FN SECURE: penetration testing

Call Us For Workshops Or Seminars.. In Your University, Colleges, or Schools.
Email Us At : vicky@globallyunique.in

Save as PDF
Showing posts with label penetration testing. Show all posts
Showing posts with label penetration testing. Show all posts

Ultimate Encoder - PHP Encoder with multiple compression by lionaneesh



Untitled


"Ultimate Encoder" - Another Online tool by lionaneesh, an Indian developer and Hacker. Its a PHP Encoder with multiple compression. A Piece of code can be encoded multiple times making it impossible for any Anti Virus to detect it.






Here is comparison of are results of Antivirus Scans:
Before Encoder
1

After Encoder
2





















Try This Tool



Read more

Linux: 25 PHP Security Best Practices For Sys Admins


PHP is an open-source server-side scripting language and it is a widely used. The Apache web server provides access to files and content via the HTTP OR HTTPS

Read more

Worlds first windows 8 Bootkit to be released at MalCon


It is amazing how fast security measures are bypassed by hackers. it seems Windows 8 is now Malconed! Peter Kleissner has created the world's first Windows 8 Bootkit which is planned to be released in India at the International Malware Conference MalCon.

An independent programmer and security analyst, peter was working for an anti-virus company from 2008 to 2009 and was speaker at the Black Hat and Hacking at Random technical security conferences. While his main operating fields are Windows security and analysis of new malware, his recent Important projects include the development of the Stoned Bootkit, a research project to subvert the Windows security model.

A bootkit is built upon the following broad parts:
  • Infector
  • Bootkit
  • Drivers
  • Plugins (the payload)
And as put by peter, those parts are easy to split up in a criminal organization: Teams A-D are writing on the different parts. If you are doing it right, Team D (the payload writers) need no internal knowledge of the bootkit! Peter's research website: http://www.stoned-vienna.com/

As per the MalCon website, peter's travel is still not confirmed citing VISA issues, however, there are chances that the presentation may be done over the video or a speaker may step in on behalf of peter and release it at MalCon.

Read more

Cotton Candy USB with Dual-Core Computer can turns Any Screen Into an Android Station


Norwegian company FXI Technologies has been showing a USB stick-sized portable computer prototype, featuring with a dual-core 1.2-GHz CPU, 802.11n Wi-Fi, Bluetooth, HDMI-out and a microSD card slot for memory.

Codenamed Cotton Candy because its 21 gram weight is the same as a bag of the confection, the tiny PC enables what its inventor calls “Any Screen Computing,” the ability to turn any TV, laptop, phone, tablet, or set-top box into a dumb terminal for its Android operating system.

The Cotton Candy has a USB 2.0 connector on one end and an HDMI jack on the other. When connected to an HDTV, it uses the HDMI port for video, the USB for power, and Bluetooth to connect to a keyboard, mouse, or tablet for controlling the operating system. The device can output up to 1080p so even a full HD screen can display the Candy’s preloaded Android 2.3 operating system at its native resolution. The dual core CPU can even play local 1080p video or stream HD clips from the internet.
The idea behind it is similar to that of FXI’s Cotton Candy, in the sense that you will need to boot Android from a USB stick. Alternatively you could use an SD card as well. They’ve managed to get just about everything up and running, including Android Market, but it seems that the majority of users who managed to get this running successfully have been owners of ASUS branded PCs, although we can’t be sure of the reason behind that particular phenomenon.

For more information about the Android-x86 project, or if you’re looking for a way to load up Android’s Honeycomb 3.2 onto your laptop or PC, head on down to Android-x86’s website for the details. In the meantime you can check out this guy who managed to load Honeycomb 3.2 onto his ASUS Eee PC.

From developers to students to mobile workers, there are a number of groups that could find innovative ways to use a computer the size of a USB stick. However, you won’t see a consumer product shipping anytime soon from FXI. The company plans to sell the Cotton Candy to developers and let OEMs license the technology and turn it into something that can appeal to a wide audience.

Read more

WAFP : Web Application Finger Printer Tool


WAFP is a Web Application Finger Printer written in ruby using a SQLite3 DB. WAFP fetches the files given by the Finger Prints from a webserver andchecks if the checksums of those files are matching to the given checksums from theFinger Prints. This way it is able to detect the detailed version andeven the build number of a Web Application.
Sample Scan Result:

   wafp.rb --verbose -p phpmyadmin https://phpmyadmin.example.de
   VERBOSE: loading the fingerprint database to the ram...
   Collecting the files we need to fetch ...
   Fetching needed files (#432), calculating checksums and storing the results to the database:
   ............................................................................................
   VERBOSE: request for "/themes/darkblue_orange/img/b_info.png" produced "Connection refused - connect(2)" for 1 times - retrying...
   ............................................................................................
   Checking gathered/stored checksums (#432) against the selected product (phpmyadmin) versions (#87) checksums:
   .......................................................................................
                                                                                          
    found the following matches (limited to 10):
   +-------------------------------------------------------------+
    phpmyadmin-2.11.9.1                  296 / 299  (98.99%)
    phpmyadmin-2.11.9.2                  295 / 299  (98.66%)
    phpmyadmin-2.11.9.4                  295 / 299  (98.66%)
    phpmyadmin-2.11.8.1                  295 / 299  (98.66%)
    phpmyadmin-2.11.9.5                  295 / 299  (98.66%)
    phpmyadmin-2.11.8                    295 / 299  (98.66%)
    phpmyadmin-2.11.9.3                  295 / 299  (98.66%)
    phpmyadmin-2.11.9                    295 / 299  (98.66%)
    phpmyadmin-2.11.4                    294 / 299  (98.33%)
    phpmyadmin-2.11.5.2                  294 / 299  (98.33%)
   +-------------------------------------------------------------+
    WAFP 0.01-26c3  - - - - - - - - -  http://mytty.org/wafp/
                                                                 
   VERBOSE: Returncode stats:
   VERBOSE: Ret-Code 200 #302
   VERBOSE: Ret-Code 404 #130
   VERBOSE: deleting the temporary database entries for scan "472312620367191262036719_httpsphpmyadmin.example.de" ...


Read more

Hacking Video Tutorials



128 Bit Wep Cracking With Injection!.swf
A Penetration Attack Reconstructed.avi
A Quick and Dirty Intro to Nessus using the Auditor Boot CD!.swf
Adding Modules to a Slax or Backtrack Live CD from Windows.swf
Airplay replay attack - no wireless client required.swf
Anonym.OS LiveCD with build in Tor Onion routing and Privoxy.swf
BackTrack LiveCD to HD Installation Instruction Video .swf
Basic Nmap Usage!.swf
Basic Tools for Wardriving!.swf
Bluesnarfer attack tool demonstration.swf
Bluesnarfing a Nokia 6310i hand set.avi
Breaking WEP in 10 minutes.avi
BufferOverflowPart2-Shellcoding ByIDEspinner.avi
BufferOverflowPart3ExploitsByIDEspinner.avi
Cain to ARP poison and sniff passwords!.avi
Complete Hacking Video using Metasploit - Meterpreter.swf
Cracking a 128 bit WEP key (Auditor).swf
Cracking a 128 Bit Wep key + entering the cridentials.swf
Cracking Syskey and the SAM on Windows Using Samdump2 and John!.swf
Cracking Windows Passwords with BackTrack and the Online Rainbow Tables at Plain-Text!.swf
Cracking WPA Networks (Auditor).swf
DoS attack against Windows FTP Server - DoS.avi
Droop s Box Simple Pen-test Using Nmap, Nikto, Bugtraq, Nslookup and Other Tools!.swf
Exploiting some bugs of tools used in Windows.swf.swf
Exploiting weaknesses of PPTP VPN (Auditor).swf
Finding Rogue SMB File Shares On Your Network!.swf
Fun with Ettercap Filters!.swf
hack.txt
How to crack the local windows passwords in the SAM database .swf
How to decrypt SSL encrypted traffic using a man in the middle attack (Auditor).swf
How to sniff around switches using Arpspoof and Ngrep!.avi
IDEspinner Buffer Overflows pt1.avi
IDEspinner Feature Addition pt1.avi
IDEspinner Feature Addition pt2.avi
IDEspinnerDNS-PoisonRouting.avi
Install VNC Remotely!.avi
Internet Explorer Remote Command Execution Exploit (CMDExe) Client Side Attack (Hi-Res).avi
Internet Explorer Remote Command Execution Exploit (CMDExe) Client Side Attack (Lo-Res).avi
John The Ripper 1.7 password cracker Installation Instruction Video .swf
Local Password Cracking Presentation for the Indiana Higher Education Cybersecurity Summit 2005!.swf
MAC Bridging with Windows XP and Sniffing!.swf
Mass De-Authentication using void11 (Auditor).swf
Metasploit Flash Tutorial!.swf
MITM Hijacking.wmv
Nmap Video Tutorial 2 Port Scan Boogaloo!.swf
Sniffing logins and passwords.avi
Sniffing Remote Router Traffic via GRE Tunnels (Hi-Res).avi
Sniffing Remote Router Traffic via GRE Tunnels (Lo-Res).avi
Sniffing VoIP Using Cain!.swf
Snort Instruction video - howto install into backtrack.swf
SSH Dynamic Port Forwarding!.swf
Start a session and get interactive commandline access to a remote Windows box!.avi
Telnet Bruteforce.avi
Tunneling Exploits through SSH.avi
Use Brutus to crack a box running telnet!.avi
Using NetworkActiv to sniff webpages on a Wi-Fi network!.swf
WEP Cracking using Aireplay v2.2 Beta 7 (Whax 3.0).swf
WMF File Code Execution Vulnerability With Metasploit!.swf
WPA Cracking using Aireplay v2.2 Beta 7 (Whax 3.0).swf

Download:
http://rapidshare.com/files/112986178/Huge_Collection_Of_Hacking_Videos.part1.rar
http://rapidshare.com/files/112993588/Huge_Collection_Of_Hacking_Videos.part2.rar
http://rapidshare.com/files/113000538/Huge_Collection_Of_Hacking_Videos.part3.rar
http://rapidshare.com/files/112963118/Huge_Collection_Of_Hacking_Videos.part4.rar
http://rapidshare.com/files/112969973/Huge_Collection_Of_Hacking_Videos.part5.rar
http://rapidshare.com/files/112975843/Huge_Collection_Of_Hacking_Videos.part6.rar
http://rapidshare.com/files/112979640/Huge_Collection_Of_Hacking_Videos.part7.rar

Read more

PwnieExpress : Pentesting suite for the Nokia N900



PwnieExpress providing one of the best Pentesting suite for the Nokia N900 .It  Includes Aircrack, Metasploit, Kismet, GrimWEPa, SET, Fasttrack, Ettercap, nmap, and more, Custom pentesting screen with shortcuts to macchanger, injection on/off, etc. Built-in wireless card supports packet injection, monitor mode, and promiscuous mode also available :



Read more

Metasploit 4.1 and Armitage: What's New?








  
 

Description: This video shows some of the new features in Armitage for Matasploit 4.1. You'll see improved tab management features, more exploit feedback, VNC, brute forcing, token stealing, and an export data feature to aid reporting.
You can learn more about Armitage at http://www.fastandeasyhacking.com

Read more

MHTML vulnerability under active exploitation !

We’ve noticed some highly targeted and apparently politically motivated attacks against our users. We believe activists may have been a specific target. We’ve also seen attacks against users of another popular social site. All these attacks abuse a publicly-disclosed MHTML vulnerability for which an exploit was publicly posted in January 2011. Users browsing with the Internet Explorer browser are affected.

For now, we recommend concerned users and corporations seriously consider deploying Microsoft’s temporary Fixit to block this attack until an official patch is available.

To help protect users of our services, we have deployed various server-side defenses to make the MHTML vulnerability harder to exploit. That said, these are not tenable long-term solutions, and we can’t guarantee them to be 100% reliable or comprehensive. We’re working with Microsoft to develop a comprehensive solution for this issue.

The abuse of this vulnerability is also interesting because it represents a new quality in the exploitation of web-level vulnerabilities. To date, similar attacks focused on directly compromising users' systems, as opposed to leveraging vulnerabilities to interact with web
services.

News Source : Googleonlinesecurity

Read more

Save this Page

Download as PDF