Shocker is a tool to find and exploit servers vulnerable to Shellshock Released as open source by NCC Group Plc – https://www.nccgroup.trust/ Developed By: Tom Watson, tom [dot] watson [at] nccgroup [dot] trust https://github.com/nccgroup/shocker Help Text usage: shocker.py -h, --help show this help message and exit --Host HOST, -H HOST…
-
-
“Uptime Funk” Music Video (parody of Uptown Funk) from SUSECon 2015 in Amsterdam.
This awesome Video Parody of Uptown Funk for OpenSuse. Uptime Funk Uptown Funk is a chartbuster from Bruno Mars. A parody “Uptime Funk” of this song is just as awesome as the original. The video was released in SUSECon 2015. Lyrics: This bit Uncontrolled A bad bug, Make my…
-
Climber – Check UNIX/Linux Systems For Privilege Escalation
Automated auditing tool to check UNIX/Linux systems misconfigurations which may allow local privilege escalation. Dependencies python >= 2.7 python-crypto python-mako python-paramiko Note Climber needs Exscript, a Python module and a template processor for automating network connections over protocols such as Telnet or SSH. https://github.com/knipknap/exscript This module is already included in…
-
Appie v3 – Android Pentesting Portable Integrated Environment
Appie is a software package that has been pre-configured to function as an Android Pentesting Environment on any windows based machine without the need of a Virtual Machine(VM) or dualboot. It is completely portable and can be carried on USB stick or your smartphone. It is one of its kind…
-
ATSCAN – Search / Site / Server Scanner
ATSCAN – Search / Site / Server Scanner SEARCH engine XSS scanner. Sqlmap. LFI scanner. Filter wordpress and Joomla sites in the server. Find Admin page. Decode / Encode MD5 + Base64. Ports scan. Scan E-mails in sites. Use proxy. Random user agent. Fandom search engine. Scan errors. Detect Cms.…
-
SQLMap – Automatic SQL Injection And Database Takeover Tool
sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting,…
-
PyScan-Scanner – Vulnerability Scanner With Custom Payload
REQUIRE urllib2 BeautifulSoup requests START Change database information $bdd = new PDO('mysql:host=localhost;dbname=pyscan', 'user', 'password'); Update a Python gate panel_url = "http://localhost/pyscan/" gate_scraper = "cmd/gate.php" gate_scanner = "cmd/scan.php" gate_vuln = "cmd/vuln.php" gate_payload = "panel/api/payload.php" gate_database = "panel/api/database.php" Upload the .SQL mysql -u username -p database_name < file.sql Login Username: root password:…
-
VBScan – a Black Box vBulletin Vulnerability Scanner
VBScan is an opensource project in perl programming language to detect VBulletin CMS vulnerabilities and analyses them Why VBScan ? If you want to do a penetration test on a vBulletin Forum, VBScan is Your best shot ever! This Project is being faster than ever and updated with the latest…
-
Androl4b – A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis
AndroL4b is an android security virtual machine based on ubuntu-Mate includes the collection of latest framework, tutorials and labs from different security geeks and researcher for reverse engineering and malware analysis. Tools APKStudio Cross-platform Qt5 based IDE for reverse-engineering android applications ByteCodeViewer Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger)…
-
APK Studio – Cross-platform Qt5 based IDE for reverse-engineering android applications
APK Studio is a cross-platform IDE for reverse-engineering (decompiling/editing) & recompiling of android application binaries within a single user-interface. It features a friendly layout, with a code editor which support syntax highlighting for Android SMALI (*.smali) code files. Instructions: Make sure JAVA_HOME point to a valid JDK (JRE may not…

