
parameterfuzz
v2.0 FINAL VERSION
http://www.enelpc.com/p/parameterfuzz.html
v1.9
https://docs.google.com/uc?id=0B74kMAGqImI9VlJ6TXVlV3p6NmM
v1.8
https://docs.google.com/uc?id=0B74kMAGqImI9YmhITTJVX0NnSVk
----------------------------------------------------------------------------
Description
ParameterFuzz is a tool to check the level of fortification in web applications, try to cover the field more exploited by hackers, as the majority of known attacks are based on exploiting poorly filtered parameters. Just as SQL injection, Cross Site Scripting or RFI among others. This tool is designed to perform security audits manually, however it is possible to automate the audit process.
It can be used for a lot of purposes such as:
- Dictionary attacks to parameters and folders
- Manual and automatic attacks to web applications
- Browse the source code viewing
- View logs of results
- Encoder/Decoder tool
- Spidering attacks
- Leaks detection
- SQL Injection detection
- Changes in the HTTP headers
- Extract valid parameters of the source code
- imagination...¿?
Video Tutorial (Spanish)
http://www.youtube.com/watch?feature=player_embedded&v=rZBuyZp7NlM' target='_blank'>http://img.youtube.com/vi/rZBuyZp7NlM/0.jpg' width='425' height=344 />
Options & Tools
ParameterFuzz includes a list of options and tools with which you can interact from the main form, GET and POST.
SQLi Detector:
Leaks Detector:
URL Spider:
Input's Parameters:
Grep Extractor:
Robots Extractor:
Project Information
The project was created on Apr 23, 2013.
- License: Other Open Source
- 4 stars
- svn-based source control
Labels:
Fuzzing
security
testing
websecurity
pentesting
parametermanipulation
SQLi
XSS
LFI
RFI
Vulnerability