Showing posts with label penetration. Show all posts
Showing posts with label penetration. Show all posts
Tuesday, April 25, 2017
Sandcat Browser 5 A Penetration Oriented Browser
Sandcat Browser 5 A Penetration Oriented Browser

Sandcat is a lightweight multi-tabbed web browser that combines the speed and power of Chromium and Lua. Sandcat comes with built-in live headers, an extensible user interface and command line console, resource viewer, and many other features that are useful for web developers and pen-testers.
Here is what changed in version 5.0 beta 1:
- Faster startup and responsiveness.
- Huge refactoring and cleanup of the current code.
- The Chromium library was upgraded to the latest release (incredibly fast!).
- Improved compatibility with 64-bit Windows editions.
- Improved source code editor.
- Available as free, open source/community edition (under a BSD-3-Clause license).
- Built using components and libraries from the Catarinka toolkit (also made open source at the same time with this release and under the same license).
- Includes the Selenite Lua library - a multi-purpose set of Lua extensions developed to make the development of Lua extensions easier in Sandcat. The code for Selenite is now open source, under the MIT license. The library documentation is available here.
- Fixed: output of the SHA1 and the full URL encoders that come with the pen-tester pack.
Download Sandcat Browser 5
Go to link download
Saturday, March 18, 2017
Maligno Penetration Testing Tool that Serves Metasploit Payloads
Maligno Penetration Testing Tool that Serves Metasploit Payloads

Maligno is an open source penetration testing tool that serves Metasploit payloads. It generates shellcode with msfvenom and transmits it over HTTP or HTTPS. The shellcode is encrypted with AES and encoded with Base64 prior to transmission.
Changelog: Metasploit multi-host support, socks4a server support (metasploit), last resort redirection for invalid requests and hosts out of scope, automatic client code obfuscation, delayed client payload execution, automatic metasploit resource file generation.
Features
- Encrypted communications: Maligno is a web server which communicates via HTTP or HTTPS with the clients. Communications are encrypted with AES and encoded with Base64 both for HTTP and HTTPS. Encryption and encoding parameters can be configured. Clients do NOT validate the server certificate by default.
- On the fly shellcode generation per session mode: Maligno will generate shellcode while starting up, and it will cache it for later use. Maligno will serve the cached shellcode to all clients that request it during the session. Maligno will maintain a cache for each configured Metasploit payload. The cache is removed when Maligno is shut down.
- Multi-payload support: You may configure Maligno with several Metasploit payloads. Clients can request different payloads to the server. Payloads are referred by an index, which is passed as a GET parameter. Such parameter can be also configured.
- Multi-server support: Maligno can run on a single server with Metasploit or in separate machines. Clients will connect to Maligno, and Maligno will generate shellcode that points to a pre-configured Metasploit multi-handler.
- SOCKS4a proxy support: Maligno helps you starting a Metasploit auxiliary socks4a proxy, which can be used with payloads such as reverse_https_proxy. This will allow you to send all your traffic through your Maligno server, in case of having a multi-server environment.
- Scope definition: Maligno allows you to define single IP addresses or ranges. This will ensure that your shellcode is served only to machines involved in your pentest. You may also use a wildcard in order to accept ANY address.
- Last resort redirection: Maligno will redirect hosts out of scope, or hosts sending invalid requests, to a configured URL.
- Client code generator and pseudorandom obfuscator: Maligno comes with a script that will generate and obfuscate (pseudorandomly) client code ready for use, based on your server configuration.
- Delayed client execution: Maligno clients use a basic random execution delay, which attempts to bypass AV-sandboxes.
- Metasploit resource file generator: Maligno generates MSF resource files based on your configuration, which can be used with msfconsole right away.
Download Maligno
Go to link download
Labels:
maligno,
metasploit,
payloads,
penetration,
serves,
testing,
that,
tool
Wednesday, March 15, 2017
Viproy v2 0 VoIP Penetration Testing and Exploitation Kit
Viproy v2 0 VoIP Penetration Testing and Exploitation Kit

Viproy Voip Pen-Test Kit provides penetration testing modules for VoIP networks. It supports signalling analysis for SIP and Skinny protocols, IP phone services and network infrastructure. Viproy 2.0 is released at Blackhat Arsenal USA 2014 with TCP/TLS support for SIP, vendor extentions support, Cisco CDP spoofer/sniffer, Cisco Skinny protocol analysers, VOSS exploits and network analysis modules. Furthermore, Viproy provides SIP and Skinny development libraries for custom fuzzing and analyse modules.
Current testing modules:
- SIP Register
- SIP Invite
- SIP Message
- SIP Negotiate
- SIP Options
- SIP Subscribe
- SIP Enumerate
- SIP Brute Force
- SIP Trust Hacking
- SIP UDP Amplification DoS
- SIP Proxy Bounce
- Skinny Register
- Skinny Call
- Skinny Call Forward
- VOSS Call Forwarder (September 2014)
- VOSS Speed Dial Manipulator (September 2014)
- MITM Proxy TCP
- MITM Proxy UDP
- Cisco CDP Spoofer
Download Viproy
Go to link download
Labels:
0,
and,
exploitation,
kit,
penetration,
testing,
v2,
viproy,
voip
Thursday, March 9, 2017
zAnti Android Penetration Testing Toolkit Free!
zAnti Android Penetration Testing Toolkit Free!

zANTI is a comprehensive network diagnostics toolkit that enables complex audits and penetration tests at the push of a button. It provides cloud-based reporting that walks you through simple guidelines to ensure network safety.
zANTI offers a comprehensive range of fully customizable scans to reveal everything from authentication, backdoor and brute-force attempts to database, DNS and protocol-specific attacks including rogue access points.
zANTI produces an Automated Network Map that shows any vulnerabilities of a given target.
Pick your audit
zANTI offers a host of penetration-testing features, including everything from Man-In-The-Middle and password complexity audits to port monitoring and a sophisticated packet sniffer.
End the discussion
zANTI employs advanced cloud-based reporting that makes it easy to demonstrate flaws and rationalize budgeting for necessary network upgrades.
Keep it simple
zANTI offers a user-friendly web-based interface that turns complex audits into a walk in the park; to quote Forbes, its as polished as a video game.
Download zAnti
Go to link download
Subscribe to:
Posts (Atom)