<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Free Web Resources - Web Resources Depot &#187; XSS</title>
	<atom:link href="http://www.webresourcesdepot.com/tag/xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webresourcesdepot.com</link>
	<description>Free Web Resources</description>
	<lastBuildDate>Sun, 12 Feb 2012 13:06:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>10+ Free Web Application Security Testing Tools</title>
		<link>http://www.webresourcesdepot.com/10-free-web-application-security-testing-tools/</link>
		<comments>http://www.webresourcesdepot.com/10-free-web-application-security-testing-tools/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 08:45:27 +0000</pubDate>
		<dc:creator>Umut M.</dc:creator>
				<category><![CDATA[Extras]]></category>
		<category><![CDATA[Other License]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.webresourcesdepot.com/?p=1594</guid>
		<description><![CDATA[<p><a href='http://rss.buysellads.com/click.php?z=1259982&k=ed230295611f656daf3115e6d682ca7d&a=1594&c=16866' target='_blank'><img src='http://rss.buysellads.com/img.php?z=1259982&k=ed230295611f656daf3115e6d682ca7d&a=1594&c=16866' border='0' alt='' /></a></p><p><a href='http://buysellads.com/buy/sitedetails/pubkey/ed230295611f656daf3115e6d682ca7d/zone/1259982' target='_blank'>Advertise here with BSA</a></p><br />Websites are getting more and more complex everyday and there are almost no static websites being built. Today, the simplest website has at least a contact or newsletter form and many are built with CMS systems or it may be using 3rd party plugins, services, etc. that we don&#39;t have an exact control over. Even [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://rss.buysellads.com/click.php?z=1259982&k=ed230295611f656daf3115e6d682ca7d&a=1594&c=30585' target='_blank'><img src='http://rss.buysellads.com/img.php?z=1259982&k=ed230295611f656daf3115e6d682ca7d&a=1594&c=30585' border='0' alt='' /></a></p><p><a href='http://buysellads.com/buy/sitedetails/pubkey/ed230295611f656daf3115e6d682ca7d/zone/1259982' target='_blank'>Advertise here with BSA</a></p><br /><p>Websites are getting more and more complex everyday and there are almost <strong>no static websites being built</strong>.</p>
<p><img align="left" alt="Security Guy" border="0" height="177" src="http://www.webresourcesdepot.com/wp-content/uploads/security-guy.jpg" style="margin-right: 5px;" width="120" />Today, the simplest website has at least a contact or newsletter form and many are built with CMS systems or it may be using 3rd party plugins, services, etc. that we don&#39;t have an exact control over.</p>
<p>Even if the website is 100% hand-coded, we trust what we created and think that it is safe, it is still possible that a special character is not sanitized or we are not aware of a new attacking technique.</p>
<p>So, <strong>it is really hard to say &quot;my website is safe</strong>&quot; without running tests over it. The good part is there are powerful and <strong>free web application security testing tools</strong> which can help you to identify any possible holes.</p>
<p>Before presenting them, let&#39;s remind the classic:<strong> &quot;something can be secure as only as its weakest link</strong>&quot; (which also tells us that it is not always the application and can still be the server it is hosted or that easy to remember FTP password).</p>
<h3><a href="http://www.mavitunasecurity.com/communityedition/" target="_blank">Netsparker Community Edition</a> (Windows)</h3>
<p><a href="http://www.mavitunasecurity.com/communityedition/" target="_blank"><img alt="Netsparker Community Edition" height="208" src="http://www.webresourcesdepot.com/wp-content/uploads/netsparker.jpg" width="481" /></a></p>
<p>This is the free-community edition of the powerful <strong>Netsparker</strong> which still comes with a bunch of features and also <strong>false-positive-free</strong>.</p>
<p>The application can <strong>detect SQL Injection + cross-site scripting issues</strong>.</p>
<p>Once a scan is complete, it <strong>displays the solutions besides the issues</strong> and enables you to see the browser view and HTTP request/response.</p>
<h3><a href="http://www.websecurify.com/" target="_blank">Websecurify</a> (Windows, Linux, Mac OS X)</h3>
<p><a href="http://www.websecurify.com/" target="_blank"><img alt="Websecurify" height="208" src="http://www.webresourcesdepot.com/wp-content/uploads/websecurify.gif" width="481" /></a></p>
<p><strong>Websecurify</strong> is a very easy-to-use and <strong>open source</strong> tool which automatically identifies web application vulnerabilities by using advanced discovery and fuzzing technologies.</p>
<p>It can create simple reports (that can be exported into multiple formats) once ran.</p>
<p>The tool is also multilingual and extensible with the add-on support.</p>
<p><span id="more-1594"></span></p>
<h3><a href="http://www.ict-romulus.eu/web/wapiti/home" target="_blank">Wapiti</a> (Windows, Linux, Mac OS X)</h3>
<p><a href="http://www.ict-romulus.eu/web/wapiti/home" target="_blank"><img alt="Wapiti" height="208" src="http://www.webresourcesdepot.com/wp-content/uploads/wapiti.jpg" width="481" /></a></p>
<p><strong>Wapiti</strong> is an <strong>open source and web-based tool</strong> that scans the web pages of the deployed web applications, looking for scripts and forms where it can inject data.</p>
<p>It is built with <strong>Python</strong> and can detect:</p>
<ul>
<li>File handling errors (Local and remote include/require, fopen, readfile&#8230;)</li>
<li>Database, XSS, LDAP and CRLF injections (HTTP response splitting, session fixation&#8230;)</li>
<li>Command execution detection (eval(), system(), passtru()&#8230;)</li>
</ul>
<h3><a href="http://nstalker.com/products/free" target="_blank">N-Stalker Free Version</a> (Windows)</h3>
<p><a href="http://nstalker.com/products/free" target="_blank"><img alt="N-Stalker Free Version" height="208" src="http://www.webresourcesdepot.com/wp-content/uploads/n-stalker.jpg" width="481" /></a></p>
<p>The free edition performs restricted-yet-still-powerful set of web security assessment checks compared to the paid versions of the application.</p>
<p>It can check up to 100 web pages at once including web server and cross-site scripting checks.</p>
<h3><a href="http://code.google.com/p/skipfish/" target="_blank">skipfish</a> (Windows, Linux, Mac OS X)</h3>
<p><a href="http://code.google.com/p/skipfish/" target="_blank"><img alt="Skipfish" height="208" src="http://www.webresourcesdepot.com/wp-content/uploads/skipfish.gif" width="481" /></a></p>
<p><strong>skipfish</strong> is a fully automated and active web application security reconnaissance tool.</p>
<p>It is lightweight and pretty fast (can perform 2000 requests/second).</p>
<p>The application has automatic learning capabilities, on-the-fly wordlist creation and form autocompletion.</p>
<p><strong>skipfish</strong> comes with low false positive, differential security checks which are capable of spotting a range of subtle flaws, including blind injection vectors.</p>
<h3><a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx" target="_blank">Scrawlr</a> (Windows)</h3>
<p><a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx" target="_blank"><img alt="Scrawlr" height="208" src="http://www.webresourcesdepot.com/wp-content/uploads/scrawlr.jpg" width="481" /></a></p>
<p><strong>Scrawlr</strong> is a <strong>free software for scanning SQL injection vulnerabilities</strong> on your web applications.</p>
<p>It is developed by HP Web Security Research Group in coordination with Microsoft Security Response Center.</p>
<h3><a href="http://websecuritytool.codeplex.com/" target="_blank">Watcher</a> (Windows)</h3>
<p><a href="http://websecuritytool.codeplex.com/" target="_blank"><img alt="Watcher" height="208" src="http://www.webresourcesdepot.com/wp-content/uploads/watcher.gif" width="481" /></a></p>
<p>It is a <strong>plugin for <a href="http://www.fiddlertool.com/" target="_blank">Fiddler</a></strong> (the awesome HTTP debugging proxy) and works as a passive-analysis tool for HTTP-based web applications.</p>
<p><strong>Watcher</strong> runs silently in the background and interact with the web-application to apply 30+ tests (where new ones can be added) while you browse.</p>
<p>It will identify issues like cross-domain form POSTs, dangerous context-switching between HTTP and HTTPS, etc.</p>
<h3><a href="http://xss.codeplex.com/" target="_blank">x5s</a> (Windows)</h3>
<p><a href="http://xss.codeplex.com/" target="_blank"><img alt="x5s" height="208" src="http://www.webresourcesdepot.com/wp-content/uploads/x5s.gif" width="481" /></a></p>
<p><strong>x5s</strong> is again a plugin for Fiddler just like Watcher which is designed to find encoding and character transformation issues that can lead to XSS vulnerability.</p>
<p>It simply tests user-controlled input using special characters like &lt;, &gt;, &#39;, and reviews how the output encodes the special characters.</p>
<h3><a href="http://labs.securitycompass.com/index.php/exploit-me/" target="_blank">Exploit-Me</a> (Windows, Linux, Mac OS X)</h3>
<p><a href="http://labs.securitycompass.com/index.php/exploit-me/" target="_blank"><img alt="Exploit-Me" height="208" src="http://www.webresourcesdepot.com/wp-content/uploads/exploit-me.jpg" width="481" /></a></p>
<p>Rather than using a proxy like most of the security testing tools, <strong>Exploit-Me directly integrates into Firefox</strong>.</p>
<p>It is a set of 3 add-ons:</p>
<ul>
<li><a href="https://addons.mozilla.org/en-US/firefox/addon/7598" target="_blank"><strong>XSS-Me</strong></a>: for testing reflected XSS vulnerabilities</li>
<li><strong><a href="https://addons.mozilla.org/en-US/firefox/addon/7597" target="_blank">SQL Inject Me</a></strong>: for testing SQL injection vulnerabilities</li>
<li><a href="https://addons.mozilla.org/en-US/firefox/addon/7595" target="_blank"><strong>Access-Me</strong></a>: for testing access vulnerabilities</li>
</ul>
<p>They are all lightweight , work while you browse websites and simply inform you by adding extra styles to the objects with vulnerabilities</p>
<h3><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" target="_blank">WebScarab</a> (Windows, Linux, Mac OS X)</h3>
<p><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" target="_blank"><img alt="WebScarab" height="208" src="http://www.webresourcesdepot.com/wp-content/uploads/webscarab.jpg" width="481" /></a></p>
<p><strong>WebScarab</strong> is actually a proxy to sniff the HTTP(s) traffic and manipulate it.</p>
<p>However, it comes with features like &quot;parameter fuzzer (for testing XSS and SQL injection vulnerabilities), or &quot;CRLF injection (HTTP response splitting)&quot; and more.</p>
<h3><a href="http://www.acunetix.com/cross-site-scripting/scanner.htm" target="_blank">Acunetix Free Version</a> (Windows)</h3>
<p><a href="http://www.acunetix.com/cross-site-scripting/scanner.htm" target="_blank"><img alt="Acunetix" height="208" src="http://www.webresourcesdepot.com/wp-content/uploads/acunetix.jpg" width="481" /></a></p>
<p>This is the free and limited-featured version of a paid/pro product.</p>
<p>It performs a check on any website and identifies cross site scripting (XSS) vulnerabilities.</p>
<p>&nbsp;</p>
<p>And, if you are looking to improve yourself in the area of web application security and need to play with an application legally, there is <strong><a href="http://www.dvwa.co.uk/" target="_blank">DVWA</a> (damn vulnerable web app.)</strong> which is there for just this purpose.</p>
<p><strong>Special Downloads:</strong><br />
<a href="http://www.webresourcesdepot.com/?download=jBasket" target="_blank">Ajaxed Add-To-Basket Scenarios With jQuery And PHP</a><br />
<a href="http://www.webresourcesdepot.com/?download=Free-Admin-Template" target="_blank">Free Admin Template For Web Applications</a><br />
<a href="http://www.webresourcesdepot.com/?download=jQuery-Dynamic-Drag-Drop" target="_blank">jQuery Dynamic Drag&#8217;n Drop</a><br />
<a href="http://www.webresourcesdepot.com/?download=sTwitter-1-0" target="_blank">ScheduledTweets</a></p>
<p><strong>Advertisements:</strong><br />
<a href="http://www.admintemplates.com" target="_blank">Professional XHTML Admin Template ($15 Discount With The Code: WRD.)</a><br />
<a href="http://www.xhtmchop.com" target="_blank">Psd to Xhtml</a><br />
<a href="http://www.sslmatic.com" target="_blank">SSLmatic &#8211; Cheap SSL Certificates (from $19.99/year)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webresourcesdepot.com/10-free-web-application-security-testing-tools/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>HTML Filtering To Secure Websites With HTML Purifier</title>
		<link>http://www.webresourcesdepot.com/html-filtering-to-secure-websites-with-html-purifier/</link>
		<comments>http://www.webresourcesdepot.com/html-filtering-to-secure-websites-with-html-purifier/#comments</comments>
		<pubDate>Thu, 28 Feb 2008 05:01:23 +0000</pubDate>
		<dc:creator>Umut M.</dc:creator>
				<category><![CDATA[Extras]]></category>
		<category><![CDATA[LGPL License]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[Html]]></category>
		<category><![CDATA[Input]]></category>
		<category><![CDATA[Php]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.webresourcesdepot.com/html-filtering-to-secure-websites-with-html-purifier/</guid>
		<description><![CDATA[<p><a href='http://rss.buysellads.com/click.php?z=1259982&k=ed230295611f656daf3115e6d682ca7d&a=161&c=9568' target='_blank'><img src='http://rss.buysellads.com/img.php?z=1259982&k=ed230295611f656daf3115e6d682ca7d&a=161&c=9568' border='0' alt='' /></a></p><p><a href='http://buysellads.com/buy/sitedetails/pubkey/ed230295611f656daf3115e6d682ca7d/zone/1259982' target='_blank'>Advertise here with BSA</a></p><br />Secure input and data handling is hard when it comes to HTML because of many different types of malicious code (XSS). HTML Purifier is a well documented, standards-compliant HTML filter library written in PHP. It simply: Removes all malicious code (better known as XSS) with an audited, secure yet permissive whitelist. Makes sure your documents [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://rss.buysellads.com/click.php?z=1259982&k=ed230295611f656daf3115e6d682ca7d&a=161&c=2394' target='_blank'><img src='http://rss.buysellads.com/img.php?z=1259982&k=ed230295611f656daf3115e6d682ca7d&a=161&c=2394' border='0' alt='' /></a></p><p><a href='http://buysellads.com/buy/sitedetails/pubkey/ed230295611f656daf3115e6d682ca7d/zone/1259982' target='_blank'>Advertise here with BSA</a></p><br /><p><strong>Secure input and data handling</strong> is hard when it comes to HTML because of many different types of malicious code (XSS).</p>
<p><a href="http://htmlpurifier.org/" target="_blank"><strong>HTML Purifier</strong></a> is a <a href="http://htmlpurifier.org/docs.html" target="_blank">well documented</a>, <strong>standards-compliant HTML filter library</strong> written in PHP. It simply:</p>
<ul>
<li>Removes all malicious code (better known as XSS) with an audited, secure yet permissive whitelist.</li>
<li>Makes sure your documents are standards compliant.&nbsp;</li>
</ul>
<p><a href="http://htmlpurifier.org/" target="_blank"><img width="480" height="150" src="http://www.webresourcesdepot.com/wp-content/uploads/image/php-html-filter-library.gif" alt="PHP HTML Filter Library" /></a></p>
<p><strong>HTML Purifier</strong> requires PHP 5&nbsp; (PHP 4 versions are not supported any more but can be downloaded). It saves so much time while developing &amp; offers much more expertise than most of the self-coded data-handling libraries as <strong>HTML Purifier</strong> is concentrated only in this area.</p>
<p>This <strong>open source secure data handling solution</strong> also has a <a href="http://htmlpurifier.org/comparison.html" target="_blank">comparison chart</a> wih other HTML filters.</p>
<p>Some community-written plugins for CMS softwares, WYSIWYG editors can be found in the <strong>HTML Purifier</strong> website.</p>
<p><strong>Special Downloads:</strong><br />
<a href="http://www.webresourcesdepot.com/?download=jBasket" target="_blank">Ajaxed Add-To-Basket Scenarios With jQuery And PHP</a><br />
<a href="http://www.webresourcesdepot.com/?download=Free-Admin-Template" target="_blank">Free Admin Template For Web Applications</a><br />
<a href="http://www.webresourcesdepot.com/?download=jQuery-Dynamic-Drag-Drop" target="_blank">jQuery Dynamic Drag&#8217;n Drop</a><br />
<a href="http://www.webresourcesdepot.com/?download=sTwitter-1-0" target="_blank">ScheduledTweets</a></p>
<p><strong>Advertisements:</strong><br />
<a href="http://www.admintemplates.com" target="_blank">Professional XHTML Admin Template ($15 Discount With The Code: WRD.)</a><br />
<a href="http://www.xhtmchop.com" target="_blank">Psd to Xhtml</a><br />
<a href="http://www.sslmatic.com" target="_blank">SSLmatic &#8211; Cheap SSL Certificates (from $19.99/year)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webresourcesdepot.com/html-filtering-to-secure-websites-with-html-purifier/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using wincache
Page Caching using wincache (User agent is rejected)
Database Caching 2/12 queries in -3.697 seconds using wincache

Served from: www.webresourcesdepot.com @ 2012-02-12 09:17:18 -->
