all the javascript as a normal load, then the links are processed from he DOM and clicked.
A visual form cracker, is also available, althow is experimental and only works on some kind of forms.


 SCANNING FEATURES

The web-fu's portscanner, has a database of a common web ports, like 80,81,8080 and so on.
The cracker module, can bruteforce web directories to find new attack vectors, and can fuzz get and post parameters for discovering vulns, and also crack passwords. There are 9 preloaded wordlists, and you can also load a custom wordlist. Prefilters, falsepositive reductor and render will be helpful. The scanners support SSL, if the website can be loaded in the chrome, can be scanned by web-fu.


ENCODERS & DECODERS

The supported encoders and decoders are: base64, urlescape and urlencode


OTHER FEATURES

A web notepad is available, saving the information on the browser localStorage, there is one notepad per site. A cookie editor is also very useful for pentesting. The inteceptor, is like a web proxy but from the inside of the browser, you can intercept a request There is also a session locker and a exploit web search.


CHROME STORE 
Here is the link to the chrome store, the prize is about one euro, very cheap if you compare with other scanners: Web-Fu on Chrome Store


 With webfu, you will do the best web site pentest and vulnerability assessment.


More articles


  1. Pentest Tools Android
  2. Hacker Tools For Ios
  3. Game Hacking
  4. Hack Tools Github
  5. Pentest Tools Review
  6. Hack Tools Pc
  7. Underground Hacker Sites
  8. Beginner Hacker Tools
  9. Hacker
  10. Hacks And Tools
  11. How To Make Hacking Tools
  12. Nsa Hack Tools
  13. Pentest Tools Subdomain
  14. Hacker Tools Hardware
  15. Hacker Security Tools
  16. Android Hack Tools Github
  17. Hacker Tools Software
  18. Pentest Tools Bluekeep
  19. Pentest Tools Github
  20. Black Hat Hacker Tools
  21. Best Hacking Tools 2019
  22. Pentest Tools Website Vulnerability
  23. Best Hacking Tools 2020
  24. Pentest Tools Github
  25. Hacking Tools For Windows Free Download
  26. Pentest Tools Website
  27. Beginner Hacker Tools
  28. Hack Tools
  29. New Hack Tools
  30. Bluetooth Hacking Tools Kali
  31. Hacker Tools For Pc
  32. Hack Tools For Games
  33. Hacker Tools Free Download
  34. Hacking Tools Online
  35. Pentest Automation Tools
  36. Hacker Search Tools
  37. Hack Rom Tools
  38. Hack Rom Tools
  39. Hacker Security Tools
  40. How To Make Hacking Tools
  41. Tools For Hacker
  42. Hacker Security Tools
  43. Tools Used For Hacking
  44. Hacker Techniques Tools And Incident Handling
  45. Hack Tools Github
  46. Hacking Tools For Windows Free Download
  47. Hack Tools For Pc
  48. Hack Tools 2019
  49. Hacking Tools For Mac
  50. Hacking Tools Download
  51. What Is Hacking Tools
  52. Hack Apps
  53. Pentest Tools List
  54. Hacking Tools Name
  55. Best Pentesting Tools 2018
  56. Hacker Tools 2020
  57. Pentest Recon Tools
  58. Hackers Toolbox
  59. Blackhat Hacker Tools
  60. Pentest Tools For Android
  61. Pentest Tools Linux
  62. Computer Hacker
  63. Hack Apps
  64. Hack Tools For Ubuntu
  65. Hacking Tools For Windows
  66. Android Hack Tools Github
  67. Hacking Tools 2019
  68. Hack Tools Download
  69. Computer Hacker
  70. Hack Tool Apk
  71. Hacker Tool Kit
  72. Hacking Tools For Pc
  73. Hacker Tool Kit
  74. Pentest Tools Subdomain
  75. What Are Hacking Tools
  76. Pentest Tools Alternative
  77. Pentest Tools Review
  78. Pentest Tools Find Subdomains
  79. Pentest Tools
  80. Best Hacking Tools 2020
  81. Hack Tools For Mac
  82. Android Hack Tools Github
  83. Ethical Hacker Tools
  84. Termux Hacking Tools 2019
  85. Pentest Tools
  86. Pentest Tools Tcp Port Scanner
  87. Hacker Tools Free
  88. Hacking Tools Pc
  89. Hack Tools Pc
  90. Hacking Tools For Windows 7
  91. Hack Tools
  92. Wifi Hacker Tools For Windows
  93. Hacking Tools For Kali Linux
  94. Hacker Tools Apk Download
  95. Hacker Tools 2020
  96. Hacker Search Tools

No hay comentarios:

Publicar un comentario