<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: 2007 Security Testing tools in review</title>
	<link>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/</link>
	<description>top secret/secure computing information</description>
	<pubDate>Tue, 14 Oct 2008 11:05:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: xzid</title>
		<link>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-4913</link>
		<dc:creator>xzid</dc:creator>
		<pubDate>Thu, 06 Mar 2008 07:37:24 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-4913</guid>
		<description>Good post! I want to find the tools that manage the workflow of network(&#124;website) auditing process. This  tool accoding to some method as OWASP, ISSAF,OSTMM,.. (ex: Step 1: include checklist, questionaire,... --&#62; pass??...something like that).
Can you give me some advice??</description>
		<content:encoded><![CDATA[<p>Good post! I want to find the tools that manage the workflow of network(|website) auditing process. This  tool accoding to some method as OWASP, ISSAF,OSTMM,.. (ex: Step 1: include checklist, questionaire,&#8230; &#8211;&gt; pass??&#8230;something like that).<br />
Can you give me some advice??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dre</title>
		<link>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-3979</link>
		<dc:creator>dre</dc:creator>
		<pubDate>Tue, 22 Jan 2008 19:00:32 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-3979</guid>
		<description>@ woany :

You have strange timing.  I just found your blog/site yesterday after reading Dinis Cruz' blog entry from 9 months ago on &lt;a href="http://blogs.owasp.org/diniscruz/2007/03/26/lists-of-tools-for-vmware-box/" rel="nofollow"&gt;lists of tools for vmware&lt;/a&gt;.  I must have skipped it when I read this last year.

Your site has a long list of tools, especially useful for a C# or VB.NET developer.  Of immediate interest to me were the ASP.NET Backdoors (because I know people obsessed with collecting and researching these), and the HTTP Library (which reminds me of the Jakarta Commons HttpClient or Billy Hoffman's favorite from Innovation.Ch, who also has an online Java compiler -- &lt;a href="http://www.innovation.ch/java/HTTPClient/" rel="nofollow"&gt;HTTPClient&lt;/a&gt;).  nnikto also looked interesting, as well as filefolderenum.

RequesterRaw looks like a more simple (and less integrated) Burp Intruder or Suru, but I will check it out.  Looks like you've done some interesting web application and network security research with these tools!  If I find a spot to mention them in the future -- I will certainly do so.</description>
		<content:encoded><![CDATA[<p>@ woany :</p>
<p>You have strange timing.  I just found your blog/site yesterday after reading Dinis Cruz&#8217; blog entry from 9 months ago on <a href="http://blogs.owasp.org/diniscruz/2007/03/26/lists-of-tools-for-vmware-box/"  onclick="javascript:urchinTracker ('/outbound/comment/blogs.owasp.org');">lists of tools for vmware</a>.  I must have skipped it when I read this last year.</p>
<p>Your site has a long list of tools, especially useful for a C# or VB.NET developer.  Of immediate interest to me were the ASP.NET Backdoors (because I know people obsessed with collecting and researching these), and the HTTP Library (which reminds me of the Jakarta Commons HttpClient or Billy Hoffman&#8217;s favorite from Innovation.Ch, who also has an online Java compiler &#8212; <a href="http://www.innovation.ch/java/HTTPClient/"  onclick="javascript:urchinTracker ('/outbound/comment/www.innovation.ch');">HTTPClient</a>).  nnikto also looked interesting, as well as filefolderenum.</p>
<p>RequesterRaw looks like a more simple (and less integrated) Burp Intruder or Suru, but I will check it out.  Looks like you&#8217;ve done some interesting web application and network security research with these tools!  If I find a spot to mention them in the future &#8212; I will certainly do so.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: woany</title>
		<link>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-3978</link>
		<dc:creator>woany</dc:creator>
		<pubDate>Tue, 22 Jan 2008 17:44:19 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-3978</guid>
		<description>You could try sslciphercheck (http://www.woany.co.uk/blogs/woanware/pages/sslciphercheck.aspx), which combines the THC and Foundstone stuff.

And RequesterRaw for all your HTTP(S) fuzzing, is flexible enough for any HTTP requests (http://www.woany.co.uk/blogs/woanware/pages/requesterraw.aspx)

And filefolderenum for file/folder bruteforcing (http://www.woany.co.uk/blogs/woanware/pages/filefolderenum.aspx)</description>
		<content:encoded><![CDATA[<p>You could try sslciphercheck (http://www.woany.co.uk/blogs/woanware/pages/sslciphercheck.aspx), which combines the THC and Foundstone stuff.</p>
<p>And RequesterRaw for all your HTTP(S) fuzzing, is flexible enough for any HTTP requests (http://www.woany.co.uk/blogs/woanware/pages/requesterraw.aspx)</p>
<p>And filefolderenum for file/folder bruteforcing (http://www.woany.co.uk/blogs/woanware/pages/filefolderenum.aspx)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jinxpuppy</title>
		<link>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-3349</link>
		<dc:creator>jinxpuppy</dc:creator>
		<pubDate>Sat, 29 Dec 2007 18:34:28 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-3349</guid>
		<description>Fantastic post!</description>
		<content:encoded><![CDATA[<p>Fantastic post!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: EchGuest</title>
		<link>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-3306</link>
		<dc:creator>EchGuest</dc:creator>
		<pubDate>Fri, 28 Dec 2007 23:39:43 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-3306</guid>
		<description>my god , it will take me ages to play with all of this stuff , just awesome ,  thankss</description>
		<content:encoded><![CDATA[<p>my god , it will take me ages to play with all of this stuff , just awesome ,  thankss</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcin</title>
		<link>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-2816</link>
		<dc:creator>Marcin</dc:creator>
		<pubDate>Wed, 05 Dec 2007 17:44:45 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-2816</guid>
		<description>damn... I didn't think it would affect the post within the RSS feed. I wanted to shorten up the home page and let me people view an excerpt quickly without having to scroll forever, since 5 posts made it super long.

Sorry about that.</description>
		<content:encoded><![CDATA[<p>damn&#8230; I didn&#8217;t think it would affect the post within the RSS feed. I wanted to shorten up the home page and let me people view an excerpt quickly without having to scroll forever, since 5 posts made it super long.</p>
<p>Sorry about that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LonerVamp</title>
		<link>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-2815</link>
		<dc:creator>LonerVamp</dc:creator>
		<pubDate>Wed, 05 Dec 2007 17:28:58 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-2815</guid>
		<description>Boo, to the "more" in the rss feed!</description>
		<content:encoded><![CDATA[<p>Boo, to the &#8220;more&#8221; in the rss feed!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nEUrOO</title>
		<link>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-2785</link>
		<dc:creator>nEUrOO</dc:creator>
		<pubDate>Mon, 03 Dec 2007 20:38:16 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-2785</guid>
		<description>andre, you should write about the perfect tools for you, I'm sure that would be interesting :)</description>
		<content:encoded><![CDATA[<p>andre, you should write about the perfect tools for you, I&#8217;m sure that would be interesting :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Javier</title>
		<link>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-2784</link>
		<dc:creator>Javier</dc:creator>
		<pubDate>Mon, 03 Dec 2007 15:52:06 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/11/24/2007-security-testing-tools-in-review/#comment-2784</guid>
		<description>Wow!!! amazing post dude, most of the tools you talked are amazing with pros and cons... :'( need to keep developing ... i really miss it :D</description>
		<content:encoded><![CDATA[<p>Wow!!! amazing post dude, most of the tools you talked are amazing with pros and cons&#8230; :&#8217;( need to keep developing &#8230; i really miss it :D</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.227 seconds -->
