'공부/Etc'에 해당되는 글 5건

  1. Phoenix/Tools 2008/10/07
  2. 포토샵 - 매크로 2008/02/15
  3. 리눅스 ip 설정 2008/02/15
  4. 악성 Blog Trackback 직접 지우기 -_- (8) 2006/12/15
  5. wget을 이용하는 Perl script 2006/11/10

Phoenix/Tools

from 공부/Etc 2008/10/07 12:05
OWASP에서 정리해놓은 툴들.
 
Fuzzer 조사하다가 찾았다.
Fuzzer도 꽤 많이 있는 듯.

(http://www.owasp.org/index.php/Phoenix/Tools)


-------------------------------------------------------------------------------------------------

Phoenix/Tools

Please send comments or questions to the Phoenix-OWASP mailing-list.

LiveCDs

Monday, January 29, 2007 4:02 PM 828569600 AOC_Labrat-ALPHA-0010.iso - http://www.packetfocus.com/hackos/
DVL (Damn Vulnerable Linux) - http://www.damnvulnerablelinux.org/

Test sites / testing grounds

SPI Dynamics (live) - http://zero.webappsecurity.com/
Cenzic (live) - http://crackme.cenzic.com/
Watchfire (live) - http://demo.testfire.net/
Acunetix (live) - http://testphp.acunetix.com/ http://testasp.acunetix.com http://testaspnet.acunetix.com
WebMaven / Buggy Bank (includes live testsite) - http://www.mavensecurity.com/webmaven
Foundstone SASS tools - http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/s3i_tools.htm
OWASP WebGoat - http://www.owasp.org/index.php/OWASP_WebGoat_Project
OWASP SiteGenerator - http://www.owasp.org/index.php/Owasp_SiteGenerator
Stanford SecuriBench - http://suif.stanford.edu/~livshits/securibench/
SecuriBench Micro - http://suif.stanford.edu/~livshits/work/securibench-micro/

HTTP proxying / editing

WebScarab - http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project
Burp - http://www.portswigger.net/
Paros - http://www.parosproxy.org/
Fiddler - http://www.fiddlertool.com/
Web Proxy Editor - http://www.microsoft.com/mspress/companion/0-7356-2187-X/
Pantera - http://www.owasp.org/index.php/Category:OWASP_Pantera_Web_Assessment_Studio_Project
Suru - http://www.sensepost.com/research/suru/
httpedit (curses-based) - http://www.neutralbit.com/en/rd/httpedit/
Charles - http://www.xk72.com/charles/
Odysseus - http://www.bindshell.net/tools/odysseus
Burp, Paros, and WebScarab for Mac OS X - http://www.corsaire.com/downloads/
Web-application scanning tool from `Network Security Tools'/O'Reilly - http://examples.oreilly.com/networkst/
JS Commander - http://jscmd.rubyforge.org/
Ratproxy - http://code.google.com/p/ratproxy/

RSnake's XSS cheat sheet based-tools, webapp fuzzing, and encoding tools

Wfuzz - http://www.edge-security.com/wfuzz.php
ProxMon - http://www.isecpartners.com/proxmon.html
Wapiti - http://wapiti.sourceforge.net/
Grabber - http://rgaucher.info/beta/grabber/
XSSScan - http://darkcode.ath.cx/scanners/XSSscan.py
CAL9000 - http://www.owasp.org/index.php/Category:OWASP_CAL9000_Project
HTMangLe - http://www.fishnetsecurity.com/Tools/HTMangLe/publish.htm
JBroFuzz - http://sourceforge.net/projects/jbrofuzz
XSSFuzz - http://ha.ckers.org/blog/20060921/xssfuzz-released/
WhiteAcid's XSS Assistant - http://www.whiteacid.org/greasemonkey/
Overlong UTF - http://www.microsoft.com/mspress/companion/0-7356-2187-X/
[TGZ] MielieTool (SensePost Research) - http://packetstormsecurity.org/UNIX/utilities/mielietools-v1.0.tgz
RegFuzzer: test your regular expression filter - http://rgaucher.info/b/index.php/post/2007/05/26/RegFuzzer%3A-Test-your-regular-expression-filter
screamingCobra - http://www.dachb0den.com/projects/screamingcobra.html
SPIKE and SPIKE Proxy - http://immunitysec.com/resources-freesoftware.shtml
RFuzz - http://rfuzz.rubyforge.org/
WebFuzz - http://www.codebreakers-journal.com/index.php?option=com_content&task=view&id=112&Itemid=99999999
TestMaker - http://www.pushtotest.com/Docs/downloads/features.html
ASP Auditor - http://michaeldaw.org/projects/asp-auditor-v2/
WSTool - http://wstool.sourceforge.net/
Web Hack Control Center (WHCC) - http://ussysadmin.com/whcc/
Web Text Converter - http://www.microsoft.com/mspress/companion/0-7356-2187-X/
HackBar (Firefox Add-on) - https://addons.mozilla.org/firefox/3899/
Net-Force Tools (NF-Tools, Firefox Add-on) - http://www.net-force.nl/library/downloads/
PostIntercepter (Greasemonkey script) - http://userscripts.org/scripts/show/743

HTTP general testing / fingerprinting

Wbox: HTTP testing tool - http://hping.org/wbox/
ht://Check - http://htcheck.sourceforge.net/
Mumsie - http://www.lurhq.com/tools/mumsie.html
WebInject - http://www.webinject.org/
Torture.pl Home Page - http://stein.cshl.org/~lstein/torture/
JoeDog's Seige - http://www.joedog.org/JoeDog/Siege/
OPEN-LABS: metoscan (http method testing) - http://www.open-labs.org/
Load-balancing detector - http://ge.mine.nu/lbd.html
HMAP - http://ujeni.murkyroc.com/hmap/
Net-Square: httprint - http://net-square.com/httprint/
Wpoison: http stress testing - http://wpoison.sourceforge.net/
Net-square: MSNPawn - http://net-square.com/msnpawn/index.shtml
hcraft: HTTP Vuln Request Crafter - http://druid.caughq.org/projects/hcraft/
rfp.labs: LibWhisker - http://www.wiretrip.net/rfp/lw.asp
Nikto - http://www.cirt.net/code/nikto.shtml
twill - http://twill.idyll.org/
DirBuster - http://www.owasp.org/index.php/Category:OWASP_DirBuster_Project
[ZIP] DFF Scanner - http://security-net.biz/files/dff/DFF.zip
[ZIP] The Elza project - http://packetstormsecurity.org/web/elza-1.4.7-beta.zip http://www.stoev.org/elza.html
HackerFox and Hacking Addons Bundled: Portable Firefox with web hacking addons bundled - http://sf.net/projects/hackfox

Browser-based HTTP tampering / editing / replaying

TamperIE - http://www.bayden.com/Other/
isr-form - http://www.infobyte.com.ar/developments.html
Modify Headers (Firefox Add-on) - http://modifyheaders.mozdev.org/
Tamper Data (Firefox Add-on) - http://tamperdata.mozdev.org/
UrlParams (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/1290/
TestGen4Web (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/1385/
DOM Inspector / Inspect This (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/1806/ https://addons.mozilla.org/en-US/firefox/addon/1913/
LiveHTTPHeaders / Header Monitor (Firefox Add-on) - http://livehttpheaders.mozdev.org/ https://addons.mozilla.org/en-US/firefox/addon/575/

Cookie editing / poisoning

[TGZ] stompy: session id tool - http://lcamtuf.coredump.cx/stompy.tgz
Add'N Edit Cookies (AnEC, Firefox Add-on) - http://addneditcookies.mozdev.org/
CookieCuller (Firefox Add-on) - http://cookieculler.mozdev.org/
CookiePie (Firefox Add-on) - http://www.nektra.com/oss/firefox/extensions/cookiepie/
CookieSpy - http://www.codeproject.com/shell/cookiespy.asp
Cookies Explorer - http://www.dutchduck.com/Features/Cookies.aspx

Ajax and XHR scanning

Sahi - http://sahi.co.in/
scRUBYt - http://scrubyt.org/
jQuery - http://jquery.com/
jquery-include - http://www.gnucitizen.org/projects/jquery-include
Sprajax - http://www.denimgroup.com/sprajax.html
Watir - http://wtr.rubyforge.org/
Watij - http://watij.com/
Watin - http://watin.sourceforge.net/
RBNarcissus - http://idontsmoke.co.uk/2005/rbnarcissus/
SpiderTest (Spider Fuzz plugin) - http://blog.caboo.se/articles/2007/2/21/the-fabulous-spider-fuzz-plugin
Javascript Inline Debugger (jasildbg) - http://jasildbg.googlepages.com/
Firebug Lite - http://www.getfirebug.com/lite.html
firewaitr - http://code.google.com/p/firewatir/

RSS extensions and caching

LiveLines (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/324/
rss-cache - http://www.dubfire.net/chris/projects/rss-cache/

SQL injection scanning

0x90.org: home of Absinthe, Mezcal, etc - http://0x90.org/releases.php
SQLiX - http://www.owasp.org/index.php/Category:OWASP_SQLiX_Project
sqlninja: a SQL Server injection and takover tool - http://sqlninja.sourceforge.net/
JustinClarke's SQL Brute - http://www.justinclarke.com/archives/2006/03/sqlbrute.html
BobCat - http://www.northern-monkee.co.uk/projects/bobcat/bobcat.html
sqlmap - http://sqlmap.sourceforge.net/
Scully: SQL Server DB Front-End and Brute-Forcer - http://www.sensepost.com/research/scully/
FG-Injector - http://www.flowgate.net/?lang=en&seccion=herramientas
PRIAMOS - http://www.priamos-project.com/

Web application security malware, backdoors, and evil code

W3AF: Web Application Attack and Audit Framework - http://w3af.sourceforge.net/
Jikto - http://busin3ss.name/jikto-in-the-wild/
XSS Shell - http://ferruh.mavituna.com/article/?1338
XSS-Proxy - http://xss-proxy.sourceforge.net
AttackAPI - http://www.gnucitizen.org/projects/attackapi/
FFsniFF - http://azurit.elbiahosting.sk/ffsniff/
HoneyBlog's web-based junkyard - http://honeyblog.org/junkyard/web-based/
BeEF - http://www.bindshell.net/tools/beef/
Firefox Extension Scanner (FEX) - http://www.gnucitizen.org/projects/fex/
What is my IP address? - http://reglos.de/myaddress/
xRumer: blogspam automation tool - http://www.botmaster.net/movies/XFull.htm
SpyJax - http://www.merchantos.com/makebeta/tools/spyjax/
Greasecarnaval - http://www.gnucitizen.org/projects/greasecarnaval
Technika - http://www.gnucitizen.org/projects/technika/
Load-AttackAPI bookmarklet - http://www.gnucitizen.org/projects/load-attackapi-bookmarklet
MD's Projects: JS port scanner, pinger, backdoors, etc - http://michaeldaw.org/my-projects/

Web application services that aid in web application security assessment

Netcraft - http://www.netcraft.net
AboutURL - http://www.abouturl.com/
The Scrutinizer - http://www.scrutinizethis.com/
net.toolkit - http://clez.net/
ServerSniff - http://www.serversniff.net/
Online Microsoft script decoder - http://www.greymagic.com/security/tools/decoder/
Webmaster-Toolkit - http://www.webmaster-toolkit.com/
myIPNeighbbors, et al - http://digg.com/security/MyIPNeighbors_Find_Out_Who_Else_is_Hosted_on_Your_Site_s_IP_Address
PHP charset encoding - http://h4k.in/encoding
data: URL testcases - http://h4k.in/dataurl

Browser-based security fuzzing / checking

Zalewski's MangleMe - http://lcamtuf.coredump.cx/mangleme/mangle.cgi
hdm's tools: Hamachi, CSSDIE, DOM-Hanoi, AxMan - http://metasploit.com/users/hdm/tools/
Peach Fuzzer Framework - http://peachfuzz.sourceforge.net/
TagBruteForcer - http://research.eeye.com/html/tools/RT20060801-3.html
PROTOS Test-Suite: c05-http-reply - http://www.ee.oulu.fi/research/ouspg/protos/testing/c05/http-reply/index.html
COMRaider - http://labs.idefense.com
bcheck - http://bcheck.scanit.be/bcheck/
Stop-Phishing: Projects page - http://www.indiana.edu/~phishing/?projects
LinkScanner - http://linkscanner.explabs.com/linkscanner/default.asp
BrowserCheck - http://www.heise-security.co.uk/services/browsercheck/
Cross-browser Exploit Tests - http://www.jungsonnstudios.com/cool.php
Stealing information using DNS pinning demo - http://www.jumperz.net/index.php?i=2&a=1&b=7
Javascript Website Login Checker - http://ha.ckers.org/weird/javascript-website-login-checker.html
Mozilla Activex - http://www.iol.ie/~locka/mozilla/mozilla.htm
Jungsonn's Black Dragon Project - http://blackdragon.jungsonnstudios.com/
Mr. T (Master Recon Tool, includes Read Firefox Settings PoC) - http://ha.ckers.org/mr-t/
Vulnerable Adobe Plugin Detection For UXSS PoC - http://www.0x000000.com/?i=324
About Flash: is your flash up-to-date? - http://www.macromedia.com/software/flash/about/
Test your installation of Java software - http://java.com/en/download/installed.jsp?detect=jre&try=1
WebPageFingerprint - Light-weight Greasemonkey Fuzzer - http://userscripts.org/scripts/show/30285

PHP static analysis and file inclusion scanning

PHP-SAT.org: Static analysis for PHP - http://www.program-transformation.org/PHP/
Unl0ck Research Team: tool for searching in google for include bugs - http://unl0ck.net/tools.php
FIS: File Inclusion Scanner - http://www.segfault.gr/index.php?cat_id=3&cont_id=25
PHPSecAudit - http://developer.spikesource.com/projects/phpsecaudit

PHP Defensive Tools

PHPInfoSec - Check phpinfo configuration for security - http://phpsec.org/projects/phpsecinfo/

A Greasemonkey Replacement can be found at http://yehg.net/lab/#tools.greasemonkey


Php-Brute-Force-Attack Detector - Detect your web servers being scanned by brute force tools such as WFuzz, OWASP DirBuster and vulnerability scanners such as Nessus, Nikto, Acunetix ..etc. http://yehg.net/lab/pr0js/files.php/php_brute_force_detect.zip


PHP-Login-Info-Checker - Strictly enforce admins/users to select stronger passwords. It tests cracking passwords against 4 rules. It has also built-in smoke test page via url loginfo_checker.php?testlic

http://yehg.net/lab/pr0js/files.php/loginfo_checkerv0.1.zip

http://yehg.net/lab/pr0js/files.php/phploginfo_checker_demo.zip


php-DDOS-Shield - A tricky script to prevent idiot distributed bots which discontinue their flooding attacks by identifying HTTP 503 header code.http://code.google.com/p/ddos-shield/


PHPMySpamFIGHTER - http://yehg.net/lab/pr0js/files.php/phpmyspamfighter.zip http://yehg.net/lab/pr0js/files.php/phpMySpamFighter_demo.rar

Web Application Firewall (WAF) and Intrusion Detection (APIDS) rules and resources

APIDS on Wikipedia - http://en.wikipedia.org/wiki/APIDS
PHP Intrusion Detection System (PHP-IDS) - http://php-ids.org/ http://code.google.com/p/phpids/
dotnetids - http://code.google.com/p/dotnetids/
Secure Science InterScout - http://www.securescience.com/home/newsandevents/news/interscout1.0.html
Remo: whitelist rule editor for mod_security - http://remo.netnea.com/
GotRoot: ModSecuirty rules - http://www.gotroot.com/tiki-index.php?page=mod_security+rules
The Web Security Gateway (WSGW) - http://wsgw.sourceforge.net/
mod_security rules generator - http://noeljackson.com/tools/modsecurity/
Mod_Anti_Tamper - http://www.wisec.it/projects.php?id=3
[TGZ] Automatic Rules Generation for Mod_Security - http://www.wisec.it/rdr.php?fn=/Projects/Rule-o-matic.tgz
AQTRONIX WebKnight - http://www.aqtronix.com/?PageID=99
Akismet: blog spam defense - http://akismet.com/
Samoa: Formal tools for securing web services - http://research.microsoft.com/projects/samoa/

Web services enumeration / scanning / fuzzing

WebServiceStudio2.0 - http://www.codeplex.com/WebserviceStudio
Net-square: wsChess - http://net-square.com/wschess/index.shtml
WSFuzzer - http://www.owasp.org/index.php/Category:OWASP_WSFuzzer_Project
SIFT: web method search tool - http://www.sift.com.au/73/171/sift-web-method-search-tool.htm
iSecPartners: WSMap, WSBang, etc - http://www.isecpartners.com/tools.html

Web application non-specific static source-code analysis

Pixy: a static analysis tool for detecting XSS vulnerabilities - http://www.seclab.tuwien.ac.at/projects/pixy/
Brixoft.Net: Source Edit - http://www.brixoft.net/prodinfo.asp?id=1
Security compass web application auditing tools (SWAAT) - http://www.owasp.org/index.php/Category:OWASP_SWAAT_Project
An even more complete list here - http://www.cs.cmu.edu/~aldrich/courses/654/tools/
A nice list that claims some demos available - http://www.cs.cmu.edu/~aldrich/courses/413/tools.html
A smaller, but also good list - http://spinroot.com/static/

Static analysis for C/C++ (CGI, ISAPI, etc) in web applications

RATS - http://www.securesoftware.com/resources/download_rats.html
ITS4 - http://www.cigital.com/its4/
FlawFinder - http://www.dwheeler.com/flawfinder/
Splint - http://www.splint.org/
Uno - http://spinroot.com/uno/
BOON (Buffer Overrun detectiON) - http://www.cs.berkeley.edu/~daw/boon/ http://boon.sourceforge.net
Valgrind - http://www.valgrind.org/

Java static analysis, security frameworks, and web application security tools

LAPSE - http://suif.stanford.edu/~livshits/work/lapse/ 
HDIV Struts - http://hdiv.org/
Orizon - http://sourceforge.net/projects/orizon/
FindBugs: Find bugs in Java programs - http://findbugs.sourceforge.net/
PMD - http://pmd.sourceforge.net/
CUTE: A Concolic Unit Testing Engine for C and Java - http://osl.cs.uiuc.edu/~ksen/cute/
EMMA - http://emma.sourceforge.net/
JLint - http://jlint.sourceforge.net/
Java PathFinder - http://javapathfinder.sourceforge.net/
Fujaba: Move between UML and Java source code - http://wwwcs.uni-paderborn.de/cs/fujaba/
Checkstyle - http://checkstyle.sourceforge.net/
Cookie Revolver Security Framework - http://sourceforge.net/projects/cookie-revolver
tinapoc - http://sourceforge.net/projects/tinapoc
jarsigner - http://java.sun.com/j2se/1.5.0/docs/tooldocs/solaris/jarsigner.html
Solex - http://solex.sourceforge.net/
Java Explorer - http://metal.hurlant.com/jexplore/
HTTPClient - http://www.innovation.ch/java/HTTPClient/
another HttpClient - http://jakarta.apache.org/commons/httpclient/
a list of code coverage and analysis tools for Java - http://mythinkpond.blogspot.com/2007/06/java-foss-freeopen-source-software.html

Microsoft .NET static analysis and security framework tools, mostly for ASP.NET and ASP.NET AJAX, but also C# and VB.NET

Threat modeling

Microsoft Threat Analysis and Modeling Tool v2.1 (TAM) - http://www.microsoft.com/downloads/details.aspx?FamilyID=59888078-9daf-4e96-b7d1-944703479451&displaylang=en
Amenaza: Attack Tree Modeling (SecurITree) - http://www.amenaza.com/software.php
Octotrike - http://www.octotrike.org/

Add-ons for Firefox that help with general web application security

Web Developer Toolbar - https://addons.mozilla.org/firefox/60/
Plain Old Webserver (POW) - https://addons.mozilla.org/firefox/3002/
XML Developer Toolbar - https://addons.mozilla.org/firefox/2897/
Public Fox - https://addons.mozilla.org/firefox/3911/
XForms Buddy - http://beaufour.dk/index.php?sec=misc&pagename=xforms
MR Tech Local Install - http://www.mrtech.com/extensions/local_install/
Nightly Tester Tools - http://users.blueprintit.co.uk/~dave/web/firefox/buildid/index.html
IE Tab - https://addons.mozilla.org/firefox/1419/
User-Agent Switcher - https://addons.mozilla.org/firefox/59/
ServerSwitcher - https://addons.mozilla.org/firefox/2409/
HeaderMonitor - https://addons.mozilla.org/firefox/575/
RefControl - https://addons.mozilla.org/firefox/953/
refspoof - https://addons.mozilla.org/firefox/667/
No-Referrer - https://addons.mozilla.org/firefox/1999/
LocationBar^2 - https://addons.mozilla.org/firefox/4014/
SpiderZilla - http://spiderzilla.mozdev.org/
Slogger - https://addons.mozilla.org/en-US/firefox/addon/143
Fire Encrypter - https://addons.mozilla.org/firefox/3208/

Add-ons for Firefox that help with Javascript and Ajax web application security

Selenium IDE - http://www.openqa.org/selenium-ide/
Firebug - http://www.joehewitt.com/software/firebug/
Venkman - http://www.mozilla.org/projects/venkman/
Chickenfoot - http://groups.csail.mit.edu/uid/chickenfoot/
Greasemonkey - http://www.greasespot.net/
Greasemonkey compiler - http://www.letitblog.com/greasemonkey-compiler/
User script compiler - http://arantius.com/misc/greasemonkey/script-compiler
Extension Developer's Extension (Firefox Add-on) - http://ted.mielczarek.org/code/mozilla/extensiondev/
Smart Middle Click (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/3885/

Bookmarklets that aid in web application security

RSnake's security bookmarklets - http://ha.ckers.org/bookmarklets.html
BMlets - http://optools.awardspace.com/bmlet.html
Huge list of bookmarklets - http://www.squarefree.com/bookmarklets/
Blummy: consists of small widgets, called blummlets, which make use of Javascript to provide rich functionality - http://www.blummy.com/
Bookmarklets every blogger should have - http://www.micropersuasion.com/2005/10/bookmarklets_ev.html
Flat Bookmark Editing (Firefox Add-on) - http://n01se.net/chouser/proj/mozhack/
OpenBook and Update Bookmark (Firefox Add-ons) - http://www.chuonthis.com/extensions/

SSL certificate checking / scanning

[ZIP] THCSSLCheck - http://thc.org/root/tools/THCSSLCheck.zip
[ZIP] Foundstone SSLDigger - http://www.foundstone.com/us/resources/termsofuse.asp?file=ssldigger.zip
Cert Viewer Plus (Firefox Add-on) - https://addons.mozilla.org/firefox/1964/

Honeyclients, Web Application, and Web Proxy honeypots

Honeyclient Project: an open-source honeyclient - http://www.honeyclient.org/trac/ 
HoneyC: the low-interaction honeyclient - http://honeyc.sourceforge.net/
Capture: a high-interaction honeyclient - http://capture-hpc.sourceforge.net/
Google Hack Honeypot - http://ghh.sourceforge.net/
PHP.Hop - PHP Honeynet Project - http://www.rstack.org/phphop/
SpyBye - http://www.monkey.org/~provos/spybye/
Honeytokens - http://www.securityfocus.com/infocus/1713

Blackhat SEO and maybe some whitehat SEO

SearchStatus (Firefox Add-on) - http://www.quirk.biz/searchstatus/
SEO for Firefox (Firefox Add-on) - http://tools.seobook.com/firefox/seo-for-firefox.html
SEOQuake (Firefox Add-on) - http://www.seoquake.com/

Footprinting for web application security

Evolution - http://www.paterva.com/evolution-e.html
GooSweep - http://www.mcgrewsecurity.com/projects/goosweep/
Aura: Google API Utility Tools - http://www.sensepost.com/research/aura/
Edge-Security tools - http://www.edge-security.com/soft.php
Fierce Domain Scanner - http://ha.ckers.org/fierce/
Googlegath - http://www.nothink.org/perl/googlegath/
Advanced Dork (Firefox Add-on) - https://addons.mozilla.org/firefox/2144/
Passive Cache (Firefox Add-on) - https://addons.mozilla.org/firefox/977/
CacheOut! (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/1453/
BugMeNot Extension (Firefox Add-on) - http://roachfiend.com/archives/2005/02/07/bugmenot/
TrashMail.net Extension (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/1813/
DiggiDig (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/2819/
Digger (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/1467/

Database security assessment

Scuba by Imperva Database Vulnerability Scanner - http://www.imperva.com/scuba/

Browser Defenses

DieHard - http://www.diehard-software.org/
LocalRodeo (Firefox Add-on) - http://databasement.net/labs/localrodeo/
NoMoXSS - http://www.seclab.tuwien.ac.at/projects/jstaint/
Request Rodeo - http://savannah.nongnu.org/projects/requestrodeo
FlashBlock (Firefox Add-on) - http://flashblock.mozdev.org/
CookieSafe (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/2497
NoScript (Firefox Add-on) - http://www.noscript.net/
FormFox (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/1579/
Adblock (Firefox Add-on) - http://adblock.mozdev.org/
httpOnly in Firefox (Firefox Add-on) - http://blog.php-security.org/archives/40-httpOnly-Cookies-in-Firefox-2.0.html
SafeCache (Firefox Add-on) - http://www.safecache.com/
SafeHistory (Firefox Add-on) - http://www.safehistory.com/
PrefBar (Firefox Add-on) - http://prefbar.mozdev.org/
All-in-One Sidebar (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/1027/
QArchive.org web file checker (Firefox Add-on) - https://addons.mozilla.org/firefox/4115/
Update Notified (Firefox Add-on) - https://addons.mozilla.org/en-US/firefox/addon/2098/
FireKeeper - http://firekeeper.mozdev.org/
Greasemonkey: XSS Malware Script Detector - http://yehg.net/lab/#tools.greasemonkey

Browser Privacy

TrackMeNot (Firefox Add-on) - https://addons.mozilla.org/firefox/3173/
Privacy Bird - http://www.privacybird.com/

Application and protocol fuzzing (random instead of targeted)

Sulley - http://fuzzing.org/
taof: The Art of Fuzzing - http://sourceforge.net/projects/taof/
zzuf: multipurpose fuzzer - http://sam.zoy.org/zzuf/
autodafé: an act of software torture - http://autodafe.sourceforge.net/
EFS and GPF: Evolutionary Fuzzing System - http://www.appliedsec.com/resources.html

2008/10/07 12:05 2008/10/07 12:05

포토샵 - 매크로

from 공부/Etc 2008/02/15 14:48

Using Batch function in Photoshop CS3 to resize and rename batch of images

Did it ever happen to you that you had large number of images which need to be renamed resized to one dimension?

This short tutorial will explain how to use Photoshop′s build in function to handle any batch operations.

To start with we will create a new action where we will record the image resizing process.
Open Photoshop CS3 and on the right hand side choose the Actions button to open Actions panel (Fig. 01).

Open Action menu in Photoshop CS3 image
Fig. 01

Now in the lower part of the top right corner click on the arrow down (Fig. 02)

Click arrow down in Action panel in Photoshop CS3 image
Fig. 02

and from the list of options choose New Set to create a new set in which we’ll be storing our custom actions (Fig. 03).

Create new Action Set in Photoshop CS3 image
Fig. 03

In the New Set window type the name of your new set – I called mine My new set – and click OK to create new action set (Fig. 04).

New Action Set window in Photoshop CS3 image
Fig. 04

You should now be able to see your new Action Set in the Actions panel (Fig. 05).

Image illustrating new Action Set folder in Photoshop CS3
Fig. 05

Now open any image in Photoshop and from the menu in the Actions panel choose New Action (Fig. 06).

Image illustrating creating new action
Fig. 06

In the New Action window choose the name for your action (I called mine resize_100w) and assign it to our new set (Fig. 07).

Image illustrating new action window
Fig. 07

Click Record to start recording your action.
With image selected go to Image > Image Size (Fig. 08).

Image illustrating new action window
Fig. 08

In the Image Size window choose the new dimensions for your image and click OK to apply them to your image (Fig. 09).

Image illustrating Image size window
Fig. 09

You should now see your image being resized and you can press the Stop button to terminate the recording session (Fig. 10).

Image illustrating action window
Fig. 10

You can now close the image.

Go to File > Automate > Batch (Fig. 11).

Image illustrating batch menu
Fig. 11

In the Batch window choose our new set (My new set) and the action which we would like to apply to a batch of images we are about to process (resize_100w) (Fig. 12).

Image illustrating batch window
Fig. 12

From the Source dropdown menu choose Folder and specify the location in which your original files are located by clicking Choose button and navigating to their folder.
Leave check boxes unchecked (Fig. 13).

Image illustrating batch source section
Fig. 13

From the Destination dropdown menu choose Folder and specify the destination folder for the new files by clicking Choose button and navigating to the folder. Doing this we will keep our original files untouched and we will create the new ones in the destination folder (Fig. 14).

Image illustrating batch destination section
Fig. 14

Now it’s time to define the new name for our files. In the first field (dropdown menu) type in the first part of the new name of your file – I called mine thumbnail_ - in the next field you can define whether you want just extension or anything else – I want to have two digits which will define the number of the new file and lastly I want to have the original extension of the file in lower case.
We can also specify the Compatibility by selecting systems with which our new files should be compatible and lastly decide what we want to happen when error occurs (Fig. 15).

Image illustrating batch file naming section
Fig. 15

Now just click OK and the action Batch automation will do the whole job for you – creating a new copy of each files from the Source folder as well as resizing and renaming them (Fig. 16).

Image illustrating two folders
Fig. 16

That´s all there is to it.

Prepared by Web Designer Sussex - Sebastian Sulinski.

2008/02/15 14:48 2008/02/15 14:48

리눅스 ip 설정

from 공부/Etc 2008/02/15 14:44

ifconfig [DEV] [IP] netmask [MSK] broadcast [BDIP]
route add default gw [GW]

DEV = 이더넷 디바이스 (eth0, eth1 ...)
IP = 설정할 IP주소
MSK = 설정할 넷마스크
BDIP = 브로드캐스트 IP 주소
GW = 게이트웨이 IP주소

****
- freebsd

fconfig [DEV] [IP] netmask [MSK]
route add -net 0.0.0.0 [GW]

****



젠투 같은 경우는 /etc/conf.d/net 파일에 설정을 적어주고
/etc/init.d/net.eth0 스크립트를 사용해서 장치를 활성화하거나 중지하거나 합니다.





http://kldp.org/node/78173
2008/02/15 14:44 2008/02/15 14:44
Tag // ,

이런 하찮은걸 Study 란에 올려야 되나 고심했지만
그냥 올린다. 캬캬.

악성 트랙백이 극성-_-인 요즘(덕택에 블로그 힛수는 올라간다만 :) ... )
테터 1.1인가로 업뎃하거나 뭐 플러그인을 설치하면
차단할 수 있다던데
알아보기 귀-_-찮아서 아직 안하고 있다.

전에는 테터 관리자 모드로 들어가서
내가 일일이 -_- 다 지우느라 귀찮고 힘들길래
요샌 걍 안지우고 있었다;

잠시 놔두니 1만개가 넘는데 그걸 어케 다 일일이 지워-_-;;
그래서 내가 직접 mysql 에 접속해서 지우기로 결정.

혹시나 하실 분들은 하시길.
굵은 글씨만 잘 따라서.

(freestar는 내 mysql id 및 DB 이름)

freestar@ ~/public_html/Old♪ mysql -u freestar -p
Enter password:
Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 288 to server version: 5.0.26-log

Type 'help;' or '\h' for help. Type '\c' to clear the buffer.

mysql> use freestar;
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
mysql> delete from tt_Trackbacks;
Query OK, 322 rows affected (0.00 sec)


끝.

명령어 하나만 치면 된다....
delete from tt_Trackbacks;
요거.



장점: 악성 트랙백이 싹 다 지워진다.
단점: 주기적으로 내가 계속 해줘야 한다 -_-
       정말 금방 다시 트랙백이 들어온다.

* 경고: 모든 트랙백이 지워진다 -_-
           난 트랙백 안써서 걍 신경안쓰고 있어서 미처 생각 못했음 -_-ㅋ
          Thanks to e0en.

결론: 업데이트 하자.



Study/etc 란에 글 좀 쓰고 싶어서..

2006/12/15 15:23 2006/12/15 15:23
어제 삽질하다
오늘도 삽질만 할 수는 없다 싶어서
script를 짰다.

결론적으로는
스크립트를 짜서 편해졌긴 하지만
아직 내가 얻고 싶은 성과는 못냈다.


어쨌든 wget 사용법을 쪼오끔 더 알게된김에
까먹지 말라고 포스팅 해야겠다.


* wget 의 옵션

1. --save-cookies [file]

말 그대로 cookie를 file에 저장시켜준다.

저장된 file의 형식을 보면

-------------------------------------------------
# HTTP cookie file.
# Generated by Wget on 2006-11-10 01:50:50.
# Edit at your own risk.

[url] TRUE / FALSE 0 [name] [value]
[url] TRUE / FALSE 0 [name2] [value2]
-------------------------------------------------

대강 이런 형식이다.
각각 무엇을 뜻하는지 정확히 모른다 -_-;;
나도 오늘 첨봐서;

url 부분은 아마 이 cookie가 유효한 Host 같고,
TRUE, FALSE는 뭔지 전혀 감이 안오고;
"/" 요건 아마 url과 비슷하게 cookie가 유효한 path 같고,

중요한건 역시 name과 value 부분이다.
사실 우리가 cookie를 봤을 때 보이는건
name=value;name2=value2;
이정도인데, 그걸 나타내는게 name, value이다.
name이 cookie내 변수 이름, value가 그 값이다.

요부분만 잘 보면 대부분 되지 싶다.



2. --keep-sesstion-cookies

정확히 무슨 옵션인지는 모르겠지만
대충 말 그대로 cookie를 유지하고 있게 해주는 옵션 인것 같다.
예를 들어, 내가 테스트한 wget 페이지는 회원 가입 페이지였는데
회원 가입을 하면서 cookie가 형성 되지만
wget이 끝나면서 연결도 끊어지므로
cookie도 사라지는 것 같다. (즉 browser가 닫히는 현상과 비슷한 것 같다)
이를 계속 유지해서 남겨두는게 이 옵션인것 같다.

man page를 살펴보면
"When specified, causes --save-cookies to also save session cookies. Session cookies are normally not saved because they are meant to be kept in memory and forgotten when you exit the browser."
그리고
"if you want --save-cookies to preserve them again, you must use --keep-session-cookies again."

즉, "--save-cookies" 옵션을 쓰기 위해서는 반드시 이 옵션을 사용해야만 한다.


3. --load-cookies [file]

wget으로 요청할 page에 cookie를 같이 보내고 싶다
cookie를 저장한 file을 만들고 저 옵션을 적용하면 된다.

cookie 파일은 형식이 있어야 하는 것 같은데
1번에서 말했던 --save-cookies 옵션을 써서 저장된 cookie file 형식이면 적용 된다.

browser 마다 다른 format이 있는 것 같은데
이 옵션에 대한 man page를 보면 설명되어있다.

이 옵션을 쓰지 않고도 cookie를 보내는 방법에는

--header "Cookie: ~~"

이런식으로 해주면 된다.



4. --post-data [data]

이 옵션은 예전에도 한번 써봤던 적이 있던 것 같다.
이것 역시 말 그대로 post-data를 전송해주게 하는 옵션이다.

사용예를 들자면
wget --post-data "name=abc&pass=1234" [url]
그냥 이렇게 사용하면 된다.

즉, 페이지를 요청할때 필요한 post-data들을 그대로 적어주면 된다.

5. -O [file]

wget으로 요청한 page를 [file] 부분에 적은 이름, 경로로 저장해준다.
O는 아마 Output의 약자 일것이다.
man page를 보면

--output-document=file

랑도 같다고 나와있다.

6. -S, -d

우연히 알게 된 옵션인데
이것 역시 둘다 정확히 아는 옵션은 아니지만
크게 필요없는 것 같다.

-S
wget을 할 때 전송되는 HTTP header를 보여준다.

-d--debug와 같은 옵션으로
header를 보여줄 뿐만 아니라
client와 server 간의 request와 response는 죄다 보여주는 느낌이다.

말그대로 debug를 하고 싶을 때 사용하면 좋을 것 같다.



//

오늘 짠 script에 사용된 옵션은 이정도이다.
이 외에 매우 다양한 wget 옵션이 있으나 사실 이외에 그닥 쓸 옵션은 없을 것 같다;
-r 정도?


그럼 오늘 짠 스크립트를 살짝 형식만 보면

------------------------------  wget.pl -------------------------------------------------
#!/usr/bin/perl

$url="http://~~/register.php";
$userID=$ARGV[0];
$data="~~~";

`wget --keep-session-cookies --save-cookies "cookie/$userID" --post-data "$data" -O tmp/"$userID"1 "$url"`;

$url=http://~~/out.php";
$data="~~~~";

`wget --load-cookies cookie/"$userID" --post-data "$data" -O tmp/"$userID"2 "$url"`;

--------------------------------------------------------------------------------------


$ARGV[0] 은 "./wget.pl [1]" 를 했을 경우 [1] 부분이 저장된다.
C의 경우에는 argv[0] 이라면 "./wget.pl" 이 들어가지만 perl 의 경우는 다르다.

그리고 perl 에서 `command` 가
system(command)랑 같다.


위 스크립트가 하는 짓은
처음에 $data에 회원 정보를 넣어서 wget으로 회원 가입을 하면서
생긴 cookie를 저장하고
두번째 wget을 할 때 그 cookie를 load 하면서 탈퇴한다.
(탈퇴하는 페이지가 cookie를 필요로했었다)

wget으로 하면서 다운 받은 page들은
tmp 에 저장되고 있다.








이 스크립트를 완성해서
아주 상당히 편해졌다.

역시 wget -_-)b


2006/11/10 11:38 2006/11/10 11:38