Vulnerability Assessment Security Vulnerabilities Vulnerability Management
Security Vulnerabilities
Beyond Security Logo
Security Vulnerabilities
Security Vulnerabilities
Security Vulnerabilities 0 Day Black Box Testing
Security Vulnerabilities

Simple Web Server (SWS) Test Case

Simple Web Server version 3.0.3
MD5: e388d763b304e92b56717e1e66ba3f6a
SHA1: 229e7b865fb678ab2ead301e09ab528c306b0efe
Beyond Security's Simple Web Server (SWS) is a web server application created for internal testing of the beSTORM fuzzer, while working on the HTTP 1.0 and HTTP 1.1 protocol modules. The server was built with a large set of common security holes which allows testing of fuzzing tools functionality and scenario coverage.

Currently, use of this application has evolved and it is also used for training new engineers in basic exploitation and customer training of QA Security engineers and Black Box Testers.

Technical details
The web server does not support the entire HTTP protocol suite, however it will work as a standard web server with any browser.


Vulnerabilities found in the application:

  1. Off-By-One in Content-Length (Integer overflow/malloc issue)
  2. Overflow in User-Agent
  3. Overflow in Method
  4. Overflow in URI
  5. Overflow in Host
  6. Overflow in Version
  7. Overflow in complete packet
  8. Off By One in Receive function (linefeed/carriage return issue)
  9. Overflow in Authorization Type
  10. Overflow in Base64 decoded
  11. Overflow in Username of authorization
  12. Overflow in Password of authorization
  13. Overflow in Body
  14. Cross site scripting

Disclaimer and legal notice
This web server MUST NEVER BE USED ON THE INTERNET, it is very vulnerable and can be trivially exploited. Beyond Security takes no responsibility for this software, nor any use or misuse made of or with it. It is provided AS-IS with no warranty or liability.

Download
To download SWS, click here.

More beSTORM Test Cases
For more information about the beSTORM fuzzer and a demo download, click here. To download the ANI 0day fuzzing module, click here.

Security Vulnerabilities
beSTORMbeSTORM
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Secure programming from the start
beSTORM Fuzzer
Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Next generation security testing
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Audit more applications with greater efficiency
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities
Automated Vulnerability Detection System Automated
Vulnerability
Detection
System
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Daily automated security assessment
AVDS Scanning System
Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Solutions to vulnerabilities found
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Manage vulnerabilities across the enterprise
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities
Web Security Audit
Web Site Security Audit
Web Security scan
Website Security scan web Security scanning Web Security Audit
Web Security Vulnerabilities
Scan your web site Scan your web site for security holes
Web Security Test
Security Vulnerabilities Website Security Vulnerabilities
Web Security risks
web security scan Fastest Scan Turnaround
website security testing
Security Vulnerabilities web security penetration testing
web security scan
Scan web site for vulnerabilites Get Help From Security Specialists
website scanning for vulnerabilities
Security Vulnerabilities Web server scanning
SecuriTeam Leading Security Portal
www.SecuriTeam.com
Best Security Portal
Security Vulnerabilities
About SQL Injection | Web Security And Web Scanning
Privacy Policy, Terms of Use
© Copyright 1998-2009 Beyond Security. All rights reserved.
Security Vulnerabilities

 
Security Vulnerabilities Among our Clients Security Vulnerabilities
Security Vulnerabilities
Customer Satisfaction

Security Vulnerabilities
Security Vulnerabilities

Contact Us

 

US: 1.800.801.2821

UK: +44.203.006.3022

Security Vulnerabilities
Red Hearing 100 Finalist Winner


Security Vulnerabilities News Headline Security Vulnerabilities
Security Vulnerabilities
Scan your web site ion-ip to offer Beyond Security's VA solutions in the Netherlands
Security Vulnerabilities
Scan your web site beSTORM the first security testing tool to introduce RMI fuzzing
Security Vulnerabilities
Scan your web site Beyond Security Finalist for the Red Herring 100 Global Awards 2007
Security Vulnerabilities
Scan your web site Beyond Security CTO's keynote in Malware 2007
Security Vulnerabilities
Security Vulnerabilities
Security Vulnerabilities
Security Vulnerabilities
Security Vulnerabilities Security News Security Vulnerabilities
Security Vulnerabilities
Scan your web site Cisco Unified Communications Manager IP Phone Personal Address Book Vulnerability.
Security Vulnerabilities
Scan your web site Garmin Communicator Plug-In Domain Locking Security Bypass.
Security Vulnerabilities
Scan your web site Ghostscript jbig2dec JBIG2 Processing Buffer Overflow.
Security Vulnerabilities
Scan your web site IBM BladeCenter Advanced Management Module Multiple vulnerabilities.
Security Vulnerabilities
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities