exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 48 of 48 RSS Feed

Files from Andrew Horton

First Active2008-10-01
Last Active2021-10-04
GGGooglescan 0.4
Posted May 12, 2011
Authored by Andrew Horton | Site morningstarsecurity.com

GGGooglescan is a Google scraper which performs automated searches and returns results of search queries in the form of URLs or hostnames. Datamining Google's search index is useful for many applications. Despite this, Google makes it difficult for researchers to perform automatic search queries. The aim of GGGooglescan is to make automated searches possible by avoiding the search activity that is detected as bot behavior.

tags | tool, scanner
systems | unix
SHA-256 | 0abe98199fa8a4eae1eec399b90f0b34422d0a08597c6fe48ec945064e408548
WhatWeb Scanner 0.4.7
Posted Apr 6, 2011
Authored by Andrew Horton | Site morningstarsecurity.com

WhatWeb is a next-generation web scanner. It recognizes web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 900 plugins, identifies version numbers, email addresses, account ID's, web framework modules, SQL errors, and more. WhatWeb can be stealthy and fast, or thorough but slow. WhatWeb supports an aggression level to control the trade off between speed and reliability.

Changes: Performance enhancements and bug fixes.
tags | tool, web, scanner, javascript
systems | unix
SHA-256 | 64994ec364de188192918e15c09cd01c62c3b8d080e9777b5d785d7f55d509db
WhatWeb Scanner 0.4.6
Posted Mar 26, 2011
Authored by Andrew Horton | Site morningstarsecurity.com

WhatWeb is a next-generation web scanner. It recognizes web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 900 plugins, identifies version numbers, email addresses, account ID's, web framework modules, SQL errors, and more. WhatWeb can be stealthy and fast, or thorough but slow. WhatWeb supports an aggression level to control the trade off between speed and reliability.

Changes: Over 900 plugins, performance improvements, new log formats (JSON, MongoDB, MagicTree), custom headers, basic authentication, nmap-style ip ranges, and much more.
tags | tool, web, scanner, javascript
systems | unix
SHA-256 | af1ed088b147290cbc61e4924fb5620a29c2b58032d102fe11e94ae109565ec6
WhatWeb Scanner 0.4.5
Posted Aug 17, 2010
Authored by Andrew Horton | Site morningstarsecurity.com

WhatWeb is a next generation web scanner that identifies what websites are running. Flexible plugin architecture with over 300 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner
systems | unix
SHA-256 | 9c9ab674ccca531106d1ae71068b6e4c59e2611154341959d1193818e14c9f6f
WhatWeb Scanner 0.4.4
Posted Jul 3, 2010
Authored by Andrew Horton | Site morningstarsecurity.com

WhatWeb is a next generation web scanner that identifies what websites are running. Flexible plugin architecture with over 80 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner
systems | unix
SHA-256 | cdeb79db86c92b37ee6aef9f12f6a6178982e75ecd8468ae3754bfb915c35df1
WhatWeb Scanner 0.4.3
Posted May 25, 2010
Authored by Andrew Horton | Site morningstarsecurity.com

WhatWeb is a next generation web scanner that identifies what websites are running. Flexible plugin architecture with over 80 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner
systems | unix
SHA-256 | 0ac0df0abf6e8e36d2d884fa1131410d54795f793c79a33b866246e2069bd4b7
WhatWeb Scanner 0.4.2
Posted Apr 30, 2010
Authored by Andrew Horton | Site morningstarsecurity.com

WhatWeb is a next generation web scanner that identifies what websites are running. Flexible plugin architecture with over 80 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner
systems | unix
SHA-256 | de9e6e8be69942bfb60ac6211dab149dbee1f67f0217105def741a0f6804663a
WhatWeb Scanner 0.4.1
Posted Apr 28, 2010
Authored by Andrew Horton | Site morningstarsecurity.com

WhatWeb next generation web scanner identifies what websites are running. Released at the Kiwicon conference (kiwicon.org) in Wellington, New Zealand. Written in Ruby for Linux. Flexible plugin architecture with over 70 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner, ruby
systems | linux, unix
SHA-256 | aceeab845573c4cd8661eb2c47f2086cfd6616595069ba6227bdfd86bf423c08
Next Generation Web Scanning Presentation
Posted Apr 16, 2010
Authored by Andrew Horton | Site morningstarsecurity.com

This is the Next Generation Web Scanning Presentation. It includes a methodology to scan the webspace of an entire nation using some new tools and techniques. WhatWeb, bing-ip2hosts, gggooglescan and basedomainname are open source security tools developed by MorningStar Security that were published during the first presentation of this at the KIWICON III conference in December, 2009.

tags | paper, web
SHA-256 | 5ba140b88894b5c3a0203028fb94ebcd13b23d6d1cb59e76c0371405ab41ddfc
Bing.com Hostname / IP Enumerator 0.2
Posted Apr 3, 2010
Authored by Andrew Horton | Site morningstarsecurity.com

This tool enumerates hostnames from Bing.com for an IP address. Bing.com is Microsoft's search engine which has an IP: search parameter. Written in Bash for Linux. Requires wget.

Changes: Can enter a hostname or IP eg. bing-ip2hosts foo.com, option to change temporary directory, optional CSV output of IP:hostname, optional http:// prefix.
tags | tool, scanner, bash
systems | linux, unix
SHA-256 | 86a430dc3cdb65715c3296f6ef2c2521adbf85863923cfb8c02792653d5ec193
How To Develop WhatWeb Plugins
Posted Mar 30, 2010
Authored by Andrew Horton | Site morningstarsecurity.com

Document on how to research and develop plugins for WhatWeb to identify content management systems, web application frameworks, etc. As an example it includes how to research and write a plugin for the SilverStripe CMS. The document covers passive plugin development only and is accurate for WhatWeb version 0.4.

tags | paper, web
SHA-256 | 5f3f119d174b65e22f243ac401684758be8a9c7c1fe680743529431b7ca20d1b
WhatWeb Scanner 0.4
Posted Mar 16, 2010
Authored by Andrew Horton | Site morningstarsecurity.com

WhatWeb next generation web scanner identifies what websites are running. Released at the Kiwicon conference (kiwicon.org) in Wellington, New Zealand. Written in Ruby for Linux. Flexible plugin architecture with over 70 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner, ruby
systems | linux, unix
SHA-256 | 20c3ad738e1fdee029d4aba2f9a577f770fe605f58b1eb9399aca929dc716c33
GeoIPGen IP By Country Generator 0.4
Posted Mar 8, 2010
Authored by Andrew Horton | Site morningstarsecurity.com

GeoIPgen is a country-to-IPs generator. It's a geographic IP generator for IPv4 networks that uses the MaxMind GeoLite Country database. Geoipgen is the first published use of a geographic ip database in reverse to translate from country-to-IPs instead of the usual use of IP-to-country. Features: Random or sorted order, unique or repeating IPs, skips broadcast addresses, one, many or all countries.

Changes: Faster and smaller memory usage. It now uses the fast-random algorithm by default instead of the bit-field method, Re-wrote README file, Simplified usage instructions.
tags | tool, scanner
systems | unix
SHA-256 | b97d378c46c8d7eec969af1eeb0fc11ccda1e1c360df558e358cbf8969c9fbd7
WhatWeb Scanner 0.3
Posted Dec 1, 2009
Authored by Andrew Horton | Site morningstarsecurity.com

WhatWeb next generation web scanner identifies what websites are running. Released at the Kiwicon conference (kiwicon.org) in Wellington, New Zealand. Written in Ruby for Linux. Flexible plugin architecture with over 60 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner, ruby
systems | linux, unix
SHA-256 | 7dd4420c9c4270ff82b2508a50149b6c683487083b7e706949972666a8657295
Top Level Domain Extractor 0.1
Posted Dec 1, 2009
Authored by Andrew Horton | Site morningstarsecurity.com

This tool can extract TLD (Top Level Domain), domain extensions (Second Level Domain + TLD), domain name, and hostname from fully qualified domain names. Written in Ruby for Unix. Recognizes all countries, top level domains and second level domains.

tags | tool, ruby
systems | unix
SHA-256 | f33c1ee29aec4d1bcb2cc50ef227fefb9b77472f44d18110ddb9a548375a874a
Google.com Hostname / URL Enumerator
Posted Dec 1, 2009
Authored by Andrew Horton | Site morningstarsecurity.com

This tool enumerates hostnames and URLs from Google. It features antibot avoidance, search within a country, custom search appliance, output either hostnames or URLs, and custom search depth. Written in Bash for Linux.

tags | tool, scanner, bash
systems | linux, unix
SHA-256 | aeaa5ee7e1288ae22a7fb24145c07239602f4b84fa6f4237e6090bab65dd8be2
Bing.com Hostname / IP Enumerator
Posted Dec 1, 2009
Authored by Andrew Horton | Site morningstarsecurity.com

This tool enumerates hostnames from Bing.com for an IP address. Bing.com is Microsoft's search engine which has an IP: search parameter. Written in Bash for Linux. Requires wget.

tags | tool, scanner, bash
systems | linux, unix
SHA-256 | 42c7c26f81e81970bb24710b0f5fa543bad39b49979aadca7945e248f12aba7c
Cute News XSS / LFI / Bypass
Posted Nov 17, 2009
Authored by Andrew Horton

Cute News version 1.4.6 and UTF-8 Cute News suffer from cross site request forgery, cross site scripting, file path disclosure, local file inclusion, authentication bypass, and php command injection vulnerabilities.

tags | exploit, local, php, vulnerability, xss, file inclusion, csrf
SHA-256 | cc0fab30e32bdf7cfa84bd8a3a839c9f6541191bedd2b0e2430e4f040589df96
Open Auto Classifieds 1.5.9 File Upload
Posted Aug 26, 2009
Authored by Andrew Horton

Open Auto Classifieds versions 1.5.9 and below remote file upload exploit.

tags | exploit, remote, file upload
SHA-256 | 7322a5373069e15092dc57a0de4058e73dee14a907bea94cf3798baa0b9bdde4
Open Auto Classifieds 1.5.9 SQL Injection
Posted Aug 26, 2009
Authored by Andrew Horton

Open Auto Classifieds versions 1.5.9 and below suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | f4d256bf5b94a24105c65130d206160fc23ebc64c40b09e1bc5146d96200727b
URLCrazy Domain Name Typo Tool 0.2
Posted Apr 1, 2009
Authored by Andrew Horton | Site morningstarsecurity.com

UrlCrazy is for the study of domainname typos and URL hijacking. It generates domainname typo permutations then tests them to learn if they are in use, estimates their popularity and more. Typo types supported are: Character Omission, Adjacent Character Swap, Adjacent Character Replacement, Adjacent Character Insertion, Missing Dot, Strip Dashes, Singular or Pluralise. Urlcrazy is written in Ruby.

tags | tool, web, ruby
SHA-256 | 0accacdc470f20231ead2b7d06716604bea1e9f5beeab45ef44e05d06c52df45
GeoIPGen IP By Country Generator
Posted Mar 9, 2009
Authored by Andrew Horton | Site morningstarsecurity.com

Geoipgen is an IPv4 network tool for generating geotargeted IP addresses. Features: Random or sorted order, unique or repeating ips, skips broadcast addresses, uses the MaxMind GeoLite Country database.

tags | tool, scanner
systems | unix
SHA-256 | 099eb122084fcd73c6d8edf386ad14a23ea749a990a8e99ad4acdeba5df01cac
geoipgen0.2b.tgz
Posted Oct 1, 2008
Authored by Andrew Horton | Site morningstarsecurity.com

geoipgen is an IP network tool written in Ruby for generating geotargeted lists of IP Addresses using MaxMind's Free Open Source GeoLite Country database (www.maxmind.com). Examples: Generate all IPs for New Zealand (./geoipgen -s nz), generate 10,000 random ips for far east asia (geoipgen -n 10000 cn hk mn tw mo jp kr kp), indefinitely generate random ips for japan (geoipgen jp).

tags | tool, scanner, ruby
systems | unix
SHA-256 | de5dbe5d6bee824eb382c532b8b1eac4a1af8c5571357c68be53c5ab6f41251d
Page 2 of 2
Back12Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close