﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>BlogJava--随笔分类-信息安全</title><link>http://www.blogjava.net/leekiang/category/47477.html</link><description>MDA/MDD/TDD/DDD/DDDDDDD</description><language>zh-cn</language><lastBuildDate>Tue, 07 Jun 2011 05:45:03 GMT</lastBuildDate><pubDate>Tue, 07 Jun 2011 05:45:03 GMT</pubDate><ttl>60</ttl><item><title>信息安全</title><link>http://www.blogjava.net/leekiang/archive/2010/12/29/341931.html</link><dc:creator>leekiang</dc:creator><author>leekiang</author><pubDate>Wed, 29 Dec 2010 13:19:00 GMT</pubDate><guid>http://www.blogjava.net/leekiang/archive/2010/12/29/341931.html</guid><wfw:comment>http://www.blogjava.net/leekiang/comments/341931.html</wfw:comment><comments>http://www.blogjava.net/leekiang/archive/2010/12/29/341931.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/leekiang/comments/commentRss/341931.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/leekiang/services/trackbacks/341931.html</trackback:ping><description><![CDATA[
		<a href="http://hi.baidu.com/hackbst/blog/item/36eb83700b24c1108601b063.html">入侵基于java Struts的JSP网站</a>
<img src ="http://www.blogjava.net/leekiang/aggbug/341931.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/leekiang/" target="_blank">leekiang</a> 2010-12-29 21:19 <a href="http://www.blogjava.net/leekiang/archive/2010/12/29/341931.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Web应用安全</title><link>http://www.blogjava.net/leekiang/archive/2010/09/21/332605.html</link><dc:creator>leekiang</dc:creator><author>leekiang</author><pubDate>Tue, 21 Sep 2010 06:48:00 GMT</pubDate><guid>http://www.blogjava.net/leekiang/archive/2010/09/21/332605.html</guid><wfw:comment>http://www.blogjava.net/leekiang/comments/332605.html</wfw:comment><comments>http://www.blogjava.net/leekiang/archive/2010/09/21/332605.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/leekiang/comments/commentRss/332605.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/leekiang/services/trackbacks/332605.html</trackback:ping><description><![CDATA[
		<h3>1. 介绍</h3>
		<p>
				<a href="http://www.80sec.com/security-about-framework.html">Web开发框架安全杂谈</a>
		</p>
		<hr />
		<h3>2. web安全检测工具paros</h3>
		<h4>2.1. 步骤</h4>
		<ol>
				<li>设置IE代理为localhost:8080</li>
				<li>在IE里访问链接</li>
				<li>扫描Analyse-&gt;scan</li>
				<li>Report-&gt;Last scan report 生成Report</li>
		</ol>
		<h4>2.2. 参考</h4>
		<ol>
				<li>
						<a href="http://www.51testing.com/html/37/n-111337.html">http://www.51testing.com/html/37/n-111337.html</a>
				</li>
				<li>
						<a href="http://www.webcastellum.org">http://www.webcastellum.org</a>
				</li>
				<li>
						<a href="http://searchsoftwarequality.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid92_gci1218180,00.html">http://searchsoftwarequality.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid92_gci1218180,00.html</a>
				</li>
				<li>
						<a href="http://weblogs.java.net/blog/caroljmcdonald/archive/2009/09/29/top-10-web-application-security-vulnerabilities-starting-xss">http://weblogs.java.net/blog/caroljmcdonald/archive/2009/09/29/top-10-web-application-security-vulnerabilities-starting-xss</a>
				</li>
		</ol>
		<hr />
		<h3>3. Google发布的Web应用安全检测工具skipfish</h3>
		<p>
				<a href="http://code.google.com/p/skipfish">http://code.google.com/p/skipfish</a>
				<br />
				<a href="http://www.linuxso.com/a/linuxxitongguanli/634.html">Google的自动Web安全扫描程序Skipfish下载及使用方法</a>
		</p>
		<p>
				<br />
		</p>4.WATOBO是一个Web应用程序工具箱，它是一个旨在帮助专业安全人员执行高效率的(半自动)Web应用程序安全审计的工具。它类似于一个本地代理，在运行中分析网络通信寻找有用的信息和漏洞。它还具备自动扫描功能。能扫描SQL注入，跨站脚本和更多安全问题。<br />http://sourceforge.net/projects/watobo/<br /><img src ="http://www.blogjava.net/leekiang/aggbug/332605.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/leekiang/" target="_blank">leekiang</a> 2010-09-21 14:48 <a href="http://www.blogjava.net/leekiang/archive/2010/09/21/332605.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>