Posts

Showing posts with the label TLS

Modlishka - An Opened Upwards Rootage Phishing Tool Alongside 2Fa Authentication

Image
Modlishka is a flexible too powerful contrary proxy, that volition stimulate got your phishing campaigns to the adjacent marking (with minimal endeavor required from your side). Enjoy :-) Features Some of the near of import 'Modlishka' features : Support for bulk of 2FA authentication schemes (by design). No website templates (just indicate Modlishka to the target domain - inwards near cases, it volition hold upwardly handled automatically). Full command of "cross" root TLS traffic period of time from your victims browsers. Flexible too easily configurable phishing scenarios through configuration options. Pattern based JavaScript payload injection. Striping website from all encryption too safety headers (back to 90's MITM style). User credential harvesting (with context based on URL parameter passed identifiers). Can hold upwardly extended alongside your ideas through plugins. Stateless design. Can hold upwardly scaled upwardly easily for an arb...

Freevulnsearch - Costless As Well As Opened Upwards Nmap Nse Script To Question Vulnerabilities Via The Cve-Search.Org Api

Image
This NMAP NSE script is component division of the Free OCSAF projection - https://freecybersecurity.org . In conjunction alongside the version scan "-sV" inwards NMAP, the corresponding vulnerabilities are automatically assigned using CVE (Common Vulnerabilities as well as Exposures) as well as the severity of the vulnerability is assigned using CVSS (Common Vulnerability Scoring System). For to a greater extent than clarity, the CVSS are however assigned to the corresponding v3.0 CVSS ratings: Critical (CVSS 9.0 - 10.0) High (CVSS 7.0 - 8.9) Medium (CVSS 4.0 - 6.9) Low (CVSS 0.1 - 3.9) None (CVSS 0.0) The CVEs are queried past times default using the CPEs determined past times NMAP via the ingenious as well as world API of the cve-search.org project, which is provided past times circl.lu. For to a greater extent than information catch https://www.cve-search.org/api/ . Confidentiality information: The queries are made using the determined CPE via the circl.lu...

Joy - A Packet For Capturing As Well As Analyzing Network Menstruation Information As Well As Intraflow Data, For Network Research, Forensics, As Well As Safety Monitoring

Image
Joy is a BSD-licensed libpcap-based software bundle for extracting information features from alive network traffic or packet capture (pcap) files, using a flow-oriented model like to that of IPFIX or Netflow, too and then representing these information features inward JSON. It also contains analysis tools that tin travel applied to these information files. Joy tin travel used to explore information at scale, peculiarly safety too threat-relevant data. JSON is used inward social club to brand the output easily consumable past times information analysis tools. While the JSON output files are somewhat verbose, they are reasonably small, too they response good to compression. Joy tin travel configured to obtain intraflow data, that is, information too information virtually events that hap inside a network flow, including: the sequence of lengths too arrival times of IP packets, upwards to roughly configurable number of packets. the empirical probability distrib...