| To: | full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com, "Web Application Security" <webappsec@securityfocus.com>, "WASC Forum" <websecurity@webappsec.org>, "webappsec @OWASP" <webappsec@lists.owasp.org> |
|---|---|
| Subject: | Technika - Attack Scripting Environment |
| From: | "pdp (architect)" <pdp.gnucitizen@googlemail.com> |
| Date: | Wed, 31 Jan 2007 22:46:07 +0000 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| Domainkey-signature: | a=rsa-sha1; c=nofws; d=googlemail.com; s=beta; h=received:message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; b=pD+KVD8GohoFFWU48G9dkX882g5a8uRNaNourRHviD43z9w1rkbcj2tfH6X3I5qLlNat2v+eRXYY/mAjdD+KamrdF3iKcpKTyN1IiJ0tWlC0goLpQ1x9rU+dhNf4UIzI6VAw17YhXC7MVDAleMfHHgSz1MJ3hxxyLyNnx4u8g/k= |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
http://www.gnucitizen.org/projects/technika/ Technika was developed for the computer security professionals to automate common exploitative task from the browser. It acts like a standard OS shell scripting environment. You can script everything from the currently viewed page and also spawn processes, unrestricted XMLHttpRequest connections and Sockets. Technika was successfuly used to implement several Web and System related exploits that run directly from the browser. Unfortunatley their source code cannot be shown here for obvious reasons. The extension is still in Alpha although it is mostly usable and quite stable. If you have a proposal, question, suggestion or correction, please contact us. -- pdp (architect) | petko d. petkov http://www.gnucitizen.org |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: stompy the session stomper - tool availability, Michal Zalewski |
|---|---|
| Next by Date: | Re: Defeating CAPTCHAs via Averaging, Lou Katz |
| Previous by Thread: | [SECURITY] [DSA 1256-1] New gtk+2.0 packages fix denial of service, Moritz Muehlenhoff |
| Indexes: | [Date] [Thread] [Top] [All Lists] |