Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: no standards for webapp exploitation

Re: no standards for webapp exploitation

From: Ingo Struck <ingo_at_ingostruck.de>
Date: 2 Jul 2003 16:37:52 -0000
('binary' encoding is not supported, stored as-is) In-Reply-To: <Pine.LNX.4.44.0307020019361.2234-100000_at_felinemenace>

Hi...

># VulnXML and the whisker.dat (and all of libwhisker
># (whisker RIP)) are for testing purposes ONLY. they
># do not scale to enterprise level where API's should
># be easy to work with and provide a high level
># interface to lower level scripting languages (like
># python, perl). variables should be extinct outside
># of module classes. the opensource web security
community
># would benefit from a standardized way to exploit
># web applications, wether they are remote code execution,
># remote command execution, server and client injection,
># remote file reading (all of which are going to be
covered
># in an independant project which seeks to build webapp
># exploit primitives provider on top of the websec class).
># feel free to send comments and code to me
(nd_at_felinemenace.org

Well, in fact the intention of VulnXML is to be a
description of application level vulnerabilities,
that is both suited for human reading and for direct
execution of the attacks described within a record.
The only problem is, that there currently is no
working execution engine for the latest VulnXML
description (VulnXML DTD 1.4).
There is some script code around to execute older
VulnXML records.
It is planned to write at least a java-based executor
for VulnXML recs next.

Watch out for the VulnXML db announcement that follows
soon.

Kind regards

Ingo Struck (OWASP)
Received on Jul 02 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos