exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 326 - 350 of 1,391 RSS Feed

Files

FGscanner Directory / Page Scanner
Posted Oct 20, 2013
Authored by FantaGhost | Site fantaghost.com

FantaGhost is a perl script that assists with penetration testing by scanning for hidden directories and pages.

tags | tool, scanner, perl
systems | unix
SHA-256 | de3d7da80da7a9e25f88605774eee513ce090e983c4a83f3f0bae900bb0affb7
IP Phone Scanning Made Easy 0.12
Posted Oct 8, 2013
Authored by Cedric Baillet | Site freecode.com

ISME is a small framework to test IP phones from several editors. It can gather information from IP phone infrastructures, test their web servers for default login/password combinations, and also implement attacks against the systems. ISME has been written in perl with a perl/Tk interface to provide a portable and easy to use tool. Full documentation is also provided.

Changes: This release adds a new SIP Scanner (UDP or TCP) module with administration services detection and information gathering on SIP UA or server. Threads have been implemented in the launcher. Several tools can now be used at the same time.
tags | tool, web, scanner, perl
systems | unix
SHA-256 | ecb0015dcaf2c33676782b33e8df8f700c71993eb29d2d41c8dc2453fdec7dc0
Lynis Auditing Tool 1.3.1
Posted Oct 3, 2013
Authored by Michael Boelen | Site cisofy.com

Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.

Changes: This release has several generic updates, including adjustments of text and fixes in the detection of binaries, including performance tweaks. Several minor adjustments have been implemented to improve several audit checks.
tags | tool, scanner
systems | unix
SHA-256 | 10532b626e8182605e3ca9215d856a20145f776c30c729387f374dd753230a15
Sparty 0.1
Posted Aug 21, 2013
Site sparty.secniche.org

Sparty is an open source tool written in python to audit web applications using sharepoint and frontpage architecture. The motivation behind this tool is to provide an easy and robust way to scrutinize the security configurations of sharepoint and frontpage based web applications. Due to the complex nature of these web administration software, it is required to have a simple and efficient tool that gathers information, check access permissions, dump critical information from default files and perform automated exploitation if security risks are identified. A number of automated scanners fall short of this and Sparty is a solution to that.

tags | tool, web, scanner, python
systems | unix
SHA-256 | f7b4720b68387a85282ee51ecffe1c6bd87d4c236fb4fcacbe37fb52ae430b18
WATOBO 0.9.13
Posted Aug 12, 2013
Authored by Andreas Schmidt | Site watobo.sourceforge.net

WATOBO, the Web Application Toolbox, is a tool that enables security professionals to perform highly efficient (semi-automated) web application security audits. It acts like a local proxy and analyzes the traffic on the fly for helpful information and vulnerabilities. It also has automated scanning capabilities, e.g. SQL injection, cross site scripting and more.

Changes: Faster socket communication. Various module updates. Addition of the WShell plugin and much more.
tags | tool, web, local, scanner, vulnerability, xss, sql injection
systems | linux, unix
SHA-256 | ecc5cef05aa502575841bd3e15d42e0dc6e464feff4a873f60fa69774446b024
Fwknop Port Knocking Utility 2.5.1
Posted Jul 28, 2013
Authored by Michael Rash | Site cipherdyne.org

fwknop implements an authorization scheme that requires only a single encrypted packet to communicate various pieces of information, including desired access through a Netfilter policy and/or specific commands to execute on the target system. The main application of this program is to protect services such as SSH with an additional layer of security in order to make the exploitation of vulnerabilities much more difficult. The authorization server works by passively monitoring authorization packets via libpcap.

Changes: A bugfix in the fwknop client to reset terminal settings to original values after entering keys via stdin. A bugfix in the fwknopd daemon to not print a PID file existence warning. A test suite bugfix to not run an iptables Rijndael HMAC test on non-Linux systems.
tags | tool, scanner, vulnerability
systems | unix
SHA-256 | 6c364875431542e3f00b8c2fc0e354e4ddf333ed282f83e28a0d6a79326572d5
ARP-Scan ARP Generation Tool 1.9
Posted Jul 25, 2013
Authored by Roy Hills | Site nta-monitor.com

arp-scan sends ARP (Address Resolution Protocol) queries to the specified targets, and displays any responses that are received. It allows any part of the outgoing ARP packets to be changed, allowing the behavior of targets to non-standard ARP packets to be examined. The IP address and hardware address of received packets are displayed, together with the vendor details. These details are obtained from the IEEE OUI and IAB listings, plus a few manual entries. It includes arp-fingerprint, which allows a system to be fingerprinted based on how it responds to non-standard ARP packets.

Changes: This release adds support for ARM 64-bit CPUs and Dragonfly BSD, adds a --rtt (-D) option to display the packet round-trip time, uses libpcap functions to obtain the interface IP address and send the packet (to increase portability), requires libpcap 0.9.3 or later, raises the default timeout from 100ms to 500ms to avoid missed responses from slow-responding hosts, modifies the get-iab and get-oui scripts to the support new IEEE website URL and new file format (also fixes the -u option in these scripts), updates MAC/Vendor mapping files from the IEEE website, and adds additional arp-fingerprint patterns.
tags | tool, scanner, protocol
systems | unix
SHA-256 | ce908ac71c48e85dddf6dd4fe5151d13c7528b1f49717a98b2a2535bd797d892
Fwknop Port Knocking Utility 2.5
Posted Jul 22, 2013
Authored by Michael Rash | Site cipherdyne.org

fwknop implements an authorization scheme that requires only a single encrypted packet to communicate various pieces of information, including desired access through a Netfilter policy and/or specific commands to execute on the target system. The main application of this program is to protect services such as SSH with an additional layer of security in order to make the exploitation of vulnerabilities much more difficult. The authorization server works by passively monitoring authorization packets via libpcap.

Changes: This release added support for HMAC SHA-256 authenticated encryption in the encrypt-then-authenticate model. Many bugs discovered by the Coverity static analyzer were fixed. OpenSSL compatibility tests were added to the test suite. Client stanza saving ability was added for the ~/.fwknoprc file, simplifying fwknop client usage. The ability to automatically generate both Rijndael and HMAC keys with --key-gen was added.
tags | tool, scanner, vulnerability
systems | unix
SHA-256 | ebf0f5a55992e516fa44063993cbcc51bb9555cef769ac9ab5d8be77a8df99dc
Against Mass Scanner / SSH Brute Forcer
Posted Jun 25, 2013
Authored by pigtail23 | Site nullsecurity.net

Against is a very fast ssh attack script which includes a multithreaded port scanning module (tcp connect) for discovering possible targets and a multithreaded brute-forcing module which attacks in parallel (multiprocessing) all discovered hosts or given ip addresses from a list.

tags | tool, scanner, tcp
systems | unix
SHA-256 | a381147676345ca9c836e4c1462e3640dcacda8fa9c672bb180705d90835376b
Web Soul 2 Scanner
Posted Jun 17, 2013
Authored by Am!r | Site irist.ir

Web Soul is a plugin based scanner for attacking and data mining web sites. Written in Perl.

tags | tool, web, scanner, perl
systems | unix
SHA-256 | ca415409ae86c574f541ca482e698ed751209791460f27cc6c8ca5dd4207e578
Maligno 0.6
Posted May 30, 2013
Authored by Juan J. Guelfo | Site encripto.no

Maligno is an open source penetration testing tool written in python, that serves Metasploit payloads. It generates shellcode with msfvenom and transmits it over HTTP or HTTPS. The shellcode is encrypted with AES and encoded with Base64 prior to transmission.

tags | tool, web, scanner, shellcode, python
systems | unix
SHA-256 | 31f2d0097dcb428cdfb4e14b20982cbccf4d799920eaa871858214dbddcd6c85
aidSQL SQL Injection Detection And Exploitation Tool 20130527
Posted May 28, 2013
Authored by Federico Stange | Site code.google.com

aidSQL SQL injection detection and exploitation tool is a modular PHP scanner that allows you to develop your own plugins for use.

Changes: This version improves --interactive mode and adds MS SQL SERVER 2000 injection and reverse engineer support.
tags | tool, scanner, php, sql injection
systems | linux, unix
SHA-256 | ede98363826326ac8e65d9fb102f11c06147d57f5417e955d5fa2422c49f5e89
Bing LFI / RFI Scanner
Posted May 12, 2013
Authored by miyachung

This is a python script for searching Bing for sites that may have local and remote file inclusion vulnerabilities.

tags | tool, remote, local, scanner, vulnerability, python, file inclusion
systems | unix
SHA-256 | b57e9c6371c8ee26ae27e8621e28c0050585e84a7b11dc144d70b52d742a8976
Multithreaded SQL Injector
Posted May 1, 2013
Authored by miyachung

This is a SQL injection tool similar to havij but is super fast per the author.

tags | tool, scanner, sql injection
systems | unix
SHA-256 | bb0ace9f65db972df40d580e46e07ff19b711b4e9d4df7895f33dec8cc400b54
Janissaries Joomla Fingerprint Tool
Posted Apr 23, 2013
Authored by miyachung

This php script fingerprints a given Joomla system and then uses Packet Storm's archive to check for bugs related to the installed components.

tags | tool, scanner, php
systems | unix
SHA-256 | 88262f0098e3ae940b541af13f63757e65e56df737aad47c872d4403ce361308
IP Phone Scanning Made Easy 0.10
Posted Apr 15, 2013
Authored by Cedric Baillet | Site freecode.com

ISME is a small framework to test IP phones from several editors. It can gather information from IP phone infrastructures, test their web servers for default login/password combinations, and also implement attacks against the systems. ISME has been written in perl with a perl/Tk interface to provide a portable and easy to use tool. Full documentation is also provided.

Changes: Added a new tool in exploit section to detect Aastra IP Phones suffering from the hardcoded telnet login/password.
tags | tool, web, scanner, perl
systems | unix
SHA-256 | aec14a937bbc7b54b411e858d71799f4d45d60a0a002a29bca604e2bf90dccff
SVN Extractor
Posted Apr 10, 2013
Authored by Anant Shrivastava | Site anantshri.info

This is a simple python tool written to extract all web resources by leveraging an exposed .SVN folder.

tags | tool, web, scanner, python
systems | unix
SHA-256 | 2675f79a415d1f1f96f60a6a337e25c1fb941c47573e612e32d8468062080155
SI6 Networks' IPv6 Toolkit 1.3.3
Posted Mar 11, 2013
Authored by Fernando Gont

This toolkit houses various IPv6 tools that have been tested to compile and run on Debian GNU/Linux 6.0, FreeBSD 9.0, NetBSD 5.1, OpenBSD 5.0, Mac OS 10.8.0, and Ubuntu 11.10.

Changes: This minor update incorporates the "--tgt-known-iids" option, which can be used to track systems across networks, even if they employ the so-called "Privacy Address" (and yes, that includes Microsoft Windows systems).
tags | tool, scanner
systems | linux, netbsd, unix, freebsd, openbsd, debian, ubuntu
SHA-256 | 8392ec6c2414194f839d154313ea7965a2c6503286828f22860c4c50a635d099
WDivulge Hidden File Web Scanner
Posted Mar 6, 2013
Authored by Blake | Site soldierx.com

wdivulge is a tool designed to find and download hidden files from a webserver. This is most commonly pictures, but you can adjust the file definitions to bruteforce any type of file that you'd like. wdivulge technically falls under the definition of a web fusker.

tags | tool, web, scanner
systems | unix
SHA-256 | 29e6623de8a65649d70f952b6b3e9f12a7eefe3ca42b4b1101b33bdfcc5fc10b
SI6 Networks' IPv6 Toolkit 1.3
Posted Feb 17, 2013
Authored by Fernando Gont

This toolkit houses various IPv6 tools that have been tested to compile and run on Debian GNU/Linux 6.0, FreeBSD 9.0, NetBSD 5.1, OpenBSD 5.0, Mac OS 10.8.0, and Ubuntu 11.10.

Changes: Addition of a full-fledged IPv6 address scanning tool. Includes support for tunnels. Various other additions and updates.
tags | tool, scanner
systems | linux, netbsd, unix, freebsd, openbsd, debian, ubuntu
SHA-256 | 182d3e7b34ea800eae21d5fbf5fd4fa7f13792f27d9a4c5f61947ae0e178a720
HostBox SSH 0.2
Posted Feb 1, 2013
Authored by Oskar Stridsman | Site stridsmanIT.wordpress.com

HostBox SSH is a SSH password/account scanner written in python.

Changes: Various updates.
tags | tool, scanner, python
systems | unix
SHA-256 | 36d0695c3fcf2240852de6eb7a08d01edaa9bc4492c28e29d3b4d044c37e3e6d
IP Phone Scanning Made Easy 0.8
Posted Jan 17, 2013
Authored by Cedric Baillet | Site freecode.com

ISME is a small framework to test IP phones from several editors. It can gather information from IP phone infrastructures, test their web servers for default login/password combinations, and also implement attacks against the systems. ISME has been written in perl with a perl/Tk interface to provide a portable and easy to use tool. Full documentation is also provided.

Changes: GUI updates. Multiple exploits added and a tool was added for Cisco phone SSH server detection.
tags | tool, web, scanner, perl
systems | unix
SHA-256 | 5aef8c3878ccdf4212191b79817bd3ebee7e973b448abb904f5c4514370f4194
OCS Cisco Scanner 0.2
Posted Jan 11, 2013
Authored by OverIP | Site hacklab.tk

Compact mass scanner for Cisco routers with default telnet/enable passwords.

Changes: Various updates and bug fixes.
tags | tool, scanner
systems | cisco, unix
SHA-256 | 867a0b5fd20fabea27f9b864ebcfd8aa4198e3378d494f86556283265b4301b0
Bing.com Hostname / IP Enumerator 0.3
Posted Dec 29, 2012
Authored by Andrew Horton | Site morningstarsecurity.com

This tool enumerates hostnames from Bing.com for an IP address. Bing.com is Microsoft's search engine which has an IP: search parameter. Written in Bash for Linux. Requires wget.

Changes: Fixed bug where version 0.2 stopped working, now uses bing.com instead of the mobile site, more detailed progress animation.
tags | tool, scanner, bash
systems | linux, unix
SHA-256 | 652f806668e2da16c60d530a21a840a2cbd6cb4da1794bfc93cc12dac7a062fe
Mptcp Packet Manipulator 1.9.0
Posted Dec 28, 2012
Authored by Khun | Site hexcodes.org

Mpctp is a tool for manipulation of raw packets that allows a large number of options. Its primary purpose is to diagnose and test several scenarios that involving the use of the types of TCP/IP packets. It is able to send certain types of packets to any specific target and manipulations of various fields at runtime. These fields can be modified in its structure as the the Source/Destination IP address and Source/Destination MAC address.

Changes: Added support for Display Packet Content (tcpdump style). More hard compiler optimizations. Full support for Darwin OS. Various other additions and improvements.
tags | tool, scanner, tcp
systems | unix
SHA-256 | 877f0fde7a1b9bb0cdd0999db9a608db6beb44a3c5860736fcb665139c816ff8
Page 14 of 56
Back1213141516Next

Top Authors In Last 30 Days

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close