QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
2e76f6e180f5757a5a3e22768205e932This Python script is a tool that can be used to check windows workstations and servers if they have accessible shared resources.
6133c28a6da9326ca17eaf0754ad7434GetHTTPStatus is a simple python script that scans a set of provided URLs and returns the status codes provided. It has the ability to use cookies if needed.
54335ecaec0670b8636903af679e2bf5This Python script is a tool that can be used to check windows workstations and servers if they have accessible shared resources.
7b0e35d450717b0255751499600422c2T50 Sukhoi PAK FA Mixed Packet Injector (f.k.a. F22 Raptor) is a tool designed to perform "Stress Testing". It is a powerful and an unique packet injection tool. The author has added in some anti-kiddo tricks.
eb9995a2116e6ba94b8d9b1eeee982d9Witchxtool is a perl script that consists of a port scanner, LFI scanner, MD5 bruteforcer, dork SQL injection scanner, fresh proxy scanner, and a dork LFI scanner.
3b6c6053b0ed272e9ff62a3f124660baaidSQL SQL injection detection and exploitation tool is a modular PHP scanner that allows you to develop your own plugins for use.
d1f8609032260a76620dc0a2ee66448dSimple LAN Scanner is a simple python script that leverages scapy for discovering live hosts on a network.
d9a87be0869375f82f00155c237d3dc8Athena is a SSL cipher scanner. Unlike most scanners, rather than scanning the few ciphers openssl supports, it checks for every possible cipher by enumerating all 65536 cipher codes.
a0d1c8da4bc42e697ab68a3db3b3b061bsqlbf is a script that tests for blind SQL injection vulnerabilities.
f3df9621078d83bbea434740725c938dWitchxtool is a perl script that consists of a port scanner, LFI scanner, MD5 bruteforcer, dork SQL injection scanner, fresh proxy scanner, and a dork LFI scanner.
804b45e6a932c9ca92e1d26d375c463eThis tool helps discover local file inclusion vulnerabilities. It creates a random user agent for the connection, supports nullbytes, supports common Unix systems, and more.
bb7120fa3e8cf077e8170499d4f6b06aHyenae is a highly flexible and platform independent network packet generator. It allows you to reproduce low level Ethernet attack scenarios (such as MITM, DoS, and DDoS) to reveal potential security vulnerabilities of your network. Besides smart wildcard-based address randomization, a highly customizable packet generation control, and an interactive attack assistant, Hyenae comes with a clusterable remote daemon for setting up distributed attack networks.
dde7446ad98a9ab80933fe0746197ee1LFImap is a python script that tests leverages local file inclusion vulnerabilities to figure out the root of a file system, looks inside of some files and more.
7903ee2d680f6c07f3940a15a038395bHyenae is a highly flexible and platform independent network packet generator. It allows you to reproduce low level Ethernet attack scenarios (such as MITM, DoS, and DDoS) to reveal potential security vulnerabilities of your network. Besides smart wildcard-based address randomization, a highly customizable packet generation control, and an interactive attack assistant, Hyenae comes with a clusterable remote daemon for setting up distributed attack networks.
7a71ee334297ab3c10d76ee84adb73d9Skipfish is a fully automated, active web application security reconnaissance tool. It is high speed, has a low false positive rate, and is easy to use.
a9f9eef2f860cadcc86e12785dc3057fThe Simple Local File Inclusion Exploiter tool helps you exploit LFI (Local File Inclusion) vulnerabilities. Post discovery, simply pass the affected URL and vulnerable parameter to this tool. You can also use this tool to scan a URL for LFI vulnerabilities.
712bb09346a5ac665a6e8d46e56f37b6XSSer is an open source penetration testing tool that automates the process of detecting and exploiting XSS injections against different applications. It contains several options to try to bypass certain filters, and various special techniques of code injection.
4fa3e7c04ad401bde889b6b3c732b4bcScannedonly is a samba VFS module that ensures that only files that have been scanned for viruses are visible and accessible to the end user. Scannedonly was developed because of scalability problems with samba-vscan. Scannedonly comes in two parts: a Samba VFS module and (one or more) daemons. The daemon scans files and marks them when they are known to be clean. The samba module simply filters out files that aren't marked clean.
1e81cc52987f30fbd63d3abcbe9e3cb3aidSQL SQL injection detection and exploitation tool is a modular PHP scanner that allows you to develop your own plugins for use.
a27a073f8cbbf0950b322d1316105e26WATOBO, the Web Application Toolbox, is a tool that enables security professionals to perform highly efficient (semi-automated) web application security audits. It acts like a local proxy and analyzes the traffic on the fly for helpful information and vulnerabilities. It also has automated scanning capabilities, e.g. SQL injection, cross site scripting and more.
0f73c21f7edd54c693f8ad4184a0825cThis is a phpBB remote file inclusion scanner written in Perl.
4d2f1988f3b314fb5249dee8a7981675WordPress SQL Injection Checker is a tool that attempts to check for known SQL injection vulnerabilities in a given WordPress installation. Written in Python.
224ee4b42822e78cb4977d0ffd3931c9This python script scans for 58 vulnerable Joomla component payloads.
1f2e168c439731b5d2528a5ef6a5466bDorkmaster is a python script that crawls Google and Bing results looking for various pieces of software that has historically had vulnerabilities. This is useful for verifying that your company is in compliance with software run on a given site.
01946e78f154ad5096a105d5a9ef9168