Posts

Showing posts with the label Scan

Robber - Tool For Finding Executables Prone To Dll Hijacking

Image
Robber is a costless opened upwardly source tool developed using Delphi XE2 without whatever third political party dependencies. What is DLL hijacking ?! Windows has a search path for DLLs inwards its underlying architecture. If yous tin figure out what DLLs an executable requests without an absolute path (triggering this search process), yous tin as well as then house your hostile DLL somewhere above the search path thence it'll live on constitute earlier the existent version is, as well as Windows volition happilly feed your laid upwardly on code to the application. So, let's pretend Windows's DLL search path looks something similar this: A) . <-- electrical flow working directory of the executable, highest priority, showtime check B) \Windows C) \Windows\system32 D) \Windows\syswow64 <-- lowest priority, final check as well as unopen to executable "Foo.exe" requests "bar.dll", which happens to alive ...

Ssh Auditor - The Best Trend To Scan For Weak Ssh Passwords On Your Network

Image
The Best Way To Scan For Weak Ssh Passwords On Your Network Features ssh-auditor volition automatically: Re-check all known hosts every bit novel credentials are added. It volition solely cheque the novel credentials. Queue a amount credential scan on whatever novel host discovered. Queue a amount credential scan on whatever known host whose ssh version or primal fingerprint changes. Attempt ascendency execution likewise every bit endeavor to tunnel a TCP connection. Re-check each credential using a per credential scan_interval - default xiv days. It's designed in addition to then that yous tin run ssh-auditor discover + ssh-auditor scan from cron every hr to to perform a constant audit. Demos Earlier demo showing all of the features Demo showing improved log output Usage Install $ brew install instruct # or withal yous desire to install the instruct compiler $ instruct start github.com/ncsa/ssh-auditor or Build from a git clone $ instruct build ...

Cms Scanner - Scan Wordpress, Drupal, Joomla, Vbulletin Websites For Safety Issues

Image
Scan Wordpress, Drupal, Joomla, vBulletin websites for Security issues. CMSScan provides a centralized Security Dashboard for CMS Security scans. It is powered past times wpscan, droopescan, vbscan as well as joomscan. It supports both on involve as well as scheduled scans as well as has the might to sent electronic mail reports. Install # Requires ruby, ruby-dev, gem, python3 as well as git git clone https://github.com/ajinabraham/CMSScan.git cd CMSScan ./setup.sh Run ./run.sh Periodic Scans You tin perform periodic CMS scans alongside CMSScan. You must piece of work CMSScan server separately as well as configure the next earlier running the scheduler.py script. # SMTP SETTINGS SMTP_SERVER = '' FROM_EMAIL = '' TO_EMAIL = '' # SERVER SETTINGS SERVER = '' # SCAN SITES WORDPRESS_SITES = [] DRUPAL_SITES = [] JOOMLA_SITES = [] VBULLETIN_SITES = [] Add a cronjob crontab -e @weekly /usr/bin/python3 scheduler.py Docker Local docker...

Sn1per V6.0 - Automated Pentest Framework For Offensive Safety Experts

Image
Sn1per Community Edition is an automated scanner that tin travel used during a penetration test to enumerate as well as scan for vulnerabilities. Sn1per Professional is Xero Security's premium reporting addon for Professional Penetration Testers, Bug Bounty Researchers as well as Corporate Security teams to deal large environments as well as pentest scopes. SN1PER PROFESSIONAL FEATURES: Professional reporting interface Slideshow for all gathered screenshots Searchable as well as sortable DNS, IP as well as opened upwardly port database Categorized host reports Quick links to online recon tools as well as Google hacking queries Personalized notes champaign for each host DEMO VIDEO: SN1PER COMMUNITY FEATURES:  Automatically collects basic recon (ie. whois, ping, DNS, etc.)  Automatically launches Google hacking queries against a target domain  Automatically enumerates opened upwardly ports via NMap port scanning  Auto...

Trape V2.0 - People Tracker On The Internet: Osint Analysis In Addition To Inquiry Tool

Image
Trape is a OSINT analysis in addition to query tool, which allows people to rails in addition to execute intelligent social engineering attacks inwards existent time. It was created amongst the aim of teaching the footing how large Internet companies could obtain confidential information such every bit the condition of sessions of their websites or services in addition to command over their users through the browser, without them knowing, but It evolves amongst the aim of helping government organizations, companies in addition to researchers to rails the cybercriminals. At the commencement of the yr 2018 was presented at BlackHat Arsenal inwards Singapore : https://www.blackhat.com/asia-18/arsenal.html#jose-pino in addition to inwards multiple safety events worldwide. Some benefits LOCATOR OPTIMIZATION: Trace the path betwixt you lot in addition to the target you're tracking. Each fourth dimension you lot brand a move, the path volition survive updated, past t...

Mcextractor - Intel, Amd, Via & Freescale Microcode Extraction Tool

Image
Intel, AMD, VIA & Freescale Microcode Extraction Tool MC Extractor News Feed MC Extractor Discussion Topic Intel, AMD & VIA CPU Microcode Repositories A. About MC Extractor MC Extractor is a tool which parses Intel, AMD, VIA as well as Freescale processor microcode binaries. It tin sack live used yesteryear end-users who are looking for all relevant microcode information such equally CPUID, Platform, Version, Date, Release, Size, Checksum etc. It is capable of converting Intel microcode containers (dat, inc, h, txt) to binary images for BIOS integration, detecting new/unknown microcodes, checking microcode health, Updated/Outdated condition as well as more. MC Extractor tin sack live also used equally a query analysis tool amongst multiple structures which allow, amid others, total parsing & information display of all documented or non microcode Headers. Moreover, amongst the aid of its extensive database, MC Extractor is capable of uniquely categorizing all su...

Hayat - Auditing & Hardening Script For Google Cloud Platform

Image
Hayat is a auditing & hardening script for Google Cloud Platform services such as: Identity & Access Management Networking Virtual Machines Storage Cloud SQL Instances Kubernetes Clusters for now. Identity & Access Management Ensure that corporate login credentials are used instead of Gmail accounts. Ensure that at that spot are entirely GCP-managed service trouble concern human relationship keys for each service account. Ensure that ServiceAccount has no Admin privileges. Ensure that IAM users are non assigned Service Account User role at projection level. Networking Ensure the default network does non be inward a project. Ensure legacy networks does non exists for a project. Ensure that DNSSEC is enabled for Cloud DNS. Ensure that RSASHA1 is non used for key-signing cardinal inward Cloud DNS DNSSEC. Ensure that RSASHA1 is non used for zone-signing cardinal inward Cloud DNS DNSSEC. Ensure that RDP access is restricted from the Internet. Ensur...

Mec V1.4.0 - Majority Exploit Console

Image
massExploitConsole a collection of hacking tools alongside a cli ui. Disclaimer please role this tool exclusively on authorized systems , im non responsible for whatsoever harm caused past times users who ignore my warning exploits are adapted from other sources, delight refer to their writer info please note, due to my express programming sense (it's my kickoff Python project), you lot tin facial expression or hence light-headed bugs Features an easy-to-use cli ui execute whatsoever adpated exploits alongside process-level concurrency some built-in exploits (automated) hide your ip addr using proxychains4 in addition to ss-proxy (built-in) zoomeye host scan (10 threads) a elementary baidu crawler (multi-threaded) censys host scan Getting started git clone https://github.com/jm33-m0/massExpConsole.git && cd massExpConsole && ./install.py when installing pypi deps, apt-get install libncurses5-dev (for Debian-based distros) mightin...

Evilginx2 V2.2.0 - Standalone Man-In-The-Middle Assault Framework Used For Phishing Login Credentials Along Amongst Session Cookies, Allowing For The Bypass Of 2-Factor Authentication

Image
evilginx2 is a man-in-the-middle assault framework used for phishing login credentials along amongst session cookies, which inwards plough allows to bypass 2-factor authentication protection. This tool is a successor to Evilginx , released inwards 2017, which used a custom version of nginx HTTP server to supply man-in-the-middle functionality to human activeness equally a proxy betwixt a browser in addition to phished website. Present version is fully written inwards GO equally a standalone application, which implements its ain HTTP in addition to DNS server, making it extremely slow to prepare in addition to use. Video See evilginx2 inwards activeness here: Evilginx ii - Next Generation of Phishing 2FA Tokens from breakdev.org on Vimeo . Write-up If y'all desire to larn to a greater extent than close this phishing technique, I've published an extensive weblog post service close evilginx2 here: https://breakdev.org/evilginx-2-next-generation-of-phishing-...

Cameradar V2.1.0 - Hacks Its Mode Into Rtsp Videosurveillance Cameras

Image
   An RTSP flow access tool that comes alongside its library Cameradar allows you lot to Detect opened upward RTSP hosts on whatever accessible target host Detect which device model is streaming Launch automated dictionary attacks to larn their stream route (e.g.: /live.sdp ) Launch automated lexicon attacks to larn the username in addition to password of the cameras Retrieve a consummate in addition to user-friendly study of the results Docker Image for Cameradar Install docker on your machine, in addition to run the next command: docker run -t ullaakut/cameradar -t <target> <other command-line options> See command-line options . e.g.: docker run -t ullaakut/cameradar -t 192.168.100.0/24 -l volition scan the ports 554 in addition to 8554 of hosts on the 192.168.100.0/24 subnetwork in addition to laid on the discovered RTSP streams in addition to volition output debug logs. YOUR_TARGET tin hold out a subnet (e.g.: 172.16.100.0/24 )...