+
+

Related Products

  • cside
    37 Ratings
    Visit Website
  • Teradata VantageCloud
    1,120 Ratings
    Visit Website
  • BrandMap® 10
    Visit Website
  • Parasoft
    148 Ratings
    Visit Website
  • Bitdefender Ultimate Small Business Security
    3 Ratings
    Visit Website
  • NovusMED
    1 Rating
    Visit Website
  • ContractSafe
    316 Ratings
    Visit Website
  • Intelex
    166 Ratings
    Visit Website
  • Aikido Security
    232 Ratings
    Visit Website
  • Retreat Guru
    133 Ratings
    Visit Website

About

Fuzz testing or fuzzing is a software testing technique, that basically consists in finding implementation bugs using malformed/semi-malformed data injection in an automated fashion. Let’s consider an integer in a program, which stores the result of a user’s choice between 3 questions. When the user picks one, the choice will be 0, 1, or 2, which makes three practical cases. Integers are stored as a static size variable. If the default switch case hasn’t been implemented securely, the program may crash and lead to “classical” security issues. Fuzzing is the art of automatic bug finding, and its role is to find software implementation faults and identify them if possible. A fuzzer is a program that automatically injects semi-random data into a program/stack and detects bugs. The data-generation part is made of generators, and vulnerability identification relies on debugging tools. Generators usually use combinations of static fuzzing vectors.

About

Wapiti is a web application vulnerability scanner. Wapiti allows you to audit the security of your websites or web applications. It performs "black-box" scans (it does not study the source code) of the web application by crawling the webpages of the deployed web app, looking for scripts and forms where it can inject data. Once it gets the list of URLs, forms, and their inputs, Wapiti acts like a fuzzer, injecting payloads to see if a script is vulnerable. Search for potentially dangerous files on the server. Wapiti supports both GET and POST HTTP methods for attacks. It also supports multipart forms and can inject payloads in filenames (upload). Warnings are raised when an anomaly is found (for example 500 errors and timeouts). Wapiti is able to make the difference between permanent and reflected XSS vulnerabilities. Generates vulnerability reports in various formats (HTML, XML, JSON, TXT, CSV).

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Professional users looking for a solution to find bugs automatically

Audience

Developers seeking a solution to improve the security of their web applications

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

No information available.
Free Version
Free Trial

Pricing

Free
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

OWASP
United States
owasp.org/www-community/Fuzzing

Company Information

Wapiti
wapiti-scanner.github.io

Alternatives

ClusterFuzz

ClusterFuzz

Google

Alternatives

API Fuzzer

API Fuzzer

Fuzzapi
LibFuzzer

LibFuzzer

LLVM Project
go-fuzz

go-fuzz

dvyukov

Categories

Categories

Integrations

CI Fuzz
Drupal
Google Chrome
Google Sheets
HTML
JSON
Microsoft Excel
Mozilla Firefox
SQL
WordPress
XML

Integrations

CI Fuzz
Drupal
Google Chrome
Google Sheets
HTML
JSON
Microsoft Excel
Mozilla Firefox
SQL
WordPress
XML
Claim OWASP WSFuzzer and update features and information
Claim OWASP WSFuzzer and update features and information
Claim Wapiti and update features and information
Claim Wapiti and update features and information