[vc_row][vc_column][vc_column_text]Hashcatch deauthenticates clients connected to all nearby WiFi networks and tries to capture the handshakes. It can be used in any linux device including Raspberry Pi and Nethunter devices so that you can capture handshakes while walking your dog Written by @SivaneshAshok PoC of hashcatch (running with a couple of WiFi…
-
Hacking - Information Gathering - Linux - Networking - Password Attacks - Pentesting Tools - Vulnerability Scanner - Wireless Attacks - Wireless Network
-
jSQL Injection is a Java application for automatic SQL database injection.
jSQL Injection is a lightweight application used to find database information from a distant server. It is free, open source and cross-platform (Windows, Linux, Mac OS X). Kali Linux logo jSQL Injection is also part of the official penetration testing distribution Kali Linux and is included in other distributions like…
-
iCloudBrutter -AppleID Bruteforce Attack
iCloudBrutter is a simple python (3.x) script to perform basic bruteforce attack againts AppleID. Usage of iCloudBrutter for attacking targets without prior mutual consent is illegal. iCloudBrutter developer not responsible to any damage caused by iCloudBrutter. Installation $ git clone https://github.com/m4ll0k/iCloudBrutter.git $ cd iCloudBrutter $ pip3 install requests,urllib3,socks $…
-
Exploitation Tools - Pentesting Tools - PHP and Website Security - Python - Security Assessment Tool - Vulnerability Scanner - Web Application
XSStrike v2.0 – An Advanced XSS Detection And Exploitation Suit
XSStrike is an advanced XSS detection suite. It has a powerful fuzzing engine and provides zero false positive result using fuzzy matching. XSStrike is the first XSS scanner to generate its own payloads. It is intelligent enough to detect and break out of various contexts. Features: Powerful fuzzing engine Context…
-
CVE-2017-17411: Linksys WVBR0 25 Command Injection
Recently a security researcher Ricky Lawshae from Trend Micro discover a critical vulnerability on Linksys Wireless Bridge WVBR0-25 this allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0 WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal.…
-
Acunetix Free Manual Pen Testing Tools
Acunetix Manual Tools allow penetration testers to further automated testing. Scan your websites SQL Injection & Blind SQL Injection Cross-site Scripting (XSS) OWASP Top 10 and other vulnerabilities Use the HTTP Editor to modify or craft HTTP requests and analyze responses, intercept and modify HTTP traffic on the fly…
-
VBScan 0.1.7 – Black Box vBulletin Vulnerability Scanner
OWASP VBScan OWASP VBScan (short for [VB]ulletin Vulnerability [Scan]ner) is an opensource project in perl programming language to detect VBulletin CMS vulnerabilities and analyses them . Why OWASP VBScan ? If you want to do a penetration test on a vBulletin Forum, OWASP VBScan is Your best shot ever! This…
-
D-TECT – Pentesting the Modern Web
D-TECT is an All-In-One Tool for Penetration Testing. This is specially programmed for Penetration Testers and Security Researchers to make their job easier, instead of launching different tools for performing different task. D-TECT provides multiple features and detection features which gather target information and finds different flaws in it. Compatibility:…
-
Shadowd – The Shadow Daemon Web Application Firewall Server
Shadow Daemon is a collection of tools to detect, record and prevent attacks on web applications. Technically speaking, Shadow Daemon is a web application firewall that intercepts requests and filters out malicious parameters. It is a modular system that separates web application, analysis and interface to increase security, flexibility and…
-
XssPy – Web Application XSS Scanner
XssPy is a python tool for finding Cross Site Scripting vulnerabilities in websites. This tool is the first of its kind. Instead of just checking one page as most of the tools do, this tool traverses the website and find all the links and subdomains first. After that, it starts…
