Follow us on Twitter
  1. OoPsRevolution #Fact: #Phone #hacking will become much more common.
  2. sk3tchymoos3 RT @secureslinger: #hacking #security InfoWorld's Windows 7 Security Deep Dive: The expert guide http://t.co/eACUpStE #slingnews
  3. bbslist #bbs #hacking #amiga #c64 #ansi #ascii BBS of The Day : MMN Online Telnet://bbs.mmn.on.ca
  4. injunction_mp #notw #hacking 'Outperforming' NHS does not need radical reform, study concludes: BMJ repor... http://t.co/gxh93Au6 http://t.co/64lJ3Uib
  5. KRTpro_News #People > CHERIE BLAIR: Stars legal proceedings over Phone Hacking http://t.co/KJmLMCWI #PhoneHacking #Hacking
  6. Netzblockierer @MichaelLee2009 do it like the #Iran: #Hacking #drones !!!
  7. codemastersnake youporn logins 2012 - http://t.co/9xl3EUK3 http://t.co/mV1hTfAD | #youporn #logins #hacking
Login
User Rating: / 1
PoorBest 

drupal-logoDe eerste security scanner voor Drupal CMS is ontwikkeld. Op het blog van Ali Elouafiq, is zijn 0.1 beta versie vrijgegeven.  In deze eerste versie zal de scanner alleen de aanwezigheid van de gebruikte modules kunnen inventariseren. 

Deze kleine tool is vrij naar eigen wens te gebruiken. Het kan helpen bij security testen. Dit zal het werk voor een penetratie tester zeker sneller maken.  Het script is in in python geschreven

 

Last Updated (Wednesday, 22 February 2012 22:01)

 
User Rating: / 2
PoorBest 

Tenable Release Nessus 5.0 vulnerability scanner Tenable Network Security announced Nessus 5.0 vulnerability and configuration assessment solution for enterprises and security professionals. Nessus version 5.0 introduces key features and improvements, separated into the four major phases of the vulnerability scanning process:

  • Installation and management (for enhanced usability) - Nessus 5.0 simplifies the installation and configuration for non-technical users. Configuration and management: Nessus v5.0 configuration and management is now done 100% through the GUI
  • Scan policy creation and design (for improved effectiveness) - Users now enjoy improved effectiveness when creating scan policies. Over two dozen new pre-built plugin filters make it easy for security and compliance professionals to simplify policy creation for laser-focused scans on the areas that matter most. Users can quickly select multiple filter criteria, such as, Vulnerability Publication Date, public vulnerability database ID (OSVDB, Bugtraq, CERT Advisory, and Secunia), Plugin type (local or remote), information assurance vulnerability alert (IAVA), and more, to quickly identify easily-exploitable vulnerabilities.Scan for all easily remotely-exploitable vulnerabilities for which there is an exploit published in your favorite exploit framework.
  • Scan execution (for improved efficiency) - Users can take advantage of real-time scan results, on-the-fly filtering and sorting, and streamlined results navigation. A new vulnerability summary and redesigned host summary make it easy to see risk level without even running a report. As the scan is being run, not only can you see the results as they are being gathered, but navigate and filter on them as well. This allows you to easily act upon the vulnerability data while the scan is happening.
  • Report customization and creation (for improved communication with all parts of the organization) - New reporting features allow for improved communication of vulnerability results with all parts of the organization:Results filtering and report creation: Results filtering and report creation is more flexible than ever before. Users can apply multiple result filtering criteria, and targeted reports can be generated against the filtered results. Reports can be generated in native Nessus formats, HTML, and now PDF formats, Multiple report templates can be combined into one report.

Nessus 5.0 Installation Guide and Download Nessus 5.0

Last Updated (Saturday, 18 February 2012 14:05)

 
User Rating: / 4
PoorBest 
nmap
Nmap release today an interesting version nmap 5.61TEST4 with number of interesting features. Also, to improve the user experience, the Windows installer nowinstalls various browser toolbars, search engine redirectors, andassociated adware.
  • a spidering library and associated scripts for crawling websites.
  • 51 new NSE scripts, bringing the total to 297.
  • a substantial decrease in the size of the Mac OS X installer due to the removal of PPC support.
  • a new vulnerability management library which stores and reports found vulnerabilities.
Mac OS X packages are now x86-only (rather than universal), reducing the download size from 30 MB to about 17. Change Log can be found here and Download Here.
 
User Rating: / 2
PoorBest 

iphone hackHet iPhone Dev Team heeft een untethered-jailbreak voor iOS 5.0.1 vrijgegeven. De jailbreak werkt alleen op oudere hardware. Tot nu toe was alleen de tethered-jailbreak nog beschikbaar, waarbij een pc nodig is om te booten.

De untethered-jailbreak die door het iPhone Dev Team is vrijgegeven werkt niet op hardware met een A5-cpu, waardoor gebruikers van de iPhone 4S en iPad 2 de methode niet kunnen toepassen. De jailbreak is beschikbaar als Cydia-installatiepakket, voor gebruikers die hun device al gejailbreakt hebben.

'Nieuwe' gebruikers kunnen de bijgewerkte versie van de redsn0w-jailbreak-tool gebruiken. Wie nog geen iOS 5.0.1 draait en toch wil jailbreaken, wordt geadviseerd om zijn software eerst bij te werken. Tot nu toe was er alleen een tethered-jailbreak beschikbaar: daarbij is een pc nodig om de telefoon of tablet te kunnen booten met een werkende jailbreak.

De ontwikkelaar van de jailbreak werkt nog aan een manier om de exploit ook op hardware met A5-cpu's te kunnen toepassen. Hiervoor zal een nieuwe kwetsbaarheid moeten worden gevonden.

bron: tweakers.net

Last Updated (Sunday, 01 January 2012 13:13)

 
User Rating: / 89
PoorBest 

I found a nice site hackertarget.com who offers free automated security scans. These are online scanning tools that are available:

"DISCOVER SECURITY ISSUES ON YOUR SYSTEMS BEFORE THE BAD GUYS DO"

 

sql_injectionOverzicht van wat online SQL Injection Scanners. Altijd handig als je even geen beschikking hebt over je tools...

 

 

 

 

 

 

 

 

 

Last Updated (Saturday, 10 December 2011 14:24)

 
User Rating: / 3
PoorBest 

This is the December 2011 'HackInfo Tooling' overview:

hacking_toolsWPScan
WPScan is a vulnerability scanner which checks the security of WordPress installations using a black box approach... more: wpscan-11 

Joomscan
Joomscan is a nice vulnerability scanner for the popular content management platform Joomla. It detects more than 550 vulnerabilities in the website based on the Joomla which includes file inclusion, sql injection, command execution. This was last updated more than 2 years ago in august 2009 with 466 vulnerabilities. Now it has updated with 550... more: joomla-security-scanner-joomscan

Network penetration testing tool
This post is about a nice network penetration testing tool. C-Scan is a penetration testing tool which scans the IP address range or a specific IP to find out network vulnerabilities. This tool is not new and no new updates have been released for years. But you can still find it useful. By using this ...more basic-free-network-vulnerability-scanner

PHP Vulnerability Hunter
PHP Vulnerability Hunter is an advanced automated whitebox fuzz testing tool which detects almost ll of the web application vulnerabilities listed on the advisories page. PHP Vulnerability Hunter is an advanced automated whitebox fuzz testing tool capable of triggering a wide range of exploitable faults in PHP web applications. Minimal configuration is necessary to begin... more: php-vulnerability-hunter-v-1-1-4-6

Advance Port scanner
Advance Port scanner is a small light weight but a powerful port scanner. Only type Ip address of the computer and the scan for all ports. It uses a multithread technique, so on fast machines you can scan ports very fast. Also, it contains descriptions for common ports, and can perform scans on predefined port ... more: download-advance-port-scanner

Automatic SQL injection Tools
I have already posted many automatic SQL injection Tools. Now one more advance automatic sqli tool which is easy to use. It only takes URL and the valid string to detect the injection and exploit. Features: Support for injections using Mysql, SQL Server, Postgres and Oracle databases. Command line interface. Different commands trigger different actions. ... more: automatic-sql-injection-sqli-exploitation-tool

Havij SQL Injection
SQL Injection is one of the most found vulnerabilities in the websites and web applications. Developers know how to kow the website but they eaasily forget to filter the date sent to the website in forms and queries. This mistake makes website vulnerable to SQL injection. I have already post many Automatic SQL injection tool ... more: how-to-hack-a-website-with-havij-sql-injection

Cain & Abel
Cain & Abel is a password recovery tool for Microsoft operating systems.It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using dictionary and brute force attacks, decoding scrambled passwords, revealing password boxes, uncovering cached passwords... more: Cain&Abel

Last Updated (Friday, 09 December 2011 13:29)

 
User Rating: / 1
PoorBest 

Cain & Abel is a password recovery tool for Microsoft operating systems.It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using dictionary and brute force attacks, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols.

cain_and_abel

Change Log :

  • Added SAP R/3 sniffer filter for SAP GUI authentications and SAP DIAG protocol decompression.
  • Added support for Licensing Mode Terminal Server connections to Windows 2008 R2 servers in APR-RDP sniffer filter.
  • Added support for MSCACHEv2 Hashes (used by Vista/Seven/2008) in Dictionary and Brute-Force Attacks.
  • Added MSCACHEv2 Hashes Cryptanalysis via Sorted Rainbow Tables.
  • Added MSCACHEv2 RainbowTables to WinRTGen v2.6.3.
  • MS-CACHE Hashes Dumper now supports MSCACHEv2 hashes extraction from Windows Vista/Seven/2008 machines and offline registry files.
  • Fixed a bug (crash) in Certificate Collector with Proxy settings enabled.

Download Here

 
User Rating: / 1
PoorBest 

wpscan_logo

Er is een nieuwe versie van de WordPress Security Scanner uitgebracht. De volgende functionaliteiten zijn toegevoegd/verbeterd:

  • Detection for 750 more plugins.
  • Detection for 107 new plugin vulnerabilities.
  • Detection for 447 possible timthumb file locations.
  • Advanced version fingerprinting implemented.
  • Full Path Disclosure (FPD) checks.
  • Auto updates.
  • Progress indicators.
  • Improved custom 404 checking.
  • Improved plugin detection.
  • Improved error_log checking.
  • Lots of bugs fixed.
  • Lots of small tweaks.

De volledige lijst van veranderingen kunnen hier gevonden worden:
http://code.google.com/p/wpscan/source/browse/trunk/CHANGELOG

 
User Rating: / 8
PoorBest 

Acunetix is a popular web vulnerability scanner and now the version 8 beta is available for download. This application is one of the most used penetration testing tool and so its a good news for all penetration testers to move a step ahead with this new beta version.



Version 8 of Web Vulnerability Scanner has been optimized to make life easier at every stage of a security scan. WVS is easier to use for web admins and security analysts alike: enhanced automation, ability to save scan settings as a template to avoid reconfiguration, and multiple instance support for simultaneous scans of several websites. WVS 8 also ushers in a new exciting co-operation between Acunetix and Imperva: developers of the industry’s leading Web Application Firewall.

Download Acunetix Web Vulnerability Scanner 8  Here

 
User Rating: / 1
PoorBest 

This is a very helpfulsite to find website exploits. Some recent examples:

DateTitleCategory
2011-10-11 intitle:#k4raeL - sh3LL Vulnerable Servers
2011-10-11 filetype:php~ (pass|passwd|password|dbpass|db_pass... Files containing passwords
2011-09-26 +intext:"AWSTATS DATA FILE" filetype:txt Files containing juicy info
2011-09-26 inurl:ftp "password" filetype:xls Files containing passwords
2011-09-26 inurl:view.php?board1_sn= Vulnerable Servers
2011-09-26 inurl:"amfphp/browser/servicebrowser.swf"... Footholds
2011-09-12 "Powered by SLAED CMS" Advisories and Vulnerabilities
2011-08-25 allinurl:forcedownload.php?file= Vulnerable Files
2011-08-25 filetype:ini "Bootstrap.php" (pass|passw... Files containing juicy info
2011-08-06 intitle:"vtiger CRM 5 - Commercial Open Sourc... Advisories and Vulnerabilities

find more on www.exploit-db.com/google-dorks

 
More Articles...
Last comments