.:[ packet storm ]:.
                             
the vulnerability safehouse
the vulnerability safehouse

 Section:  .. / Last 100 Tool Files /

 ///  File Name:pktanon-1.2.0-dev.tar.gz
Description:
PKtAnon performs network trace anonymization. It is highly configurable and uses anonymization profiles. Anonymization profiles allow for mapping of arbitrary anonymization primitives to protocol attributes, thus providing high flexibility and easy usability. A huge number of anonymization primitives and network protocols are supported and ready to use for online and offline anonymization.
Author:Christoph Mayer
Homepage:http://www.tm.uka.de/pktanon
File Size:160561
Last Modified:Jun 30 11:50:42 2008
MD5 Checksum:6e62d3f5495216ac5d24dd82b3025314

 ///  File Name:unhide20080519.tgz
Description:
Unhide is a forensic tool to find hidden processes and TCP/UDP ports that are hidden via rootkits, LKMs, or other techniques.
Author:YJesus
Homepage:http://www.security-projects.com/?Unhide
Changes:Fixed a race condition and added man pages.
File Size:17104
Last Modified:Jun 28 10:55:29 2008
MD5 Checksum:1194ec0f89c6f28e8eb64fb66836f70f

 ///  File Name:prelude-manager-0.9.13.tar.gz
Description:
Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis.
Homepage:http://prelude.sourceforge.net
Changes:Updated libev and GnuLib code. Prelude-Manager-SMTP plugin is now open sourced.
File Size:746817
Last Modified:Jun 27 11:58:35 2008
MD5 Checksum:b83b6bf8ce7ca3976446c830c0602ce2

 ///  File Name:nwldapbf.txt
Description:
LDAP user enumerator and brute forcer for Novell Netware.
Author:George Hedfors
Homepage:http://www.pinion.se/
File Size:4062
Last Modified:Jun 24 15:27:48 2008
MD5 Checksum:9504941324506757d05e8d2be224d3a5

 ///  File Name:dnsenum1.2.tar.gz
Description:
dnsenum is a perl script that enumerates DNS information from a domain, attempts zone transfers, performs a brute force dictionary style attack, and then performs reverse look-ups on the results. It has been completely revamped.
Author:Filip Waeytens
Changes:Various bugs and code clean up.
File Size:12413
Last Modified:Jun 23 18:17:04 2008
MD5 Checksum:59d92826d06119a21f197ea7fd8bcb17

 ///  File Name:grubbrute.txt
Description:
This is a GRUB bootloader password cracker. It finds the MD5 hashes in the /boot/grub/menu.lst and when given a dictionary list it does its magic! (needs the passwdmd5 perl module).
File Size:962
Last Modified:Jun 23 04:07:48 2008
MD5 Checksum:ac5ffebfa346a0c505b2b33450e4b194

 ///  File Name:bsqlbf-v2.1.zip
Description:
Bsqlbf was originally written by A. Ramos from www.514.es and was intended to exploit blind sql injection against mysql backend database. This is a modified version of the same tool. It supports blind sql injection against the following databases: MS-SQL, MY-SQL, PostgresSQL, and Oracle.
Author:Sumit Siddharth
Homepage:http://notsosecure.com/
File Size:8664
Last Modified:Jun 23 03:59:24 2008
MD5 Checksum:4112eeb244251498680c145ca8209a05

 ///  File Name:rfdump-1.6.tar.gz
Description:
RFDump is a tool to detect RFID-Tags and show their meta information: Tag ID, Tag Type, manufacturer etc. The user data memory of a tag can be displayed and modified using either a Hex or an ASCII editor. Tag contents can be stored and loaded using a specific XML format. This effectively allows the copy of data from one tag to another. In addition, the integrated cookie feature demonstrates how easy it is for a company to abuse RFID technology to spy on their customers. RFDump works with the ACG Multi-Tag Reader or similar card reader hardware. The tags that are supported for reading, writing, and editing are ISO 15693, ISO 14443 A, ISO 14443 B, SR176(1,2), Tag-itĀ®, and I-CodeĀ®.
Author:lgrunwald
Homepage:http://www.rfdump.org/
File Size:151954
Last Modified:Jun 20 15:06:40 2008
MD5 Checksum:9db8053b5e2268234f516daed2731db8

 ///  File Name:tmin-0.04.tar.gz
Description:
tmin is a quick and simple tool to minimize the size and syntax of complex test cases in automated security testing. It is meant specifically for dealing with unknown or complex data formats (without the need to tokenize and re-serialize testcases), and for easy integration with UI testing harnesses.
Author:Michal Zalewski
Homepage:http://code.google.com/p/tmin/
File Size:11336
Last Modified:Jun 19 18:23:25 2008
MD5 Checksum:ec8d0047b0441cd963979080d427c0bd

 ///  File Name:iptables-1.4.1.1.tar.bz2
Description:
iptables is built on top of netfilter, the packet alteration framework for Linux 2.4.x and 2.6.x. It is a major rewrite of its predecessor ipchains, and is used to control packet filtering, Network Address Translation (masquerading, portforwarding, transparent proxying), and special effects such as packet mangling.
Homepage:http://www.iptables.org
Changes:Various fixes in this release.
File Size:436366
Last Modified:Jun 19 18:21:50 2008
MD5 Checksum:723fa88d8a0915e184f99e03e9bf06cb

 ///  File Name:0x4553-Intercepter.v072.zip
Description:
0x4553-Intercepter is a WinPcap-based sniffer that offers various capabilities including sniffing for password hashes related to ICQ/IRC/AIM/FTP/IMAP/POP3/SMTP/LDAP/BNC/SOCKS/HTTP/WWW/NNTP/CVS/TELNET/MRA/DC++/VNC/MYSQL and ORACLE. It also sniffs ICQ/AIM/JABBER/YAHOO/MSN/GADU-GADU/IRC and MRA protocols. It has a built-in arp poisoning module, can change MAC addresses of LAN adapters, and has various other interesting functionality.
Homepage:http://intercepter.nerf.ru/
File Size:567426
Last Modified:Jun 18 21:29:42 2008
MD5 Checksum:4cf52ad4236bf5a3016dbc1ef9580326

 ///  File Name:opennhrp-0.7.1.tar.bz2
Description:
OpenNHRP implements the NBMA Next Hop Resolution Protocol (as defined in RFC 2332). It makes it possible to create a dynamic multipoint VPN Linux router using NHRP, GRE, and IPsec. It aims to be Cisco DMVPN compatible.
Author:Timo Teras
Homepage:http://sourceforge.net/projects/opennhrp/
Changes:Couple of bug fixes and improvements.
File Size:85244
Last Modified:Jun 18 18:06:27 2008
MD5 Checksum:6be5332e40bd83412b62c2e8863eef3e

 ///  File Name:iphonedbg-toolkit-1.01.tgz
Description:
The iPhoneDbg Toolkit is a set of tools that will enable you to delve into iPhone binary reversing. The iPhone Debugger allows you to debug running or newly-created native processes inside iPhone. The Library Loader Patcher will allow to debug iPhone libraries. You can also build a tunnel from your PC to your iPhone through USB.
Author:Nicolas A. Economou
Homepage:http://oss.coresecurity.com/
File Size:131593
Last Modified:Jun 17 14:30:15 2008
MD5 Checksum:9ae4ad8c0a267d937a21a3a771c0ccdf

 ///  File Name:zzuf-0.12.tar.gz
Description:
zzuf is a transparent application input fuzzer. It works by intercepting file operations and changing random bits in the program's input. zzuf's behavior is deterministic, making it easy to reproduce bugs.
Author:Sam Hocevar
Homepage:http://sam.zoy.org/zzuf/
Changes:Finished the libzzuf manual page, a crash, and some other bugs.
File Size:446043
Last Modified:Jun 13 19:14:01 2008
MD5 Checksum:39f97432b02e358cdf2915f844ee3106

 ///  File Name:fwknop-1.9.5.tar.gz
Description:
fwknop implements an authorization scheme that requires only a single encrypted packet to communicate various pieces of information, including desired access through a Netfilter policy and/or specific commands to execute on the target system. The main application of this program is to protect services such as SSH with an additional layer of security in order to make the exploitation of vulnerabilities much more difficult. The authorization server works by passively monitoring authorization packets via libpcap.
Author:Michael Rash
Homepage:http://www.cipherdyne.org/fwknop/
Changes:Various updates and additions. Removed legacy knopmd.conf file since knopmd uses the fwknop.conf file instead.
File Size:561965
Last Modified:Jun 13 12:44:48 2008
MD5 Checksum:425c54c86f60f71a58891443fec57be0

 ///  File Name:xplico_phpgui-0.1_deft3x.tgz
Description:
PHP GUI for the Xplico open source network forensic analysis tool.
Author:Gianluca Costa, Andrea de Franceschi
Homepage:http://www.xplico.org/
File Size:361621
Last Modified:Jun 11 14:57:21 2008
MD5 Checksum:bdf7aa8d13d7a81ebd683b91b31be310

 ///  File Name:xplico-0.1_deft3x.tgz
Description:
Xplico is an open source Network Forensic Analysis Tool (NFAT) that allows for data extraction from traffic captures. It supports extraction of mail from POP, IMAP, and SMTP, can extract VoIP streams, etc.
Author:Gianluca Costa, Andrea de Franceschi
Homepage:http://www.xplico.org/
File Size:113370
Last Modified:Jun 11 14:55:27 2008
MD5 Checksum:7dcbccad6b164ebfcf8327aff97fd2ca

 ///  File Name:tor.uclibc.i686.20080606.iso
Description:
Tor-ramdisk is an i686 uClibc-based micro Linux distribution (3.1 MB) whose only purpose is to host a Tor server in an environment that maximizes security and privacy. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. Security is enhanced by employing a monolithically compiled GRSEC/PAX patched kernel and hardened system tools. Privacy is enhanced by turning off logging at all levels so that even the Tor operator only has access to minimal information. Finally, since everything runs in ephemeral memory, no information survives a reboot, except for the Tor configuration file and the private RSA key which may be exported/imported by FTP.
Author:Anthony G. Basile
Homepage:http://opensource.dyc.edu/tor-ramdisk
File Size:3280896
Last Modified:Jun 11 00:16:12 2008
MD5 Checksum:38f1054f081f8a4caf673c6778cc96e5

 ///  File Name:inth-v0.2.tgz
Description:
This code utilizes the p0f derived OS signature database of disco to actively fingerprint operating systems. It is able to fingerprint hosts based on a single SYN-ACK received from a probed port, and as such can be used to identify multiple hosts NAT Masquerading behind a single IP.
Author:skrye
File Size:22947
Last Modified:Jun 9 18:41:52 2008
MD5 Checksum:a8fd06ab8f79804d5d8ea6a3c0fc72e3

 ///  File Name:clamav-0.93.1.tar.gz
Description:
Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a commandline scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.
Author:Tomasz Kojm
Homepage:http://www.clamav.net
Changes:Various bug fixes and some enhancements.
File Size:17246314
Last Modified:Jun 9 17:31:08 2008
MD5 Checksum:64468e54624e51994e171a7f76e6c243

 ///  File Name:sipwitch-0.2.0.tar.gz
Description:
GNU SIP Witch is a pure SIP-based office telephone call server that supports generic phone system features like call forwarding, hunt groups and call distribution, call coverage and ring groups, holding, and call transfer, as well as offering SIP specific capabilities such as presence and messaging. It supports secure telephone extensions for making calls over the Internet, and intercept/decrypt-free peer-to-peer audio and video extensions. It is not a SIP proxy, a multi-protocol telephone server, or an IP-PBX, and does not try to emulate Asterisk, FreeSWITCH, or Yate.
Author:David Sugar
Homepage:http://www.gnutelephony.org/
Changes:Added plugin support, zeroconf, and scripting plugins.
File Size:425646
Last Modified:Jun 6 18:45:34 2008
MD5 Checksum:44647e3d57e7a5ed4125d2edd6e44d7c

 ///  File Name:sipvicious-0.2.3.tar.gz
Description:
SIPVicious tools address the need for traditional security tools to be ported to SIP. This package consists of a SIP scanner, a SIP wardialer, and a SIP PBX cracker. Written in Python.
Author:Sandro Gauci
Homepage:http://sipvicious.org/
Changes:Multiple features added including fingerprinting support for svmap. Included fphelper.py and 3 databases used for fingerprinting.
File Size:259424
Last Modified:Jun 4 14:36:54 2008
MD5 Checksum:4665134f2d6bd0595e771b4f1af7adcf

 ///  File Name:alph-0.24.tar.gz
Description:
alph implements and analyzes historical and traditional ciphers and codes, such as polyalphabetic, substitutional, and mixed employing human-reconstructable algorithms. It provides a pipe filter interface in order to encrypt and decrypt block text to achieve transparency. The program is meant to be used in conjunction with external programs that transfer data, resulting in transparent encryption or decryption of information. The program can thus be used as a mail filter, IRC filter, IM filter, and so on.
Author:Corcalciuc V. Horia
Homepage:http://sourceforge.net/projects/alph/
Changes:Added MILLENIUM photographic steganography. Switched to git repository. Optimised permutation and combination functions. Repaired ALBERTI cypher. Repaired LEWIS cypher. Repaired ROT-13 cypher. Repaired MORSE cypher.
File Size:253393
Last Modified:Jun 4 14:35:37 2008
MD5 Checksum:e9c957f01e18068692c39c7f059d09a3

 ///  File Name:ArpON-1.10.tar.gz
Description:
ArpON (Arp handler inspectiON) is a portable ARP handler. It detects and blocks all ARP poisoning/spoofing attacks with the Static Arp Inspection (SARPI) and Dynamic Arp Inspection (DARPI) approaches on switched/hubbed LAN with/without DHCP protocol.
Author:Andrea Di Pasquale
Homepage:http://arpon.sourceforge.net/
File Size:17302
Last Modified:Jun 2 17:31:53 2008
MD5 Checksum:37b2d73535865a0498a857bb079bfd34

 ///  File Name:kismet-2008-05-R1.tar.gz
Description:
Kismet is an 802.11 layer 2 wireless network sniffer. It can sniff 802.11b, 802.11a, and 802.11g traffic. It is capable of sniffing using almost any wireless card supported in Linux, which currently divide into cards handled by libpcap and the Linux-Wireless extensions (such as Cisco Aironet), and cards supported by the Wlan-NG project which use the Prism/2 chipset (such as Linksys, Dlink, and Zoom). Besides Linux, Kismet also supports FreeBSD, OpenBSD and Mac OS X systems. Features Multiple packet capture sources, Runtime network sorting by AP MAC address (bssid), IP block detection via ARP and DHCP packet dissection, Cisco product detection via CDP, Ethereal and tcpdump compatible file logging, Airsnort-compatible "interesting" (cryptographically weak) logging, Secure SUID behavior, GPS devices and wireless devices fingerprinting. Kismet also includes a tool called gpsmap that can be used to create maps from logged GPS data.
Author:Mike Kershaw
Homepage:http://www.kismetwireless.net/
Changes:WRT54 fixes, multiple Darwin fixes, GPS rewrite and fixes, Nokia tweaks, and Imagemagick fixes.
File Size:655362
Last Modified:May 30 14:56:32 2008
MD5 Checksum:6ee365d36354b4dee4945e67f8149294

 ///  File Name:nebula-0.2.2.tar.gz
Description:
Nebula is a data analysis tool that automatically generates intrusion signatures from attack traces. It runs as a daemon that processes data submitted from honeypots. New signatures are published as Snort rules and can be used to defend a network from future intrusion attempts.
Author:Tillmann Werner
Homepage:http://nebula.mwcollect.org/
File Size:228547
Last Modified:May 30 14:54:27 2008
MD5 Checksum:9d388753e6bf14c9811a92a586ce8cfa

 ///  File Name:haxssl.tgz
Description:
This Ruby code will test a specified Host's SSL certificate against the Debian-based blacklist of keys (RSA 2048 and DSA 1024) generated during the period where openssl on Debian-based installs suffered from a weakness in random number generation. Note that the blacklist is embedded in the code so the file is about 23 MB.
Author:Cody Tubbs
Related File:dsa-1571-1.txt
File Size:13052186
Related CVE(s):CVE-2008-0166
Last Modified:May 29 14:12:08 2008
MD5 Checksum:96666f341f89b312294862723156679c

 ///  File Name:openssl-0.9.8h.tar.gz
Description:
OpenSSL is a robust, fully featured Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols with full-strength cryptography world-wide.
Homepage:http://www.openssl.org/
Changes:Two crash related security flaws have been fixed in this version.
File Size:3439981
Related CVE(s):CVE-2008-0891, CVE-2008-1672
Last Modified:May 28 10:41:17 2008
MD5 Checksum:7d3d41dafc76cf2fcb5559963b5783b3

 ///  File Name:lynis-1.1.3.tar.gz
Description:
Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.
Author:Michael Boelen
Homepage:http://www.rootkit.nl/projects/lynis.html
File Size:55617
Last Modified:May 27 19:38:11 2008
MD5 Checksum:bf6984cd11846353a32dd979971d20c5

 ///  File Name:sqlninja-0.2.3.tgz
Description:
sqlninja is a small tool to exploit SQL injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end. Its main goal is to provide a remote shell on the vulnerable database server, even in a very hostile environment. It should be used by penetration testers to help and automate the process of taking over a database Server when a SQL injection vulnerability has been discovered. It is written in perl and runs on Unix-like boxes.
Author:icesurfer
Homepage:http://sqlninja.sourceforge.net
Changes:Added metasploit module and makescr.pl.
File Size:124338
Last Modified:May 27 18:21:29 2008
MD5 Checksum:daa9e815aa82d9f3859fb416e6eda1d0

 ///  File Name:check_weak_dh_ssh.pl.bz2
Description:
Debian OpenSSL weak client Diffie-Hellman Exchange checker version 0.1.
Author:Alexander Klink
Homepage:https://www.cynops.de/
File Size:1101005
Last Modified:May 27 17:55:31 2008
MD5 Checksum:b32413a2c121cd11b7a2754daf8f75e3

 ///  File Name:fslint-2.26.tar.gz
Description:
FSlint is a toolkit to find various forms of lint on a filesystem. At the moment it reports duplicate files, bad symbolic links, troublesome file names, empty directories, non stripped executables, temporary files, duplicate/conflicting (binary) names, and unused ext2 directory blocks.
Author:pixelbeat
Homepage:http://www.pixelbeat.org/fslint/
Changes:Added and updated multiple translations. Multiple bug fixes.
File Size:93755
Last Modified:May 22 19:45:33 2008
MD5 Checksum:edaee1b2514dbf190ecd8ba1d764f604

 ///  File Name:bunny-0.93.tgz
Description:
Bunny the Fuzzer - A closed loop, high-performance, general purpose protocol-blind fuzzer for C programs. Uses compiler-level integration to seamlessly inject precise and reliable instrumentation hooks into the traced program. These hooks enable the fuzzer to receive real-time feedback on changes to the function call path, call parameters, and return values in response to variations in input data. This architecture makes it possible to significantly improve the coverage of the testing process without a noticeable performance impact usually associated with other attempts to peek into run-time internals.
Author:Michal Zalewski
Homepage:http://code.google.com/p/bunny-the-fuzzer/
Changes:Bug fix release.
File Size:64575
Last Modified:May 22 19:44:45 2008
MD5 Checksum:95fac3531bf5b64e20aab748278c2129

 ///  File Name:volatile.txt
Description:
Volatile is an automatic SQL injection exploitation tool that takes advantage of applications discovered in search results and attempts to leverage xp_cmdshell.
Author:rfds, hash
Homepage:http://www.rfdslabs.com.br/
File Size:8176
Last Modified:May 22 01:46:10 2008
MD5 Checksum:c65ad112959ae126db862ae0b8b75f8c

 ///  File Name:LockDown-1.0.tar.gz
Description:
LockDown is an application that can be run interactively, non-interactively, or really-non-interactively to lock down a server that runs Red Hat, Fedora, CentOS, or similar systems. It sets things like umask and SGID/SUID, creates a simple firewall, and more.
Author:Rick Collette
Homepage:http://www.bayareatechops.org/rcollette/template.php?page=projects&style=default
File Size:18124
Last Modified:May 19 21:08:49 2008
MD5 Checksum:bfae47f30a4724398d62237b8546b860

 ///  File Name:unhash-1.0.tgz
Description:
UnHash is a program that performs a brute force attack against a given hash. The hash can be MD5 or SHA1, and the program will auto-detect which one is given.
Author:dxp
Homepage:http://www.geocities.com/dxp2532
Changes:Various code updates and improvements.
File Size:15626
Last Modified:May 19 19:13:27 2008
MD5 Checksum:f299bd2edd5f6f7dd1d6417d524243e5

 ///  File Name:zzuf-0.11.tar.gz
Description:
zzuf is a transparent application input fuzzer. It works by intercepting file operations and changing random bits in the program's input. zzuf's behavior is deterministic, making it easy to reproduce bugs.
Author:Sam Hocevar
Homepage:http://sam.zoy.org/zzuf/
Changes:Minor memory and speed optimizations.
File Size:440335
Last Modified:May 19 19:11:53 2008
MD5 Checksum:bcb727ffb2af3574d22f8c5768f95490

 ///  File Name:rtpbreak-1.3a.tgz
Description:
rtpBreak detects, reconstructs and analyzes any RTP [rfc1889] session through heuristics over the UDP network traffic. It works well with SIP, H.323, SCCP and any other signaling protocol. In particular, it does not require the presence of RTCP packets (voipong needs them) that are not always transmitted from the recent VoIP clients.
Author:Michele Dallachiesa
Homepage:http://xenion.antifork.org/rtpbreak/rtpbreak.html
Changes:Improved logging output of net.c Added missing gcc option. Fixed a bug.
File Size:41355
Last Modified:May 19 18:27:53 2008
MD5 Checksum:b22fc9e3f7958b00948df080b94cc339

 ///  File Name:d3sqlfuzz.py.txt
Description:
SQL fuzzing utility written in Python.
Author:d3hydr8
Homepage:http://www.darkc0de.com/
File Size:5544
Last Modified:May 19 18:22:18 2008
MD5 Checksum:cbdb6d893a58c32233f6b46bf2bace89

 ///  File Name:ttyrpld-2.51.tar.bz2
Description:
ttyrpld is a kernel-based TTY shell, screen, and key logger for Linux, FreeBSD/PCBSD, and OpenBSD. It has a real-time log analyzer. It supports any TTY type (vc (console), BSD/Unix98 pty (xterm/SSH), serial, ISDN, USB, etc.).
Author:Jan Engelhardt
Homepage:http://ttyrpld.sourceforge.net/
Changes:Updated rpldhk and rpldev for Linux 2.6.25, OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0.
File Size:183529
Last Modified:May 19 14:52:33 2008
MD5 Checksum:cc635d7f709c96115111b64185eaccf4

 ///  File Name:sqlfuzzer.py.txt
Description:
SQL Injector version 1.0 is a fuzzing utility written in Python.
Author:Beenu Arora
File Size:775
Last Modified:May 15 04:17:36 2008
MD5 Checksum:30658df42570e5cc8bf5a21363643df6

 ///  File Name:xsschecker.py.txt
Description:
Cross site scripting fuzzing utility written in Python.
Author:Beenu Arora
File Size:1945
Last Modified:May 15 04:16:34 2008
MD5 Checksum:87e7d424c10d56a7fc8c08dc5f96dc2a

 ///  File Name:nipper-0.11.7.tgz
Description:
nipper is a Network Infrastructure Configuration Parser. nipper takes a network infrastructure device configuration, processes the file and details security-related issues with the configuration together with detailed recommendations. nipper was previous known as CiscoParse. nipper currently supports Cisco switches (IOS), Cisco Routers (IOS), Cisco Firewalls (PIX/ASA/FWSM) and Juniper NetScreen (ScreenOS). Output is in HTML, Latex, XML and Text. Encrypted passwords can be output to a John-the-Ripper file for strength testing.
Author:Ian Ventura-Whiting
Homepage:http://nipper.titania.co.uk/
Changes:The release adds support for the CSV output of a devices network filtering rules and optional output of CheckPoint rule comments. Support for Nokia IP and Accelar devices is also enhanced. The update includes other minor updates that are detailed in the Changelog.
File Size:273091
Last Modified:May 12 10:53:09 2008
MD5 Checksum:cc6e500d2cefef2322ad8b4a1102aae1

 ///  File Name:nipper-0.11.7.zip
Description:
nipper is a Network Infrastructure Configuration Parser. nipper takes a network infrastructure device configuration, processes the file and details security-related issues with the configuration together with detailed recommendations. nipper was previous known as CiscoParse. nipper currently supports Cisco switches (IOS), Cisco Routers (IOS), Cisco Firewalls (PIX/ASA/FWSM) and Juniper NetScreen (ScreenOS). Output is in HTML, Latex, XML and Text. Encrypted passwords can be output to a John-the-Ripper file for strength testing. This is the Windows version.
Author:Ian Ventura-Whiting
Homepage:http://nipper.titania.co.uk/
Changes:The release adds support for the CSV output of a devices network filtering rules and optional output of CheckPoint rule comments. Support for Nokia IP and Accelar devices is also enhanced. The update includes other minor updates that are detailed in the Changelog.
File Size:662600
Last Modified:May 12 10:51:38 2008
MD5 Checksum:e9a5c045af4cfb8381c08ab8e4c3bec7

 ///  File Name:browserrecon-1.0-php.tar.gz
Description:
browserrecon is a framework that performs client-side HTTP fingerprinting. Be sure to hit their site to download the latest fingerprints database.
Author:Marc Ruef
Homepage:http://www.computec.ch/projekte/browserrecon/
File Size:8367
Last Modified:May 9 13:50:03 2008
MD5 Checksum:8dc3b53449d21666803e0b051280d3af

 ///  File Name:dradis-v1.2.tar.gz
Description:
dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.
Author:etd
Homepage:http://dradis.nomejortu.com/
File Size:2011899
Last Modified:May 7 13:42:52 2008
MD5 Checksum:481beae4f13e322aad1066ba943aafd4

 ///  File Name:samhain-2.4.4.tar.gz
Description:
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
Author:Rainer Wichmann
Homepage:http://samhain.sourceforge.net
Changes:Various updates.
File Size:1729502
Last Modified:May 6 16:13:34 2008
MD5 Checksum:6777eb51fb868b543ba846a6fa5f41fd

 ///  File Name:plash_1.19.orig.tar.gz
Description:
Plash is a sandbox for running GNU/Linux programs with minimum privileges. It is suitable for running both command line and GUI programs. It can dynamically grant Gtk-based GUI applications access rights to individual files that you want to open or edit. This happens transparently through the Open/Save file chooser dialog box, by replacing GtkFileChooserDialog. Plash virtualizes the file namespace and provides per-process/per-sandbox namespaces. It can grant processes read-only or read-write access to specific files and directories, mapped at any point in the filesystem namespace. It does not require modifications to the Linux kernel.
Author:Mark Seaborn
Homepage:http://plash.beasts.org/
Changes:Various updates and fixes.
File Size:1145328
Last Modified:May 6 16:10:52 2008
MD5 Checksum:c44d14f2ed27e248cbfd5d148c844c23

 ///  File Name:opennhrp-0.7.tar.bz2
Description:
OpenNHRP implements the NBMA Next Hop Resolution Protocol (as defined in RFC 2332). It makes it possible to create a dynamic multipoint VPN Linux router using NHRP, GRE, and IPsec. It aims to be Cisco DMVPN compatible.
Author:Timo Teras
Homepage:http://sourceforge.net/projects/opennhrp/
Changes:Multiple bug fixes, some code cleanups, and improvements.
File Size:85317
Last Modified:Apr 30 20:45:24 2008
MD5 Checksum:e653d4194e47051cad7c9ad8ccf92533

 ///  File Name:ZoneMinder-1.23.3.tar.gz
Description:
ZoneMinder is a suite of applications intended for use in video camera security applications, including theft prevention and child or family member monitoring. It supports capture, analysis, recording, and monitoring of video data coming from one or more cameras attached to a Linux system. It also features a user-friendly Web interface which allows viewing, archival, review, and deletion of images and movies captured by the cameras. The image analysis system is highly configurable, permitting retention of specific events, while eliminating false positives. ZoneMinder supports both directly connected and network cameras and is built around the definition of a set of individual 'zones' of varying sensitivity and functionality for each camera. This allows the elimination of regions which should be ignored or the definition of areas which will alarm if various thresholds are exceeded in conjunction with other zones. All management, control, and other functions are supported through the Web interface.
Author:Philip Coombes
Homepage:http://www.zoneminder.com
Changes:Fixed a number of potential vulnerabilities in remote script execution that could allow an authenticated ZoneMinder user to create and run arbitrary code on your system as the web user. Various other updates made as well.
File Size:764528
Last Modified:Apr 29 20:00:35 2008
MD5 Checksum:ee803f0f71d6e67adf602c3557fb6bc9

 ///  File Name:wtmpclean-0.6.3.tar.bz2
Description:
wtmpClean is a tool for Unix which clears a given user from the wtmp database.
Author:Davide Madrisan
Homepage:http://davide.madrisan.googlepages.com/opensource
Changes:A couple of new options and some fixes.
File Size:110490
Last Modified:Apr 29 19:58:56 2008
MD5 Checksum:d661d1fb631c9ce91bb91383d365e725

 ///  File Name:tmin-0.03.tar.gz
Description:
tmin is a quick and simple tool to minimize the size and syntax of complex test cases in automated security testing. It is meant specifically for dealing with unknown or complex data formats (without the need to tokenize and re-serialize testcases), and for easy integration with UI testing harnesses.
Author:Michal Zalewski
Homepage:http://code.google.com/p/tmin/
File Size:11319
Last Modified:Apr 28 18:38:32 2008
MD5 Checksum:403793ec22c6d0f7675c87cce652edd3

 ///  File Name:scnc-1.00.tgz
Description:
SSL Capable NetCat is just what it sounds like. It's a perl script that works just like netcat but has SSL capabilities.
Author:GomoR
Homepage:http://www.gomor.org/
File Size:3202
Last Modified:Apr 28 18:19:17 2008
MD5 Checksum:b0bfc706f65b950a94e7f20a26cfa5c4

 ///  File Name:bluemaho_v080422_beta.tar.gz
Description:
BlueMaho is a graphical user interface for a suite of tools used to test the security of bluetooth devices. It is freeware, open source, written in python, and uses wxPyhon.
Homepage:http://wiki.thc.org/BlueMaho
File Size:787754
Last Modified:Apr 28 11:18:43 2008
MD5 Checksum:1e86b38c0efb3a520188eb5acbe507fd

 ///  File Name:sipwitch-0.1.1.tar.gz
Description:
GNU SIP Witch is a pure SIP-based office telephone call server that supports generic phone system features like call forwarding, hunt groups and call distribution, call coverage and ring groups, holding, and call transfer, as well as offering SIP specific capabilities such as presence and messaging. It supports secure telephone extensions for making calls over the Internet, and intercept/decrypt-free peer-to-peer audio and video extensions. It is not a SIP proxy, a multi-protocol telephone server, or an IP-PBX, and does not try to emulate Asterisk, FreeSWITCH, or Yate.
Author:David Sugar
Homepage:http://www.gnutelephony.org/
Changes:Introduction of system and anon user identifiers. Support for SMS message generation. Various other additions.
File Size:417603
Last Modified:Apr 24 16:54:37 2008
MD5 Checksum:caf97dbd9cac8e46eef2f74db456a3de

 ///  File Name:nicelog-1.0.tgz
Description:
logtamper is a modified version of wtmpclean that also modifies UTMP and lastlog related entries.
Author:xi4oyu
File Size:160711
Last Modified:Apr 24 16:43:24 2008
MD5 Checksum:b70dede37a1971929702af7eecaba7a5

 ///  File Name:sp_2.0.zip
Description:
SQL Playground (SP) is a tool written in Perl that aims to exploit SQL injection vulnerabilities while presenting itself in a command line shell. Full paper provided to explain use.
Author:real
File Size:16174
Last Modified:Apr 23 12:41:47 2008
MD5 Checksum:8a7582ef7cdb8c929e8ad1d44c9b6017

 ///  File Name:metagoofil-1.4.tar.gz
Description:
Metagoofil is an information gathering tool designed for extracting the Meta-Data of public documents (pdf,doc,xls,ppt,etc) available on target/victim websites. It will generate a html page with the results of the Meta-Data extracted, plus a list of potential usernames.
Author:Christian Martorella
Homepage:http://www.edge-security.com/soft.php
Changes:This new version extracts the MAC address of Microsoft Office documents. The output has some changes and some minor fixes have been implemented.
File Size:10633
Last Modified:Apr 21 18:33:21 2008
MD5 Checksum:1e291245f802261ea669d82e94001ef3

 ///  File Name:incognito-v0.1.zip
Description:
Incognito is a tool for manipulating windows access tokens and is intended for use by penetration testers, security consultants and system administrators.
Author:Luke Jennings
Homepage:http://www.mwrinfosecurity.com/
Related File:mwri_security-implications-of-windows-access-tokens_2008-04-14.pdf
File Size:223814
Last Modified:Apr 21 17:25:39 2008
MD5 Checksum:7a7edfc965e2b70db37bc32b72f0438e

 ///  File Name:RFIDIOt-Windows-0.1s.zip
Description:
RFIDIOt is a python library for exploring RFID devices. It currently drives a couple of RFID readers made by ACG, called the HF Dual ISO and the LFX. Includes sample programs to read/write tags and the beginnings of library routines to handle the data structures of specific tags like MIFARE(r). This is the Windows version.
Author:Adam Laurie
Homepage:http://rfidiot.org/
Changes:Multiple bug fixes and a few additions.
File Size:4886159
Last Modified:Apr 18 14:27:01 2008
MD5 Checksum:520d182efdaa3ab5d39da0c3edb79051

 ///  File Name:RFIDIOt-0.1s.tgz
Description:
RFIDIOt is a python library for exploring RFID devices. It currently drives a couple of RFID readers made by ACG, called the HF Dual ISO and the LFX. Includes sample programs to read/write tags and the beginnings of library routines to handle the data structures of specific tags like MIFARE(r).
Author:Adam Laurie
Homepage:http://rfidiot.org/
Changes:Multiple bug fixes and a few additions.
File Size:377971
Last Modified:Apr 18 14:26:33 2008
MD5 Checksum:52a220220f699296d1c7cd90ea70ace6

 ///  File Name:afick-2.11-1.tgz
Description:
afick is another file integrity checker, designed to be fast and fully portable between Unix and Windows platforms. It works by first creating a database that represents a snapshot of the most essential parts of your computer system. Then a user can run the script to discover all modifications made since the snapshot was taken (i.e. files added, changed, or removed). The configuration syntax is very close to that of aide or tripwire, and a graphical interface is provided.
Author:Eric Gerbier
Homepage:http://afick.sourceforge.net/
Changes:Some bug fixes and additions.
File Size:616464
Last Modified:Apr 16 17:44:52 2008
MD5 Checksum:37e671d34f09a84e19deeed7b19597bf

 ///  File Name:nufw-2.2.15.tar.gz
Description:
NuFW is a set of daemons that filters packets on a per-user basis. The gateway authorizes a packet depending on which remote user has sent it. On the client side, users have to run a client that sends authentication packets to the gateway. On the server side, the gateway associates user ids to packets, thus enabling the possibility to filter packets on a user basis. Furthermore, the server architecture is done to use external authentication source such as an LDAP server.
Author:regit
Homepage:http://www.nufw.org/
Changes:This is a maintenance release which mainly contains a performance improvement in the acl cache system.
File Size:785905
Last Modified:Apr 15 13:32:11 2008
MD5 Checksum:62e0efb91229f53d918c48dce4049a53

 ///  File Name:clamav-0.93.tar.gz
Description:
Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a commandline scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.
Author:Tomasz Kojm
Homepage:http://www.clamav.net
Changes:Various bug fixes.
File Size:16134725
Last Modified:Apr 14 16:36:41 2008
MD5 Checksum:72ed6f4706858e72f24dda8a591df0da

 ///  File Name:blindsql.tgz
Description:
Blind SQL injection tool for MySQL servers using a true-false method. You can obtain MySQL information and extract data from tables without the use of quotes.
Author:Pepelux
Homepage:http://www.enye-sec.org/
File Size:6850
Last Modified:Apr 11 14:41:39 2008
MD5 Checksum:c2da36dbe2c1b79886994cd3815ae15c

 ///  File Name:nipper-0.11.6.tgz
Description:
nipper is a Network Infrastructure Configuration Parser. nipper takes a network infrastructure device configuration, processes the file and details security-related issues with the configuration together with detailed recommendations. nipper was previous known as CiscoParse. nipper currently supports Cisco switches (IOS), Cisco Routers (IOS), Cisco Firewalls (PIX/ASA/FWSM) and Juniper NetScreen (ScreenOS). Output is in HTML, Latex, XML and Text. Encrypted passwords can be output to a John-the-Ripper file for strength testing.
Author:Ian Ventura-Whiting
Homepage:http://nipper.titania.co.uk/
Changes:Multiple bug fixes and some changes.
File Size:271513
Last Modified:Apr 10 17:03:16 2008
MD5 Checksum:8f77b21a5b27ddfffb8b302275c82344

 ///  File Name:nipper-0.11.6.zip
Description:
nipper is a Network Infrastructure Configuration Parser. nipper takes a network infrastructure device configuration, processes the file and details security-related issues with the configuration together with detailed recommendations. nipper was previous known as CiscoParse. nipper currently supports Cisco switches (IOS), Cisco Routers (IOS), Cisco Firewalls (PIX/ASA/FWSM) and Juniper NetScreen (ScreenOS). Output is in HTML, Latex, XML and Text. Encrypted passwords can be output to a John-the-Ripper file for strength testing. This is the Windows version.
Author:Ian Ventura-Whiting
Homepage:http://nipper.titania.co.uk/
Changes:Multiple bug fixes and some changes.
File Size:657570
Last Modified:Apr 10 17:02:11 2008
MD5 Checksum:ced7ea05476f4805fc82a5d5c487c4de

 ///  File Name:pykeylogger-1.0.2_win32.zip
Description:
Simple Python Keylogger is a cross-platform keylogger. It is primarily designed for backup purposes, but can be used as a stealth keylogger too. Windows version.
Author:nanotube
Homepage:http://pykeylogger.sourceforge.net/
Changes:Added some graphics and icons. Various bug fixes.
File Size:4852013
Last Modified:Apr 10 16:32:54 2008
MD5 Checksum:983fa933a7c7aac48dcc185c4106a5a6

 ///  File Name:pykeylogger-1.0.2_src.zip
Description:
Simple Python Keylogger is a cross-platform keylogger. It is primarily designed for backup purposes, but can be used as a stealth keylogger too. Source archive that works on Linux.
Author:nanotube
Homepage:http://pykeylogger.sourceforge.net/
Changes:Added some graphics and icons. Various bug fixes.
File Size:88256
Last Modified:Apr 10 16:32:25 2008
MD5 Checksum:cf63c1f0c0b29045c3daa19f5a2096c7

 ///  File Name:syslog-fuzzer.txt
Description:
Syslog Fuzzer is a small perl script tool that is useful for testing some attack vectors against syslog servers. It has support for buffer/integer overflows and format string vulnerabilities.
Author:Jaime Blasco
Homepage:http://www.aitsec.com/syslog-fuzzer.php
File Size:4063
Last Modified:Apr 8 22:49:48 2008
MD5 Checksum:7a282e1f7d9772d3b3cb116e108c966c

 ///  File Name:fwbuilder-2.1.18.tar.gz
Description:
Firewall Builder for PIX hides the complexity of PIX command line interface and automatically configures options and parameters that usually make manual configuration a real chore. With this module, the same workstation running Firewall Builder can create and manage security policy on Cisco PIX or FWSM firewalls, as well as on firewalls built with iptables, OpenBSD pf, or ipfilter.
Homepage:http://www.fwbuilder.org
Changes:Various updates.
File Size:1967764
Last Modified:Apr 7 23:07:57 2008
MD5 Checksum:dade153059782164b0d326f964eca63a

 ///  File Name:d3vscan-alpha8.bz2
Description:
d3vscan is a network manager that is able to uniquely identify and graphically plot network and bluetooth devices to provide a higher degree of understanding of a particular network. It is also simple enough to be used by an average end user.
Author:devtar
Homepage:http://d3vscan.sourceforge.net/
Changes:Windows installer added. Vulnerability scanner plugin released. Several bug fixes.
File Size:13479904
Last Modified:Apr 4 19:59:57 2008
MD5 Checksum:0a9312d18748a2db3f19b727cab30ddd

 ///  File Name:opennhrp-0.6.2.tar.bz2
Description:
OpenNHRP implements the NBMA Next Hop Resolution Protocol (as defined in RFC 2332). It makes it possible to create a dynamic multipoint VPN Linux router using NHRP, GRE, and IPsec. It aims to be Cisco DMVPN compatible.
Author:Timo Teras
Homepage:http://sourceforge.net/projects/opennhrp/
Changes:Multiple bug fixes, some code cleanups, and improvements.
File Size:83951
Last Modified:Apr 4 19:14:06 2008
MD5 Checksum:190b49b866dc17288b8fff656b189b56

 ///  File Name:prelude-manager-0.9.12.tar.gz
Description:
Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis.
Homepage:http://prelude.sourceforge.net
Changes:New connection-timeout option, various fixes.
File Size:716120
Last Modified:Apr 4 19:09:14 2008
MD5 Checksum:60be3113caa01d3389433aa5b43880b6

 ///  File Name:accbrute.py.txt
Description:
Local account bruteforcing utility using the su command and a python module called pexpect.
Author:d3hydr8
Homepage:http://www.darkc0de.com/
File Size:1261
Last Modified:Apr 4 18:50:07 2008
MD5 Checksum:8e1f68783134c3682af356330a0e0f06

 ///  File Name:FTPNullSearch02.tar.gz
Description:
FTPNullSearch is a FTP scanner that can scan a range of IPs looking for servers that allow anonymous logins. Written for Linux.
Author:Simpp
File Size:4538
Last Modified:Apr 4 18:49:04 2008
MD5 Checksum:71b1286f3af2a1d9dd75a3de11410700

 ///  File Name:silk-1.0.0.tar.gz
Description:
SiLK (System for Internet-Level Knowledge) consists of two sets of tools: a packing system and an analysis suite. The packing system receives Netflow V5 PDUs and converts them into a more space efficient format, recording the packed records into service-specific binary flat files. The analysis suite consists of tools that can read these flat files and then perform various query operations, ranging from per-record filtering to statistical analysis of groups of records. The analysis tools interoperate using pipes, allowing a user to develop a relatively sophisticated query from a simple beginning.
Author:CERT NetSA
Homepage:http://tools.netsa.cert.org/silk/
File Size:2120408
Last Modified:Apr 3 01:39:34 2008
MD5 Checksum:77498d53d396c4040ac23cfdb71dc6cf

 ///  File Name:httpry-0.1.3.tar.gz
Description:
httpry is a specialized packet sniffer designed for displaying and logging HTTP traffic. It is not intended to perform analysis itself, but instead to capture, parse, and log the traffic for later analysis. It can be run in real-time displaying the live traffic on the wire, or as a daemon process that logs to an output file. It is written to be as lightweight and flexible as possible, so that it can be easily adaptable to different applications. It does not display the raw HTTP data transferred, but instead focuses on parsing and displaying the request/response line along with associated header fields.
Author:Jason
Homepage:http://dumpsterventures.com/jason/httpry/
File Size:40720
Last Modified:Apr 3 01:16:46 2008
MD5 Checksum:3d91e672272054e0bebd9ef9bab38a50

 ///  File Name:nipper-0.11.5.zip
Description:
nipper is a Network Infrastructure Configuration Parser. nipper takes a network infrastructure device configuration, processes the file and details security-related issues with the configuration together with detailed recommendations. nipper was previous known as CiscoParse. nipper currently supports Cisco switches (IOS), Cisco Routers (IOS), Cisco Firewalls (PIX/ASA/FWSM) and Juniper NetScreen (ScreenOS). Output is in HTML, Latex, XML and Text. Encrypted passwords can be output to a John-the-Ripper file for strength testing. This is the Windows version.
Author:Ian Ventura-Whiting
Homepage:http://nipper.titania.co.uk/
Changes:This release includes updates to the report output from Nipper, some minor PQR issues and resolves issues reported by the community.
File Size:237191
Last Modified:Apr 3 00:57:59 2008
MD5 Checksum:d01cd5cccaf3095dc5c098ea17ee1cab

 ///  File Name:nipper-0.11.5.tgz
Description:
nipper is a Network Infrastructure Configuration Parser. nipper takes a network infrastructure device configuration, processes the file and details security-related issues with the configuration together with detailed recommendations. nipper was previous known as CiscoParse. nipper currently supports Cisco switches (IOS), Cisco Routers (IOS), Cisco Firewalls (PIX/ASA/FWSM) and Juniper NetScreen (ScreenOS). Output is in HTML, Latex, XML and Text. Encrypted passwords can be output to a John-the-Ripper file for strength testing. This is the source version.
Author:Ian Ventura-Whiting
Homepage:http://nipper.titania.co.uk/
Changes:This release includes updates to the report output from Nipper, some minor PQR issues and resolves issues reported by the community.
File Size:271788
Last Modified:Apr 3 00:57:33 2008
MD5 Checksum:e9d2cb237ef775e63b955fe7a17693f7

 ///  File Name:proxystrike-v1.0.zip
Description:
ProxyStrike is an active Web Application Proxy and is a tool designed to find vulnerabilities while browsing an application. It current has SQL injection and cross site scripting modules. This is the Windows version. Written in Python.
Author:Carlos del Ojo Elias
Homepage:http://www.edge-security.com/
File Size:8579802
Last Modified:Mar 31 22:41:52 2008
MD5 Checksum:bd80bf552c714af9a119ea7644e9f236

 ///  File Name:proxystrike-v1.0.tar.gz
Description:
ProxyStrike is an active Web Application Proxy and is a tool designed to find vulnerabilities while browsing an application. It current has SQL injection and cross site scripting modules. This is the Linux / Mac OSX version. Written in Python.
Author:Carlos del Ojo Elias
Homepage:http://www.edge-security.com/
File Size:34585
Last Modified:Mar 31 22:41:12 2008
MD5 Checksum:c21708cc21671b83f1bd286f0407e4bb

 ///  File Name:jscript.txt
Description:
This is an interesting little tool that converts shellcode to javascript.
Author:pentest
Homepage:http://security-sh3ll.com/
File Size:4525
Last Modified:Mar 31 22:09:42 2008
MD5 Checksum:9142baf7c6d41af013d3ac5b121cb166

 ///  File Name:arpalert-2.0.10.tar.gz
Description:
arpalert uses ARP address monitoring to help prevent unauthorized connections on the local network. If an illegal connection is detected, a program or script is launched, which could be used to send an alert message, for example.
Author:Thierry Fournier
Homepage:http://perso.numericable.fr/~fourthie/arpalert.php
Changes:A bug fix and a new script added.
File Size:602693
Last Modified:Mar 28 16:50:44 2008
MD5 Checksum:762298e677122c6ab2786ef3d57aa2f1