Posts

Showing posts with the label Testing

Babysploit - Babysplot Beginner Pentesting Framework

Image
Tested on Kali Linux. Should hold upwards alongside all Debian based distros (and other ones if you lot accept the correct packages installed) BabySploit is a penetration testing framework aimed at making it slow to larn how to purpose bigger, to a greater extent than complicated frameworks similar Metasploit. With a real slow to purpose UI in addition to toolkit, anybody from whatever sense score volition abide by purpose out of BabySploit. Features (Current, In The Works, Planned): Information Gathering Exploitation Post Exploitation Bruteforcing Phishing Cryptography/Stenography Information Gathering: Nmap IP Info Tcpdump (In The Works) Datasploit (In The Works) Censys Lookup DNS Lookup Exploitation: Searchsploit ReverseShell Wizard Post Exploitation: In The Works Bruteforcing: In The Works Phishing: BlackEye Python Crypto/Steno: MetaKiller (In The Works) Download BabySploit

Infection Monkey V1.6 - An Automated Pentest Tool

Image
The Infection Monkey is an opened upward source safety tool for testing a information center's resiliency to perimeter breaches in addition to internal server infection. The Monkey uses diverse methods to self-propagate across a information oculus in addition to reports success to a centralized Monkey Island server. The Infection Monkey is comprised of 2 parts: Monkey - H5N1 tool which infects other machines in addition to propagates to them Monkey Island - H5N1 dedicated server to command in addition to visualize the Infection Monkey's progress within the information center To read to a greater extent than almost the Monkey, see http://infectionmonkey.com Main Features The Infection Monkey uses the next techniques in addition to exploits to propagate to other machines. Multiple propagation techniques: Predefined passwords Common logical exploits Password stealing using Mimikatz Multiple exploit methods: SSH SMB RDP WMI Shellshock Conficker Sam...

Evilginx2 V2.2.0 - Standalone Man-In-The-Middle Assault Framework Used For Phishing Login Credentials Along Amongst Session Cookies, Allowing For The Bypass Of 2-Factor Authentication

Image
evilginx2 is a man-in-the-middle assault framework used for phishing login credentials along amongst session cookies, which inwards plough allows to bypass 2-factor authentication protection. This tool is a successor to Evilginx , released inwards 2017, which used a custom version of nginx HTTP server to supply man-in-the-middle functionality to human activeness equally a proxy betwixt a browser in addition to phished website. Present version is fully written inwards GO equally a standalone application, which implements its ain HTTP in addition to DNS server, making it extremely slow to prepare in addition to use. Video See evilginx2 inwards activeness here: Evilginx ii - Next Generation of Phishing 2FA Tokens from breakdev.org on Vimeo . Write-up If y'all desire to larn to a greater extent than close this phishing technique, I've published an extensive weblog post service close evilginx2 here: https://breakdev.org/evilginx-2-next-generation-of-phishing-...

Knock V.4.1.1 - Subdomain Scan

Image
Knockpy is a python tool designed to enumerate subdomains on a target domain through a wordlist. It is designed to scan for DNS zone transfer together with to endeavor to bypass the wildcard DNS record automatically if it is enabled. Now knockpy supports queries to VirusTotal subdomains, you lot tin setting the API_KEY inside the config.json file. Very simply $ knockpy domain.com Export amount study inwards JSON If you lot desire to relieve amount log like this one precisely type: $ knockpy domain.com --json Install Prerequisites Python 2.7.6 Dependencies Dnspython $ sudo apt-get install python-dnspython Installing $ git clone https://github.com/guelfoweb/knock.git $ cd knock $ nano knockpy/config.json <- prepare your virustotal API_KEY $ sudo python setup.py install Note that it's recommended to purpose Google DNS : 8.8.8.8 together with 8.8.4.4 Knockpy arguments $ knockpy -h usage: knockpy [-h] [-v] [-w WORDLIST] [-r] [-c] [-j] domain...

Scavenger - Is A Multi-Threaded Post-Exploitation Scanning Tool For Scavenging Systems, Finding Almost Ofttimes Used Files As Well As Folders Equally Good Equally Interesting Files Containing Sensitive Information

Image
scavenger : is a multi-threaded post-exploitation scanning tool for scavenging systems, finding close ofttimes used files as well as folders every bit good every bit "interesting" files containing sensitive information. Problem Definition: Scavenger confronts a challenging lawsuit typically faced yesteryear Penetration Testing consultants during internal penetration tests; the lawsuit of having besides much access to besides many systems alongside express days for testing. Requirements: Install CrackMapExec - CrackMapExec Installation Page Examples: $ python3 ./scavenger.py smb -t 10.0.0.10 -u administrator -p Password123 -d test.local $ python3 ./scavenger.py smb --target iplist --username administrator --password Password123 --domain test.local --overwrite Blog Post: Link to Trustwave SpiderLabs Blog Acknowledgements - Powered as well as Inspired by: Impacket (@agsolino) CrackMapExec (@byt3bl33d3r) ccsrch (@adamcaudill) LaZagne Download ...

Pe-Sieve - Recognizes In Addition To Dumps A Diversity Of Potentially Malicious Implants (Replaced/Injected Pes, Shellcodes, Hooks, In-Memory Patches)

Image
PE-sieve is a light-weight tool that helps to detect malware running on the system, equally good equally to collect the potentially malicious fabric for farther analysis. Recognizes in addition to dumps diversity of implants inside the scanned process: replaced/injected PEs, shellcodes, hooks, in addition to other in-memory patches. Detects inline hooks, Process Hollowing, Process Doppelgänging, Reflective DLL Injection, etc. uses library: https://github.com/hasherezade/libpeconv.git Clone: Use recursive clone to larn the repo together alongside the submodule: git clone --recursive https://github.com/hasherezade/pe-sieve.git Latest builds*: *those builds are available for testing in addition to they may last ahead of the official release : 32-bit 64-bit Download Pe-Sieve

Ftw - Framework For Testing Wafs

Image
This projection was created past times researchers from ModSecurity together with Fastly to help render rigorous tests for WAF rules. It uses the OWASP Core Ruleset V3 every bit a baseline to exam rules on a WAF. Each dominion from the ruleset is loaded into a YAML file that issues HTTP requests that volition trigger these rules. Users tin verify the execution of the dominion later on the tests are issued to brand certain the expected reply is received from an attack. Goals / Use cases include: Find regressions inwards WAF deployments past times using continuous integration together with issuing repeatable attacks to a WAF Provide a testing framework for novel rules into ModSecurity, if a dominion is submitted it MUST accept corresponding positive & negative tests Evaluate WAFs against a common, agreeable baseline ruleset (OWASP) Test together with verify custom rules for WAFs that are non business office of the heart dominion set For our 1.0 loose announcement,...

Adapt - Tool That Performs Automated Penetration Testing For Webapps

Image
ADAPT is a tool that performs Automated Dynamic Application Penetration Testing for spider web applications. It is designed to growth accuracy, speed, too confidence inward penetration testing efforts. ADAPT automatically tests for multiple manufacture measure OWASP Top 10 vulnerabilities, too outputs categorized findings based on these potential vulnerabilities. ADAPT also uses the functionality from OWASP ZAP to perform automated active too passive scans, too auto-spidering. Due to the flexible nature of the ADAPT tool, all of theses features too tests tin endure enabled or disabled from the configuration file. For to a greater extent than information on tests too configuration, delight view the ADAPT wiki. How it Works ADAPT uses Python to practise an automated framework to utilization manufacture measure tools, such every bit OWASP ZAP too Nmap, to perform repeatable, well-designed procedures alongside anticipated results to practise an easly understandable written report ...

Cdf - Crypto Differential Fuzzing

Image
CDF is a tool to automatically attempt the correctness in addition to safety of cryptographic software. CDF tin dismiss observe implementation errors, compliance failures, side-channel leaks, in addition to thus on. CDF implements a combination of unit of measurement tests amongst "differential fuzzing", an approach that compares the demeanor of unlike implementations of the same primitives when fed border cases in addition to values maximizing the code coverage. Unlike general-purpose fuzzers in addition to testing software, CDF is: Smart : CDF knows what form of algorithm it's testing in addition to adapts to the tested functions Fast : CDF tests alone what needs to last tested in addition to parallelizes its tests equally much equally possible Polyvalent : CDF isn't specific to whatever linguistic communication or API, but supports arbitrary executable programs or scripts Portable : CDF volition run on whatever Unix or Windows platfor...

Decker - Declarative Penetration Testing Orchestration Framework

Image
Decker is a penetration testing orchestration framework. It leverages HashiCorp Configuration Language 2 (the same config linguistic communication every bit Terraform ) to allow declarative penetration testing every bit code , too thus your tests tin hold upward versioned, shared, reused, too collaborated on amongst your squad or the community. Example of a decker config file: // variables are pulled from environs // ex: DECKER_TARGET_HOST // they volition hold upward available throughout the config files every bit var.* // ex: ${var.target_host} variable "target_host" { type = "string" } // resources refer to plugins // resources demand unique names too thus plugins tin hold upward used to a greater extent than than in 1 lawsuit // they are declared amongst the form: 'resource "plugin_name" "unique_name" {}' // their outputs volition hold upward available to others using the shape unique_name.* // ex: nmap.443 resourc...

Jwt Tool - A Toolkit For Testing, Tweaking Together With Non Bad Json Spider Web Tokens

Image
jwt_tool.py is a toolkit for validating, forging together with cracking JWTs (JSON Web Tokens). Its functionality includes: Checking the validity of a token Testing for the RS/HS256 world cardinal mismatch vulnerability Testing for the alg=None signature-bypass vulnerability Testing the validity of a secret/key/key file Identifying weak keys via a High-speed Dictionary Attack Forging novel token header together with payload values together with creating a novel signature alongside the key or via or thence other ready on method Audience This tool is written for pentesters , who bespeak to cheque the forcefulness of the tokens inward use, together with their susceptibility to known attacks. It may also live on useful for developers who are using JWTs inward projects, but would similar to examine for stability together with for known vulnerabilities, when using forged tokens. Requirements This tool is written natively inward Python 2.x using the mutual librarie...

Andrax V3 - The Starting Fourth Dimension As Well As Unique Penetration Testing Platform For Android Smartphones

Image
ANDRAX The showtime in addition to unique Penetration Testing platform for Android smartphones. Thanks to Jessica Helena she made ANDRAX v3 possible. What is ANDRAX ANDRAX is a penetration testing platform developed specifically for Android smartphones, ANDRAX has the might to run natively on Android then it behaves similar a mutual Linux distribution, But to a greater extent than powerful than a mutual distribution! Why is Android then powerful? Simple, everyone has a smartphone in addition to spends all the fourth dimension amongst it! We get got the possibility to camouflage easily inwards the middle of everyone, the processor architecture of most Android smartphones is ARM a modern in addition to robust architecture extremely superior to the rest, With impact screens nosotros tin flame run the tools amongst groovy agility in addition to accept payoff of the graphical interface of Android, nosotros tin flame arrive almost anywhere amongst our smartphones... ...