Showing posts with label framework. Show all posts
Showing posts with label framework. Show all posts
Wednesday, April 26, 2017
Zarp Local Network Attack Framework
Zarp Local Network Attack Framework

Zarp is a network attack tool centered around the exploitation of local networks. This does not include system exploitation, but rather abusing networking protocols and stacks to take over, infiltrate, and knock out. Sessions can be managed to quickly poison and sniff multiple systems at once, dumping sensitive information automatically or to the attacker directly. Various sniffers are included to automatically parse usernames and passwords from various protocols, as well as view HTTP traffic and more. DoS attacks are included to knock out various systems and applications. These tools open up the possibility for very complex attack scenarios on live networks quickly, cleanly, and quietly.
The long-term goal of zarp is to become the master command center of a network; to provide a modular, well-defined framework that provides a powerful overview and in-depth analysis of an entire network. This will come to light with the future inclusion of a web application front-end, which acts as the television screen, whereas the CLI interface will be the remote. This will provide network topology reports, host relationships, and more. zarp aims to be your window into the potential exploitability of a network and its hosts, not an exploitation platform itself; it is the manipulation of relationships and trust felt within local intranets. Look for zeb, the web-app frontend to zarp, sometime in the future.
Tool Overview
Broad categories are (see wiki for more information on these):
- Poisoners
- Denial of Service
- Sniffers
- Scanners
- Services
- Parameter
- Attacks
List of modules accessible from the command line:
bryan@debdev:~/tools/zarp$ sudo ./zarp.py --help
[!] Loaded 34 modules.
____ __ ____ ____
(__ ) / _ ( _ ( _
/ _/ / ) / ) __/
(____)_/_/(___)(__) [Version: 0.1.5]
usage: zarp.py [-h] [-q FILTER] [--update] [--wap] [--ftp] [--http] [--smb]
[--ssh] [--telnet] [-w] [-s] [--service-scan]
optional arguments:
-h, --help show this help message and exit
-q FILTER Generic network sniff
--update Update Zarp
Services:
--wap Wireless access point
--ftp FTP server
--http HTTP Server
--smb SMB Service
--ssh SSH Server
--telnet Telnet server
Scanners:
-w Wireless AP Scan
-s Network scanner
--service-scan Service scanner
bryan@debdev:~/tools/zarp$ Download Zarp
Go to link download
Friday, April 21, 2017
Radare The Reverse Engineering Framework
Radare The Reverse Engineering Framework

r2 is a rewrite from scratch of radare in order to provide a set of libraries and tools to work with binary files
This is the rewrite of radare (1.x branch) to provide a framework with a set of libraries and programs to work with binary data.
Radare project started as a forensics tool, an scriptable commandline hexadecimal editor able to open disk files, but later support for analyzing binaries, disassembling code, debugging programs, attaching to remote gdb servers, ..
radare2 is portable.
Architectures:
6502, 8051, arm, arc, avr, bf, tms320 (c54x, c55x, c55+), gameboy csr, dcpu16, dalvik, i8080, mips, m68k, mips, msil, snes, nios II, sh, sparc, rar, powerpc, i386, x86-64, H8/300, malbolge, T8200
File Formats:
bios, dex, elf, elf64, filesystem, java, fatmach0, mach0, mach0-64, MZ, PE, PE+, TE, COFF, plan9, bios, dyldcache, Gameboy and Nintendo DS ROMs
Operating Systems:
Android, GNU/Linux, [Net|Free|Open]BSD, iOS, OSX, QNX, w32, w64, Solaris, Haiku, FirefoxOS
Bindings:
Vala/Genie, Python (2, 3), NodeJS, LUA, Go, Perl, Guile, php5, newlisp, Ruby, Java, OCAM
Features:
- Multi-architecture and multi-platform
- GNU/Linux, Android, *BSD, OSX, iPhoneOS, Windows{32,64} and Solaris
- i8080, 8051, x86{16,32,64}, avr, arc{4,compact}, arm{thumb,neon,aarch64}, c55x+, dalvik, ebc, gb, java, sparc, mips, nios2, powerpc, whitespace, brainfuck, malbolge, z80, psosvm, m68k, msil, sh, snes, gb, dcpu16, csr, arc
- pe{32,64}, te, [fat]mach0{32,64}, elf{32,64}, bios/uefi, dex and java classes
- Highly scriptable
- Vala, Go, Python, Guile, Ruby, Perl, Lua, Java, JavaScript, sh, ..
- batch mode and native plugins with full internal API access
- native scripting based in mnemonic commands and macros
- Hexadecimal editor
- 64bit offset support with virtual addressing and section maps
- Assemble and disassemble from/to many architectures
- colorizes opcodes, bytes and debug register changes
- print data in various formats (int, float, disasm, timestamp, ..)
- search multiple patterns or keywords with binary mask support
- checksumming and data analysis of byte blocks
- IO is wrapped
- support Files, disks, processes and streams
- virtual addressing with sections and multiple file mapping
- handles gdb:// and rap:// remote protocols
- Filesystems support
- allows to mount ext2, vfat, ntfs, and many others
- support partition types (gpt, msdos, ..)
- Debugger support
- gdb remote and brainfuck debugger support
- software and hardware breakpoints
- tracing and logging facilities
- Diffing between two functions or binaries
- graphviz friendly code analysis graphs
- colorize nodes and edges
- Code analysis at opcode, basicblock, function levels
- embedded simple virtual machine to emulate code
- keep track of code and data references
- function calls and syscall decompilation
- function description, comments and library signatures
Download Radare
Go to link download
Labels:
engineering,
framework,
radare,
reverse,
the
Sunday, April 16, 2017
Samurai Web Testing Framework 3 0 LiveCD Web Pen testing Environment
Samurai Web Testing Framework 3 0 LiveCD Web Pen testing Environment

The Samurai project team is happy to announce the release of a development version of the Samurai Web Testing Framework. This release is currently a fully functional linux environment that has a number of the tools pre-installed. Our hope is that people who are interested in making this the best live CD for web testing will provide feedback for what they would like to see included on the CD.
The Samurai Web Testing Framework is a live linux environment that has been pre-configured to function as a web pen-testing environment. The CD contains the best of the open source and free tools that focus on testing and attacking websites. In developing this environment, we have based our tool selection on the tools we use in our security practice. We have included the tools used in all four steps of a web pen-test.
Starting with reconnaissance, we have included tools such as the Fierce domain scanner and Maltego. For mapping, we have included tools such WebScarab and ratproxy. We then chose tools for discovery. These would include w3af and burp. For exploitation, the final stage, we included BeEF, AJAXShell and much more. This CD also includes a pre-configured wiki, set up to be the central information store during your pen-test.
Tools
- recon-?ng
- w3af
- BeEF
- Burp
- OWASP
- Rat
- DirBuster
- CeWL
- Sqlmap
- Maltego
- WebScarab
- Nmap
- - Zenmap
- Nikto
- Metasploit
- Firefox
- Tilt
- Wappalyzer
- FoxyProxy
- ZAP
- Firebug
- ZAP
- Burp
- Nikto
- DirBuster
- RaJ
- ZAP
- w3af
- iMacro
- CeWL
- ZAP
- ZAP TokenGen
- Burpsuite Sequencer
- User Agent Switcher
- Cookies
- Laudanum
- BeEF
Download Samurai Web Testing Framework 3.0
Go to link download
Saturday, March 18, 2017
Mobius Forensic Framework written in Python GTK
Mobius Forensic Framework written in Python GTK

Mobius Forensic Toolkit is a forensic framework written in Python/GTK that manages cases and case items, providing an abstract interface for developing extensions. Cases and item categories are defined using XML files for easy integration with other tool.
Release 0.5.20 published
This release introduces the CellPhone Agent extension, an extension to browse Cellebrites report.xml files. Minor improvements have been made and a few bugs have been fixed. See the ChangeLog:
- new extension cellphone-agent
- report-model: new service report.run-dialog
- report-model: verbatim generates % instead of %%
- report-model: do not generate duplicated methods in .py
- gtk-ui: forbid treeitem DND onto itself
- gtk-ui: case treeview icon cache implemented
- gtk-ui: do not expand selected item when item.children is modified
- skype-agent: "generate report" option
- skype-agent: account view disables DND when not selected
- skype-agent: account tile image repositioned
- ice: use service report.run-dialog
- sdi-window-manager: call to on_widget_started eliminated
- partition-viewer: scan only partition-system components
- partition-agent: update item.children only if it detects partitions
- partition-agent-dos: keep item.children when building components
- turing: test dictionary option fixed
Download Mobius
Go to link download
Wednesday, March 15, 2017
Xposed Framework Kya Hai Aur Ise Kaise Install Kare
Xposed Framework Kya Hai Aur Ise Kaise Install Kare

Hello friends, Hindi Helpz me aapka swagat hai. Aapne xposed framework ka naam to suna hi hoga lekin yadi aap nahi jaante hai ki ye kya hai aur iska kya use hai?
Ham aapko is post me batayenge ki ye kya hai ?, Iska kya use hai ?, Aur ise kaise install kare ?
Xposed Framework Kya Hai ?
Mai aapko ise install karne ke bare me batane se pehle short me batana chahunga ki ye kya hai aur iska kya use hai ?
Aap log custom rom ke bare me to jante hi honge ki custom rom ke throw ham apne phone ko customize kar sakte hai. Example ke liye yadi aapke phone ka version kitkat hai to aap usko lolipop kar sakte ho. Isi tarah aap custom rom ki madad se iske alawa aur bhi customization kar sakte hai.
Yadi internet par aapke phone ki custom rom available nahi hai ya aap custom rom install nahi karna chahte hai, kyoki usme risk rehta hai aur kuch problems hoti hai to aap xposed framework ki madad se apne phone ko customize kar sakte hai. Iski madad se aap apne phone ko custom rom se bhi jyada advance level me customize kar sakte hai.
Xposed framework me tarah tarah ke modules (apps) hote hai, jinki madad se aap apne phone ko customize kar sakte hai. Isme har ek cheez ke liye alag - alag modules hote hai. inki jankari ham aapko aane wali posts me denge.
Aapko apne phone me jo bhi customization karna hai uske liye aap isme diye hue modules ko install karke kar sakte hai. Iska sabse bada fayda ye hai ki yadi aapke phone me is se koi problem hoti hai ya aapko wo module pasand nahi aata to aap use uninstall kar sakte hai. Jabki custom rom me yadi koi problem aati hai to poori rom change karna padta hai aur ye thoda risky work bhi hai.
Xposed framework android phone par nahi balki android version par depend karta hai. Ye 4.0.3 version se lekar 6.0.3 tak ke android version par work karta hai. Isme 4.0.3 se 4.4.4 tak ke version ke liye ek alag xposed framework install karna hota hai aur 5.0 se 6.0.3 version tak ek alag framework install karna padta hai.
Xposed Framework Kaise Install Kare
Jaisa ki maine aapko bataya ki 4.0.3 se 4.4.4 tak ke version ke liye ek alag xposed framework install karna hota hai aur 5.0 se 6.0.3 version tak ek alag framework install karna padta hai. Isiliye aap neeche di hui dono link me se apne phone ke version ke hisab se download kare.
Iske liye aapka phone rooted hona chahiye. Yadi aapka phone rooted nahi hai to android phone ko without pc root kaise kare post read karke apna phone root kare.
1. Sabse pehle neeche di hui link se xposed installer download kare.
> For 4.0.3 to 4.4.4 - Download
> For 5.0.1 to 6.0.3 - Download
2. Download hone ke baad install kare aur open kare.
3. Root permission grant kare.
4. Framework option open kare.
5. Install / update button me click kare.
6. framework update hone ke baad ok button me click kare, aapka phone reboot ho jayega.
7. Phone on hone ke baad xposed installer open kare aur download option open kare.
8. Aapko bohot se modules show honge unme se apni requirement ya pasan ka module download and install kare.
9. Iske baad xposed framework ke home jaye aur modules option choose kare.
10. aapne jo bhi modules download kiya hai wo yaha par show hoga, iske samne jo small box diya hai usme tap karke right check kare.
11. Ab aap us download kiye hue module ko run kar sakte ho aur apne phone me customization kar sakte ho.
> For 5.0.1 to 6.0.3 - Download
2. Download hone ke baad install kare aur open kare.
3. Root permission grant kare.
4. Framework option open kare.
5. Install / update button me click kare.
6. framework update hone ke baad ok button me click kare, aapka phone reboot ho jayega.
7. Phone on hone ke baad xposed installer open kare aur download option open kare.
8. Aapko bohot se modules show honge unme se apni requirement ya pasan ka module download and install kare.
9. Iske baad xposed framework ke home jaye aur modules option choose kare.
10. aapne jo bhi modules download kiya hai wo yaha par show hoga, iske samne jo small box diya hai usme tap karke right check kare.
11. Ab aap us download kiye hue module ko run kar sakte ho aur apne phone me customization kar sakte ho.
Done
Ham aapko aane wali posts iske jaroori modules and tricks ke baare me batayenge.
Friends aapko ye post kaisi lagi hame comment me bataye. Ye post apne friends ke sath share kare. Hamare blog ki new updates facebook me pane ke liye hamara facebook page like kare aur email me pane ke liye hamara blog subscribe kare.
Go to link download
Sunday, March 12, 2017
OWASP Xenotix XSS Exploit Framework 6
OWASP Xenotix XSS Exploit Framework 6

OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. Xenotix provides Zero False Positive XSS Detection by performing the Scan within the browser engines where in real world, payloads get reflected. Xenotix Scanner Module is incorporated with 3 intelligent fuzzers to reduce the scan time and produce better results. If you really dont like the tool logic, then leverage the power of Xenotix API to make the tool work like you wanted it to be. It is claimed to have the worlds 2nd largest XSS Payloads of about 4800+ distinctive XSS Payloads. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes real world offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation.
Features
SCANNER MODULES
- GET Request Manual Mode
- GET Request Auto Mode
- Multiple Parameter Scanner
- GET Request Fuzzer
- POST Request Fuzzer
- Advanced Request Fuzzer
- OAuth 1.0a Request Scanner
- DOM Scanner
- Hidden Parameter Detector
INFORMATION GATHERING MODULES
- WAF Fingerprinting
- Victim Fingerprinting
- IP to Location
- IP to GeoLocation
- Network
- Network IP (WebRTC)
- Ping Scan
- Port Scan
- Internal Network Scan
- Browser
- Fingerprinting
- Features Detector
EXPLOITATION MODULES
- Send Message
- Cookie Thief
- Keylogger
- HTML5 DDoSer
- Load File
- Grab Page Screenshot
- JavaScript Shell
- Reverse HTTP WebShell
- Metasploit Browser Exploit
- Social Engineering
- Phisher
- Tabnabbing
- Live WebCam Screenshot
- Download Spoofer
- Geolocation HTML5 API
- Java Applet Drive-By (Windows)
- Java Applet Drive-By Reverse Shell (Windows)
- HTA Network Configuration (Windows, IE)
- HTA Drive-By (Windows, IE)
- HTA Drive-By Reverse Shell (Windows, IE)
- Firefox Addons
- Reverse TCP Shell Addon (Windows, Persistent)
- Reverse TCP Shell Addon (Linux, Persistent)
- Session Stealer Addon (Persistent)
- Keylogger Addon (Persistent)
- DDoSer Addon (Persistent)
- Linux Credential File Stealer Addon (Persistent)
- Drop and Execute Addon (Persistent)
AUXILIARY MODULES
- WebKit Developer Tools
- Encoder/Decoder
- JavaScript Encoders
- JSFuck 6 Char Encoder
- jjencode Encoder
- aaencode Encoder
- JavaScript Beautifier
- Hash Calculator
- Hash Detector
- View Injected JavaScript
- View XSS Payloads
XENOTIX SCRIPTING ENGINE
- Xenotix API
- IronPython Scripting Support
- Trident and Gecko Web Engine Support
Download OWASP Xenotix XSS Exploit Framework 6
Go to link download
Viper A binary management and analysis framework dedicated to malware and exploit researchers
Viper A binary management and analysis framework dedicated to malware and exploit researchers


Viper is a binary analysis and management framework. Its fundamental objective is to provide a solution to easily organize your collection of malware and exploit samples as well as your collection of scripts you created or found over the time to facilitate your daily research. Think of it as a Metasploit for malware researchers: it provides a terminal interface that you can use to store, search and analyze arbitraty files with and a framework to easily create plugins of any sort.
Download Viper
Go to link download
Wednesday, March 8, 2017
Arachni v1 0 Web Application Security Scanner Framework
Arachni v1 0 Web Application Security Scanner Framework

Arachni is an Open Source, feature-full, modular, high-performance Ruby framework aimed towards helping penetration testers and administrators evaluate the security of web applications.
It is smart, it trains itself by monitoring and learning from the web applications behavior during the scan process and is able to perform meta-analysis using a number of factors in order to correctly assess the trustworthiness of results and intelligently identify (or avoid) false-positives.
Unlike other scanners, it takes into account the dynamic nature of web applications, can detect changes caused while travelling through the paths of a web applications cyclomatic complexity and is able to adjust itself accordingly. This way, attack/input vectors that would otherwise be undetectable by non-humans can be handled seamlessly.
Moreover, due to its integrated browser environment, it can also audit and inspect client-side code, as well as support highly complicated web applications which make heavy use of technologies such as JavaScript, HTML5, DOM manipulation and AJAX.
Finally, it is versatile enough to cover a great deal of use cases, ranging from a simple command line scanner utility, to a global high performance grid of scanners, to a Ruby library allowing for scripted audits, to a multi-user multi-scan web collaboration platform.
Download Arachni v1.0
Go to link download
Monday, March 6, 2017
OWASP OWTF 1 0 1 Offensive Web Testing Framework
OWASP OWTF 1 0 1 Offensive Web Testing Framework

OWASP OWTF, the Offensive (Web) Testing Framework, is an OWASP+PTES-focused try to unite great tools and make pen testing more efficient.OWASP OWTF, the Offensive (Web) Testing Framework, is an OWASP+PTES-focused try to unite great tools and make pen testing more efficient.
OWTF aims to make pen testing:
- Aligned with OWASP Testing Guide + PTES + NIST
- More efficient
- More comprehensive
- More creative and fun (minimise un-creative work)
- See the big picture and think out of the box
- More efficiently find, verify and combine vulnerabilities
- Have time to investigate complex vulnerabilities like business logic/architectural flaws or virtual hosting sessions
- Perform more tactical/targeted fuzzing on seemingly risky areas
- Demonstrate true impact despite the short timeframes we are typically given to test.
Features
OWTF uses "Scumbag spidering", ie. instead of implementing yet another spider (a hard job), OWTF will scrub the output of all tools/plugins run to gather as many URLs as possible.This is somewhat "cheating" but tremendously effective since it combines the results of different tools, including several tools that perform brute forcing of files and directories.
Resilience
If one tool crashes OWTF, will move on to the next tool/test, saving the partial output of the tool until it crashed. OWTF also allow you to monitor worker processes and estimated plugin runtimes.Flexibilty
If your internet connectivity or the target host goes down during an assessment, you can pause the relevant worker processes and resume them later avoiding losing data to little as possible.
Download OWASP OWTF 1.0.1
Go to link download
Thursday, March 2, 2017
Drozer The Leading Security Assessment Framework for Android
Drozer The Leading Security Assessment Framework for Android

drozer is a comprehensive security audit and attack framework for Android.
With increasing pressure to support mobile working, the ingress of Android into the enterprise is gathering momentum. Have you considered the threat posed by the Android app that supports your business function, or Android devices being used as part of your BYOD strategy?
drozer helps to provide confidence that Android apps and devices being developed by, or deployed across, your organisation do not pose an unacceptable level of risk. By allowing you to interact with the Dalvik VM, other apps IPC endpoints and the underlying OS.
drozer provides tools to help you use and share public exploits for Android. For remote exploits, it can generate shellcode to help you to deploy the drozer Agent as a remote administrator tool, with maximum leverage on the device.
Faster Android Security Assessments
drozer helps to reduce the time taken for Android security assessments by automating the tedious and time-consuming.
- Discover and interact with the attack surface exposed by Android apps.
- Execute dynamic Java-code on a device, to avoid the need to compile and install small test scripts.
Test against Real Android Devices
drozer runs both in Android emulators and on real devices. It does not require USB debugging or other development features to be enabled; so you can perform assessments on devices in their production state to get better results.
Automate and Extend
drozer can be easily extended with additional modules to find, test and exploit other weaknesses; this, combined with scripting possibilities, helps you to automate regression testing for security issues.
Test your Exposure to Public Exploits
drozer provides point-and-go implementations of many public Android exploits. You can use these to identify vulnerable devices in your organisation, and to understand the risk that these pose.
Download drozer
Go to link download
Subscribe to:
Posts (Atom)