
There are various tools available to perform security testing of an application. There are few tools that can perform end-to-end security testing while some are dedicated to spot a particular type of flaw in the system.
Some open source security testing tools are as given −
| S.No. | Tool Name |
|---|---|
| 1 | Zed Attack Proxy Provides Automated Scanners and other tools for spotting security flaws. |
| 2 | OWASP WebScarab Developed in Java for Analysing Http and Https requests. |
| 3 | OWASP Mantra Supports multi-lingual security testing framework https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework |
| 4 | Burp Proxy Tool for Intercepting & Modyfying traffic and works with work with custom SSL certificates. |
| 5 | Firefox Tamper Data Use tamperdata to view and modify HTTP/HTTPS headers and post parameters |
| 6 | Firefox Web Developer Tools The Web Developer extension adds various web developer tools to the browser. |
| 7 | Cookie Editor Lets user to add, delete, edit, search, protect and block cookies |
The following tools can help us spot a particular type of vulnerability in the system −
| S.No. | Link |
|---|---|
| 1 | DOMinator Pro − Testing for DOM XSS |
| 2 | OWASP SQLiX − SQL Injection |
| 3 | Sqlninja − SQL Injection |
| 4 | SQLInjector − SQL Injection |
| 5 | sqlpowerinjector − SQL Injection |
| 6 | SSL Digger − Testing SSL |
| 7 | THC-Hydra − Brute Force Password |
| 8 | Brutus − Brute Force Password |
| 9 | Ncat − Brute Force Password |
| 10 | OllyDbg − Testing Buffer Overflow |
| 11 | Spike − Testing Buffer Overflow |
| 12 | Metasploit − Testing Buffer Overflow |
Here are some of the commercial black box testing tools that help us spot security issues in the applications that we develop.
| S.No | Tool |
|---|---|
| 1 | NGSSQuirreL |
| 2 | IBM AppScan |
| 3 | Acunetix Web Vulnerability Scanner |
| 4 | NTOSpider |
| 5 | SOAP UI |
| 6 | Netsparker |
| 7 | HP WebInspect |
| S.No | Tool |
|---|---|
| 1 | OWASP Orizon |
| 2 | OWASP O2 |
| 3 | SearchDiggity |
| 4 | FXCOP |
| 5 | Splint |
| 6 | Boon |
| 7 | W3af |
| 8 | FlawFinder |
| 9 | FindBugs |
These analyzers examine, detect, and report the weaknesses in the source code, which are prone to vulnerabilities −
| S.No | Tool |
|---|---|
| 1 | Parasoft C/C++ test |
| 2 | HP Fortify |
| 3 | Appscan |
| 4 | Veracode |
| 5 | Armorize CodeSecure |
| 6 | GrammaTech |