|
THC-Flood Connect v1.5
hot!
|
|
Hits: 80 |
|
Date added: 04/08/2007 |
|
Flood Connect is a connection flooding tool which supports SSL, sending + dumping data, closing or keeping sessions etc. Just a small release. Have fun. |
|
|
|
|
YaHa
hot!
|
|
Hits: 86 |
|
Date added: 10/20/2006 |
|
YaHa is an HTTP authentication attack tool which tries combinations of user IDs and passwords. You need Perl to run this tool! |
|
|
|
|
dsniff v2.3
hot!
|
|
Hits: 93 |
|
Date added: 06/25/2005 |
|
dsniff is a collection of tools for network auditing and penetration testing. dsniff, filesnarf, mailsnarf, msgsnarf, urlsnarf, and webspy passively monitor a network for interesting data (passwords, e-mail, files, etc.). arpspoof, dnsspoof, and macof facilitate the interception of network traffic normally unavailable to an attacker (e.g, due to layer-2 switching). sshmitm and webmitm implement active monkey-in-the-middle attacks against redirected SSH and HTTPS sessions by exploiting weak bindings in ad-hoc PKI |
|
|
|
|
BlackWidow 4.37
hot!
|
|
Hits: 96 |
|
Date added: 06/29/2005 |
|
BlackWidow is a multi-function internet tool. It is an off-line browser, web site scanner, a site mapping tool, a site ripper, and a site mirroring tool. Use it to scan a site, print and create a complete profile of the site's structure, files, external links and even link errors. Then use it to download part or entire web site to your computer, with its structure and files intact, to use as a site mirror or to be converted by BlackWidow into a locally linked site for offline browsing and long-term reference. Or use it to scan for and download any selection of files: from 'JPG' to 'CGI' to 'HTM' to MIME types, from small to large files, in part of a site or in a group of sites. These pre-scan filtering options can save you countless on-line hours of searching and sorting. BlackWidow will scan HTTP sites, SSL sites (HTTPS) and FTP sites. Accesses password-protected sites, use threads, download part or entire web site to your computer, you can now Edit and Print the structure of a web site. Write your own Plug-ins for impossible to scan sites. Will scan Adobe Acrobat (.pdf) files for links and much more... |
|
|
|
|
Nikto v1.36
hot!
|
|
Hits: 103 |
|
Date added: 04/11/2007 |
|
Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3300 potentially dangerous files/CGIs, versions on over 625 servers, and version specific problems on over 230 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired).
Nikto is not designed as an overly stealthy tool. It will test a web server in the shortest timespan possible, and it's fairly obvious in log files. However, there is support for LibWhisker's anti-IDS methods in case you want to give it a try (or test your IDS system).
Not every check is a security problem, though most are. There are some items that are info only type checks that look for items that may not have a security flaw, but the webmaster or security engineer may not know are present on the server. These items are usually marked appropriately in the information printed. There are also some checks for unknown items which have been seen scanned for in log files.
Features
# Uses rfp's LibWhisker as a base for all network funtionality
# Main scan database in CSV format for easy updates
# Determines OK vs NOT FOUND responses for each server, if possible
# Determines CGI directories for each server, if possible
# Switch HTTP versions as needed so that the server understands requests properly
# SSL Support (Unix with OpenSSL or maybe Windows with ActiveState's Perl/NetSSL)
# Output to file in plain text, HTML or CSV
# Generic and server type specific checks
# Plugin support (standard PERL)
# Checks for outdated server software
# Proxy support (with authentication)
# Host authentication (Basic)
# Watches for bogus OK responses
# Attempts to perform educated guesses for Authentication realms
# Captures/prints any Cookies received
# Mutate mode to go fishing on web servers for odd items
# Builds Mutate checks based on robots.txt entries (if present)
# Scan multiple ports on a target to find web servers (can integrate nmap for speed, if available)
# Multiple IDS evasion techniques
# Users can add a custom scan database
# Supports automatic code/check updates (with web access)
# Multiple host/port scanning (scan list files)
# Username guessing plugin via the cgiwrap program and Apache ~user methods |
|
|
|