TCP Listener - Security Testing Tool
Enter a port number and a description and any scans on that port will see your description. Minimizes to the tray. Each connection is logged. TCP Listener is a great tool for testing security on your system. A great way to check the security of your firewall is to set TCP Listener to listen on different ports and then run a port scanner and see if it can connect through your firewall. No need to install, runs right from the exe file. Requires the .NET Framework from Microsoft.
|
|
Introduction to Netstat Tutorial
Netstat is a versatile tool catered for the windows platform by means of the MS-DOS (now a days referred to as "Command Prompt") command line. Netstat is also used in other platforms and operating systems apart from Windows such as Unix and Linux. In the following thesis I will demonstrate the security-oriented uses for this basic DOS and bash command designed for the newbie.
|
|
SARA
The Security Auditor's Research Assistant (SARA) is a third generation network security analysis tool. SARA interfaces with the popular NMAP package for superior "Operating System fingerprinting". Also, SARA provides a transparent interface to SAMBA for SMB security analysis.
|
|
SDT Cleaner
SDT Cleaner is a tool that intends to clean the SSDT (system service descriptor table) from hooks. The SDT Cleaner allows you to clean hooks installed by Anti-Virus and Firewalls. This little tool (in this first release) tries to collect info from your current kernel and then switches to kernel land and if there are any hooks in SSDT, this tool will replace them with the original entries.
|
|
Top 10 Hacker Attack Tools
Computer security "agents" must master the same tools used by the hackers they seek, and many of these programs are available to download for free. The man-in-the middle attack, (also known as the monkey-in-the middle) is a useful method of scanning network data and extracting what is known as interesting data, (passwords, e-mail, data files). Listed below you will find 10 programs used to assault and defend networks around the world.
|
|
Network Stumbler
Free Windows 802.11 Sniffer. Netstumbler is the best known Windows tool for finding open wireless access points ("wardriving"). They also distribute a WinCE version for PDAs and such called Ministumbler. The tool is currently free but Windows-only and no source code is provided. They note that "the author reserves the right to change this license agreement as he sees fit, without notice." UNIX users (and advanced Win users) may want to look at Kismet instead.
|
|
Honeyd
Honeyd is a small daemon that creates virtual hosts on a network. The hosts can be configured to run arbitrary services, and their TCP personality can be adapted so that they appear to be running certain versions of operating systems. Honeyd enables a single host to claim multiple addresses on a LAN for network simulation. It is possible to ping the virtual machines, or to traceroute them. Any type of service on the virtual machine can be simulated according to a simple configuration file. It is also possible to proxy services to another machine rather than simulating them.
|
|
SPIKE Proxy
Spike Proxy is an open source HTTP proxy for finding security flaws in web sites. It is part of the Spike Application Testing Suite and supports automated SQL injection detection, web site crawling, login form brute forcing, overflow detection, and directory traversal detection.
|
|
THC-Keyfinder
Keyfinder analyses files for public/private keys, encrypted or compressed data. It identified such areas by measuring the entropy, arithemtical mean and counter checking, and dumps appropriate file sections.
|
|
THC-Hydra
THC-Hydra - the best parallized login hacker: for Samba, FTP, POP3, IMAP, Telnet, HTTP Auth, LDAP, NNTP, MySQL, VNC, ICQ, Socks5, PCNFS, Cisco and more. Includes SSL support and is part of Nessus. Visit the project web site to download Win32, Palm and ARM binaries. Changes: Teamspeak module, ldap v3 support, bugfixes.
|
|
dsniff
dsniff is a collection of tools for network auditing and penetration testing. dsniff, filesnarf, mailsnarf, msgsnarf, urlsnarf, and webspy passively monitor a network for interesting data (passwords, e-mail, files, etc.). arpspoof, dnsspoof, and macof facilitate the interception of network traffic normally unavailable to an attacker (e.g, due to layer-2 switching). sshmitm and webmitm implement active monkey-in-the-middle attacks against redirected SSH and HTTPS sessions by exploiting weak bindings in ad-hoc PKI.
|
|
|