Hiển thị các bài đăng có nhãn Tools. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn Tools. Hiển thị tất cả bài đăng

Thứ Ba, 13 tháng 12, 2016

Code counter by Juno_okyo - Th?ng k� l�?ng code s? d?ng trong project

Trong qu� tr?nh code J2TeaM Security, Juno_okyo c� vi?t c�i tool nho nh? v?i t�n g?i Code Counter d�ng �? th?ng k� xem m?nh �? vi?t ��?c bao nhi�u Lines-of-Code (d?ng code).

Ch? c?n ch?n th� m?c ch?a m? ngu?n v� nh?p c�c extension c?a file m� b?n mu?n �?m. V� d?, J2TeaM Security l� extension n�n m?nh ch? l?a ra c�c ng�n ng? ��?c h? tr? l� HTML/CSS/JS/JSON. Ph?n Exclude Folders l� �? ch?n c�c th� m?c con s? b? b? qua, v� d? trong h?nh l� m?nh b? qua m?t s? th� m?c ch?a file t?m.

code-counter-by-juno-okyo

Theo nh� k?t qu? th? m?nh �? vi?t h�n 5500 d?ng. Trong �� ch? ri�ng JS chi?m h�n 4300 d?ng. Reaction s? hi?n th? d?a theo k?t qu?. V� d? h�n 100 l� Love, h�n 500 l� Haha, h�n 1000 tr? l�n s? hi?n Wow.

B?n n�o th�ch c� th? t?i tool n�y t?i ��y: http://bit.ly/2gD3RCN

M?t kh?u gi?i n�n: junookyo.blogspot.com

M? ngu?n s? share tr�n trang GitHub c?a Juno_okyo trong th?i gian t?i.

Thứ Tư, 20 tháng 7, 2016

PentestBox - m�i tr�?ng ki?m th? th�m nh?p tuy?t v?i tr�n Windows

pentest-box-windows-hacking-toolkit

L?i m? �?u

��i khi, b?n th?y c� nh?ng c�ng c? b?o m?t, qu�t l? h?ng r?t tuy?t v?i cho �?n khi b?n v�o trang ch? �? t?i v? th? b?t g?p d?ng ch? "Windows is not supported"... Nh�ng �?ng bu?n, v? b?n kh�ng ph?i l� ng�?i duy nh?t g?p v?n �? ��.
wpscan-beef-hydra-on-windows
V� may m?n thay, �� c?ng ch�nh l� l? do v? sao PentestBox ra �?i!

PentestBox l� g??

PentestBox l� m?t m�i tr�?ng th? nghi?m th�m nh?p Portable m? ngu?n m? ��?c c?u h?nh s?n cho h? �i?u h�nh Windows.
Read More

Thứ Năm, 12 tháng 5, 2016

Thứ Bảy, 6 tháng 6, 2015

G? b? bi?u t�?ng "Get Windows 10" ch? v?i 1 click!

G? b? bi?u t�?ng "Get Windows 10" ch? v?i 1 click!
G? b? bi?u t�?ng "Get Windows 10" ch? v?i 1 click!

G? b? bi?u t�?ng "Get Windows 10" ch? v?i 1 click!

T?nh h?nh l� kho?ng m?t tu?n g?n ��y th? d�?i Tray Menu �? b?t �?u xu?t hi?n th�m 1 bi?u t�?ng "Get Windows 10" �? th�ng b�o, ch�o m?i ng�?i d�ng ��ng k? n�ng c?p l�n Windows 10. B?n n�o �ang d�ng Windows 7/8 ch?c c?ng �? th?y nh?.


Read More

Thứ Hai, 4 tháng 5, 2015

C�c c�ng c?, add-on Firefox h?u �ch cho nh� ph�t tri?n web

C�c c�ng c?, add-on Firefox h?u �ch cho nh� ph�t tri?n web
C�c c�ng c?, add-on Firefox h?u �ch cho nh� ph�t tri?n web
M?t trong nh?ng m?c ti�u lu�n ��?c quan t�m c?a Firefox l� l�m cho cu?c s?ng c?a c�c nh� ph�t tri?n web tr? n�n d? d�ng v� hi?u qu? nh?t c� th? b?ng c�ch cung c?p c�c c�ng c? v� m?t tr?nh duy?t web r?t m? r?ng �? cho ph�p m?i ng�?i t?o ra nh?ng �i?u tuy?t v?i.

Danh s�ch n�y li?t k� r?t nhi?u c�c c�ng c?, add-on v� c�c t�y ch?n c� s?n d�nh cho nh� ph�t tri?n web s? d?ng tr?nh duy?t Firefox.


Read More

Thứ Bảy, 2 tháng 5, 2015

C�c c�ng c? b?o m?t c?a Google (Security Tools)

Google Security Tools
Google Security Tools
Google lu�n coi tr?ng b?o m?t h? th?ng c?a h? c?ng nh� b?o v? d? li?u c?a ng�?i d�ng. V� Google c?ng mu?n gi�p �? ng�?i kh�c t�ng �? b?o m?t c?a t?t c? c�c h? th?ng k?t n?i Internet. M?t trong nh?ng c�ch h? l�m �i?u n�y �� l� ph�t h�nh m?t s? c�ng c? b?o m?t d�?i d?ng m? ngu?n m?.


Read More

Chủ Nhật, 1 tháng 3, 2015

FBHT v3.0 - Facebook Hacking Tool (Like flood, Note DDoS attack, FBFriendlyLogout, more...)

 
 
FBHT (Facebook Hacking Tool) is an open-source tool written in Python that exploits multiple vulnerabilities on the Facebook platform

The tool provides:
  • 1) Create accounts
  • 2) Delete all accounts for a given user
  • 3) Send friendship requests (Test Accounts)
  • 4) Accept friendship requests (Test Accounts)
  • 5) Connect all the accounts of the database
  • 6) Link Preview hack (Simple web version)
  • 7) Link Preview hack (Youtube version)
  • 8) Youtube hijack
  • 9) Private message, Link Preview hack (Simple web version)
  • 10) Private message, Link Preview hack (Youtube version)
  • 11) NEW Like flood
  • 12) Publish a post as an App (App Message Spoof)
  • 13) Bypass friendship privacy
  • 14) Bypass friendship privacy with graph support
  • 15) Analyze an existing graph
  • 16) Link to disclosed friendships
  • 17) Print database status
  • 18) Increase logging level globally
  • 19) Set global login (Credentials stored in memory - Danger)
  • 20) Print dead attacks :\'( 
  • 21) Send friend request to disclosed friend list from your account
  • 22) Bypass friendship (only .dot without graph integration)
  • 23) Note DDoS attack
  • 24) Old Like Flood (Not working)
  • 25) NEW! SPAM any fanpage inbox
  • 26) Bypass - database support (Beta)
  • 27) Logout all your friends - FB blackout 
  • 28) Close the application

Web Application Protection - Tool to detect and correct vulnerabilities in PHP web applications

 

WAP 2.0 is a source code static analysis and data mining tool to detect and correct input validation vulnerabilities in web applications written in PHP (version 4.0 or higher) and with a low rate of false positives. WAP detects and corrects the following vulnerabilities:
  • SQL Injection (SQLI)
  • Cross-site scripting (XSS)
  • Remote File Inclusion (RFI)
  • Local File Inclusion (LFI)
  • Directory Traversal or Path Traversal (DT/PT)
  • Source Code Disclosure (SCD)
  • OS Command Injection (OSCI)
  • PHP Code Injection
This tool semantically analyses the source code. More precisely, it does taint analysis (data-flow analysis) to detect the input validation vulnerabilities. The aim of the taint analysis is to track malicious inputs inserted by entry points ($_GET, $_POST arrays) and to verify if they reaches some sensitive sink (PHP functions that can be exploited by malicious input). After the detection, the tool uses data mining to confirm if the vulnerabilities are real or false positives. At the end, the real vulnerabilities are corrected with the insertion of the fixes (small pieces of code) in the source code. WAP is written in Java language and is constituted by three modules:
  • Code Analyzer: composed by tree generator and taint analyser. The tool has integrated a lexer and a parser generated by ANTLR, and based in a grammar and a tree grammar written to PHP language. The tree generator uses the lexer and the parser to build the AST (Abstract Sintatic Tree) to each PHP file. The taint analyzer performs the taint analysis navigating through the AST to detect potentials vulnerabilities.

  • False Positives Predictor: composed by a supervised trained data set with instances classified as being vulnerabilities and false positives and by the Logistic Regression machine learning algorithm. For each potential vulnerability detected by code analyser, this module collects the presence of the attributes that define a false positive. Then, the Logistic Regression algorithm receives them and classifies the instance as being a false positive or not (real vulnerability).

  • Code Corrector: Each real vulnerability is removed by correction of its source code. This module for the type of vulnerability selects the fix that removes the vulnerability and signalizes the places in the source code where the fix will be inserted. Then, the code is corrected with the insertion of the fixes and new files are created.    

UFONet - DDoS attacks via Web Abuse (XSS/CSRF)



UFONet - is a tool designed to launch DDoS attacks against a target, using 'Open Redirect' vectors on third party web applications, like botnet.

See this links for more info:
- CWE-601:Open Redirect
- OWASP:URL Redirector Abuse

Main features:

--version             show program's version number and exit
  -v, --verbose         active verbose on requests
  --check-tor           check to see if Tor is used properly
  --update              check for latest stable version

  *Configure Request(s)*:
    --proxy=PROXY       Use proxy server (tor: http://localhost:8118)
    --user-agent=AGENT  Use another HTTP User-Agent header (default SPOOFED)
    --referer=REFERER   Use another HTTP Referer header (default SPOOFED)
    --host=HOST         Use another HTTP Host header (default NONE)
    --xforw             Set your HTTP X-Forwarded-For with random IP values
    --xclient           Set your HTTP X-Client-IP with random IP values
    --timeout=TIMEOUT   Select your timeout (default 30)
    --retries=RETRIES   Retries when the connection timeouts (default 1)
    --delay=DELAY       Delay in seconds between each HTTP request (default 0)

  *Manage Botnet*:
    -s SEARCH           Search 'zombies' on google (ex: -s 'proxy.php?url=')
    --sn=NUM_RESULTS    Set max number of result to search (default 10)
    -t TEST             Test list of web 'zombie' servers (ex: -t zombies.txt)

  *Configure Attack(s)*:
    -r ROUNDS           Set number of 'rounds' for the attack (default: 1)
    -b PLACE            Set a place to 'bit' on target (ex: -b /path/big.jpg)
    -a TARGET           Start a Web DDoS attack (ex: -a http(s)://target.com)


PhEmail - Sending Phishing Emails



Pass unrar:  quylevhb.blogspot.com


PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test. The main purpose of PhEmail is to send a bunch of phishing emails and prove who clicked on them without attempting to exploit the web browser or email client but collecting as much information as possible. PhEmail comes with an engine to garther email addresses through LinkedIN, useful during the information gathering phase. Also, this tool supports Gmail authentication which is a valid option in case the target domain has blacklisted the source email or IP address. Finally, this tool can be used to clone corporate login portals in order to steal login credentials.

Installation
You can download the latest version of PhEmail by cloning the GitHub repository:

git clone https://github.com/Dionach/PhEmail

Usage
PHishing EMAIL tool v0.13
Usage: phemail.py [-e <emails>] [-m <mail_server>] [-f <from_address>] [-r <replay_address>] [-s <subject>] [-b <body>]
          -e    emails: File containing list of emails (Default: emails.txt)
          -f    from_address: Source email address displayed in FROM field of the email (Default: Name Surname <name_surname@example.com>)
          -r    reply_address: Actual email address used to send the emails in case that people reply to the email (Default: Name Surname <name_surname@example.com>)
          -s    subject: Subject of the email (Default: Newsletter)
          -b    body: Body of the email (Default: body.txt)
          -p    pages: Specifies number of results pages searched (Default: 10 pages)
          -v    verbose: Verbose Mode (Default: false)
          -l    layout: Send email with no embedded pictures
          -B    BeEF: Add the hook for BeEF
          -m    mail_server: SMTP mail server to connect to
          -g    Google: Use a google account username:password
          -t    Time delay: Add deleay between each email (Default: 3 sec)
          -R    Bunch of emails per time (Default: 10 emails)
          -L    webserverLog: Customise the name of the webserver log file (Default: Date time in format "%d_%m_%Y_%H_%M")
          -S    Search: query on Google
          -d    domain: of email addresses
          -n    number: of emails per connection (Default: 10 emails)
          -c    clone: Clone a web page
          -w    website: where the phishing email link points to
          -o    save output in a file
          -F    Format (Default: 0):
                0- firstname surname
                1- firstname.surname@example.com
                2- firstnamesurname@example.com
                3- f.surname@example.com
                4- firstname.s@example.com
                5- surname.firstname@example.com
                6- s.firstname@example.com
                7- surname.f@example.com
                8- surnamefirstname@example.com
                9- firstname_surname@example.com

Examples: phemail.py -e emails.txt -f "Name Surname <name_surname@example.com>" -r "Name Surname <name_surname@example.com>" -s "Subject" -b body.txt
          phemail.py -S example -d example.com -F 1 -p 12
          phemail.py -c https://example.com

Disclaimer

Usage of PhEmail for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume NO liability and are NOT responsible for any misuse or damage caused by this program.

Thứ Tư, 25 tháng 2, 2015

SSH Scanner & SSH Checker (cracked)

1. Lazy SSH - Scanner
- Ch?c n�ng: d�ng �? scan SSH, h? tr? scan c�ng l�c nh?u range, mullti threads m?nh m?

2. Lazy SSH - Checker
- Ch?c n�ng: d�ng �? m? username/password c?a SSH, multi threads lu�n


Pass unrar:  quylevhb.blogspot.com

SSH Scanner & SSH Checker (cracked)

1. Lazy SSH - Scanner
- Chức năng: dùng để scan SSH, hỗ trợ scan cùng lúc nhìu range, mullti threads mạnh mẽ

2. Lazy SSH - Checker
- Chức năng: dùng để mò username/password của SSH, multi threads luôn


Pass unrar:  quylevhb.blogspot.com

Gr3eNoX Exploit Scanner V1.1 - Tool scan shop l?i


Gr3eNoX Exploit Scanner
Pass unrar: quylevhb.blogspot.com

Gr3eNoX Exploit Scanner V1.1 - Tool scan shop lỗi


Gr3eNoX Exploit Scanner
Pass unrar: quylevhb.blogspot.com

Thứ Ba, 24 tháng 2, 2015

Ani Shell

Ani Shell




Ani-Shell is a simple PHP shell with some unique features like Mass Mailer , A simple Web-Server Fuzzer , DDoser, Back Connect , Bind Shell etc etc ! This shell has immense capabilities and have been written with some coding standards in mind for better editing and customization.

Customisation
1. Email Trace back is set to Off as default and emails will not be sent , If you are setting
this feature on make sure you change the default email address (lionaneesh@gmail.com)
 to Your email address , Please Change it before using.
2. Username and Passwords are set to lionaneesh and lionaneesh respectively , Please change them for better
security.
3. As a default Lock Mode is set to on! This should not be change unless you want your shell exposed.

Default Login
Username : lionaneesh
Password : lionaneesh

Features
    Shell
    Platform Independent
    Mass - Mailer
    Small Web-Server Fuzzer
    DDoser
    Design
    Secure Login
    Deletion of Files
    Bind Shell
    Back Connect
    Fixed Some Coding errors!
    Rename Files
    Encoded Title
    Traceback (Email Alerts)
    PHP Evaluate
    Better Command Execution (even supports older version of PHP)
    Mass Code Injector (Appender and Overwriter)
    Lock Mode Customization

Latest Version Addition
    Mail Bomber (With Less Spam detection feature)
    PHP Decoder
    Better Uploader
    Fixed some Coding errors
DRIL � Domain Reverse IP Lookup Tool

DRIL � Domain Reverse IP Lookup Tool



DRIL (Domain Reverse IP Lookup) Tool is a Reverse Domain Tool that will really be useful for penetration testers to find out the domain names which are listed in the the target host, DRIL is a GUI, JAVA based application which uses a Bing API key.

DRIL has a simple user friendly interface which will be helpful for penetration tester to do their work fast without a mess, this is only tested on Linux but as it is JAVA it should work on Windows too.
There are various other tools which carry out similar tasks..


DRIL – Domain Reverse IP Lookup Tool

DRIL – Domain Reverse IP Lookup Tool



DRIL (Domain Reverse IP Lookup) Tool is a Reverse Domain Tool that will really be useful for penetration testers to find out the domain names which are listed in the the target host, DRIL is a GUI, JAVA based application which uses a Bing API key.

DRIL has a simple user friendly interface which will be helpful for penetration tester to do their work fast without a mess, this is only tested on Linux but as it is JAVA it should work on Windows too.
There are various other tools which carry out similar tasks..