Sn1per is an automated scanner that can be used during a penetration test to enumerate and scan for vulnerabilities. Features Automatically collects basic recon (ie. whois, ping, DNS, etc.) Automatically launches Google hacking queries against a target domain Automatically enumerates open ports Automatically brute forces sub-domains and DNS info Automatically…
-
-
SPF – SpeedPhish Framework
SPF – SpeedPhish Framework -is a python tool designed to allow for quick recon and deployment of simple social engineering phishing exercises. Requirements: dnspython twisted PhantomJS Usage: usage: spf.py [-h] [-f ] [-C ] [--all] [--test] [-e] [-g] [-s] [--simulate] [-w] [-W] [-d ] [-c <company's name>] [--ip ] [-v]…
-
Damn Vulnerable iOS Application (DVIA)
Damn Vulnerable iOS Application was born from the need to have a tool where a user can test their iOS penetration testing skills in a safe and legal environment. Also, this application can be used by mobile security enthusiasts and students to learn or review the basics of mobile application…
-
Sentry – Bruteforce Attack Blocker
Sentry can detects and prevents bruteforce attacks against sshd using minimal system resources. Synopsis: sentry --ip=N.N.N.N [ --connect | --blacklist | --whitelist | --delist ] sentry --report [--verbose --ip=N.N.N.N ] sentry --help sentry --update Safe To prevent inadvertant lockouts, Sentry manages a whitelist of IPs that have connected more than 3 times…
-
Web Security Dojo – Stand-alone Training Environment for Web Application Security
Web Security Dojo is a preconfigured, stand-alone training environment for Web Application Security. Virtualbox and VMware versions for download. See “View all files” for VMware version. Features: Ethical hacking sandbox Pre-configured vulnerable targets Common web hacking tools Training materials and user guides for some targets What is Web Security…
-
XSSYA – Cross Site Scripting Scanner & Vulnerability Confirmation
XSSYA is a Cross Site Scripting Scanner & Vulnerability Confirmation that is working in two methods. Method number 1 for Confirmation Request and Response Method number 2 for Confirmation Execute encoded payload and search for the same payload in web HTML code but decoded What is Cross-site scripting (XSS) is…
-
WPScan1.1 Released – WordPress Security Scanner
WPScan is a vulnerability scanner which checks the security of WordPress installations using a black box approach. [singlepic id=59 w=320 h=240 float=] Changelog: Detection for 750 more plugins. Detection for 107 new plugin vulnerabilities. Detection for 447 possible timthumb file locations. Advanced version fingerprinting implemented. Full Path Disclosure (FPD) checks.…