Showing posts with label testing. Show all posts
Showing posts with label testing. Show all posts
Sunday, April 16, 2017
Samurai Web Testing Framework 3 0 LiveCD Web Pen testing Environment
Samurai Web Testing Framework 3 0 LiveCD Web Pen testing Environment

The Samurai project team is happy to announce the release of a development version of the Samurai Web Testing Framework. This release is currently a fully functional linux environment that has a number of the tools pre-installed. Our hope is that people who are interested in making this the best live CD for web testing will provide feedback for what they would like to see included on the CD.
The Samurai Web Testing Framework is a live linux environment that has been pre-configured to function as a web pen-testing environment. The CD contains the best of the open source and free tools that focus on testing and attacking websites. In developing this environment, we have based our tool selection on the tools we use in our security practice. We have included the tools used in all four steps of a web pen-test.
Starting with reconnaissance, we have included tools such as the Fierce domain scanner and Maltego. For mapping, we have included tools such WebScarab and ratproxy. We then chose tools for discovery. These would include w3af and burp. For exploitation, the final stage, we included BeEF, AJAXShell and much more. This CD also includes a pre-configured wiki, set up to be the central information store during your pen-test.
Tools
- recon-?ng
- w3af
- BeEF
- Burp
- OWASP
- Rat
- DirBuster
- CeWL
- Sqlmap
- Maltego
- WebScarab
- Nmap
- - Zenmap
- Nikto
- Metasploit
- Firefox
- Tilt
- Wappalyzer
- FoxyProxy
- ZAP
- Firebug
- ZAP
- Burp
- Nikto
- DirBuster
- RaJ
- ZAP
- w3af
- iMacro
- CeWL
- ZAP
- ZAP TokenGen
- Burpsuite Sequencer
- User Agent Switcher
- Cookies
- Laudanum
- BeEF
Download Samurai Web Testing Framework 3.0
Go to link download
Sunday, April 2, 2017
LOIC 1 0 8 Low Orbit Ion Cannon A network stress testing application
LOIC 1 0 8 Low Orbit Ion Cannon A network stress testing application

Low Orbit Ion Cannon (LOIC) is an open source network stress testing and denial-of-service attack application, written in C#. LOIC was initially developed by Praetox Technologies, but was later released into the public domain, and now is hosted on several open source platforms.
LOIC performs a denial-of-service (DoS) attack (or when used by multiple individuals, a DDoS attack) on a target site by flooding the server with TCP or UDP packets with the intention of disrupting the service of a particular host. People have used LOIC to join voluntary botnets. The software inspired the creation of an independent JavaScript version called JS LOIC, as well as LOIC-derived web version called Low Orbit Web Cannon. These enable a DoS from a web browser.
Download LOIC 1.0.8
Go to link download
Saturday, March 18, 2017
Maligno Penetration Testing Tool that Serves Metasploit Payloads
Maligno Penetration Testing Tool that Serves Metasploit Payloads

Maligno is an open source penetration testing tool that serves Metasploit payloads. It generates shellcode with msfvenom and transmits it over HTTP or HTTPS. The shellcode is encrypted with AES and encoded with Base64 prior to transmission.
Changelog: Metasploit multi-host support, socks4a server support (metasploit), last resort redirection for invalid requests and hosts out of scope, automatic client code obfuscation, delayed client payload execution, automatic metasploit resource file generation.
Features
- Encrypted communications: Maligno is a web server which communicates via HTTP or HTTPS with the clients. Communications are encrypted with AES and encoded with Base64 both for HTTP and HTTPS. Encryption and encoding parameters can be configured. Clients do NOT validate the server certificate by default.
- On the fly shellcode generation per session mode: Maligno will generate shellcode while starting up, and it will cache it for later use. Maligno will serve the cached shellcode to all clients that request it during the session. Maligno will maintain a cache for each configured Metasploit payload. The cache is removed when Maligno is shut down.
- Multi-payload support: You may configure Maligno with several Metasploit payloads. Clients can request different payloads to the server. Payloads are referred by an index, which is passed as a GET parameter. Such parameter can be also configured.
- Multi-server support: Maligno can run on a single server with Metasploit or in separate machines. Clients will connect to Maligno, and Maligno will generate shellcode that points to a pre-configured Metasploit multi-handler.
- SOCKS4a proxy support: Maligno helps you starting a Metasploit auxiliary socks4a proxy, which can be used with payloads such as reverse_https_proxy. This will allow you to send all your traffic through your Maligno server, in case of having a multi-server environment.
- Scope definition: Maligno allows you to define single IP addresses or ranges. This will ensure that your shellcode is served only to machines involved in your pentest. You may also use a wildcard in order to accept ANY address.
- Last resort redirection: Maligno will redirect hosts out of scope, or hosts sending invalid requests, to a configured URL.
- Client code generator and pseudorandom obfuscator: Maligno comes with a script that will generate and obfuscate (pseudorandomly) client code ready for use, based on your server configuration.
- Delayed client execution: Maligno clients use a basic random execution delay, which attempts to bypass AV-sandboxes.
- Metasploit resource file generator: Maligno generates MSF resource files based on your configuration, which can be used with msfconsole right away.
Download Maligno
Go to link download
Labels:
maligno,
metasploit,
payloads,
penetration,
serves,
testing,
that,
tool
Wednesday, March 15, 2017
Viproy v2 0 VoIP Penetration Testing and Exploitation Kit
Viproy v2 0 VoIP Penetration Testing and Exploitation Kit

Viproy Voip Pen-Test Kit provides penetration testing modules for VoIP networks. It supports signalling analysis for SIP and Skinny protocols, IP phone services and network infrastructure. Viproy 2.0 is released at Blackhat Arsenal USA 2014 with TCP/TLS support for SIP, vendor extentions support, Cisco CDP spoofer/sniffer, Cisco Skinny protocol analysers, VOSS exploits and network analysis modules. Furthermore, Viproy provides SIP and Skinny development libraries for custom fuzzing and analyse modules.
Current testing modules:
- SIP Register
- SIP Invite
- SIP Message
- SIP Negotiate
- SIP Options
- SIP Subscribe
- SIP Enumerate
- SIP Brute Force
- SIP Trust Hacking
- SIP UDP Amplification DoS
- SIP Proxy Bounce
- Skinny Register
- Skinny Call
- Skinny Call Forward
- VOSS Call Forwarder (September 2014)
- VOSS Speed Dial Manipulator (September 2014)
- MITM Proxy TCP
- MITM Proxy UDP
- Cisco CDP Spoofer
Download Viproy
Go to link download
Labels:
0,
and,
exploitation,
kit,
penetration,
testing,
v2,
viproy,
voip
Thursday, March 9, 2017
zAnti Android Penetration Testing Toolkit Free!
zAnti Android Penetration Testing Toolkit Free!

zANTI is a comprehensive network diagnostics toolkit that enables complex audits and penetration tests at the push of a button. It provides cloud-based reporting that walks you through simple guidelines to ensure network safety.
zANTI offers a comprehensive range of fully customizable scans to reveal everything from authentication, backdoor and brute-force attempts to database, DNS and protocol-specific attacks including rogue access points.
zANTI produces an Automated Network Map that shows any vulnerabilities of a given target.
Pick your audit
zANTI offers a host of penetration-testing features, including everything from Man-In-The-Middle and password complexity audits to port monitoring and a sophisticated packet sniffer.
End the discussion
zANTI employs advanced cloud-based reporting that makes it easy to demonstrate flaws and rationalize budgeting for necessary network upgrades.
Keep it simple
zANTI offers a user-friendly web-based interface that turns complex audits into a walk in the park; to quote Forbes, its as polished as a video game.
Download zAnti
Go to link download
Monday, March 6, 2017
OWASP OWTF 1 0 1 Offensive Web Testing Framework
OWASP OWTF 1 0 1 Offensive Web Testing Framework

OWASP OWTF, the Offensive (Web) Testing Framework, is an OWASP+PTES-focused try to unite great tools and make pen testing more efficient.OWASP OWTF, the Offensive (Web) Testing Framework, is an OWASP+PTES-focused try to unite great tools and make pen testing more efficient.
OWTF aims to make pen testing:
- Aligned with OWASP Testing Guide + PTES + NIST
- More efficient
- More comprehensive
- More creative and fun (minimise un-creative work)
- See the big picture and think out of the box
- More efficiently find, verify and combine vulnerabilities
- Have time to investigate complex vulnerabilities like business logic/architectural flaws or virtual hosting sessions
- Perform more tactical/targeted fuzzing on seemingly risky areas
- Demonstrate true impact despite the short timeframes we are typically given to test.
Features
OWTF uses "Scumbag spidering", ie. instead of implementing yet another spider (a hard job), OWTF will scrub the output of all tools/plugins run to gather as many URLs as possible.This is somewhat "cheating" but tremendously effective since it combines the results of different tools, including several tools that perform brute forcing of files and directories.
Resilience
If one tool crashes OWTF, will move on to the next tool/test, saving the partial output of the tool until it crashed. OWTF also allow you to monitor worker processes and estimated plugin runtimes.Flexibilty
If your internet connectivity or the target host goes down during an assessment, you can pause the relevant worker processes and resume them later avoiding losing data to little as possible.
Download OWASP OWTF 1.0.1
Go to link download
Subscribe to:
Posts (Atom)