lo0.ro cat /dev/null > stupidity – nobody is safe

13Feb/120

DotDotPwn v3.0 The Directory Traversal Fuzzer

Version: DotDotPwn v3.0
Release date: 03/Feb/2012 (Release at BugCon Security Conferences 2012)

Changes / Enhancements / Features:

  1. -X switch that implements the Bisection Algorithm in order to detect the exact deepness once a directory traversal vulnerability has been found. - http://en.wikipedia.org/wiki/Bisection_method
  2. -M switch to specify another method different from the default (GET) when the http module is used.
  3. Other HTTP methods are [POST | HEAD | COPY | MOVE]
  4. -e switch to specify the file extension to be appended at the end of each fuzz string (e.g. ".php", ".jpg", ".inc")
  5. New dots & slashes encodings (fuzz patterns) based on: https://www.owasp.org/index.php/Canonicalization,_locale_and_Unicode and http://wikisecure.net/security/uri-encoding-to-bypass-idsips

Supported modules:
- HTTP
- HTTP URL
- FTP
- TFTP
- Payload (Protocol independent)
- STDOUT

Feel free to download this new release from the following sites:

Download location #1
Download location #2

Contact us: dotdotpwn@sectester.net

Source

  • Google Reader
  • Facebook
  • Identi.ca
  • Twitter
  • Reddit
  • Delicious
  • E-Mail
  • StumbleUpon
  • Digg
  • Tumblr
Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

No trackbacks yet.