How To Do Web Penetration Testing?

What are open source tools for web security auditing?

  • List of open source tools for web security penetration testing/auditing.

  • Answer:

    Go to sourceforge. You can go for HConSTFP It is a browser but can do a lot more than just browsing. LOL.

Akshay Nair at Quora Visit the source

Was this solution helpful to you?

Other answers

the best would be either backtrack or kali both are flavours of linux and they are free. just Google it and you will get the link these OS have multiple tools in them

Krishna Chaitanya Kadaba

Web security auditing will require a lot of tools your arsenal. So, the following are a must if we talk about web security realm:Operating System:Kali Linux 2.0 (latest version)Browser add-ons: https://docs.google.com/a/tothenew.com/document/d/1-T0RmofQh5f_QmgwKD50VqUtWYcLHXbC08OrMwi0XEs/edit?usp=sharing Tools:Burp suite (preferably professional version) is the all-in-one tools that consists of a proxy, scannner, fuzzer, decoder, sequencer. To further enhance it's functionality one can add extension as well which comes handy in taking POCs.Knockpy (for sub-domain enumeration)wfuzz (for fuzzing on parameters)Nmap (port scanning)Owasp ZAP (open-source web application security scanner.)Nikto (vulnerability scanner)sqlmap (for sql injection)wpscan (if auditing a WordPress application)You can follow our blog for tutorials and demonstration on how to use these tools at http://www.tothenew.com/blog/category/technology/appsec/

Ankit Shankar Giri

Find solution

For every problem there is a solution! Proved by Solucija.

  • Got an issue and looking for advice?

  • Ask Solucija to search every corner of the Web for help.

  • Get workable solutions and helpful tips in a moment.

Just ask Solucija about an issue you face and immediately get a list of ready solutions, answers and tips from other Internet users. We always provide the most suitable and complete answer to your question at the top, along with a few good alternatives below.