Paros. Tool for finding vulnerabilities


Paros – HTTP / HTTPS proxy server intended to find vulnerabilities in Web applications. With the help of Paros you can observe the whole process of interaction between client software and web applications that make your job easier to find vulnerabilities.

Main features of Paros:

  • View and edit HTTP requests;
  • Apply filters to HTTP requests;
  • Work through a chain of proxy (proxy-chaining);
  • Mapping the site;
  • Scan the web server for configuration errors;
  • Scan sites for XSS vulnerabilities;
  • Scan sites for SQL Injection vulnerabilities;
  • Creating HTML report about the found vulnerabilities.

Work with the program extremely easy. To do this you must install on your PC java-machine version 1.4 and above, run Paros, as well as prescribe in the browser address of the proxy server localhost: 8080 (incidentally, the port can be changed in program settings). Then you can easily monitor all HTTP requests in the process vaschey with web application.

Unfortunately, at this moment the program does not develop (the authors, seems to have engaged in the development of similar functionality Pay tool Milescan Web Security Auditor), but this did not detract from its merits.

Download Paros and its documentation can be on the official website of the program Parosproxy.org

See Also

    Advertising

    Archives