“w3af” (Web Application Attack and Audit Framework) is a complete environment for auditing and attacking web applications. This environment provides a solid platform for auditing and penetration-testing. The framework will work on all platforms that support Python (Linux, WinXP, Vista, OpenBSD, etc )

For this week’s “Tutorial Tuesday” I would like to help those who may be asking a question I once found myself very curious about – “How can I learn Penetration Testing without having an entire lab setup at home?” – I can already hear some of you shouting “Virtual Machines!” – And you’re absolutely correct. But instead of simply telling you how to setup a plethora of VMs, configuring them, then going into endless tutorials on how to secure and exploit those “fake” servers yourself, why not point you to a place where you can get pre-configured VMs and the tutorials and assignments for learning how to discover the vulnerabilities? The focus point I’m speaking of is De-Ice.net. More specifically[…]