PHP Vulnerability Hunter是一款高级自动化的白盒模糊测试工具,它几乎可以检测在advisories页面中列出的web应用程序漏洞,特别是php web应用程序中的可利用漏洞。只需较少的配置就可以开始扫描。PHP Vulnerability Hunter甚至不需要用户指定起始url。PHP Vulnerability Hunter的主要特点:
* Automated input vector discovery.
* Integrate fault detection
* Minimal configuration.
* Proven effective
* Added code coverage report
* Updated GUI validation
* Several instrumentation fixes
* Fixed lingering connection issue
* Fixed GUI and report viewer crashes related to working directory
工具下载:
http://code.google.com/p/php-vulnerability-hunter/downloads/list