1. 介紹
2. web安全檢測工具paros
2.1. 步驟
- 設置IE代理為localhost:8080
- 在IE里訪問鏈接
- 掃描Analyse->scan
- Report->Last scan report 生成Report
2.2. 參考
- http://www.51testing.com/html/37/n-111337.html
- http://www.webcastellum.org
- http://searchsoftwarequality.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid92_gci1218180,00.html
- http://weblogs.java.net/blog/caroljmcdonald/archive/2009/09/29/top-10-web-application-security-vulnerabilities-starting-xss
3. Google發布的Web應用安全檢測工具skipfish
http://code.google.com/p/skipfish
Google的自動Web安全掃描程序Skipfish下載及使用方法
http://sourceforge.net/projects/watobo/