[TOOL] Taof - The Art of Fuzzing



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Taof - The Art of Fuzzing
------------------------------------------------------------------------


SUMMARY



DETAILS

Taof is a GUI cross-platform Python generic network protocol fuzzer. It
has been designed for minimizing set-up time during fuzzing sessions and
it is especially useful for fast testing of proprietary or undocumented
protocols.

Taof aids the researcher during the data retrieval process by providing a
transparent proxy functionality that forwards and logs requests from a
client to a server. After the data retrieval phase, Taof presents the
logged requests and allows the user to specify the fuzzing points within
the requests.

This is the first public release, and as it is in beta state, every
comment/suggestion/request is more than welcome. Contact regarding the
project can be made by posting to the web forums or directly mailing the
project's administrator.

Source code, windows binaries and guide are now available for download.
Screenshots are also provided.


ADDITIONAL INFORMATION

The information has been provided by <mailto:taof@xxxxxxxxxx> Taof.
The original article can be found at:
<http://sourceforge.net/project/showfiles.php?group_id=176014>
http://sourceforge.net/project/showfiles.php?group_id=176014



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [TOOL] mod_dosevasive, Apache Evasive Maneuvers Module
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... * Making any requests while temporarily blacklisted ... This method has worked well in both single-server script attacks as well ...
    (Securiteam)
  • [UNIX] Multiple Vendor X Font Server Multiple Vulnerabilities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... System font server is used to render fonts for the X server. ... Remote exploitation of a multiple vulnerabilities in X.Org Foundation's X ... QueryXBitmaps and QueryXExtents protocol requests. ...
    (Securiteam)
  • [TOOL] Apache mod_evasive - Evasive Maneuvers for Apache
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Apache mod_evasive - Evasive Maneuvers for Apache ... Making any requests while temporarily blacklisted ... This method has worked well in both single-server script attacks as well ...
    (Securiteam)
  • [NT] RaidenHTTPD Directory Traversal
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Due to improper testing by RaidenHTTPD of user provided filename, ... "/../" into HTTP requests, but the program doesn't well manage the initial ... The web server will return the requested file if available in the disk ...
    (Securiteam)
  • [NEWS] Java JNI/DNS Queries DoS
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... unhandled exception on a Java application if the application is tricked ... Java uses an 'InitialDirContext' to perform DNS lookups. ... the next 32768 requests. ...
    (Securiteam)