Tampilkan postingan dengan label Hacking. Tampilkan semua postingan
Tampilkan postingan dengan label Hacking. Tampilkan semua postingan

04/05/14

0 Download Network Hack Course Tutorial (Full 3 CD Pack)

This is a 3-CD's Hack Tutorial Pack which covers all Wifi, Network Hacking Procedures and Guides for Hacking tools.

+++++++++++++++++++
CD1 Contents
+++++++++++++++++++

1. Introduction to Information Security & Ethical Hacking
2. Basics of Networking (Tutorial for beginners)
3. Introduction
4. Hacker Vs Cracker
5. Ethical Hacking
6. Precautions
7. Current Cyber Threats
8. Desktop and Server Security
9. Windows Security
10. Hacking into Windows XP, NT
11. SAM (Security Accounts Manager)
12. Registries
13. Counter Measures
14. Linux Security
15. Hacking into Linux
16. Keyloggers - Hardware & Software
17. Anti Keyloggers
18. Trojans or Remote Administration Tools
19. Spywares
20. Viruses and Worms Introduction
21. Classification of Viruses and Worms
22. Examples of Viruses and Worms
23. Countermeasures
24. Anti Virus
25. LAN Security
26. Threats to LAN
27. Countermeasures
28. Network and File Sharing
29. Firewalls
30. Anti Virus
31. Anti Spywares
32. Network Scanners
33. Introduction to Firewalls
34. Working of a Firewall
35. Types of Firewalls
36. Packet Filters
37. Proxy Gateways
38. Network Address Translation
39. Intrusion Detection
40. Logging
41. Network Tools and Commands (Tutorial)
42. TCP/IP Commands
43. ARP Command
44. Trace route Command
45. Netstat Command
46. Finger Command
47. Ping Command
48. Nbtstat Command
49. Ipconfig Command
50. Telnet Command

+++++++++++++++++++
CD 2 Contents:
+++++++++++++++++++

1. Internet Security
2. IP Addresses
3. Finding an IP Address
4. Through Instant Messaging Software
5. Through Internet Relay Chat
6. Through Website
7. Through Email Headers
8. Through Message Board Postings
9. Proxies Servers
10. Transparent Proxies
11. Anonymous Proxies
12. Distorting Proxies
13. Elite Proxies
14. Free Proxy Servers
15. Analysis of Email Headers
16. Yahoo Email
17. Google Email
18. SSL (Secure Sockets Layer)
19. IP Spoofing
20. Information Gathering for a Remote System
21. Daemon Grabbing
22. Port Scanning
23. ICMP Messages
24. Banner Grabbing
25. Sockets
26. Detection of TCP Port Scan TCP SYN Scanning
27. Detection of SYN Scans
28. SYN/ACK Scanning
29. Detection of SYN/ACK Port Scan
30. TCP FIN Scanning
31. TCP XMAS tree scanning
32. ACK Scanning
33. UDP Ports
34. Utility
35. Fingerprinting
36. OS Fingerprinting
37. Remote OS Fingerprinting
38. Attacking the System
39. Nontechnical Attacks
40. Network Infrastructure Attacks
41. Operating System Attacks
42. Technical Attacks
43. Denial of Services attacks (DOS Attacks)
44. Threat from Sniffing and Key Logging
45. Trojan Attacks
46. HTTP Request Smuggling g
47. IP Spoofing
48. Cross site scripting (XSS)
49. Buffer Overflows
50. Format Bugs
51. SQL Injection s
52. Input Validation
53. Viruses & Worms
54. Spy Ware Software
55. Password Cracking
56. All other types of Attacks
57. Password Cracking
58. Password Guessing
59. Dictionary Based Attacks
60. Brute-Force Attacks
61. Default Passwords
62. Attacks on LOG files
63. Sniffer Attacks
64. Wireless & Bluetooth Security (Tutorial only) (Introduction Only*)
65. Penetration Testing
66. Definition
67. Methodology
68. Basic Approaches
69. Google Hacking
70. Terminologies
71. Basic Search Techniques
72. Basic Keyword searching
73. Phrase search
74. + Operator search
75. - Operator search
76. Range search
77. Advanced Search Techniques Site
78. Intitle, allintitle
79. Inurl, allinurl
80. Link .
81. Phonebook
82. Rphonebook
83. Bphonebook
84. Daterange
85. Cache
86. Filetype .
87. Robots.txt

+++++++++++++++++++
CD 3 Contents:
+++++++++++++++++++

1. Encryption & Cryptography (Introduction Only*)
2. Introduction to Cryptography
3. Private Key Encryption
4. Public Key Encryption
5. DES Algorithm
6. RSA Algorithm
7. Hash Functions
8. MD5 HASH algorithm
9. Digital Signatures
10. Encyptorsetup
11. Computer Forensics (Introduction Only*)
12. Introduction to Forensics
13. Digital Evidence
14. Requirements for Forensics
15. Steps taken in Forensics investigation
16. Acquisition
17. Identification
18. Evaluation
19. Presentation
20. Forensic Toolkit
21. Steganography and Data Hiding
22. Introduction
23. Digital Watermarking
24. Types of Steganography
25. In band Data Insertion
26. Data Algorithmic
27. Overt based grammar
28. Out-band Data Insertion
29. Overwriting Data Insertion
30. Steganography Tools & Applications
31. Catching Criminals
32. Cyber Terrorism
33. Forms of Cyber Terrorism
34. Factors & Reasons
35. Countermeasures
36. Challenges
37. Honey Pots
38. Definition
39. Research Honey Pots
40. Production Honey Pots
41. Low Involved Honey Pots
42. High Involved Honey Pots
43. Pros & Cons
44. Famous Honey Pots
45. Cyber Laws & IT Act India (Introduction Only*)
46. IT Act 2000
47. Domain Name Disputes
48. Definitions and Laws
49. Cyber Crimes & penalties
50. Security Auditing (Introduction Only*)
51. Audit Objectives
52. Risk Analysis
53. Auditing Steps
54. Previous Check
55. Planning & Organisation
56. Network Control - Policies / Stds
57. Network Control - Hardware / Software
58. Network Data Standards and Data Access
59. Hardware and Software Backup and Recovery
60. Software Communications
61. Access to Network Operating Systems Software and Facilities
62. Data Encryption and Filtering
63. Internet Applications
64. Password Protection 



All Link Download :
CD1 ~ CD2

03/04/14

0 Subgraph Vega Web Vulnerability Scanner


Vega adalah scanner gratis dan open source dan platform penetration test untuk menguji keamanan aplikasi web. Vega dapat membantu Anda menemukan dan memvalidasi SQL Injection, Cross-Site Scripting (XSS),  mengungkapkan informasi sensitif, dan kerentanan lainnya. Scanner ini ditulis dalam bahasa Java, yang berbasis GUI, dan dapat berjalan pada Linux, OS X, dan Windows.

Vega mencakup scanner otomatis untuk pengujian secara cepat dan memiliki fitur proxy dalam pemeriksaan taktis. Vega scanner dapat menemukan XSS (cross-site scripting), injeksi SQL, dan kerentanan lainnya. Vega dapat dikembangkan dengan menggunakan API dalam bahasa web: Javascript.

FITURES :

Modules

  • Cross Site Scripting (XSS)
  • SQL Injection
  • Directory Traversal
  • URL Injection
  • Error Detection
  • File Uploads
  • Sensitive Data Discovery
Core
  • Automated Crawler and Vulnerability Scanner
  • Consistent UI
  • Website Crawler
  • Intercepting Proxy
  • SSL MITM
  • Content Analysis
  • Extensibility through a Powerful Javascript Module API
  • Customizable alerts
  • Database and Shared Data Model

Untuk menjalaankan scanner ini dibutuhkan aplikasi Java sebagai pendukung.

Java SE Development Kit 7u45 - Windows x86 | Download

Download Subgraph Vega Web Vulnerability Scanner :

15/03/14

0 Free Download All Hacking Video



Download all My Collection Video Hacking

Hacking Video Tutorial - Phpmyadmin
phpmyadmin.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Cpanel Hacking
C_p4nel.rar - 4shared.com - online file sharing and storag
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Brute Force
4shared.com - free file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Joomla Reset Password
4shared.com - free file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - RFI Metode + Patch
rfi_patc.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - LFI (Local file disclosure)
L_F_I.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Sqli + Backdoring
SQLi_B4CKd0r.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Deface with HTML
4shared.com - free file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Sqli V.4
S-v4.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Sqli V.5
www.4shared.com/Tutorial_SQL_Injection.html
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Jumping
JumP_N4ck0.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Metasploit
tutor_metas.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Rooting
R00tin9.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Asp Sql inj_TUTOR
4shared.com - free file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Scemafuzzy
scema.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Backdoring + Inject + Deface
4shared.com - free file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Sqli Malingsial Version
Malingsial.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Patching Joomla
joomla_patch.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------
Hacking Video Tutorial - Defacing Tutorial
defac-tutor.rar - 4shared.com - online file sharing and storage
---------------------------------------------------------------------
---------------------------------------------------------------------

12/02/14

0 Cara Mengetahui user dan Password Server FTP

Protokol pengiriman berkas (Bahasa inggris: File Transfer Protocol) adalah sebuah protokol Internet yang berjalan di dalam lapisan aplikasi yang merupakan standar untuk pengiriman berkas (file) komputer antar mesin-mesin dalam sebuah Antarjaringan.

FTP ialah sebuah aplikasi atau service atau protocol yang digunakan untuk mentransfer dari satu tempat ke tempat yang lain. Ini sangatlah cepat dan ringkas bukan, Jika diumpamakan ada suatu orang yang 

menyebabkan kamu mempunyai sebuah mimpi buruk dengan mengupload file yang kurang apa gitu sebutannya :D. tentu saja tidak mengenakkan bagi kita bukan. 

Inilah yang aku bicarakan bagaimana cara crack FTP password yaitu dg menggunakan Brute Force. 


 


Download dulu Brute-Rorce (Brutus) di HERE 

1: mencari target seperti ftp://123.456.xxx.xxx/ 

2 : jalankan brutus ,lalu isilah target mu, lalu pilih wordlist dan FTP dari dropdown menu. Lalu Klik Start. Jika kamu bingung lihatlah gambar dibawah ini. 
 


3: Waktunya tergantung panjangnya dari panjangnya password. Setelah selesai kata sandi akan dipertunjukkan seperti gambar di atas.

hanya sekedar buat pengetahuan saja...

0 1337 Admin Page Finder Tolls


[Image: anminpagefinder-setandarisurga.jpg]

1337 Admin Page Finder Tolls adalah tools untuk mencari halaman login admin sebuah website, bagi yang kesusahan untuk mencari halaman admin website yang sudah menjadi target anda bisa mencoba menggunakan 1337 Admin Page Finder ini, silahkan download di link di bawah ini


04/01/14

0 Wordpress Bruteforce Perl script

http://img32.imageshack.us/img32/8658/hqe9.png


Bahan – Bahan :


  • Perl (Bisa Memakai Strawberry Perl )
  • Script Wordpress Brute ( HERE )

Langkah - Langkah :
1.Install Perl Dulu Kalo Sudah Download Script Tadi Dan Simpan Dengan Format .pl contoh brute.pl
2.Buka CMD Ketikan Sesuai Letak Directory Untuk Lebih Mudahnya Letakan di C:/perl/brute.pl


http://i.imgur.com/eUyp2mC.png

3.Ketik perl namafile.pl site userwordpress wordlistkamu Contoh : perl brute.pl site root pass.txt Teken Enter.

 http://img35.imageshack.us/img35/725/zz5k.png

4.Tunggu Hingga Succes Jika Anda Memakai Metode Ini Harus Bersabar.

 http://img12.imageshack.us/img12/9942/m74h.png

5.Jika Succes Akan Terlihat Seperti Ini

http://img32.imageshack.us/img32/8658/hqe9.png

02/01/14

0 Hacking and Security Tools for Beginners and Elite - Complete Tool Kit

Here is this post I have listed out few of the frequently and widely used Tools used by Hackers of all levels.But one thing i would like to mention is that "Hackers make tool but tool do not make Hackers"If you depend more on tools then you cannot evolve as a hacker rather you will be surrounded by tools and dependent on them.


1.Password Cracking Tools

a) John the ripper-http://www.openwall.com/john/

b) THC hydra-http://www.thc.org/thc-hydra/

c) Brutus-http://www.hoobie.net/brutus/

d) L0PhtCrack-http://www.l0phtcrack.com/

e) SAMInside-http://insidepro.com

f) Cain and abel-http://www.oxid.it/cain.html

g) Pwdump-http://www.foofus.net/fizzgig/pwdump/

2.Pentesting Tools:

a) Metasploit framework- http://www.metasploit.com/

b) Canvas- http://www.immunitysec.com/products-canvas.shtml

3.Sql injector Tools

a) Sqlihelper

b) Havij

c) SQL Exploiter

4.Website Vulnerability Scanner

a) Acunetix- http://www.acunetix.com/

b) Rational appscan- http://www.ibm.com/software/awdtools/appscan/

5.Vulnerability Scanner

a) Nessus-http://www.nessus.org/

b) Retina-http://www.eeye.com/html/Products/Retina/index.html

c) Sara-http://www-arc.com/sara/

6.Port Scanner

a) Nmap- http://nmap.org/

b) Angry Ip scanner- http://www.angryziber.com/ipscan/

c) Super Scan- http://www.foundstone.com/us/resources/proddesc/superscan.htm

7.Intrusion detection Tools

a) Snort-http://www.snort.org/

b) Sguil-http://sguil.sourceforge.net/

8.Live CDs

a) Ophcrack- http://ophcrack.sourceforge.net/

b) Backtrack- http://www.backtrack-linux.org/

c) Hiren’s boot cd- http://www.hiren.info/pages/bootcd

d) Ultimate boot cd- http://www.ultimatebootcd.com/


9.Wireless Tools

a) Wireshark- http://www.wireshark.org/

b) Kismet-http://www.kismetwireless.net/

c) Aircrack- http://www.aircrack-ng.org/

d) Netstumbler- http://www.stumbler.net/

10.Steganography Tools

A list of  few "STEGANOGRAPHY TOOLS " free to DOWNLOAD.

11.IP Tracing Tools

a) Neo Trace- http://www.networkingfiles.com/neotrace/

b) Visual Trace-http://www.visualiptrace.com

12.Software Cracking Tools

a) Debuggers-OllyDbg,WinDbg

b) Unpackers-QUnpack

c) DisAssemblers-WIN32Dasm

d) Decompilers-Boomerang,Mocha,JAD

e) Hex Editors-Hexworkshop,Hview, HxDSetupEN

A list of few "REVERSE ENGINEERING" tools free to Download.

13.Virtual Enviroment Software

a) Vmware- http://www.vmware.com

b) Virtual box- http://www.virtualbox.org

c) Sandboxie- http://www.sandboxie.com

21/12/13

0 Hack Modem Smartfren untuk unlimited Sepuasnya 2013

 langsung ke caranya aja ya sob :  dial dulu modem sob pake kartu smartfren dan coba aja ke chome or firefox, lalu ketikkan:
Code:
smartfren.com@url:google.com

dan coba liat halaman pencarian google kebuka... jd ada vuln disitu.

yuk kita gabungin pake proxy....

langsung saja!
1. Install program ispce td, trus buka, beri centang pada query mode, dan kita atur listen portx127 biar gampang nantinya. klik OK.



2. Coz domain yg hanya bisa diakses saat pulsa smart sob habis "nol" adalh smartfren.com,smart-telecom.co.id, dan jump.smart-telecom.co.id, jadi masuklah pd Query URL Configuration, pilih front query, trus masukkan salah satu domain tsb pd font query + simbol "@".
3. Kita beralih pd proxy configuration, unk proxy server silahkan cari sendiri, dgn catatan proxy dgn port 80 dan 3128 yg hanya bisa dgunakan disini, coz pihak smartfren mungkin hanya membuka kedua port tsb. unk proxy cari di google sendiri ea ato ke hidemyass.com banyak koq.. cari yang fast proxy, biar liar larinyaaa,,, hehehehhe
Ato kalo gak pengen repot pake aja ne proxy, tp gak ane jamin, lemoootnya ampuuunnn..!!


4. Udahan dulu, klik REFRESH 3x, lalu minimize, jangan di-exit!!
buka firefox. ke menu Options - Advanced - Network - Setting. Atur http proxy 127.0.0.1, dan gunakan listen portx yg tadi yaitu 127., berikan centang pd use this proxy.........
kemudian kosongkan pd No proxy for.
dan silahkan menikmati yg gratisan.


Bagi sob yg daerahx sudah tercover EVDO n make perangkat (modem) yg mendukung kecepatan EVDO rev A ato rev B,. pihak smart tdk membatasi bandwidth (kecepatan), speed bisa mencapai 3.1 Mbps ato sekitar 396,8 kb per detik. (bedakan antara bit dgn byte, 1 bytes= 8 bit)
Unk daerah yg hanya trdapat jaringan CDMA 1x cuma bs donlot sampek 19 kb per detik. jadi yg sabar aja ya..... heheheh
NOTE :
1. Pertama, agar gratisan dapat digunakan pd browser chrome da IE, pd browser IE masuklah keInternet Options - Connections, pilih pd koneksi yg sedang sob gunakan, klik Settings. Masukkan proxy dan portnya seperti pd firefox td. lalu klik OKOK lagi. dan OK lagi.
Agar bisa dgunakan unk mendownload lewat IDM, pilih Download - Options - Proxy, berikan centang dan masukkan proxy di Use Http proxy. Klik OK.


2. Kedua, beberapa situs ato blog mungkin tidak dpt dbuka dg sempurna, ataupun tdk dpt dibuka sama sekali, misl: mail.google.com, mail.yahoo.com. coz menggunakan protokol HTTPSyg mungkin perluh make port selain yg ane cantumkan d ats.

silahkan mencoba..haha

12/12/13

0 New Online Tools for Computer and Online Security

Computer security is of foremost importance these days even more than our physical security..lol.There are few online tools available through which we ensure our security to certain extent.We cannot say our PC will be 100% secure but to some extent we will be benefited  for sure.
(if you are looking for Antiviru software Click here)
File scanner:

1.Kaspersky:
It can used to scan files upto size 1mb and archieve file(zip,arj format etc) upto 1mb.The database is updated every 3 hours to ensure that newest virus are detected.

2.Avast:
Here you can scan a single file each time and that should not be more than 16mb.

3.VirusTotal:
Here you can scan a file upto 20mb.You can send file by SSL and via email also.

4.NovirusThanks:
Here you can scan file upto 20mb,where the file will be scanned by 24 antivirus engine and is one of the best online scanning tool.

System scanner:

1.Bitdefender:
It can scan your PC ,system memory,boot sector.It can be used without uninstalling the existing security product.

2.Symantec(Norton):
It can be used to scan the system.It is the one of the old Anti-virus company and easy to use.

3.Eset:
Administrative previleges is required to use this online scanner.It is user friendly and operates from the browser.

4.PandaSecurity:
You need the activex control to use this online tool.It is a good product from panda.

Browser scanner:

1.Qualys:
You need to install the required plugin to use this tool.It checks for vulnerability and issues in the browser.

2.BrowserScope:
It scans for browser functionality and issues.

3.Scanit:
It will scan the browser for issues and vulnerabilites.You need to close all other tabs before using it and enable persistent cookies.

4.Panopticlick:
It test your browser and give scores for uniqueness and trackable functionality.

Url scanner:

1.UrlVoid:
It scans the url with multiple antivirus engine.It is simple to use.

2.Avg:
Just copy and drop the suspicious url and press enter.

3.VirusTotal:
It is a simple tool to use as the file scanner of it.

4.OnlineLinkscan:
It scan the link from potential threats with a simple click.

Port scanner:

1.T1shopper:
It scans the Ipaddress for open ports.There is a list of some essential ports on the webpage.

2.Nmap:
It is one of the best port scanning tool and easy to use.

3.SubnetOnline:
It scans an Ipaddress for open and closed TCP ports.

4.AuditmyPc:
Here you can scan for ports to test the strength of your firewall.

5.Hashmian:
It provide a range of ports to scan and list of some essential ports.

0 HOW TO BECOME THE WORLD'S NO. 1 HACKER



Premium E-book Teaches You Advanced Hacking!



This guide teaches the basics and advanced techniques of:


  •  METASPLOIT TO REMOTELY HACK ANYONE'S COMPUTER
  •  USING PROGRAMS TO SEE PEOPLE'S TXT MESSAGES
  •  DDOSING SITES TO TAKE THEM DOWN IN MINUTES!
  •  CREATING AND USING SPYWARE TO MAKE KEYLOGGERS
  •  MAKING MONEY AS A HACKER (IT WORKS!)
  •  PORT SCANNING TO FIND ANY VENERABILITY TO HACK




Why it works:
This is different than all other hacking books. The difference? It is real hacking! Not just changing things in gmail, firefox, ect.



0 TOP 15 HACKING/CRACKING TOOLS 2013


A bash script to launch the AP, can be configured with a variety of attack options. Including a php script and server index.html, for phishing. Can act as a multi-client captive portal using php and iptables. Exploitation classics such as crime-PDF, De-auth with aireplay, etc..


[Image: PwnSTARscreenshot.png]

General Features:
Managing Interfaces and MAC Spoofing
Set sniffing
Phishing Web
Karmetasploit
WPA handshake
De-auth client
Managing Iptables

Download Pwn-Star Here

2. ZED ATTACK PROXY (ZAP)

(ZAP) is an integrated penetration testing tool for finding vulnerabilities in web applications. This tool is designed for use by people with a variety of security experience and as such is ideal for developers and functional testers who are new to penetration testing as well as being a useful addition to the toolbox tester.

[Image: zap1-3historyfilter.jpg]

Key Features:
Intercepting Proxy
Active scanners
Passive scanners
Brute Force scanner
Spider
Fuzzer
Port Scanner
Dynamic SSL certificates
API
Beanshell integration

Download ZAP Here

3. SET (SOCIAL ENGINEERING TOOLKIT)

Tools that focus on attacking the human element of weakness and inadvertence. This tool is widely used today and is one of the most successful tools demonstrated at Defcon.

[Image: Set-Box_2.png]

Key Features:
Spear-Phishing Attack Vector
Java Applet Attack Vector
Metasploit Browser Exploit Method
Credential Harvester Attack Method
Tabnabbing Attack Method
Man Left in the Middle Attack Method
Web Jacking Attack Method
Multi-Attack Web Vector
Infectious Media Generator
Teensy USB HID Attack Vector

Download SET Here


4. BURP SUITE

Burp Suite is a very nice tool for web application security testing. This tool is great for pentester and security researchers. It contains a variety of tools with many interfaces between them designed to facilitate and accelerate the process of web application attacks.

[Image: scanner.png]

General Function:
Interception proxies
Radar and spiders crawling
Webapps scanner
Tool assault
Repeater and sequencer tools

Download Burp Suit Here

5. ETTERCAP

Ettercap is a multipurpose sniffer / interceptor / logger for Local Area Network . It supports active and passive dissection of many protocols (even in code) and includes many feature for network and host analysis.

[Image: Ettercap_2.jpg]

General Function:
To capture traffic and data
To do logging network
Etc.

Download Ettercap Here

6. SANS INVESTIGATIVE FORENSIC TOOLKIT (SIFT)

The SANS Investigative Forensic Toolkit (SIFT) Workstation is a VMware Appliance that can be configured with all the requirements to perform a detailed digital forensic. Compatible with Expert Witness Format (E01), Advanced Forensic Format (AFF), and raw (dd) evidence formats. The new version has been completely rebuilt on the Ubuntu base with many additional tools and capabilities that are used in modern forensic technology.

[Image: SANS+Investigative+Forensic+Toolkit+2.14+Released.jpg]

General Function :
iPhone, Blackberry, and Android Forensic Capabilities
Registry Viewer (YARU)
Compatibility with F-Response Tactical, Standard, and Enterprise
PTK 2.0 (Special Release - Not Available for Download)
Automated Generation Timeline via log2timeline
Many Firefox Investigative Tools
Windows Journal Parser and Shellbags Parser (jp and sbag)
Many Windows Analysis Utilities (prefetch, usbstor, event logs, and more)
Complete Overhaul of Regripper Plugins (added over 80 additional plugins)

Download SIFT Here


7. WIRESHARK


Wireshark is the most widely used and most popular in the world the protocol analyzer, and is the de facto standard across many industries and educational institutions to analyze the network in different protocol.

Image has been scaled down 18% (700x518). Click this bar to view original image (845x625). Click image to open in new window.
[Image: ws-main.png]




General Function:
Live capture and offline analysis
Standard three-pane packet browser
Multi-platform: Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others
Captured data network can be browsed via a GUI, or via the TTY-mode tshark utility
The most powerful display filters in the industry
Rich VoIP analysis
Read / write many different capture file formats
Etc.

Download wireshark Here


8. WEBSPLOIT


WebSploit is an Open Source Project for Remote Scan and Analysis System of the weaknesses in web applications.

[Image: WebSploit+Framework+2.0.3+with+Wifi+Jammer.jpg]


Key Features: 
[>] Social Engineering Works
[>] Scan, Web Crawler & Analysis
[>] Automatic Exploiter
[>] Support Network Attacks
-
[+] Autopwn - Used From Metasploit For Scan and Exploit Target Service
[+] WMAP - Scan, Target Used Crawler From Metasploit WMAP plugin
[+] format infector - inject the payload into reverse and bind file format
[+] phpmyadmin Scanner
[+] LFI Bypasser
[+] Apache Users Scanner
[+] Dir Bruter
[+] admin finder
[ +] MLITM Attack - Man Left In The Middle, XSS Phishing Attacks
[+] MITM - Man In The Middle Attack
[+] Java Applet Attack
[+] MFOD Attack Vector
[+] USB Infection Attack
[+] Dos ARP Attack
[+ ]'s Killer Attack
[+] Attack Fake Update
[+] Fake Access Point Attack


Download Websploit Framework Here

9. WINAUTOPWN

WinAutoPWN is a tool that is used to exploit the Windows Framework directly, so that we are automatically going to be an administrator on the windows. 

Image has been scaled down 30% (700x505). Click this bar to view original image (999x720). Click image to open in new window.
[Image: winAUTOPWN+v3.2+Released.jpg]




Download WinAutoPWN Here


10. HASHCAT

Hashcat are a variety of tools to crack passwords in encrypted, it is very powerful for password recovery.

Image has been scaled down 3% (700x510). Click this bar to view original image (720x524). Click image to open in new window.
[Image: hashcat.png]





General Function:
Multi-Threaded
Free
Multi-Hash (up to 24 million hashes)
Multi-OS (Linux, Windows and OSX native binaries)
Multi-Algo (MD4, MD5, SHA1, DCC, NTLM, MySQL, ...)
SSE2 accelerated
All Attack-Modes except Brute-Force and Permutation can be extended by rules
Very fast Rule-engine
Rules compatible with JTR and PasswordsPro
Possible to resume or limit session
Automatically recognizes recovered hashes from outfile at startup
Can automatically generate random rules
Load saltlist from an external file and then use them in a Brute-Force Attack variant
Able to work in an distributed environment
Specify multiple wordlists or multiple directories of wordlists
Number of threads can be configured
Lowest priority threads run on
30 + Algorithms is implemented with performance in mind
... and much more

Download HashCat Here

11. UNISCAN

Uniscan is a scanner for web applications, written in perl for Linux. Currently Uniscan version is 6.2.

[Image: uniscan.png]

General Function:Identification of system pages through a Web Crawler.
Use of threads in the crawler.
Control the maximum number of requests the crawler.
Control of variation of system pages identified by Web Crawler.
Control of file extensions that are ignored.
Test of pages found via the GET method.
Test the forms found via the POST method.
Support for SSL requests ( HTTPS ).
Proxy support.
Generate site list using Google.
Generate site list using Bing.
Plug-in support for Crawler.
Plug-in support for dynamic tests.
Plug-in support for static tests.
Plug-in support for stress tests.
Multi-language support.
Web client.General Function:
Identification of system pages through a Web Crawler.
Use of threads in the crawler.
Control the maximum number of requests the crawler.
Control of variation of system pages identified by Web Crawler.
Control of file extensions that are ignored.
Test of pages found via the GET method.
Test the forms found via the POST method.
Support for SSL requests ( HTTPS ).
Proxy support.
Generate site list using Google.
Generate site list using Bing.
Plug-in support for Crawler.
Plug-in support for dynamic tests.
Plug-in support for static tests.
Plug-in support for stress tests.
Multi-language support.
Web client.

Download Uniscan Here


12. OLYYDBG

OllyDbg is a 32-bit assembler debugger for Microsoft Windows. Emphasis on binary code analysis makes it particularly useful in cases where source code is not available.

[Image: cracking-dengan-ollydbg.jpg?d8e507]


General Function:
Intuitive user interface, no cryptical commands
Code analysis - traces registers, recognizes procedures, loops, API calls, switches, tables, constants and strings
Directly loads and debugs DLLs
Object file scanning - locates routines from object files and libraries
Allows for user-defined labels, comments and function descriptions
Understands debugging information in Borland ® format
Saves patches between sessions, writes them back to executable file and updates fixups
Open architecture - many third-party plugins are available
No installation - no trash in registry or system directories
Debugs multithreaded applications
Attaches to running programs
Configurable disassembler, supports both MASM and IDEAL formats
MMX, 3DNow! and SSE instructions and the data types, Including Athlon extensions
Full UNICODE support
Dynamically recognizes ASCII and UNICODE strings - also in Delphi format!
Recognizes complex code constructs, like call to jump to procedure
Decodes calls to more than 1900 standard API and 400 C functions
Gives context-sensitive help on API functions from external help file
Sets conditional, logging, memory and hardware breakpoints
Traces program execution, logs arguments of known functions
Shows fixups
Dynamically traces stack frames
Searches for imprecise commands and masked binary sequences
Searches whole allocated memory
Finds references to constant or address range
Examines and modifies memory , sets breakpoints and Pauses program on-the-fly
Assembles commands into the shortest binary form
Starts from the floppy disk


Download OllyDbj Here


13. BBQSQL

BBQSQL an Opensource SQL injection tools with the framework specifically designed to carry out the process in hyper fast, database agnostic, easy to setup, and easy to modify. This is another amazing release from Arsenal Blackhat USA 2012. When conducting security assessments of applications, we often find that it is difficult to SQL vulnerabilities exploitable, with this tool will be extremely easy.
BBQSQL written in the Python programming language. This is very useful when complex SQL injection attack vulnerabilities. BBQSQL also a semi-automated tool, which allows little customization for those who are finding it difficult to trigger a SQL injection. The tool is built to be database agnostic and very versatile. It also has an intuitive UI for setting up the attack much easier.


[Image: BBQSQL.jpg]


General Function:
SQL Injection Tools
URL
HTTP Method
Headers
Cookies
Encoding methods
Redirect behavior
Files
HTTP Auth
Proxies

Download BBQSQL Here


14. CRYPTOHAZE


Tools to crack password / hash where cryptohaze supports CUDA, OpenCL , and the CPU code (SSE, AVX, etc.). Can run on OS that support CUDA. These are intended to make it easier to pentester did crack the hash.


[Image: Hacker+going+to+demonstrate+open+source+...er+sec.png]


General Function:
Crack various kinds of hash
Showing results from crackhash
Cracking on various OS platforms


Download Cryptohaze Here


15. SAMURAI WEB TESTING FRAMEWORK (SWTF)

SWTF is used to do testing / pentest against web application, is used to find a weakness and exploited to perform web. 

[Image: The+Samurai+Web+Testing+Framework+v+2.0RC5.jpg]

General Function:
Web Scanner
Web Mapping
Web Exploitation


Download SWTF Here


SO Thats It .enjoy 
Blogger Tricks