Kali Linux 2018: Assuring Security by Penetration Testing - Fourth Edition
by Shiva V. N. Parasram, Alex Samm, Damian Boodoo, Gerard Johansen, Lee Allen, Tedi Heriyanto, Shakeel Ali
W3AF
W3AF is a feature-rich web application attack-and-audit framework that aims to detect and exploit web vulnerabilities. The whole application-security assessment process is automated, and the framework is designed to follow three major steps: discover, audit, and attack. Each of these steps includes several plugins that might help the auditor focus on specific testing criteria. All of these plugins can communicate and share test data in order to achieve the required goal. It supports the detection and exploitation of multiple web application vulnerabilities, including SQL injection, cross-site scripting, remote and local file inclusion, buffer overflows, XPath injections, OS commanding, and application misconfiguration.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access