W3af is an extremely popular, powerful, and flexible framework for finding and exploiting web application vulnerabilities. It is easy to use and extend and features dozens of web assessment and exploitation plugins. In some ways it is like a web-focused Metasploit.
For downloads and more information,
visit the w3af homepage.
I've really tried to love w3af - it's python, it's web pentesting, it's open-source - everything I love.
Unfortunately, once you get around the seemingly strict set of prereq's to install it, it is incredibly buggy. It seems to try to do too many things and be too fancy, but simply isn't useful.
The best free software for pentesting web applications.
Your comment
Along with your rating, you can use the comment form to post a review,
tutorial, tips and tricks, or anything else others will find useful.
If you develop this software (or work for the company), please don't rate it. You may leave a clarifying comment as long as you state your affiliation and don't specify a star rating (just leave it as “No rating”).
I've really tried to love w3af - it's python, it's web pentesting, it's open-source - everything I love.
Unfortunately, once you get around the seemingly strict set of prereq's to install it, it is incredibly buggy. It seems to try to do too many things and be too fancy, but simply isn't useful.
A real pity.
Nice tool...will be sure to try it for my web apps.
I found it buggy - probably takes expert user who knows programming to work it properly
Great. It worked. Can't really complain about that. Lots of tests and lots of results, not good for the PM....
Great Web Application PenTest tool. Fine to see it here.
Couldn't use it because I couldn't open the GUI, installed everything but no idea how to open the GUI >.< I tried lol.
one of the most powerful web penetration tools.
great
very powerful tool in the hands of the right ppl. here is their twitter if you wanna follow them for updates http://twitter.com/#!/w3af
w00t! We made it to the list! Thanks for everybody who voted for us and the community effort behind each line of code :)
[Moderator note: 5-star rating removed from this review since it is by tool author]
The best free software for pentesting web applications.