exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 576 - 600 of 1,391 RSS Feed

Files

SQLSUS MySQL Injection Tool 0.4.1
Posted Dec 10, 2009
Authored by sativouf | Site sqlsus.sf.net

sqlsus is a MySQL injection and takeover tool, written in perl. Via a command line interface that mimics a mysql console, you can retrieve the database structure / contents, inject a SQL query, download files from the web server, upload and control a backdoor, and much more.

Changes: New brute command. Multithreading support for inband queries. Some additions.
tags | tool, web, scanner, perl, sql injection
systems | unix
SHA-256 | 3ac31ec61fc3009c88c24749920a68b2abfeec486f2dfcc6a9678ed802e7e157
Lynis Auditing Tool 1.2.8
Posted Dec 8, 2009
Authored by Michael Boelen | Site cisofy.com

Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.

Changes: This release adds initial support for Squid and several tests related to user authentication. Several improvements have been made, including some small bugfixes.
tags | tool, scanner
systems | unix
SHA-256 | 47ec0734e5807709802da023edf6ec49be71018d5f9ccec8e1b2a6553baaa0fc
WhatWeb Scanner 0.3
Posted Dec 1, 2009
Authored by Andrew Horton | Site morningstarsecurity.com

WhatWeb next generation web scanner identifies what websites are running. Released at the Kiwicon conference (kiwicon.org) in Wellington, New Zealand. Written in Ruby for Linux. Flexible plugin architecture with over 60 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner, ruby
systems | linux, unix
SHA-256 | 7dd4420c9c4270ff82b2508a50149b6c683487083b7e706949972666a8657295
Google.com Hostname / URL Enumerator
Posted Dec 1, 2009
Authored by Andrew Horton | Site morningstarsecurity.com

This tool enumerates hostnames and URLs from Google. It features antibot avoidance, search within a country, custom search appliance, output either hostnames or URLs, and custom search depth. Written in Bash for Linux.

tags | tool, scanner, bash
systems | linux, unix
SHA-256 | aeaa5ee7e1288ae22a7fb24145c07239602f4b84fa6f4237e6090bab65dd8be2
Bing.com Hostname / IP Enumerator
Posted Dec 1, 2009
Authored by Andrew Horton | Site morningstarsecurity.com

This tool enumerates hostnames from Bing.com for an IP address. Bing.com is Microsoft's search engine which has an IP: search parameter. Written in Bash for Linux. Requires wget.

tags | tool, scanner, bash
systems | linux, unix
SHA-256 | 42c7c26f81e81970bb24710b0f5fa543bad39b49979aadca7945e248f12aba7c
SambaScan2 0.4.2
Posted Dec 1, 2009
Authored by Claudio Clemens | Site asturio.gmxhome.de

Sambascan2 allows you to search an entire network or a number of hosts for SMB shares. It will also list the contents of all public shares that it finds. The difference between sambascan2 and other SMB viewers and scanners is that it will search everything using TCP/IP, and it will not send a lot of broadcast messages, so it can be used over LAN boundaries. It only uses SMB to list the shares and their contents.

Changes: Scanning shares with spaces now works.
tags | tool, scanner, tcp
systems | unix
SHA-256 | ea26f18aa88817ae9a6c600d317c4f4f743ee8507b769a6b2d9c56902cafd888
PPScan Portscanner 0.3
Posted Nov 24, 2009
Authored by aaron conole

ppscan is yet another portscanner. However, it can scan an entire Class C subnet for a range of ports not only using tcp-syn/tcp-connect but also by tunneling through HTTP proxies (either HTTP GET or HTTP CONNECT), or using FTP servers which allow arbitrary connections via PORT bounce method. It is multi-threaded, so it can blaze through connection attempts.

tags | tool, web, arbitrary, scanner, tcp
systems | unix
SHA-256 | 662c1cf506bf0d8bb74216f8ea2f0047e7c33238eb1860284b5d9c9fbb2ccc27
Htrosbif HTTP Server Fingerprinting Tool
Posted Nov 17, 2009
Authored by Erik Inge Bolso

htrosbif is a tool that actively probes an HTTP server. It prods the Web server in all sorts of old, new, basic, fancy, spec-compliant, and spec-breaking ways. It tries to characterize both the well-spoken educated responses and the seriously deviant babble it receives in return. Signatures contain no user data, only header names and HTTP-level quirks. As a useful side effect, this might detect reverse proxies, HTTP load balancers, intrusion prevention systems, and Web application firewalls.

tags | tool, web, scanner
systems | unix
SHA-256 | 9f2e98af019d3b5445bede40d649c0dc8245787e77eeaa688ee2285e7c7efeb0
MapSweeper 1.0 Ping Sweeper
Posted Nov 3, 2009
Authored by 0x90

MapSweeper version 1.0 ping sweeping script.

tags | tool, scanner
systems | unix
SHA-256 | 78c58f4e6a6537b3dfef8851eccfd453b7b677c8f62d6b7760cde32ccbb49583
Lynis Auditing Tool 1.2.7
Posted Nov 3, 2009
Authored by Michael Boelen | Site cisofy.com

Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.

Changes: This release adds AIX support and several new tests related to SSH, logging, databases, and SMTP. Many minor issues are solved or improved.
tags | tool, scanner
systems | unix
SHA-256 | dc734ad1f8bdce30d7604c3eb4176dbaf92cf0e5c54d3ea12ec6cd3128e402ac
Uber Web Security Scanner 0.0.2
Posted Oct 29, 2009
Authored by noptrix | Site nullsecurity.net

uwss is a web security scanner and used for testing security holes in web applications. It can act as a fuzzer whose objective is to probe the application with various crafted attack strings. uwss is built upon a modular concept.

Changes: Various updates.
tags | tool, web, scanner, fuzzer
systems | unix
SHA-256 | f5889f915e9116c5d6e219bc6ac51f19112545db98937dc7898dbe14386f4937
ACE 1.10
Posted Oct 23, 2009
Authored by Jason Ostrom | Site sourceforge.net

ACE (Automated Corporate Enumerator) is a simple yet powerful VoIP Corporate Directory enumeration tool that mimics the behavior of an IP Phone in order to download the name and extension entries that a given phone can display on its screen interface. In the same way that the "corporate directory" feature of VoIP hardphones enables users to easily dial by name via their VoIP handsets, ACE was developed as a research idea born from "VoIP Hopper" to automate VoIP attacks that can be targeted against names in an enterprise Directory. The concept is that in the future, attacks will be carried out against users based on their name, rather than targeting VoIP traffic against random RTP audio streams or IP addresses. ACE works by using DHCP, TFTP, and HTTP in order to download the VoIP corporate directory. It then outputs the directory to a text file, which can be used as input to other VoIP assessment tools. ACE is a standalone utility, but its functions are integrated into UCSniff.

tags | tool, web, scanner
systems | unix
SHA-256 | d5b4c5ef2b4537b8f6cb4ab98d0bfd6f34392477aafb0f492fd833f4f55aca49
Scannedonly Samba VFS Module 0.15
Posted Oct 16, 2009
Authored by Olivier Sessink | Site olivier.sessink.nl

Scannedonly is a samba VFS module that ensures that only files that have been scanned for viruses are visible and accessible to the end user. Scannedonly was developed because of scalability problems with samba-vscan. Scannedonly comes in two parts: a Samba VFS module and (one or more) daemons. The daemon scans files and marks them when they are known to be clean. The samba module simply filters out files that aren't marked clean.

Changes: This release adds compatibility with samba 3.4. There are no other changes.
tags | tool, scanner
systems | unix
SHA-256 | 9842b07d7ecd6d2ebf5d42b180dc29e13e74b4b56dd66cf96d7cdb6a0a156b70
Hyenae Packet Generator 0.35-1
Posted Oct 2, 2009
Authored by Robin Richter | Site sourceforge.net

Hyenae is a highly flexible and platform independent network packet generator. It allows you to reproduce low level Ethernet attack scenarios (such as MITM, DoS, and DDoS) to reveal potential security vulnerabilities of your network. Besides smart wildcard-based address randomization, a highly customizable packet generation control, and an interactive attack assistant, Hyenae comes with a clusterable remote daemon for setting up distributed attack networks.

Changes: Bugs and build warnings were fixed and the documentation was updated. Cisco HSRP-Hello, HSRP-Coup, and HSRP-Resign support was added. The attack blocking handler, attack parameter structure, and default value assignment were refactored. Opcode (code) arguments were made optional. A DNS patch was applied and DNS query URL format validation was removed. Cisco HSRP active router hijacking was added to the attack assistant. The daemon now binds to every capable network interface by default.
tags | tool, remote, scanner, vulnerability
systems | unix
SHA-256 | 36250f88b0f0698ce2d7b3675799c4f33449f1a9b5fd3d21cb6ba7a07a716149
Hyenae Packet Generator
Posted Sep 15, 2009
Authored by Robin Richter | Site sourceforge.net

Hyenae is a highly flexible and platform independent network packet generator. It allows you to reproduce low level Ethernet attack scenarios (such as MITM, DoS, and DDoS) to reveal potential security vulnerabilities of your network. Besides smart wildcard-based address randomization, a highly customizable packet generation control, and an interactive attack assistant, Hyenae comes with a clusterable remote daemon for setting up distributed attack networks.

Changes: Bugs were fixed. The documentation was updated. The debian run script was added. PPPoE-Discover support was added. PPPoE session initiation flood was added to attack assistant. Blind PPPoE session termination was added to attack assistant. The -l argument now lists interface descriptions instead of names.
tags | tool, remote, scanner, vulnerability
systems | unix
SHA-256 | 7350552cefc567f7eb5f9f877f55aca96d41599543c7f10bbf9cf512d99d19e4
Fwknop Port Knocking Utility
Posted Sep 10, 2009
Authored by Michael Rash | Site cipherdyne.org

fwknop implements an authorization scheme that requires only a single encrypted packet to communicate various pieces of information, including desired access through a Netfilter policy and/or specific commands to execute on the target system. The main application of this program is to protect services such as SSH with an additional layer of security in order to make the exploitation of vulnerabilities much more difficult. The authorization server works by passively monitoring authorization packets via libpcap.

Changes: The FKO module that is part of the libfko library was fully integrated for all SPA routines: encryption/decryption, digest calculation, replay attack detection, etc. The ability to recover from interface error conditions was added, such as when fwknopd sniffs a ppp interface (say, associated with a VPN) that goes away and then is recreated. The fwknop client was updated to include the SPA destination before DNS resolution when sending an SPA packet over an HTTP request.
tags | tool, scanner, vulnerability
systems | unix
SHA-256 | b4fcde370773c710927230c0d84100a4aaa2060eb497cf896a97d752b2856e87
MySqloit SQL Injection Takeover Tool
Posted Sep 2, 2009
Authored by Muhaimin Dzulfakar | Site code.google.com

MySqloit is a SQL Injection takeover tool focused on LAMP (Linux, Apache, MySQL, PHP) and WAMP (Windows, Apache, MySQL, PHP) platforms. It has the ability to upload and execute Metasploit shellcodes through the MySQL SQL Injection vulnerabilities.

tags | tool, scanner, php, vulnerability, shellcode, sql injection
systems | linux, windows, unix
SHA-256 | 97e06597309a5714f14fba6fa3ea6ae49105d79129f7455ebc3be206b0cab04a
Hyenae Packet Generator
Posted Sep 2, 2009
Authored by Robin Richter | Site sourceforge.net

Hyenae is a highly flexible and platform independent network packet generator. It allows you to reproduce low level Ethernet attack scenarios (such as MITM, DoS, and DDoS) to reveal potential security vulnerabilities of your network. Besides smart wildcard-based address randomization, a highly customizable packet generation control, and an interactive attack assistant, Hyenae comes with a clusterable remote daemon for setting up distributed attack networks.

Changes: This release has bugfixes and fixes for build warnings. It adds ICMPv6-Echo support, and adds ICMPv6-Echo flood to the attack assistant.
tags | tool, remote, scanner, vulnerability
systems | unix
SHA-256 | 24e96c74ab7f179042a146f12914546dc1c7a7d95b6ffe4238ef38490d616034
Quick And Simple PHP TCP Port Scanner
Posted Aug 25, 2009
Authored by the_Edit0r

This is a quick and simple TCP port scanning utility written in PHP.

tags | tool, scanner, php, tcp
systems | unix
SHA-256 | c0fbd6b658908af4cb4a3272dc3c7b366d57256efceaaa57640c208b9bea5c0c
Quick And Simple TCP Port Scanner
Posted Aug 25, 2009
Authored by the_Edit0r

This is a quick and simple TCP port scanning utility.

tags | tool, scanner, tcp
systems | unix
SHA-256 | ca2361f0996c2deb8b4e5664c3723449c147a40f24187fda1f254d15ad72b61e
Hyenae Packet Generator
Posted Aug 24, 2009
Authored by Robin Richter | Site sourceforge.net

Hyenae is a highly flexible and platform independent network packet generator. It allows you to reproduce low level Ethernet attack scenarios (such as MITM, DoS, and DDoS) to reveal potential security vulnerabilities of your network. Besides smart wildcard-based address randomization, a highly customizable packet generation control, and an interactive attack assistant, Hyenae comes with a clusterable remote daemon for setting up distributed attack networks.

Changes: This release adds DNS-Query attack support. It adds DNS-Query flood to the attack assistant. It fixes DHCP source/destination pattern randomization.
tags | tool, remote, scanner, vulnerability
systems | unix
SHA-256 | 2389a66440d5635d196fccc4471fe836efc0c4f571071145d2159d57cd276797
Hyenae Packet Generator
Posted Aug 17, 2009
Authored by Robin Richter | Site sourceforge.net

Hyenae is a highly flexible and platform independent network packet generator. It allows you to reproduce low level Ethernet attack scenarios (such as MITM, DoS, and DDoS) to reveal potential security vulnerabilities of your network. Besides smart wildcard-based address randomization, a highly customizable packet generation control, and an interactive attack assistant, Hyenae comes with a clusterable remote daemon for setting up distributed attack networks.

Changes: This release has bugfixes, an improved attack assistant, extended / fixed documentation, a TCP-Land attack in the attack assistant, and an ICMP-Smurf attack in the attack assistant. It changes the daemon max clients argument (from -C to -m).
tags | tool, remote, scanner, vulnerability
systems | unix
SHA-256 | 250217ea75c2bc9d734031a5fdbcd9407e3c3c910c95de1378b359368cb5f07f
Hyenae Packet Generator
Posted Jul 28, 2009
Authored by Robin Richter | Site sourceforge.net

Hyenae is a highly flexible and platform independent network packet generator. It allows you to reproduce low level Ethernet attack scenarios (such as MITM, DoS, and DDoS) to reveal potential security vulnerabilities of your network. Besides smart wildcard-based address randomization, a highly customizable packet generation control, and an interactive attack assistant, Hyenae comes with a clusterable remote daemon for setting up distributed attack networks.

Changes: An attack assistant was added. Minor code refactoring was done. The documentation was updated and fixed. Randomization on ARP attacks was made equal for source and sender HW-Address.
tags | tool, remote, scanner, vulnerability
systems | unix
SHA-256 | c56bfbe97e29a46bf1cb1b30c024b38b31ee81e5be5d165417e22712be8c9faf
Uber Web Security Scanner
Posted Jul 22, 2009
Authored by noptrix | Site nullsecurity.net

uwss is a web security scanner and used for testing security holes in web applications. It can act as a fuzzer whose objective is to probe the application with various crafted attack strings. uwss is built upon a modular concept.

tags | tool, web, scanner, fuzzer
systems | unix
SHA-256 | 13057a6d9a4ce6617d07316cf3ac864b76984cb10985c54168293dbc49851d8a
NullSearchAccess Login Scanner
Posted Jul 17, 2009
Authored by Simpp

NullSearchAccess is a scanner that attempts default logins for various services like ftp, pop3, imap, mysql, and more.

Changes: Some functions fixed. Compiled without mysql lib.
tags | tool, scanner, imap
systems | unix
SHA-256 | a10a9044c809fd3349b9ec60b05ed552425f65705f4c73c9f835870f23fb0bbd
Page 24 of 56
Back2223242526Next

Top Authors In Last 30 Days

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close