\

Featured

Browsing Category "Tools"
Powered by Blogger.

Browsing "Older Posts"

Argus Logo
Argus is a fixed-model Real Time Flow Monitor designed to track and report on the status and performance of all network transactions seen in a data network traffic stream. Argus provides a common data format for reporting flow metrics such as connectivity, capacity, demand, loss, delay, and jitter on a per transaction basis. The record format that Argus uses is flexible and extensible, supporting generic flow identifiers and metrics, as well as application/protocol specific information.

Argus is composed of an advanced comprehensive network flow data generator, the Argus sensor, which processes packets (either capture files or live packet data) and generates detailed network flow status reports of all the flows in the packet stream. Argus captures much of the packet dynamics and semantics of each flow, with a great deal of data reduction, so you can store, process, inspect and analyze large amounts of network data efficiently. Argus provides reachability, availability, connectivity, duration, rate, load, good-put, loss, jitter, retransmission, and delay metrics for all network flows, and captures most attributes that are available from the packet contents, such as L2 addresses, tunnel identifiers (MPLS, GRE, ESP, etc...), protocol ids, SAP's, hop-count, options, L4 transport identification (RTP, RTCP detection), host flow control indications, etc...

Argus is used by many sites to generate network activity reports for every network transaction on their networks. The network audit data that Argus generates is great for security, operations and performance management. The data is used for network forensics, non-repudiation, network asset and service inventory, behavioral baselining of server and client relationships, detecting covert channels, and analyzing Zero day events.

Argus is an Open Source project, currently running on Mac OS X, Linux, Solaris, FreeBSD, OpenBSD, NetBSD, AIX, IRIX, Windows (under Cygwin) and OpenWrt, and has been ported to many hardware accelerated platforms, such as Bivio, Pluribus, Arista, and Tilera. The software should be portable to many other environments with littleor no modifications. Performance is such that auditing an entire enterprise's Internet activity can be accomplished using modest computing resources.

Tutorials ::

How To :: Click Here
Wiki :: Click Here

Download ::

Windows | Mac | Linux ::  Argus v3.0.6.1 | Argus v3.0.6.1 Client
Official Website :: http://www.qosient.com/argus/



Tags:

Argus (Auditing Network Activity)

By admin → Saturday, April 5, 2014
VoIP Hacking
VoIPong is a utility which detects all Voice Over IP calls on a pipeline, and for those which are G711 encoded, dumps actual conversation to seperate wave files. It supports SIP, H323, Cisco's Skinny Client Protocol, RTP and RTCP.
It's been written in C language for performance reasons, proved to be running on Solaris, Linux and FreeBSD; though it's thought to compile and run on other platforms as well.
On a 45 Mbit/sec network traffic, it's been verified that VoIPong successfully detected all VoIP gateways and the VoIP calls. CPU utilization during the run has been found ranging between 66% - 80% on a 256MB RAM, Celeron 1700 Mhz Toshiba notebook. 
Features :: 
  • Produces real .Wav files for direct audio hearing.
  • Simple, optimized, extandable fast code
  • The algorithm doesn't depend on signalling but on RTP/RTCP
  • Detailed logging. (Comfortable for 'cut' and 'cat' operations to produce statistics.)
  • Powerful management console interface
  • Easy installation and administration
  • Easy debugging.

Tutorials ::

Users Manual :: Click Here 



Tags:

VoIPong (VoIP Sniffer and Call Detector)

By admin →
KisMAC Logo
KisMAC is a popular wireless stumbler for Mac OS X offers many of the features of its namesake Kismet, though the codebase is entirely different. Unlike console-based Kismet, KisMAC offers a pretty GUI and was around before Kismet was ported to OS X. It also offers mapping, Pcap-format import and logging, and even some decryption and deauthentication attacks.

KisMAC is an open-source and free sniffer/scanner application for Mac OS X. It has an advantage over MacStumbler / iStumbler / NetStumbler in that it uses monitor mode and passive scanning.
KisMAC supports many third party USB devices: Intersil Prism2, Ralink rt2570, rt73, and Realtek rtl8187 chipsets. All of the internal AirPort hardware is supported for scanning.
The rest of this wiki assumes you are prepared for advanced topics and know what you are doing with your system.

Features ::

  • Reveals hidden / cloaked / closed SSIDs
  • Shows logged in clients (with MAC Addresses, IP addresses and signal strengths)
  • Mapping and GPS support
  • Can draw area maps of network coverage
  • PCAP import and export
  • Support for 802.11b/g
  • Different attacks against encrypted networks
  • Deauthentication attacks
  • AppleScript-able
  • Kismet drone support (capture from a Kismet drone)

Supported Hardware Chipsets ::

  • Apple AirPort and AirPort Extreme (dependent upon Apple's drivers)
  • Intersil Prism 2, 2.5, 3 USB devices
  • Ralink rt2570 and rt73 USB devices
  • Realtek RTL8187L USB (such as the Alfa AWUS036H, which does not work on Mac OS 10.6.7 or later)

Crypto Support ::

  • Bruteforce attacks against LEAP, WPA and WEP
  • Weak scheduling attack against WEP
  • Newsham 21-bit attack against WEP

Tutorials :: 

Wiki :: Click Here
Forum :: Click Here


Tags:

KisMAC (Sniffer/Scanner for Mac OS X)

By admin →
maligno image
Maligno is an open source penetration testing tool written in python, that serves Metasploit payloads. It generates shellcode with msfvenom and transmits it over HTTP or HTTPS. The shellcode is encrypted with AES and encoded with Base64 prior to transmission.

Tutorials ::

Download ::

Linux :: Maligno v1.0 (.tar.gz)
Official Website ::  http://www.encripto.no/tools/

Tags:

Maligno (Penetration Testing)

By admin →
Cloud Cracker is an online password cracking service for penetration testers and network auditors who need to check the security of WPA protected wireless networks, crack password hashes or break document encryption. 

Features :: 

  • Ease to use
  • Save money, save time
  • Support WPA/WPA2, NTLM, SHA-512, MD5, MS-CHAPv2 
  • Secure transmission
  • Fast password cracking service
Tags:

Cloud Cracker (Online WPA/WPA2 and Hash Cracker)

By admin → Monday, March 31, 2014

BTCrack is the worlds first Bluetooth Pass phrase (PIN) bruteforce toolBTCrack will bruteforce the Passkey and the Link key from captured pairing* exchanges.
BTcrack was demoed and realeased at Hack.lu 2007 and 23C3 in Berlin, the video of the presentation is available on Google Video .
To capture the pairing data it is necessary to have a Professional Bluetooth Analyzer : FTE (BPA 100, BPA 105, others), Merlin OR flash a CSR based consumer USB dongle with special firmware.
Speed Comparison :
· P4 2Ghz - Dual Core 200.000 keys/sec

· FPGA E12 @ 50Mhz 7.600.000 keys/sec
· FPGA E12 @ 75Mhz 10.000.000 keys/sec
· FPGA E14 30.000.000 keys/sec

Changes :
· 1.0 First release
· 1.1 Intermediate Release
  E12 + E14 FPGA Support ( http://www.picocomputing.com)
  Splash Screen
  Process Priority
  Speed increase (+15%)
 

Tutorials ::

Video :: Click Here

Download ::

Windows :: BTCrack (.zip)
Tags:

BTCrack (Bluetooth PIN Bruteforce)

By admin → Wednesday, January 15, 2014

iPhone Analzyer allows you to forensically examine or recover date from in iOS device. It principally works by importing backups produced by iTunes or third party software, and providing you with a rich interface to explore, analyse and recover data in human readable formats. Because it works from the backup files everything is forensically safe, and no changes are made to the original data.

Features ::

  • Supports iOS 2, iOS 3, iOS 4 and iOS 5 devices
  • Multi-platform (Java based) product, supported on Linux, Windows and Mac
  • Fast, powerful search across device including regular expressions
  • Integrated mapping supports visualisation of geo-tagged information, including google maps searches, photos, and cell-sites and wifi locations observed by the device (the infamous "locationd" data)
  • Integrated support for text messages, voicemail, address book entries, photos (including metadata), call records and many many others
  • Recovery of "deleted" sqlite records (records that have been tagged as deleted, but have not yet been purged by the device can often be recovered),/li>
  • Integrated visualisation of plist and sqlite files
  • Includes support for off-line mapping, supporting mapping on computers not connected to the Internet
  • Support for KML export and direct export to Google Earth
  • Browse the device file structure, navigate directly to key files or explore the device using concepts such as "who", "when", "what" and "where".
  • Analyse jail broken device directly over SSH without need for backup (experimental)
  • iPhone Backup Browsing
  • Native file viewing (plist, sqlite, etc)
  • Searching including regular expressions
  • ssh access for jailbroken phones (beta)
  • Reports
  • Restore files
  • Recover backups
  • View all iPhone photos
  • examine address book, sms and loads of others
  • find and recover passwords
  • Export files to local filesytem
  • Online and offline mapping
  • Geo track where a device has been
  • IOS5 and earlier versions supported
  • IOS6 is only partially supported (several known problems)

Tutorials ::

User Manual (PDF) :: Click Here

Download :: 

Tags:

iPhone Analyzer

By admin →

After a short break m back with gazing hacky stuffs! I hope you've been upto my previous post :Hack Website using Local File Inclusion Vulnerability.: so today m gonna teach you DOM Based XSS with Live Vulnerable website. 

#Complete Tutorial for beginners. but, first of all it is strongly recommended you to read our previous posts of XSS
[Read it now]. So keep your Browsers ready to tuneup your advance XSS Skills. [DOM Based XSS]




What is DOM Based XSS ?
                      DOM (Document Object Module) XSS is common web vulnerability, which occurs due to bad coding in Javascript & that create a DOM XSS Vulnerability which allows Client-Side-Scripts for eg.: (Javascript), an attacker can modify webpage content, can also lead to CSS (Cascading Style Sheets) Injection, etc.

DOM XSS Vulnerability Tutorial.
So, let's start our DOM XSS Vulnerability Coding, Hunting, & Exploiting. First of all you must know Stored & Reflected XSS Vulnerability Exploitation. Actually DOM Based XSS is very advance XSS vulnerabilities, it's bit kinda hard to find DOM XSS Vulnerabilites but if you've experience in hacking web applications & programming then it's like a piece of cake for you. & here we go!!

So, today is something speciality in this post .: I'll show you live tutorial of DOM XSS with Vulnerable website. It would be easy to understand & Learn DOM XSS, So proceed to next step.


  • Click here to go on our Vulnerable Web-Page
  • Always Remember that DOM based XSS is bit different,Advance and may be HARD :D because to find DOM based XSS. Finder must scan each parameter and javascript.
  • So,here when you'll go to Vulnerable Web-page there is nothing much contents on that Page. Then also it is Vulnerable to DOM XSS.
  • Same, as always scan source code. :) Analyze Javascript.
  • Okay! Just open source code and search for Javascript Code

    Click on Image to Enlarge it

  • You must HTML and Javascript to learn DOM XSS perfectly, well - you can see there is one tag of Javascript <script> Now, just understand that complete Javascript code.
  • After analyzing the code, you'll understand that the Javascript gets value from the URL Parameter "name" and writes the value in our Page.


  • Well, now you've found URL Parameter. Just Enter ?name=w0rm After URL and Hit Enter.

  • Value will be execute by Javascript and show on WebPage Like Hello-Viv or w0rm.

    Click on Image to Enlarge it

  • DOM XSS can be found at many web-contents like Choose language, Name, etc thousands of way are there to discover XSS into Web-Pages, Just you need Knowledge, skills, and Techniques.
  • Back to Hack Guys.! - So now use some evil minds Just Enter some Javascript tag into Value Paramter.
  • Note : if you'll enter <script>alert(XSS)</script> from Chrome browser it might won't work, because Chrome have XSS filters that bypass your command and doesn't gives you pop-up.

     Click Image to enlarge it

  • Then also there is always a way you can also use <b>, <u>, <i>, eval() or Javascript tags to execute your command and get pop-up. But I'll recommend you to use Firefox, Opera or IE.
  • So, Just replace name value w0rm with any Script Tag.
  • As m using <script>alert(3)</script> in Firefox.
Click on Images to Enlarge it

This is called DOM based XSS. We Injected and Our Command executed by DOM (Document Object Module). Simply this is very simple tutorial for beginners to understand DOM Based XSS. In our more upcoming post we'll teach : Advance DOM Based XSS techniques and Methods.

Just Stay connected with us on Facebook (Hackerz and crackerz) and feel free to comment and let me know your Problem. And also Please Share it to Increase us.

Complete DOM based XSS Live Tutorial for Beginners

By admin → Sunday, January 5, 2014