Posts

Showing posts with the label Fingerprinting

Scannerl - The Modular Distributed Fingerprinting Engine

Image
Scannerl is a modular distributed fingerprinting engine implemented past times Kudelski Security . Scannerl tin give the axe fingerprint thousands of targets on a unmarried host, but tin give the axe precisely every bit easily last distributed across multiple hosts. Scannerl is to fingerprinting what zmap is to port scanning. Scannerl industrial plant on Debian/Ubuntu/Arch (but volition likely locomote on other distributions every bit well). It uses a master/slave architecture where the master copy node volition distribute the locomote (host(s) to fingerprint) to its slaves (local or remote). The entire deployment is transparent to the user. Why job Scannerl When using conventional fingerprinting tools for large-scale analysis, safety researchers volition oftentimes hitting 2 limitations: first, these tools are typically built for scanning comparatively few hosts at a fourth dimension as well as are inappropriate for large ranges of IP addresses. Second, if large hit of IP...

Hassh - A Network Fingerprinting Measure Which Tin Locomote Used To Grade Specific Customer As Well As Server Ssh Implementations

Image
"HASSH" is a network fingerprinting criterion which tin live on used to position specific Client too Server SSH implementations. The fingerprints tin live on easily stored, searched too shared inwards the shape of an MD5 fingerprint. What tin HASSH tending with: Use inwards highly controlled, good understood environments, where whatever fingerprints exterior of a known adept laid upward are alertable. It is possible to detect, command too investigate brute force or Cred Stuffing password attempts at a higher degree of granularity than IP Source - which may live on impacted past times NAT or botnet-like behaviour. The hassh volition live on a characteristic of the specific Client software implementation beingness used, fifty-fifty if the IP is NATed such that it is shared past times many other SSH clients. Detect covert exfiltration of information inside the components of the Client algorithm sets. In this case, a particularly coded SSH Client tin ship information o...

Lightbulb Framework - Tools For Auditing Wafs

Image
LightBulb is an opened upwards source python framework for auditing spider web application firewalls as well as filters. Synopsis The framework consists of ii top dog algorithms: GOFA : An active learning algorithm that infers symbolic representations of automata inwards the measure membership/equivalence inquiry model. Active learning algorithms permits the analysis of filter as well as sanitizer programs remotely, i.e. given simply the mightiness to inquiry the targeted plan as well as honour the output. SFADiff : Influenza A virus subtype H5N1 black-box differential testing algorithm based on Symbolic Finite Automata (SFA) learning Finding differences betwixt programs alongside similar functionality is an of import safety work every bit such differences tin live on used for fingerprinting or creating evasion attacks against safety software similar Web Application Firewalls (WAFs) which are designed to give away malicious inputs to spider web applications. Motivati...

Aztarna - A Footprinting Tool For Robots

Image
This repository contains Alias Robotics' aztarna, a footprinting tool for robots. Alias Robotics supports original robot manufacturers assessing their safety too improving their character of software. By no way nosotros encourage or promote the unauthorized tampering amongst running robotic systems. This tin displace serious human harm too cloth damages. For ROS A listing of the ROS nodes acquaint inward the organisation (Publishers too Subscribers) For each node, the published too subscribed topis including the theme type For each node, the ROS services each of the nodes offer A listing of all ROS parameters acquaint inward the Parameter Server A listing of the active communications running inward the system. H5N1 unmarried communication includes the involved publiser/subscriber nodes too the topics For SROS Determining if the organisation is a SROS master. Detecting if demo configuration is inward use. A listing of the nodes institute inward the system. (E...

Adapt - Tool That Performs Automated Penetration Testing For Webapps

Image
ADAPT is a tool that performs Automated Dynamic Application Penetration Testing for spider web applications. It is designed to growth accuracy, speed, too confidence inward penetration testing efforts. ADAPT automatically tests for multiple manufacture measure OWASP Top 10 vulnerabilities, too outputs categorized findings based on these potential vulnerabilities. ADAPT also uses the functionality from OWASP ZAP to perform automated active too passive scans, too auto-spidering. Due to the flexible nature of the ADAPT tool, all of theses features too tests tin endure enabled or disabled from the configuration file. For to a greater extent than information on tests too configuration, delight view the ADAPT wiki. How it Works ADAPT uses Python to practise an automated framework to utilization manufacture measure tools, such every bit OWASP ZAP too Nmap, to perform repeatable, well-designed procedures alongside anticipated results to practise an easly understandable written report ...

Joy - A Packet For Capturing As Well As Analyzing Network Menstruation Information As Well As Intraflow Data, For Network Research, Forensics, As Well As Safety Monitoring

Image
Joy is a BSD-licensed libpcap-based software bundle for extracting information features from alive network traffic or packet capture (pcap) files, using a flow-oriented model like to that of IPFIX or Netflow, too and then representing these information features inward JSON. It also contains analysis tools that tin travel applied to these information files. Joy tin travel used to explore information at scale, peculiarly safety too threat-relevant data. JSON is used inward social club to brand the output easily consumable past times information analysis tools. While the JSON output files are somewhat verbose, they are reasonably small, too they response good to compression. Joy tin travel configured to obtain intraflow data, that is, information too information virtually events that hap inside a network flow, including: the sequence of lengths too arrival times of IP packets, upwards to roughly configurable number of packets. the empirical probability distrib...