Code Monkey home page Code Monkey logo

Cystack team

We are a team of young developers who are energetic and enthusiastic about security. Our team members include:

  • Nguyen Huu Trung (leader)
  • Le Van Giap
  • Phan Xuan Tien
  • Do Quang Thanh
  • Do Minh Tuan

About WebFuzzer

What is WebFuzzer?

WebFuzzer is a SAAS (Software As A Service) Web Application Penetration product in which it has:

  • Input: Web application domain
  • Output: Overall graph report, list of vulnerabilities and their details

The spectacular superority of WebFuzzer is that it provides patching strategies after finding vulnerabilities in Web application by 2 selections:

  • Automatically generating rules for modsecurity and iptables for customers to update on their system
  • Guiding customers to use Web Application Firewall and then apply patches to revamp their Web application system

WebFuzzer advantages

  • Easy to use:
    • Friendly Web application user interface
    • No need to install any additional modules or plugins except a browser
    • No need to care about client computer specs
  • Opensource, build on the top of w3afi, with a highly extensible ability
  • Having the ability to detect more than 200 types of vulnerabilities (and this number will be increased in the future)
  • Distributed handling, be able to simultaneously handle a considerable amount of Web application
  • REST API: Allow security specialists build their Scanner base on the WebFuzzer architecture
  • Multiplatform: Currently WebFuzzer works as a Web service. CLI, Mobile, PC and other platforms will be supported in the near future base on the built APIs

System architecture

alt text

Deploy guide (for service providers, not endpoint users)

  1. Install w3af on dedicated servers and start the w3af_api process. Multiple w3af_api processes can be opened on every server based on their system specification
  2. Install RabbitMQ for Message Queuing
  3. Config Server and Dispatcher, additionally provide w3af servers list by their IP and Port
  4. Establish environment for Flask server by nginx, gunicorn
  5. Start the server

User Interface

alt text

alt text

alt text

CyStack's Projects

security-controls icon security-controls

This repository houses CyStack's security controls along with their mappings to industry standards such as SOC2, ISO 27001, and HIPAA.

webfuzzer icon webfuzzer

WebFuzzer - Web Application Security Scanner by Cystack Team

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.