Main > Development > WEB >

Ratproxy 1.58

Ratproxy 1.58

Sponsored Links

Ratproxy 1.58 Ranking & Summary

RankingClick at the star to rank
Ranking Level
User Review: 0 (0 times)
File size: 164 KB
Platform: Mac OS X
License: Freeware
Price: FREE
Downloads: 21
Date added: 2009-06-07
Publisher: Michal Zalewski

Ratproxy 1.58 description

Open Source web app security audit program

Ratproxy is a semi-automated, largely passive web application security audit tool. It is meant to complement active crawlers and manual proxies more commonly used for this task.
Ratproxy is optimized specifically for an accurate and sensitive detection, and automatic annotation, of potential problems and security-relevant design patterns based on the observation of existing, user-initiated traffic in complex web 2.0 environments.
Detects and prioritizes broad classes of security problems, such as dynamic cross-site trust model considerations, script inclusion issues, content serving problems, insufficient XSRF and XSS defenses, and much more.
Ratproxy is currently believed to support Mac OS X, FreeBSD, Linux, and Windows (Cygwin) environments.
The approach taken with ratproxy offers several important advantages over more traditional methods:
- No risk of disruptions. In the default operating mode, tool does not generate a high volume of attack-simulating traffic, and as such may be safely employed against production systems at will, for all types of ad hoc, post-release audits. Active scanners may trigger DoS conditions or persistent XSSes, and hence are poorly suited for live platforms.
- Low effort, high yield. Compared to active scanners or fully manual proxy-based testing, ratproxy assessments take very little time or bandwidth to run, and proceed in an intuitive, distraction-free manner - yet provide a good insight into the inner workings of a product, and the potential security vulnerabilities therein. They also afford a consistent and predictable coverage of user-accessible features.
- Preserved control flow of human interaction. By silently following the browser, the coverage in locations protected by nonces, during other operations valid only under certain circumstances, or during dynamic events such as cross-domain Referer data disclosure, is greatly enhanced. Brute-force crawlers and fuzzers usually have no way to explore these areas in a reliable manner.
- WYSIWYG data on script behavior. Javascript interfaces and event handlers are explored precisely to a degree they are used in the browser, with no need for complex guesswork or simulations. Active scanners often have a significant difficulty exploring JSON responses, XMLHttpRequest() behavior, UI-triggered event data flow, and the like.
- Easy process integration. The proxy can be transparently integrated into an existing manual security testing or interface QA processes without introducing a significant setup or operator training overhead.
NOTE: Ratproxy is licensed and provided under the terms of the Apache License 2.0.

Ratproxy 1.58 Screenshot

Advertisements

Ratproxy 1.58 Keywords

Bookmark Ratproxy 1.58

Hyperlink code:
Link for forum:

Ratproxy 1.58 Copyright

WareSeeker periodically updates pricing and software information of Ratproxy 1.58 full version from the publisher, so some information may be slightly out-of-date. You should confirm all information before relying on it. Software piracy is theft, Using crack, password, serial numbers, registration codes, key generators is illegal and prevent future development of Ratproxy 1.58 Edition. Download links are directly from our publisher sites, torrent files or links from rapidshare.com, yousendit.com or megaupload.com are not allowed

Allok Video Splitter 2.2.0 Review:

Name (Required)
Email(Required)
Captcha
Featured Software

Want to place your software product here?
Please contact us for consideration.

Contact WareSeeker.com
Related Software
Used to give client machines within a protected network access to streaming servers outside that Free Download
Free and open source HTTP proxy for your Mac Free Download
deliVRator - optimize/edit QuickTime VR movies for the web Free Download
Web proxy with advanced filtering capabilities. Free Download
EyeTV EPG Proxy is designed to meet all the needs for EPG data for users in certain countries, and its free. Free Download
Open Source framework for agile development of secure web based database driven web applications, programmable in Python. Free Download
TuneUp Companion is a tool to fix your music collection is a mess automagically. Free Download
MacNikto - an AppleScript GUI shell script wrapper built in Apples Xcode and Interface Builder Free Download