DefenseMatrix helps individuals and organizations who use Linux to secure their servers on various dimentions automatically. It makes securing a Linux server faster and easier. Never before have a program been able to have so many security features packed in one. Therefore we provide you with this all-in-one solution that…
-
-
CVE-2017-17411: Linksys WVBR0 25 Command Injection
Recently a security researcher Ricky Lawshae from Trend Micro discover a critical vulnerability on Linksys Wireless Bridge WVBR0-25 this allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0 WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal.…
-
Acunetix Free Manual Pen Testing Tools
Acunetix Manual Tools allow penetration testers to further automated testing. Scan your websites SQL Injection & Blind SQL Injection Cross-site Scripting (XSS) OWASP Top 10 and other vulnerabilities Use the HTTP Editor to modify or craft HTTP requests and analyze responses, intercept and modify HTTP traffic on the fly…
-
idb – iOS App Security Assessment Tool
idb is a tool to simplify some common tasks for iOS app security assessments and research. Please see the Documentationfor a more detailed summary of each function. Features Assessment Setup SSH port forwarding Installation of helper utilities App Information Bundle information Registered URL Schemes Platform and SDK Versions Data folder…
-
Shellsploit Framework – New Generation Exploit Development Kit
Shellsploit let’s you generate customized shellcodes, backdoors, injectors for various operating system. And let’s you obfuscation every byte via encoders. Dependencies: sudo pip install capstone sudo pip install readline(Not necessary for windows coz preinstalled in shellsploit) sudo pip install pefile sudo pip install colorama sudo pip install pylzma Installation: Pip…
-
Doork – Google Dorks Passive Vulnerability Auditor
Doork is a open-source passive vulnerability auditor tool that automates the process of searching on Google information about specific website based on dorks. doork can update his own database from ghdb and use it for find flaws without even contact the target endpoint. You can provide your custom wordlist and…
-
Mosca – Static analysis tool to find bugs like a grep unix command
Static analysis tool to find bugs like a grep unix command, egg modules is a config to find to vulnerabilities you can use at C, PHP, javascript, ruby etc Save results at XML file create your own modules etc… Download Mosca
-
Wifi Arsenal – A pack of various usefull/useless tools for 802.11 hacking
WiFi arsenal is a pack of various usefull/useless tools for 802.11 hacking Short description: P0cL4bs/3vilTwinAttacker -Framework for Rogue Wi-Fi Access Point Attack ewa/802.11-data – Formulas and constants from the 802.11 standards, in machine-readable formats CTU-IIG/802.11p-wireless-regdb – Wireless regulatory database for CRDA flupzor/80211-fun – Fun with 80211 frames. mcgrof/acs – Automatic…
-
Heartbleed Scanner – Network Scanner for OpenSSL Memory Leak (CVE-2014-0160)
Heartbleed Scanner – Network Scanner for OpenSSL Memory Leak (CVE-2014-0160) -t parameter to optimize the timeout in seconds. -f parameter to log the memleak of vulnerable systems. -n parameter to scan entire network. -i parameter to scan from a list file. Useful if you already have targets. -r parameter to…
-
w3tw0rk / Pitbull Perl IRC Bot Remote Code Execution PoC Exploit by Shipcode
The Pitbull and w3tw0rk IRC bots contain a flaw that is triggered as input is not properly sanitized when handling channel PRIVMSGs. This may allow a remote attacker to execute arbitrary commands. # thehunter.py # Exploit Title: Pitbull / w3tw0rk Perl IRC Bot Remote Code Execution # Author: Jay Turla…
