Showing posts with label Tools. Show all posts
Showing posts with label Tools. Show all posts

WAVSEP 2014 Web Application Scanner Benchmark

The *2014* WAVSEP web application scanner benchmark has been published

Currently includes new products that were tested for the first time (ScanToSecure, N-Stalker), as well as returning vendors that were not tested for a while (NTOSpider).

Covering a total *63* vulnerability scanners, including commercial scanners, multiple SAAS engines and open source vendors, the research compares the performance of the various tested scanners in the following aspects:

(*) Prices vs. Features
(*) Automated Crawling (WIVET)
(*) Technology and Input Delivery Method Support
(*) Backup/Hidden File Detection Accuracy (*NEW!*)
(*) Unvalidated Redirect Detection Accuracy (*NEW!*)
(*) SQL Injection Detection Accuracy
(*) Cross Site Scripting Detection Accuracy
(*) Path Traversal / LFI Detection Accuracy
(*) (XSS/Phishing via) Remote File Inclusion
(*) Supported Vulnerability Detection Features (e.g. audit features)
(*) Authentication and Usability Features
(*) Coverage and Scan Barrier Support (AntiCSRF Tokens, CAPTCHA, etc)
(*) Etc

The benchmark *one page* result summary can be viewed through the following link:

The full article, which includes analysis and conclusions, can be accessed through the following link:

To be up to date with all news just follow https://twitter.com/sectooladdict

Faraday - Penetration Test IDE

Faraday introduces a new concept (IPE) Integrated Penetration-Test Environment a multiuser Penetration test IDE. Designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

Features:

* +40 Plugins (Metasploit, Amap, Arachini, Dnsenum, Medusa, Nmap, Nessus, w3af, Zap and More!)
* Collaborative support
* Information Highlighting
* Knowledge Filtering
* Information Dashboard
* Conflict Detection
* Support for multiple Workspaces
* IntelliSense Support
* Easy Plugin Development
* XMLRPC, XML and Regex Parsers

More info and Download: https://github.com/infobyte/faraday

Evil Foca - IPv4 and IPv6 Penetration testing tool

 


Evil Foca is a tool for Pentesters and Security Auditors to perform security testing in IPv4/ IPv6 data networks.  


The tool is capable to do different attacks such as:
  • MITM on IPv4 networks using ARP Spoofing and DHCP ACK injection.
  • MITM on IPv6 networks using Neighbor Advertisement Spoofing, SLAAC Attack, fake DHCPv6.
  • DoS (Denial of Service) on IPv4 networks using ARP Spoofing.
  • DoS (Denial of Service) on IPv6 networks using SLAAC Attack.
  • DNS Hijacking. 

Download: http://www.informatica64.com

Retire.js - Command line Scanner and Chrome plugin

 Retire.js identify JavaScript libraries with known vulnerabilities in your application  


Retire.js is a command line scanner that helps you identify dependencies with known vulnerabilites in your application. Using the provided Grunt plugin you can easily include Retire.js into your build process. Retire.js also provides a chrome extension allowing you to detect libraries while surfing your website.

To detect a given version of a given component, Retire.js uses filename or URL. If that fails, it will download/open the file and look for specific comments within the file. If that also fails, there is the possibility to use hashes for minified files. And if that fails as well, the Chrome plugin will run code in a sandbox to try to detect the component and version. This last detection mechanims is not available in the command line scanner, as running arbitrary JavaScript-files in the node-process could have unwanted consequences. If anybody knows of a good way to sandbox the code on node, feel free to register and issue or contribute. 

It's important to note that even though your site is using a vulnerable library, that does not necessarily mean your site is vulnerable. It depends on whether and how your site exercises the vulnerable code. That said, it's better to be safe than sorry. 

More Info and Download: https://github.com/bekk/retire.js
                                           

SpearPhisher � A Simple Phishing Email Generation Tool




SpearPhisher is a simple point and click Windows GUI tool designed for (mostly) non-technical people who would like to supplement the education and awareness aspect of their information security program. Not only is it useful to non-technical folks, penetration testers may find it handy for sending quick and easy ad-hoc phishing emails. The tool supports specifying different sending names and email addresses, multiple recipients via TO, CC, BCC, and allows bulk loading with one recipient email address per line in a file. It allows customization of the subject, adding one attachment, and SSL support for SMTP enabled mail servers. One of the popular features with our client is the WYSIWYG HTML editor that allows virtually anyone to use the tool; previewing results as you point and click edit your malicious email body. If you want to add custom XSS exploits, client side attacks, or other payloads such as a Java Applet code generated by the Social Engineer Toolkit (SET), its split screen editor allows more advanced users to edit HTML directly.


Download and more info: https://www.trustedsec.com/september-2013/introducing-spearphisher-simple-phishing-email-generation-tool/

CookieCatcher - Session Hijacking Tool

CookieCatcher is an open source application which was created to assist in the exploitation of XSS (Cross Site Scripting) vulnerabilities within web applications to steal user session IDs (aka Session Hijacking). The use of this application is purely educational and should not be used without proper permission from the target application.

Features:
- Prebuilt payloads to steal cookie data
- Just copy and paste payload into a XSS vulnerability
- Will send email notification when new cookies are stolen
- Will attempt to refresh cookies every 3 minutes to avoid inactivity timeouts
- Provides full HTTP requests to hijack sessions through a proxy (BuRP, etc)
- Will attempt to load a preview when viewing the cookie data
- PAYLOADS
- Basic AJAX Attack
- HTTPONLY evasion for Apache CVE-20120053
- More to come

Video Demo: http://www.youtube.com/watch?v=2GH6RRozOpY

Download: https://github.com/DisK0nn3cT/CookieCatcher

GoLismero - The Web Knife Version 2.0 beta Released

GoLismero is an open source framework for security testing. It's currently geared towards web security, but it can easily be expanded to other kinds of scans. 

The most interesting features of the framework are:
  • Real platform independence. Tested on Windows, Linux, *BSD and OS X.
  • No native library dependencies. All of the framework has been written in pure Python.
  • Good performance when compared with other frameworks written in Python and other scripting languages.
  • Very easy to use.
  • Plugin development is extremely simple.
  • The framework also collects and unifies the results of well known tools: sqlmap, xsser, openvas, dnsrecon, theharvester...
  • Integration with standards: CWE, CVE and OWASP. 
Get  GoLismero from http://golismero-project.com

    ZMap Internet Scanner v1.0.3 Released

    ZMap is a fast network scanner designed for Internet-wide network surveys. On a
    typical desktop computer with a gigabit Ethernet connection, ZMap is capable
    scanning the entire public IPv4 address space in under 45 minutes.

    While previous network tools have been designed to scan small network segments,
    ZMap is specifically architected to scan the entire address space. It is built
    in a modular manner in order to allow incorporation with other network survey
    tools. ZMap operates on GNU/Linux and supports TCP SYN and ICMP echo request
    scanning out of the box.


    Download and more info: https://zmap.io

    WATOBO 0.9.13 Released

    WATOBO is intended to enable security professionals to perform highly efficient (semi-automated ) web application security audits. WATOBO works like a local proxy, similar to Webscarab, Paros or BurpSuite. Additionally, WATOBO supports passive and active checks. Passive checks are more like filter functions. They are used to collect useful information, e.g. email or IP addresses. Passive checks will be performed during normal browsing activities. No additional requests are sent to the (web) application.

    New Features:

    * WATOBO has Session Management capabilities! You can define login scripts as well as logout signatures.
    * WATOB can act as a transparent proxy (requires nfqueue)
    * WATOBO can perform vulnerability checks out of the box
    * WATOBO can perform checks on functions which are protected by Anti-CSRF-/One-Time-Tokens
    * WATOBO supports Inline De-/Encoding.
    * WATOBO has smart filter functions, so you can find and navigate to the most interesting parts of the application easily.
    * WATOBO is written in (FX)Ruby and enables you to easily define your own checks
    * WATOBO runs on Windows, Linux, MacOS ... every OS supporting (FX)Ruby
    * WATOBO is free software ( licensed under the GNU General Public License Version 2)  

    Download: http://sourceforge.net/projects/watobo/

    Zarp - Network Attack Framework

    Zarp is a network attack tool centered around the exploitation of local networks. This does not include system exploitation, but rather abusing networking protocols and stacks to take over, infiltrate, and knock out. Sessions can be managed to quickly poison and sniff multiple systems at once, dumping sensitive information automatically or to the attacker directly. Various sniffers are included to automatically parse usernames and passwords from various protocols, as well as view HTTP traffic and more. DoS attacks are included to knock out various systems and applications. These tools open up the possibility for very complex attack scenarios on live networks quickly, cleanly, and quietly.  

     Functionality:

    - Poisoners
    - Parameter
    - Services
    - Sessions
    - Scanners
    - DoS Attacks
    - Sniffers

    Download: https://github.com/hatRiot/zarp
                      https://defense.ballastsecurity.net/wiki/index.php/Zarp

    Nishang v.0.2.7 Released

    PowerShell for Penetration Testing  

    Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security and post exploitation during Penetraion Tests. The scripts are written on the basis of requirement by the author during real Penetration Tests.It contains many interesting scripts like download and execute, keylogger, dns txt pwnage, wait for command and much more.   

    Changelog:
    - DNS_TXT_Pwnage, Time_Execution and Wait_For_Command can now be stopped remotely. Also, these does not stop autmoatically after running a script/command now.
    - DNS_TXT_Pwnage, Time_Execution and Wait_For_Command can now return results using selected exfiltration method.
    - Fixed a minor bug in DNS_TXT_Pwnage.
    - All payloads which could post data to the internet now have three options pastebin/gmail/tinypaste for exfiltration.
    - Added Get-PassHashes payload.
    - Added Download-Execute-PS payload.
    - The keylogger logs only fresh keys after exfiltring the keys 30 times.
    - A delay after success has been introduced in various payloads which connect to the internet to avoid generating too much traffic.  

    Download: http://code.google.com/p/nishang/downloads/list

    PenQ - The Security Testing Browser Bundle

    PenQ is an open source Linux based penetration testing browser bundle we built over Mozilla Firefox. It comes pre-configured with security tools for spidering, advanced web searching, fingerprinting, anonymous browsing, web server scanning, fuzzing, report generating and more. 


    PenQ is configured to run on Debian based distributions including Ubuntu and its derivative distros, and penetration testing operating systems such as BackTrack and Kali.With all its integrations, PenQ is a powerful tool. Be mindful of what use you put it to. Responsible use of PenQ can help secure web apps in a zap.

    Features

    • OWASP ZAP
    • OWASP WebScarab
    • OWASP WebSlayer
    • Nikto Web Server Scanner
    • Wfuzz Web Application Fuzzer
    • Mozilla Add-ons Collection
    • Integrated Tor
    • OWASP Penetration Testing Checklist
    • PenTesting Report Generator
    • Vulnerability Databases Search
    • Access to Shell and System Utilities
    • Collection of Useful Links
    Download and more info: http://www.qburst.com/products/PenQ

    DroidSQLi - MySQL Injection tool for Android

    DroidSQLi is the first automated MySQL Injection tool for Android. It allows you to test your MySQL-based web application against SQL injection attacks.  




    DroidSQLi supports the following injection techniques:
    - Time based injection
    - Blind injection
    - Error based injection
    - Normal injection

    Get it from  https://play.google.com/store/apps/details?id=net.edgard.droidsqli

    SpiderFoot v.2.0 Released



    Open source Footprinting tool 

    SpiderFoot is an open source footprinting tool, available for Windows and Linux. It is written in Python and provides an easy-to-use GUI. SpiderFoot obtains a wide range of information about a target, such as web servers, netblocks, e-mail addresses and more.


    SpiderFoot is designed from the ground-up to be modular. This means you can easily add your own modules that consume data from other modules to perform whatever task you desire.
    As a simple example, you could create a module that automatically attempts to brute-force usernames and passwords any time a password-handling webpage is identified by the spidering module.



    Download:  https://github.com/smicallef/spiderfoot
                       http://sourceforge.net/projects/spiderfoot/

    More Info:  http://www.spiderfoot.net

    Arachni v0.4.2 Released

    Web Application Security Scanner Framework

    Arachni is an Open Source, feature-full, modular, high-performance Ruby framework aimed towards helping penetration testers and administrators evaluate the security of web applications. It is smart, it trains itself by learning from the HTTP responses it receives during the audit process and is able to perform meta-analysis using a number of factors in order to correctly assess the trustworthiness of results and intelligently identify false-positives. It is versatile enough to cover a great deal of use cases, ranging from a simple command line scanner utility, to a global high performance grid of scanners, to a Ruby library allowing for scripted audits, to a multi-user multi-scan web collaboration platform.  

    The change-log is quite sizeable but the gist is:

    * Brand new web interface -- allowing for team collaboration.
    * Significant decreases in memory usage.
    * Issue remarks � Providing extra context to logged issues.
    * Improved payloads for Windows machines for path traversal and OS command injection.
    * RPC API updates allowing for much easier remote scan management.
    * Much improved profiling and detection of custom 404 responses.
    * The ability to exclude pages from the scan based on content.


    For more details and Download visit:    http://www.arachni-scanner.com

    Canari Framework

    Canari - Maltego Rapid Transform Development Framework  

    Canari is a rapid transform development framework for Maltego written in Python. The original focus of Canari was to provide a set of transforms that would aid in the execution of penetration tests, and vulnerability assessments. Ever since it's first prototype, it has become evident that the framework can be used for much more than that. Canari is perfect for anyone wishing to graphically represent their data in Maltego without the hassle of learning a whole bunch of unnecessary stuff. It has generated interest from digital forensics analysts to pen-testers, and even psychologists.  
     
    Canari's core features include:   
    - An easily extensible and configurable framework that promotes maximum reusability;  
    - A set of powerful and easy-to-use scripts for debugging, configuring, and installing transforms; 
    -Finally, a great number of community provided transforms.


    More info and Download: http://www.canariproject.com 

    Video demo: http://www.youtube.com/allfro

    XSSF - Cross-Site Scripting Framework v.3.0 Released

    The Cross-Site Scripting Framework (XSSF) is a security tool designed to turn the XSS vulnerability exploitation task into a much easier work. The XSSF project aims to demonstrate the real dangers of XSS vulnerabilities, vulgarizing their exploitation. This project is created solely for education, penetration testing and lawful research purposes. 

    XSSF allows creating a communication channel  with the targeted browser (from a XSS vulnerability) in order to perform further attacks. Users are free to select existing modules (a module = an attack) in order to target specific browsers.

    XSSF provides a powerfull documented API, which facilitates development of modules and attacks. In addition, its integration into the Metasploit Framework allows users to launch MSF browser based exploit easilly from an XSS vulnerability.


    XSSF Basics: Install on Kali-1.0 Video Demo : http://www.youtube.com/watch?v=AhUhOirEfTE

    Download: https://code.google.com
     

    jSQL Injection v0.3



     jSQL Injection is a lightweight application used to find database information from a distant server. 

    jSQL is free, open source and cross-platform (Windows, Linux, Mac OS X, Solaris). 





    Features:
    • GET, POST, header, cookie methods
    • Normal, error based, blind, time based algorithms
    • Automatic best algorithm selection
    • Thread control (start/pause/resume/stop)
    • Expose URL calls
    • Simple evasion
    • Data retrieving progression bar
    • Proxy setting
    • Distant file reading
    • Webshell deposit
    • Terminal for webshell commands
    • Configuration backup
    • jSQL version checker
    • Supports MySQL

    Download: https://code.google.com

    SCIP � Indentify, Enumerate and Execute Invisible ASP.net Controls



    SCIP is an OWASP ZAP extension designed to assess the security of ASP.net and Mono applications, while abusing platform specific behaviors and misconfigurations. 





    The extension currently supports the following features: 

    Identify the existence of invisible, commented and disabled server side web controls in ASP.net � passively (!). Identify which ASP.net security configuration is active in each page (EventValidation, MAC), and in which cases the invisible controls are exploitable � passively (!) 

    Enumerate the names of invisible controls using built-in customizable dictionaries with ASP.net naming conventions.
    Rebuild the event validation whenever possible (MAC=off)

    Execute invisible controls when either one of the security features is turned OFF, or when there is a server-side callback implementation flaw.
     
    Execute disabled controls and commented out controls regardless of security
    Support additional manual techniques for executing controls despite the security features.

    The extension can be obtained from the project's website or from ZAP's built-in marketplace feature: 

    https://code.google.com/p/ria-scip/

    WPScan - WordPress Security Scanner Android App.

    WPScan is a black box WordPress Security Scanner written in Ruby which attempts to find known security weaknesses within WordPress installations. Its intended use it to be for security professionals or WordPress administrators to asses the security posture of their WordPress installations.  




      Download: https://play.google.com  or from Github https://github.com

     

    AbheLink Black or White ? Copyright © 2011-2012 | Powered by Blogger