<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tanasi.it &#187; hacker tools</title>
	<atom:link href="http://www.tanasi.it/tag/hacker-tools/feed" rel="self" type="application/rss+xml" />
	<link>http://www.tanasi.it</link>
	<description>Alessandro `jekil` Tanasi blog</description>
	<lastBuildDate>Fri, 02 Jul 2010 11:06:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Penetration Testing Tools</title>
		<link>http://www.tanasi.it/1188-penetration-testing-tools.html</link>
		<comments>http://www.tanasi.it/1188-penetration-testing-tools.html#comments</comments>
		<pubDate>Sun, 13 Jan 2008 16:03:44 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[In English]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[hacker tools]]></category>
		<category><![CDATA[hacking tools]]></category>
		<category><![CDATA[penetration testing]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=1103</guid>
		<description><![CDATA[Packet Shaper: Nemesis: a command line packet shaper Packit: The Packet Toolkit &#8211; A network packet shaper. Hping by Antirez: a command line TCP/IP packet shaper Sing: stands for &#8216;Send ICMP Nasty Garbage&#8217;; sends fully customizeable ICMP packets Scapy: a new python-based packet generator Password Cracker/Login Hacker: John the Ripper: a well-known password cracker for [...]]]></description>
			<content:encoded><![CDATA[<p class="smallheadline"><font color="#000000">Packet<br />
Shaper:</font></p>
<ul>
<li class="stdtext"><font color="#000000"><a href="http://www.packetfactory.net/projects/nemesis/" class="stdtext">Nemesis</a>:<br />
a command line packet shaper</font></li>
<li class="stdtext"><font color="#000000"><a href="http://packit.sourceforge.net/">Packit</a>:<br />
The Packet Toolkit &#8211; A network packet shaper.</font></li>
<li><font color="#000000"><span class="stdtext"><a href="http://www.hping.org/">Hping</a><br />
by Antirez: a command line TCP/IP packet shaper</span></font></li>
<li class="stdtext"><font color="#000000"><a href="http://sourceforge.net/projects/sing/">Sing</a>:<br />
stands for &#8216;Send ICMP Nasty Garbage&#8217;; sends fully customizeable ICMP<br />
packets</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.cartel-securite.fr/pbiondi/scapy.html">Scapy</a>:<br />
a new python-based packet generator </font></li>
</ul>
<p class="smallheadline"><font color="#000000">Password<br />
Cracker/Login Hacker:</font></p>
<ul>
<li class="stdtext"><font color="#000000"><a name="john"></a><a href="http://www.openwall.com/john/">John<br />
the Ripper</a>: a well-known<br />
password cracker for Windows and *nix Systems</font></li>
<li class="stdtext"><font color="#000000"><a href="http://ktulu.com.ar/en/djohn.php">Djohn</a>:<br />
a distributed password cracker based on &quot;<a href="http://www.forinsect.de/pentest/pentest-tools.html#john" target="_self">John<br />
the Ripper</a>&quot; </font></li>
<li class="stdtext"><font color="#000000"><a name="cainabel"></a><a href="http://www.oxid.it/cain.html">Cain<br />
&amp; Abel</a>: an advanced<br />
password recovery tool for windows systems. It sniffs the network<br />
packets an cracks authentication brute-force or with dictionary<br />
attacks. </font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.antsight.com/zsl/rainbowcrack/">Project<br />
RainbowCrack</a>: Advanced instant<br />
NT password cracker</font></li>
<li class="stdtext"><font color="#000000"><a href="http://rainbowtables.shmoo.com/">Rainbowtables</a>: <span class="stdtext">The<br />
shmoo group provides pre-generated rainbow tables for bittorrent<br />
download. The tables are generated with RainbowCrack (see above).</span></font></li>
<li><font color="#000000"><span class="stdtext">Windows<br />
NT<a href="http://home.eunet.no/%7Epnordahl/ntpasswd/"><br />
password recovery tool</a> by Peter<br />
Nordahl</span></font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.thc.org/releases.php">THC-Dialup<br />
Login Hacker</a> by THC. It tries to<br />
guess username and password against the modem carrier. As far as I know<br />
the only available dialup password guesser for *NIX. </font></li>
<li class="stdtext"><font color="#000000"><a name="hydra"></a><a href="http://www.thc.org/releases.php">Hydra</a><br />
by THC: a multi-protocol login hacker. Hydra is also integrated with <a href="http://www.forinsect.de/pentest/pentest-tools.html#nessus" target="_self">Nessus</a>.</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.foofus.net/jmk/medusa/medusa.html">Medusa</a>: parallel network login auditor</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.thc.org/root/tools/">THC<br />
imap bruter</a>: a very fast imap<br />
password brute forcer</font></li>
<li><font color="#000000"><span class="stdtext"><a href="http://wayreth.eu.org/x25bru.c">x25bru</a>:<br />
a login/password bruteforcer for x25 pad</span></font></li>
<li><font color="#000000"><span class="stdtext"><a href="http://www.sensepost.com/research/crowbar/">Crowbar</a>:  a generic web brute force tool (Windows only; requires .NET Framework)</span></font></li>
<li><font color="#000000"><span class="stdtext"><a href="http://membres.lycos.fr/mdcrack/nsindex.html">MDCrack-NG</a>: a very fast MD4/MD5/NTLMv1 hash cracker; works optionally with precomputed hash tables
<p>          </span></font></li>
</ul>
<p class="smallheadline"><font color="#000000">Advanced<br />
Sniffers:</font></p>
<ul>
<li class="stdtext"><font color="#000000"><a name="wireshark"></a><a href="http://www.wireshark.org/">Wireshark</a> (formerly known as Ethereal): an open source network protocol analyzer</font></li>
<li class="stdtext"><font color="#000000"><a href="http://monkey.org/%7Edugsong/dsniff/">Dsniff</a><br />
by Dug Song: a combination of very useful sniffer and man-in-the-middle<br />
attack tools</font></li>
<li class="stdtext"><font color="#000000"><a href="http://ettercap.sourceforge.net/">Ettercap</a>:<br />
a multipurpose sniffer/interceptor/logger for switched LAN environments</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.aimsniff.com/">aimsniffer</a>:<br />
monitors AOL instant messager communication on the network</font></li>
<li class="stdtext"><font color="#000000"><a href="http://forgate.sourceforge.net/">4G8</a>:<br />
a tool ,similar to ettercap, to capture network traffic in switched<br />
environments</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.remote-exploit.org/codes.html">cdpsniffer</a>:<br />
Cisco discovery protocol (CDP) decoding sniffer</font></li>
</ul>
<p class="smallheadline"><font color="#000000">Port<br />
Scanner / Information Gathering:</font></p>
<ul>
<li class="stdtext"><font color="#000000"><a name="nmap"></a><a href="http://www.insecure.org/nmap/">nmap</a>:<br />
the currently most well-known port scanner. Since version 3.45 it<br />
supports <a href="http://www.insecure.org/nmap/versionscan.html">version<br />
scans</a>. Have a look at <a href="http://pbnj.sourceforge.net/">PBNJ</a> for diffing different nmap scans. </font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.isecom.org/">ISECOM</a><br />
released their nmap wrapper <a href="http://www.isecom.org/projects/toolsandtemplates.shtml">NWRAP</a>,<br />
which shows all known protocols for the discovered ports form the Open<br />
Protocol Resource Database </font></li>
<li class="stdtext"><font color="#000000"><a href="http://webwizarddesign.com/nmap/">Nmap::Scanner</a>:<br />
Perl output parser for nmap </font></li>
<li class="stdtext"><font color="#000000"><a name="amap"></a><a href="http://www.thc.org/releases.php">Amap</a><br />
by THC: An advanced portscanner which determines the application behind<br />
a network port by its application handshake. Thus it detects well-known<br />
applications on non-standard ports or unknown applications on<br />
well-known ports.</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.thc.org/releases.php">vmap</a><br />
by THC: version mapper to determine the version (sic!) of scanned daemons</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.dyadsecurity.com/s_unicornscan.html">Unicornscan</a>:<br />
a information gathering and correlation engine</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.mor-pah.net/index.php?file=projects/dmitry">DMitry</a> (Deepmagic Information Gathering Tool): a host information gathering tool for *nix systems</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.buyukada.co.uk/projects/athena/">Athena</a>:<br />
a search engine query tool for passive information gathering</font></li>
</ul>
<p class="smallheadline"><font color="#000000">Security<br />
Scanner:</font></p>
<ul>
<li class="stdtext"><font color="#000000"><a name="nessus"></a><a href="http://www.nessus.org/">Nessus</a><br />
- In version 2 an OpenSource network scanner. Version 3 is only available in binary form and under a proprietary license.</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.openvas.org/doku.php">OpenVAS</a>: a fork of Nessus 2.2.5 (formerly known as GNessUs)
<p>          </font></li>
<li class="stdtext"><font color="#000000"><span class="stdtext"><span style="text-decoration: underline;">Nessj</span>: a java based <a target="_self" href="http://www.forinsect.de/pentest/pentest-tools.html#nessus">nessus</a> (and compatibles) client (formerly known as Reason)</span></font></li>
<li class="stdtext"><font color="#000000">Paul<br />
Clip from @stake released <a href="http://blog.cyberclip.com/wp-content/AUSTIN_1.0.1.zip">AUSTIN</a>,<br />
a security scanner for Palm OS 3.5+. </font></li>
</ul>
<p>      <font color="#000000"><span class="smallheadline">Webserver:</span></font></p>
<ul class="stdtext">
<li><font color="#000000"><a href="http://www.cirt.net/code/nikto.shtml">Nikto</a>:<br />
a web server scanner with anti IDS features. Based on Rain Forest<br />
Puppies <a href="http://sourceforge.net/projects/whisker/">libwhisker</a><br />
library.</font></li>
<li><font color="#000000"><a href="http://www.sensepost.com/research/crowbar/">Wikto</a>: a webserver assessment tool (Windows only; requires .NET framework)</font></li>
<li><font color="#000000"><span class="stdtext"><a href="http://www.foundstone.com/resources/s3i_tools.htm">WSDigger</a>:<br />
a  black box web pen testing tool from Foundstone (Windows based)</span></font></li>
<li><font color="#000000"><span class="stdtext"><a href="http://www.severus.org/sacha/metis/">Metis</a>:<br />
a java based information gathering tool for web sites</span></font></li>
</ul>
<p class="smallheadline"><font color="#000000">Fingerprinting:</font></p>
<ul>
<li class="stdtext"><font color="#000000"><a href="http://www.gomor.org/cgi-bin/index.pl?mode=view;page=sinfp">SinFP</a>: a fingerprinting tool which requires only an open tcp port and sends maximum 3 packets</font></li>
<li class="stdtext"><font color="#000000"><a href="http://winfingerprint.sourceforge.net/">Winfingerprint</a>:<br />
much more than a simple fingerprinting tool.It scans for Windows<br />
shares, enumerates usernames, groups, sids and much more.</font></li>
<li class="stdtext"><font color="#000000"><a href="http://lcamtuf.coredump.cx/p0f-beta.tgz">p0f<br />
2</a>: Michal Zalewski announced his<br />
new release of p0f 2, a passive OS fingerprinting tool. p0f 2 is a<br />
completely rewrite of the old p0f code. </font></li>
<li class="stdtext"><font color="#000000"><a name="xprobe"></a><a href="http://www.sys-security.com/html/projects/X.html">xprobe2</a>:<br />
a remote active operating system fingerprinting tool from Ofir Arkin<br />
and the xprobe2 team</font></li>
<li class="stdtext"><font color="#000000"><a href="http://home.gna.org/cronos/">Cron-OS</a>:<br />
an active OS fingerprinting tool based on TCP timeout behavior. This<br />
project was formerly known as &quot;RING&quot; and is now published as a nmap<br />
addon.</font></li>
</ul>
<p class="smallheadline"><font color="#000000">Proxy<br />
Server:</font></p>
<ul>
<li class="stdtext"><font color="#000000"><a href="http://portswigger.net/proxy/">Burp<br />
proxy</a>: an interactive HTTP/S<br />
proxy server for attacking and debugging web-enabled applications</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.screen-scraper.com/screen-scraper/doc.shtml">Screen-scraper</a>:<br />
a http/https-proxy server with a scripting engine for data manipulation<br />
and searching</font></li>
<li class="stdtext"><font color="#000000"><a name="paros"></a><a href="http://www.proofsecure.com/download.shtml">Paros</a>:<br />
a man-in-the-middle proxy and application vulnerability scanner</font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project">WebScarab</a>: a framework for analyzing web applications. One of it&#8217;s basic functionality is the usage as intercepting proxy. </font></li>
</ul>
<p>      <font color="#000000"><span class="smallheadline"><br />
War Dialers:</span></font></p>
<ul class="stdtext">
<li><font color="#000000"><a href="http://www.softwink.com/iwar/">IWar</a>: a classic war dialer. One of a few wardialers for *nix operation systems, and the only with VOIP functionality (to my knowledge) </font></li>
<li><font color="#000000"><a href="http://www.thc.org/releases.php">THC-Scan</a>: a war dialer for DOS, Windows and DOS emulators</font></li>
</ul>
<p>      <font color="#000000"><span class="smallheadline">Malware / Exploit Collections:</span></font></p>
<ul class="stdtext">
<li><font color="#000000"><a href="http://packetstormsecurity.org/">packetstormsecurity.org</a>:<br />
Huge collections of tools and exploits</font></li>
<li><font color="#000000"><span class="stdtext"><a href="http://elsenot.com/">ElseNot Project</a>: The project tries to publish an exploit for each MS Security Bulltin. A script kiddie dream come true.</span></font></li>
<li><font color="#000000"><a href="http://www.offensivecomputing.net/">Offensive Computing</a>: Another malware collection site </font></li>
<li><font color="#000000"><a href="http://www.securityforest.com/wiki/index.php/Main_Page">Securityforest</a>: try the ExploitTree to get a collection of exploit code; have a look at the ToolTree for a huge list of pentest stuff</font></li>
</ul>
<p>      <font color="#000000"><br /><span class="smallheadline"></p>
<p>Databases / SQL:</span></font></p>
<ul>
<li><font color="#000000"><a class="stdtext" href="http://sqlninja.sourceforge.net/">sqlninja</a><span class="stdtext">: a tool to exploit sql injection vulnerabilities in web applications with MS SQL Servers (alpha stage)</span></font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.cisecurity.org/bench_oracle.html">CIS<br />
Oracle Database Scoring Tool</a>:<br />
scans Oracle 8i for compliance with the CIS Oracle Database<br />
Benchmark</font></li>
<li class="stdtext"><font color="#000000"><span class="stdtext"><a href="http://www.specialopssecurity.com/labs/sqlrecon/">SQLRecon</a>:<br />
an active and passive scanner for MSSQL server. Works on Windows 2000,<br />
XP and 2003.</span></font></li>
<li class="stdtext"><font color="#000000"><span class="stdtext"><a href="http://www.0x90.org/releases/absinthe/">absinthe</a>: a<br />
gui-based tool that automates the process of downloading the schema<br />
&amp; contents of a database that is vulnerable to Blind SQL Injection<br />
(see <a href="http://www.spidynamics.com/whitepapers/Blind_SQLInjection.pdf">here</a><br />
and <a href="http://www.imperva.com/download.asp?id=4">here</a>). </span></font></li>
<li class="stdtext"><font color="#000000"><a href="http://www.sqlpowerinjector.com/">SQL Power Injector</a>: a GUI based SQL injector for web pages (Windows, .Net Framework 1.1 required, Internet Explorer 5.0+ required)</font></li>
</ul>
<p>      <font color="#000000"><span class="smallheadline">Voice over IP (VOIP):</p>
<p>      </span></font></p>
<ul>
<li><font color="#000000"><a href="http://vomit.xtdnet.nl/">vomit</a> (voice over misconfigured internet telephones): converts Cisco IP phone conversations into wave files</font></li>
<li><font color="#000000"><a href="http://www.vopsecurity.org/html/tools.html">SiVuS</a>: a VOIP vulnerability scanner &#8211; SIP protocol (beta, Windows only)</font></li>
<li><font color="#000000"><a target="_self" href="http://www.forinsect.de/pentest/pentest-tools.html#cainabel">Cain &amp; Abel</a>: mostly a password cracker, can also record VOIP conversations (Windows only)</font></li>
<li><font color="#000000"><a href="http://sipsak.org/">sipsak</a> (SIP swis army knife): a SIP packet generator</font></li>
<li><font color="#000000"><a href="http://sipp.sourceforge.net/">SIPp</a>: a SIP test tool and packet generator</font></li>
<li><font color="#000000"><a href="http://phoenix.labri.fr/documentation/sip/Documentation/Material/Clients/Tools/Test/NastySIP/SX%20Design.htm">Nastysip</a>: a SIP bogus message generator</font></li>
<li><font color="#000000"><a href="http://www.enderunix.org/voipong/index.php">voipong</a>: dumps G711 encoded VOIP communications to wave files. Supports: SIP, H323, Cisco Skinny Client Protocol, RTP and RTCP</font></li>
<li><font color="#000000"><a href="http://skora.net/voip/voip.html">Perl based tools</a> by Thomas Skora: sip-scan, sip-kill, sip-redirectrtp, rtpproxy and ipq_rules</font></li>
<li><font color="#000000"><a href="http://www.cs.columbia.edu/IRT/software/rtptools/">rtptools</a>: a toolset for rtp recording and playing</font></li>
</ul>
<p>      <font color="#000000"><span class="smallheadline"></p>
<p>Networkbased Tools</span>:</font></p>
<ul>
<li><font color="#000000"><span class="stdtext"><a name="yersinia"></a><a href="http://yersinia.sourceforge.net/">yersinia</a>: a network tool<br />
designed to take advantage of some weakeness in different network<br />
protocols (STP, CDP, DTP, DHCP, HSRP, 802.1q, VTP)</span></font></li>
<li>
<p class="stdtext"><font color="#000000"><a href="http://lcamtuf.coredump.cx/soft/netsed.tgz">Netsed</a>:<br />
alters content of network packets<span class="stdtext"> while<br />
forwarding the packets</span></font></p>
</li>
<li><font color="#000000"><a href="http://ip6sic.sourceforge.net/">ip6sic</a>:<br />
a IPv6 stack integrity tester</font></li>
</ul>
<p>      <font color="#000000"><span class="smallheadline">VPN:</span></font></p>
<ul>
<li><font color="#000000"><span class="stdtext"><a name="ikescan"></a><a href="http://www.nta-monitor.com/ike-scan/">ike-scan</a>:<br />
an IPSec enumeration and fingerprinting tool</span></font></li>
<li><font color="#000000"><span class="stdtext"><a name="ikeprobe"></a><a href="http://www.ernw.de/download/ikeprobe.zip">ikeprobe</a>:<br />
ike scanning tool</span></font></li>
<li><font color="#000000"><span class="stdtext"><a href="http://chewies.net/ipsectrace-0.1.0.tar.gz">ipsectrace</a>:<br />
a tool for profiling ipsec traffic in a dump file. Initial alpha release</span></font></li>
<li><font color="#000000"><a href="http://vpnmonitor.sourceforge.net/index.html">VPNMonitor</a>:<br />
a Java application to observer network traffic. It graphically<br />
represents network connections and highlights all VPN connections. Nice<br />
for demonstrations, if somewhat of limited use in a real pen test.</font></li>
<li><font color="#000000"><a href="http://ikecrack.sourceforge.net/">IKECrack</a>:an IKE/IPSec cracker for pre-shared keys (in aggressive mode authentication [RFC2409])</font></li>
</ul>
<p class="stdtext"><font color="#000000"><a href="http://www.packetfactory.net/projects/dnsa/">DNSA</a>:<br />
DNS Auditing tool by Pierre Betouin</font><font color="#000000"><span class="stdtext"></p>
<p>      <a href="http://lin.fsid.cvut.cz/%7Ekra/index.html#HUNT">Hunt</a>:<br />
a session hijacking tool with curses GUI</span></font></p>
<p class="stdtext"><font color="#000000"><span class="stdtext"><a href="http://www.klcconsulting.net/smac/">SMAC</a>:<br />
a Windows MAC Address Modifying Utility. Supports Windows 2000 and XP.</span></font></p>
<p class="stdtext"><font color="#000000"><span class="stdtext"><a href="http://www.owasp.org/webgoat">The<br />
WebGoat Project</a>: a web<br />
application written in Java with intentional vulnerabilities. Supports<br />
an interactive learning environment with individual lessons. </span></font></p>
<p class="stdtext"><font color="#000000"><a href="http://softlabs.spacebitch.com/tscrack/">TSCrack</a>:<br />
a Windows Terminal Server brute forcer </font></p>
<p class="stdtext"><font color="#000000">Ollie<br />
Whitehouse from @stake released some new cellular phone based<br />
pentesting tools for scanning<br />
(<a href="http://my-symbian.com/uiq/download/search.php?name=NetScan">NetScan</a>,<br />
      <a href="http://my-symbian.com/uiq/download/search.php?name=MobilePenTester">MobilePenTester</a>).<br />
All tools<br />
require a Sony Ericsson P800 mobile phone. Unfortunately, @stake seems<br />
no longer to support much of their free<br />
security tools. So, use instead the alternativ download links above. </font></p>
<p class="stdtext"><font color="#000000"><a name="fuzzyprint"></a><a href="http://www.thc.org/releases.php">THC-FuzzyFingerprint</a>:<br />
generates fuzzy fingerprints that look almost nearly equal to a given<br />
fingerprint/hash-sum. Very useful for MITM attacks.</font></p>
<p class="stdtext"><font color="#000000"><a href="http://www.securityfriday.com/tools/BeatLM.html">BeatLM</a>,<br />
a password finder for LM/NTLM hashes. Currently, there is no support<br />
for NTLM2 hashes. In order to get the hashes from network traffic, try <a href="http://www.securityfriday.com/ToolDownload/ScoopLM/scooplm_doc.html">ScoopLM</a>.<br />
      </font></p>
<p class="stdtext"><font color="#000000"><a href="http://www.thc.org/releases.php">THC<br />
vlogger</a>: a linux kernel based<br />
keylogger </font></p>
<p class="stdtext"><font color="#000000"><a name="metasploit"></a><a href="http://metasploit.com/projects/Framework/">The<br />
Metasploit Framework</a>: an<br />
&quot;advanced open-source platform for developing, testing, and using<br />
exploit code&quot;.</font></p>
<p class="stdtext"><font color="#000000"><a href="http://www.computec.ch/projekte/atk/">ATK</a> (Attack Tool Kit): a comination of security scanner and exploit framework (Windows only)</font></p>
<p class="stdtext"><font color="#000000"><a href="http://www.guay-leroux.com/projects/pirana-0.2.1.tar.gz">Pirana</a>: an exploitation framework to test the security of email content filters. See also the <a href="http://www.guay-leroux.com/projects/SMTP%20content%20filters.pdf">whitepaper</a></font> </p>
<p class="stdtext"><font color="#000000"><a href="http://www.imperva.com/adc/tools/passloc">PassLoc</a>:<br />
a tool which provides the means to locate keys within a buffer. Based<br />
on the article &quot;<a href="http://www.forinsect.de/pentest/Playing%20hide%20and%20seek%20with%20encryption%20keys">Playing<br />
hide and seek with stored keys</a>&quot;<br />
by Adi Shamir. </font></p>
<p class="stdtext"><font color="#000000"><a href="http://www.imperva.com/adc/tools/dlhell">Dl-Hell</a>:<br />
identifies an executables dynamic link library (DLL) files </font></p>
<p class="stdtext"><font color="#000000"><a href="http://c3rb3r.openwall.net/dhcping/">DHCPing</a>:<br />
a security tool for testing dhcp security</font></p>
<p class="stdtext"><font color="#000000"><a href="https://sourceforge.net/projects/ldapenum">ldapenum</a>:<br />
a perl<br />
script for enumeration against ldap servers.</font></p>
<p class="stdtext"><font color="#000000"><a href="http://www.red-database-security.com/software/checkpwd.html">Checkpwd</a>: a dictionary based password checker for oracle databases</font></p>
<p class="stdtext"> <font color="#000000"><a href="http://www.nirsoft.net/utils/nircmd.html">NirCmd from NirSoft</a>: a windows command line tool to manipulate the registry, initiate a dialup connection and much more</font></p>
<p class="stdtext"><font color="#000000"><a href="http://www.stationx.net/windows_permission_identifier.php">Windows Permission Identifier</a>: a tools for auditing user permissions on a windows system</font></p>
<p class="stdtext"><font color="#000000"><a href="http://net-square.com/msnpawn/index.shtml">MSNPawn</a>: a toolset for footprinting, profiling and assesment via the MSN Search. Windows-only, .NET required</font></p>
<p class="stdtext"> <font color="#000000"><a href="http://www.nothink.org/perl/snmpcheck/">snmpcheck</a>:a tool to gather information via snmp. Works on Linux, *BSD and Windows systems. </font></p>
<p class="stdtext"><font color="#000000"><a href="http://www.foofus.net/fizzgig/pwdump/">pwdump6</a>: extract NTLM and LanMan hashes from Windows targets</font></p>
<ul class="related_post"><li><a href="http://www.tanasi.it/1130-must-have-bluetooth-hacking-tools.html" title="Must have Bluetooth hacking tools">Must have Bluetooth hacking tools</a></li><li><a href="http://www.tanasi.it/1062-great-list-of-hacking-tools.html" title="Great list of hacking tools">Great list of hacking tools</a></li><li><a href="http://www.tanasi.it/1354-splmap-06-released.html" title="splmap 0.6 released">splmap 0.6 released</a></li><li><a href="http://www.tanasi.it/1185-voip-hacking-software.html" title="VoIP Hacking software">VoIP Hacking software</a></li><li><a href="http://www.tanasi.it/952-free-sql-injection-scanners.html" title="Free SQL Injection Scanners">Free SQL Injection Scanners</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/1188-penetration-testing-tools.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Must have Bluetooth hacking tools</title>
		<link>http://www.tanasi.it/1130-must-have-bluetooth-hacking-tools.html</link>
		<comments>http://www.tanasi.it/1130-must-have-bluetooth-hacking-tools.html#comments</comments>
		<pubDate>Fri, 19 Oct 2007 23:11:25 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[In English]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[bluetooth]]></category>
		<category><![CDATA[hacker tools]]></category>
		<category><![CDATA[hacking tools]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=1054</guid>
		<description><![CDATA[This is a lis of the essential Bleutooth hacking tools, mostly for the Linux platform, that can be used to search out and hack Bluetooth-enabled devices. Discovering Bluetooth Devices BlueScanner &#8211; BlueScanner searches out for Bluetooth-enabled devices. It will try to extract as much information as possible for each newly discovered device. Download BlueScan. BlueSniff [...]]]></description>
			<content:encoded><![CDATA[<p>This is a lis of the essential Bleutooth hacking tools, mostly for the Linux<br />
platform, that can be used to search out and hack Bluetooth-enabled<br />
devices.</p>
<p><strong>Discovering Bluetooth Devices</strong></p>
<p><em>BlueScanner</em> &#8211; BlueScanner searches out for<br />
Bluetooth-enabled devices. It will try to extract as much information<br />
as possible for each newly discovered device. <a target="_blank" href="http://sourceforge.net/project/platformdownload.php?group_id=195755">Download BlueScan</a>.</p>
<p><em>BlueSniff</em> &#8211; BlueSniff is a GUI-based utility for finding discoverable and hidden Bluetooth-enabled devices. <a target="_blank" href="http://bluesniff.shmoo.com/bluesniff-0.1.tar.gz">Download BlueSniff</a>.</p>
<p><em>BTBrowser</em> &#8211; Bluetooth Browser is a J2ME application that<br />
can browse and explore the technical specification of surrounding<br />
Bluetooth-enabled devices. You can browse device information and all<br />
supported profiles and service records of each device. BTBrowser works<br />
on phones that supports JSR-82 &#8211; the Java Bluetooth specification. <a target="_blank" href="http://www.benhui.net/bluetooth/btbrowser.html">Download BTBrowser</a>.</p>
<p><em>B</em><em>TCrawler</em> -BTCrawler is a scanner for Windows<br />
Mobile based devices. It scans for other devices in range and performs<br />
service query. It implements the BlueJacking and BlueSnarfing attacks. <a target="_blank" href="http://www.silentservices.de/btCrawler.html">Download BTCrawler</a>.</p>
<p><strong>Hacking Bluetooth</strong> <strong>Devices</strong></p>
<p><em>BlueBugger</em> -BlueBugger exploits the BlueBug vulnerability.<br />
BlueBug is the name of a set of Bluetooth security holes found in some<br />
Bluetooth-enabled mobile phones. By exploiting those vulnerabilities,<br />
one can gain an unauthorized access to the phone-book, calls lists and<br />
other private information. <a target="_blank" href="http://www.remote-exploit.org/codes/bluebugger/bluebugger-0.1.tar.gz">Download BlueBugger</a>.</p>
<p><em>CIHWB</em> &#8211; Can I Hack With Bluetooth (CIHWB) is a Bluetooth<br />
security auditing framework for Windows Mobile 2005. Currently it only<br />
support some Bluetooth exploits and tools like BlueSnarf, BlueJack, and<br />
some DoS attacks. Should work on any PocketPC with the Microsoft<br />
Bluetooth stack. <a target="_blank" href="http://sourceforge.net/project/showfiles.php?group_id=173145">Download CIHWB</a>.</p>
<p><em>Bluediving</em> &#8211; Bluediving is a Bluetooth penetration testing<br />
suite. It implements attacks like Bluebug, BlueSnarf, BlueSnarf++,<br />
BlueSmack, has features such as Bluetooth address spoofing, an AT and a<br />
RFCOMM socket shell and implements tools like carwhisperer, bss, L2CAP<br />
packetgenerator, L2CAP connection resetter, RFCOMM scanner and<br />
greenplaque scanning mode. <a target="_blank" href="http://sourceforge.net/project/showfiles.php?group_id=155933">Download Bluediving</a>.</p>
<p><em>Transient Bluetooth Environment Auditor</em> &#8211; T-BEAR is a<br />
security-auditing platform for Bluetooth-enabled devices. The platform<br />
consists of Bluetooth discovery tools, sniffing tools and various<br />
cracking tools. <a target="_blank" href="http://freshmeat.net/redir/t-bear/67412/url_tgz/tbear.tar.gz">Download T-BEAR</a>.</p>
<p><em>Bluesnarfer</em> &#8211;  Bluesnarfer will download the phone-book of any mobile device vulnerable to <a target="_blank" href="http://www.salzburgresearch.at/research/publications_detail_e.php?pub_id=152">Bluesnarfing</a>.<br />
Bluesnarfing is a serious security flow discovered in several<br />
Bluetooth-enabled mobile phones. If a mobile phone is vulnerable, it is<br />
possible to connect to the phone without alerting the owner, and gain<br />
access to restricted portions of the stored data. <a target="_blank" href="http://www.alighieri.org/tools/bluesnarfer.tar.gz">Download Bluesnarfer</a>.</p>
<p><em>BTcrack</em> &#8211; BTCrack is a Bluetooth Pass phrase (PIN) cracking<br />
tool. BTCrack aims to reconstruct the Passkey and the Link key from<br />
captured Pairing exchanges. <a target="_blank" href="http://www.nruns.com/_en/security_tools_btcrack.php">Download BTcrack</a>.</p>
<p><em>Blooover II</em> &#8211; Blooover II is a J2ME-based auditing tool. It<br />
is intended to serve as an auditing tool to check whether a mobile<br />
phone is vulnerable. <a target="_blank" href="http://trifinite.org/Downloads/Blooover2.jar">Download Blooover II</a>.</p>
<p><em>BlueTest</em> &#8211; BlueTest is a Perl script designed to do data extraction from vulnerable Bluetooth-enabled devices. <a target="_blank" href="http://packetstorm.linuxsecurity.com/wireless/bluetest.pl.txt">Download BlueTest</a>.</p>
<p><em>BTAudit</em> &#8211; BTAudit is a set of programs and scripts for auditing Bluetooth-enabled devices. <a target="_blank" href="http://www.betaversion.net/btdsd/download/bt_audit-0.1.1.tar.gz">Download BTAuding</a>.</p>
<ul class="related_post"><li><a href="http://www.tanasi.it/1188-penetration-testing-tools.html" title="Penetration Testing Tools">Penetration Testing Tools</a></li><li><a href="http://www.tanasi.it/1062-great-list-of-hacking-tools.html" title="Great list of hacking tools">Great list of hacking tools</a></li><li><a href="http://www.tanasi.it/1354-splmap-06-released.html" title="splmap 0.6 released">splmap 0.6 released</a></li><li><a href="http://www.tanasi.it/1185-voip-hacking-software.html" title="VoIP Hacking software">VoIP Hacking software</a></li><li><a href="http://www.tanasi.it/952-free-sql-injection-scanners.html" title="Free SQL Injection Scanners">Free SQL Injection Scanners</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/1130-must-have-bluetooth-hacking-tools.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Great list of hacking tools</title>
		<link>http://www.tanasi.it/1062-great-list-of-hacking-tools.html</link>
		<comments>http://www.tanasi.it/1062-great-list-of-hacking-tools.html#comments</comments>
		<pubDate>Wed, 08 Aug 2007 14:36:28 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[In English]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacker tools]]></category>
		<category><![CDATA[hacking tools]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=983</guid>
		<description><![CDATA[On darknet blog you can found a great list of hacker tools: http://www.darknet.org.uk/category/hacking-tools/ Penetration Testing ToolsMust have Bluetooth hacking toolsSecDocs &#8211; Documenti vari di IT securityLol: A Geek Lifesplmap 0.6 released]]></description>
			<content:encoded><![CDATA[<p>On darknet blog you can found a great list of hacker tools: <a href="http://www.darknet.org.uk/category/hacking-tools/">http://www.darknet.org.uk/category/hacking-tools/</a></p>
<ul class="related_post"><li><a href="http://www.tanasi.it/1188-penetration-testing-tools.html" title="Penetration Testing Tools">Penetration Testing Tools</a></li><li><a href="http://www.tanasi.it/1130-must-have-bluetooth-hacking-tools.html" title="Must have Bluetooth hacking tools">Must have Bluetooth hacking tools</a></li><li><a href="http://www.tanasi.it/1834-secdocs-documenti-vari-di-it-security.html" title="SecDocs &#8211; Documenti vari di IT security">SecDocs &#8211; Documenti vari di IT security</a></li><li><a href="http://www.tanasi.it/1802-lol-a-geek-life.html" title="Lol: A Geek Life">Lol: A Geek Life</a></li><li><a href="http://www.tanasi.it/1354-splmap-06-released.html" title="splmap 0.6 released">splmap 0.6 released</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/1062-great-list-of-hacking-tools.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
