django-axes alternatives

Looking for an alternative tool to replace django-axes? During the review of django-axes we looked at other open source tools. Based on their category, tags, and text, these are the ones that have the best match.

Top 3

  1. django-defender (defender against brute force login attempts)
  2. django-security (Security add-ons for Django)
  3. 0d1n (fuzzing tool for web applications)

These tools are ranked as the best alternatives to django-axes.

Alternatives (by score)

76

django-defender (Django Defender)

Introduction

Django-defender is a reusable app for Django that blocks people from performing brute forcing login attempts.

Project details

django-defender is written in Python.

Strengths and weaknesses

  • + More than 10 contributors
  • + The source code of this software is available

    Typical usage

    • Application security

    django-defender review

    97

    django-security

    Introduction

    Django-security is an extension for developers seeking more security measures in their Django project. The toolkit can set or activate particular settings improving security. Examples of these settings include the use of particular HTTP headers that increase the security defenses of the web application.

    Part of the toolkit is middleware to enforce password strength, set the do-not-track header, enable content security policy (CSP), enable privacy policy (P3P), limit session length, use HTTPS (HSTS), XSS protection, and more.

    Project details

    django-security is written in Python.

    Strengths and weaknesses

    • + More than 10 contributors
    • + The source code of this software is available

      Typical usage

      • Application security

      django-security review

      60

      0d1n

      Introduction

      0d1n is useful to perform brute-force login attempts for authentication forms. It can discover useful directory names by using a predefined list of paths. With options to use a random proxy per request and load CSRF tokens, it is a tool that can be used in different type of assignments.

      Project details

      0d1n is written in C.

      Strengths and weaknesses

      • + The source code of this software is available

        Typical usage

        • Information gathering
        • Penetration testing
        • Security assessment
        • Vulnerability scanning

        0d1n review

        60

        Crowbar

        Introduction

        While most brute forcing tools take a similar approach, Crowbar can use different methods that are not always available in other utilities. For example, Crowbar can use SSH keys, instead of the typical username and password combination. This might be useful during penetration testing when these type of details are discovered.

        Project details

        Crowbar is written in Python.

        Strengths and weaknesses

        • + The source code of this software is available

          Typical usage

          • Penetration testing

          Crowbar review

          96

          Fail2ban

          Introduction

          Fail2Ban is an intrusion prevention software framework that protects computer servers from brute-force attacks

          Project details

          Fail2ban is written in Python.

          Strengths and weaknesses

          • + More than 2000 GitHub stars
          • + The source code of this software is available

            Typical usage

            • Network traffic filtering
            • Security monitoring

            Fail2ban review

            64

            IKEForce

            Introduction

            IKEForce is a command line utility to brute force VPN connections (IPSEC) that allow group name/ID enumeration and XAUTH.

            Project details

            IKEForce is written in Python.

            Strengths and weaknesses

            • + The source code of this software is available

              IKEForce review

              56

              John the Ripper

              Introduction

              John the Ripper is a mature password cracker to find weak or known passwords. It works on Linux and other flavors of Unix and Microsoft Windows.

              Project details

              68

              Patator

              Introduction

              Patator is based on similar tools like Hydra, yet with the goal to avoid the common flaws these tools have like performance limitations. The tool is modular and supports different types of brute-force attacks or enumeration of information.

              Project details

              Patator is written in Python.

              Strengths and weaknesses

              • + More than 500 GitHub stars
              • + The source code of this software is available

                Typical usage

                • Password discovery
                • Penetration testing
                • Reconnaissance
                • Vulnerability scanning

                Patator review

                64

                RouterSploit

                Introduction

                RouterSploit is a framework to exploit embedded devices such as cameras and routers. It can be used during penetration testing to test the security of a wide variety of devices. RouterSploit comes with several modules to scan and exploit the devices. The tool helps in all steps, like from credential testing to deploying a payload to perform an exploitation attempt.

                Project details

                RouterSploit is written in Python.

                Strengths and weaknesses

                • + More than 50 contributors
                • + More than 6000 GitHub stars
                • + The source code of this software is available

                  Typical usage

                  • Penetration testing
                  • Self-assessment
                  • Software testing
                  • Vulnerability scanning

                  RouterSploit review

                  78

                  THC Hydra (thc-hydra)

                  Introduction

                  THC Hydra is a brute-force cracking tool for remote authentication services. It supports many protocols, including telnet, FTP, LDAP, SSH, SNMP, and others.

                  Project details

                  THC Hydra is written in C.

                  Strengths and weaknesses

                  • + More than 25 contributors
                  • + More than 1000 GitHub stars
                  • + Project is mature (10+ years)
                  • + The source code of this software is available

                    Typical usage

                    • Penetration testing
                    • Security assessment

                    THC Hydra review

                    60

                    WPForce

                    Introduction

                    This toolkit is fairly new and consists of WPForce and Yertle. As the name implies, the first component has the focus on brute force attacking of login credentials. When admin credentials have been found, it is Yertle that allows uploading a shell. Yertle also has post-exploitation modules for further research.

                    Project details

                    WPForce is written in Python.

                    Strengths and weaknesses

                    • + The source code of this software is available
                    • - Full name of author is unknown

                    Typical usage

                    • Penetration testing
                    • Security assessment
                    • Vulnerability scanning

                    WPForce review

                    52

                    WPSeku

                    Introduction

                    With WPSeku a WordPress installation can be tested for the presence of security issues. Some examples are cross-site scripting (XSS), sql injection, and local file inclusion. The tool also tests for the presence of default configuration files. These files may reveal version numbers, used themes and plugins.

                    Project details

                    WPSeku is written in Python.

                    Strengths and weaknesses

                    • + The source code of this software is available
                    • - Unknown project license

                    Typical usage

                    • Penetration testing
                    • Security assessment
                    • Vulnerability scanning

                    WPSeku review

                    60

                    Wfuzz

                    Introduction

                    Wfuzz is a fuzzing tool written in Python. Tools like Wfuzz are typically used to test web applications and how they handle both expected as unexpected input.

                    Project details

                    Wfuzz is written in Python.

                    Strengths and weaknesses

                    • + More than 1000 GitHub stars
                    • + The source code of this software is available

                      Typical usage

                      • Application fuzzing
                      • Application security
                      • Application testing
                      • Web application analysis

                      Wfuzz review

                      60

                      aiodnsbrute (Async DNS Brute)

                      Introduction

                      When a project requires resolving or guessing host names, then this tool is a great addition to the toolkit. It focuses on 'fast' by using asynchronous operations. The list of names to try is provided with a wordlist.

                      Project details

                      aiodnsbrute is written in Python.

                      Strengths and weaknesses

                      • + Very low number of dependencies
                      • + The source code of this software is available

                        Typical usage

                        • Network scanning
                        • Penetration testing

                        aiodnsbrute review

                        60

                        dirsearch

                        Introduction

                        Dirsearch is a tool to guide security professionals to find possible information leaks or sensitive data. It does this by looking for directory and file names.

                        Project details

                        dirsearch is written in Python.

                        Strengths and weaknesses

                        • + More than 10 contributors
                        • + More than 500 GitHub stars
                        • + The source code of this software is available

                          Typical usage

                          • Information gathering
                          • Penetration testing
                          • Security assessment

                          dirsearch review

                          63

                          ArpON

                          Introduction

                          ArpOn protects a system by running as a daemon and guard against a Man in the Middle (MitM) attack due to ARP spoofing, cache poisoning, or an ARP poison routing attack.

                          The tool works by using three types of inspection to detect a related attack.

                          • SARPI (Static ARP Inspection), statically configured networks (without DHCP)
                          • DARPI (Dynamic ARP Inspection), dynamically configured networks (with DHCP)
                          • HARPI (Hybrid ARP Inspection), statically and dynamically configured networks (with DHCP)

                          Project details

                          ArpON is written in C.

                          Strengths and weaknesses

                          • + The source code of this software is available

                            ArpON review

                            74

                            DBShield

                            Introduction

                            This tool is typically used by developers and system administrators to protect their database against common database attacks. One of them is the SQL injection attack, that tries to bypass checks, resulting in data leakage. By using this tool, another level of security defense is implemented.

                            Project details

                            DBShield is written in Golang.

                            Strengths and weaknesses

                            • + The source code of this software is available

                              Typical usage

                              • Database security

                              DBShield review

                              60

                              MongoSanitizer (python-mongo-sanitizer)

                              Introduction

                              Typically this type of tool would be used as an additional defense layer to prevent injection attacks from reaching the database.

                              Project details

                              MongoSanitizer is written in Python.

                              Strengths and weaknesses

                              • + The source code of this software is available

                                Typical usage

                                • Application security
                                • Database security

                                MongoSanitizer review

                                97

                                OpenSnitch

                                Introduction

                                OpenSnitch is a tool based on Little Snitch, a macOS application level firewall. All outgoing connections are monitored and the user is alerted when a new outgoing connection occurs. This allows the user to detect and block any unwanted connections.

                                Project details

                                OpenSnitch is written in Golang.

                                Strengths and weaknesses

                                • + More than 3000 GitHub stars
                                • + The source code of this software is available
                                • - No releases on GitHub available

                                Typical usage

                                • Network traffic filtering

                                OpenSnitch review

                                63

                                Portspoof

                                Introduction

                                Portspoof is a small utility with the goal to make port scanning by other much harder. It achieves this by showing all configured TCP ports to be in the 'open' state instead of closed or filter. The related ports are also emulating valid services. This way a port scan on the system will reveal many open ports and look to have legitimate services running.

                                Project details

                                68

                                Bleach

                                Introduction

                                Bleach is a library for Django that can sanitize HTML by escaping and stripping harmful content. It provides a filter for untrusted content and disarms potential unwanted scripts from the input. This may be useful to apply to data that is transmitted via HTML forms or otherwise.

                                Project details

                                Bleach is written in Python.

                                Strengths and weaknesses

                                • + More than 25 contributors
                                • + More than 1000 GitHub stars
                                • + The source code of this software is available

                                  Typical usage

                                  • Data sanitizing

                                  Bleach review

                                  74

                                  django-guardian

                                  Introduction

                                  The django-guardian project is typically used in environments and projects where the default Django permissions are not enough. For example, an application with multiple users and many objects may require detailed permissions on who can see a particular record. This could go as far as giving only the creator of a record (=object) access plus the people with a particular access level.

                                  Project details

                                  django-guardian is written in Python.

                                  Strengths and weaknesses

                                  • + More than 1000 GitHub stars
                                  • + The source code of this software is available
                                  • + Well-known tool

                                    Typical usage

                                    • Application security

                                    django-guardian review

                                    74

                                    django-sudo

                                    Introduction

                                    For some destructive events like removing an account, you may want to revalidate if the user really wants to continue. To ensure it is the actual owner of the account, django-sudo requests authentication again within the web application. GitHub uses this as well for some events like ownership changes and deletions.

                                    Project details

                                    django-sudo is written in Python.

                                    Strengths and weaknesses

                                    • + More than 10 contributors
                                    • + The source code of this software is available

                                      Typical usage

                                      • Application security

                                      django-sudo review

                                      74

                                      Arachni

                                      Introduction

                                      Arachni is framework written in Ruby with focus on evaluating the security of web applications. Typical users include security professionals and system administrators.

                                      The tooling is free and open source. Besides Linux, it also runs on macOS and Microsoft Windows.

                                      Project details

                                      Arachni is written in Ruby.

                                      Strengths and weaknesses

                                      • + More than 1000 GitHub stars
                                      • + The source code of this software is available

                                        Typical usage

                                        • Penetration testing
                                        • Security assessment
                                        • Web application analysis

                                        Arachni review

                                        89

                                        Commix

                                        Introduction

                                        Commix is short for COMMand Injection eXploiter.

                                        Project details

                                        Commix is written in Python.

                                        Strengths and weaknesses

                                        • + More than 10 contributors
                                        • + More than 1000 GitHub stars
                                        • + The source code of this software is available

                                          Commix review

                                          Some relevant tool missing as an alternative to django-axes? Please contact us with your suggestion.