SQL Power Injector is an application created in .Net 1.1 that helps the penetration tester to inject SQL commands on a web page.
Browser based tool for website XSS testing
wow. Check the source, luke
Microsoft ASP.NET version 2 also fights cross-site request forgeries with a MAC'ed token:
Thor is Internet Explorer driven tool for manual web application testing.