Security Testing - Automation Tools



There are various tools that are available to perform security testing of an application. There are few tools that can perform end to end security testing while some are dedicated to spot a particular type of flaw in the system.

Open Source tools

Below are the some of the open source testing tools which can be used for security testing purposes.

S.NoTool Name
1Zed Attack Proxy
Provides Automated Scanners and other tools for spotting security flaws.
https://www.zaproxy.org/
2OWASP WebScarab
Developed in Java for Analysing Http and Https requests.
https://www.owasp.org/index.php/OWASP_WebScarab_Project
3OWASP Mantra
Supports multi-lingual security testing framework
https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework
4Burp Proxy
Tool for Intercepting & Modyfying traffic and works with work with custom SSL certificates.
http://www.portswigger.net/Burp/
5Firefox Tamper Data
Use tamperdata to view and modify HTTP/HTTPS headers and post parameters
https://addons.mozilla.org/en-US/firefox/addon/tamper-data/
6Firefox Web Developer Tools
The Web Developer extension adds various web developer tools to the browser.
https://addons.mozilla.org/en-US/firefox/addon/web-developer/
7Cookie Editor
Lets user to add, delete, edit, search, protect and block cookies
https://chrome.google.com/webstore/detail/fngmhnnpilhplaeedifhccceomclgfbg?hl=en-US

Specific Tool sets

Following are the tools that can help us to spot a particular type of vulnerabilities in the system.

S.NoLink
1DOMinator Pro - Testing for DOM XSS
https://portswigger.net/web-security/cross-site-scripting/dom-based
2OWASP SQLiX - SQL Injection
https://www.owasp.org/index.php/Category:OWASP_SQLiX_Project
3Sqlninja - SQL Injection
http://sqlninja.sourceforge.net/
4SQLInjector - SQL Injection
http://sourceforge.net/projects/safe3si/
5sqlpowerinjector - SQL Injection
http://www.sqlpowerinjector.com/
6SSL Digger - Testing SSL
http://www.mcafee.com/us/downloads/free-tools/ssldigger.aspx
7THC-Hydra - Brute Force Password
https://www.imperva.com/learn/application-security/brute-force-attack/
8Brutus - Brute Force Password
https://www.kaspersky.com/resource-center/definitions/brute-force-attack
9Ncat - Brute Force Password
http://nmap.org/ncat/
10OllyDbg - Testing Buffer Overflow
http://www.ollydbg.de/
11Spike - Testing Buffer Overflow
http://www.immunitysec.com/downloads/SPIKE2.9.tgz
12Metasploit - Testing Buffer Overflow
http://www.metasploit.com/

Commercial Black Box Testing tools

Below are some of the commercial Black box testing tools which helps us to spot security issues in the application that we develop.

Free Source Code Analyzers

Commercial Source Code Analyzers

Advertisements