??????????????????????Web???????????Powerfuzzer??N-Stalker??w3af.???????????????????????????xss??sqli????????????????????????????
????Powerfuzzer
????????????http://www.powerfuzzer.com
????Powerfuzzer??????????????????????????á?
????????Powerfuzzer v1???e????棬??????????

????Target URL??????????????????
????Exclude URL/s or dir????????岻???????????????????????????????
????Credentials?????Щ?????????????????????????????????????????????д????????
????Proxy???????????????????????????
????Timeout:?????????????????????
????Verbosity????????????????????????
?????ù??????????????????????
??????????
????CRLF???
??????豨????????????????????????? ???? ???????
?????ù???????
??????ò?????????????????????????κξ??顣
?????ù???????
????2009???????и??1??????治????????
????N-Stalker
????????????http://www.nstalker.com/
??????????????????
??????????????????к??????????????????????????????????????????е??Щ?????

?????????????
??????? Policy Editor(???????)???????????Щ????????Policy Editor???????????ν?????????????????????????????Щ??????????
??????????????
????????????е????????????????????????????????????Σ?????????????????????????????????????.
????????????
??????迪??????????????£?????????????????:

???????Choose url&Policy???????????????????
????Enter Web Application URL:??д????????URL???
????Choose Scan Policy:??????????????XSS??????OWASP????????
????Load Scan Session:???????????????
????Load Spider Date:?????????????????ù?????????????
??????:???????
?????????????????????????Щ?????????????????????????????????????????????Web??ó???????????????404??500?????
???????????????????
?????????????????????”next”?????????????????????????????IP??????????
??????????????????”close session“????????????????????????????????????????”Report manager’????????????????????????PDF????????????
????w3af
????????????http://sourceforge.net/projects/w3af/

????

?????????????”Profiles(????)“??????????????????????????????????????.
???????????????????????????????????????????
????????????У?????????Web??ó????URL?????????????????????
??????迪??????????”log(???)“??????????????????
???????????????????????????????????????????????????