No account yet?
Home » Downloads » Tools » Penetration Testing
Downloads
Penetration Testing
Categories
 
Documents
Order by : Name | Date | Hits [ Descendent ]
Fuzzled
Fuzzled Tooltip
Hits: 14
Date added: 03/26/2007
A Perl Based Fuzzer is a powerful fuzzing framework. Fuzzled includes helper functions, namespaces, factories which allow a wide variety of fuzzing tools to be developed. Fuzzled comes with several example protocols and drivers for them.
Details
 
Sprajax
Sprajax Tooltip
Hits: 21
Date added: 03/30/2007
Sprajax is an open source black box security scanner used to assess the security of AJAX-enabled applications. By detecting the specific AJAX frameworks in use, Sprajax is able to better formulate test requests and identify potential vulnerabilities. Denim Group developed this innovative tool that will revolutionize security assessments by providing a more thorough diagnosis of security vulnerabilities within the AJAX code that other web security scanners are not designed to read. The software then produces a report of possible weaknesses for developers to remedy. - Support for Microsoft Atlas web applications - Support for fuzzing Web Services based on a WSDL description
Details
 
THC-Flood Connect v1.5
THC-Flood Connect v1.5 hot! Tooltip
Hits: 80
Date added: 04/08/2007
Flood Connect is a connection flooding tool which supports SSL, sending + dumping data, closing or keeping sessions etc. Just a small release. Have fun.
Details
 
Nikto v1.36
Nikto v1.36 hot! Tooltip
Hits: 103
Date added: 04/11/2007
Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3300 potentially dangerous files/CGIs, versions on over 625 servers, and version specific problems on over 230 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired). Nikto is not designed as an overly stealthy tool. It will test a web server in the shortest timespan possible, and it's fairly obvious in log files. However, there is support for LibWhisker's anti-IDS methods in case you want to give it a try (or test your IDS system). Not every check is a security problem, though most are. There are some items that are info only type checks that look for items that may not have a security flaw, but the webmaster or security engineer may not know are present on the server. These items are usually marked appropriately in the information printed. There are also some checks for unknown items which have been seen scanned for in log files. Features # Uses rfp's LibWhisker as a base for all network funtionality # Main scan database in CSV format for easy updates # Determines OK vs NOT FOUND responses for each server, if possible # Determines CGI directories for each server, if possible # Switch HTTP versions as needed so that the server understands requests properly # SSL Support (Unix with OpenSSL or maybe Windows with ActiveState's Perl/NetSSL) # Output to file in plain text, HTML or CSV # Generic and server type specific checks # Plugin support (standard PERL) # Checks for outdated server software # Proxy support (with authentication) # Host authentication (Basic) # Watches for bogus OK responses # Attempts to perform educated guesses for Authentication realms # Captures/prints any Cookies received # Mutate mode to go fishing on web servers for odd items # Builds Mutate checks based on robots.txt entries (if present) # Scan multiple ports on a target to find web servers (can integrate nmap for speed, if available) # Multiple IDS evasion techniques # Users can add a custom scan database # Supports automatic code/check updates (with web access) # Multiple host/port scanning (scan list files) # Username guessing plugin via the cgiwrap program and Apache ~user methods
Details
 
THC-CUPASS v1.0
THC-CUPASS v1.0 hot! Tooltip
Hits: 68
Date added: 04/12/2007
CUPASS uses techniques to guess the password of ANY user on a WindowsNT/W2K server or domain. CUPASS uses a flaw in the implementation of Microsofts NetUserChangePassword API to guess/change the users password. This release is the proof of concept code for the THC paper CUPASS and the NetUserChangePassword Problem
Details
 
<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>
Page 10 of 11

Downloads Home
Downloads Home
Search Document
Search Document

Get Archive RSS

The latest tools and texts wherever you are


Do you own a website?
Add these feeds to your site and get a link on our home page!

Newsletter


Every week our tools in your inbox?


Enter your Email


Preview

Security Services by HSC