<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" gd:etag="W/&quot;CEYMQH06fip7ImA9WhBaEkQ.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003</id><updated>2013-05-23T08:56:21.316+02:00</updated><category term="Browser" /><category term="Malware" /><category term="Rootkit" /><category term="0day" /><category term="Security-Distro" /><category term="Bugs" /><category term="SQL Injection" /><category term="Fuzzer" /><category term="Tools" /><category term="Botnet" /><category term="Security" /><category term="XSS" /><category term="News" /><category term="Papers" /><title>Security-Shell</title><subtitle type="html">Hacking and Security tools . News and Views for the World ®</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>1193</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Security-shell" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="security-shell" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">Security-shell</feedburner:emailServiceId><feedburner:feedburnerHostname xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">http://feedburner.google.com</feedburner:feedburnerHostname><entry gd:etag="W/&quot;CEYMQH04eSp7ImA9WhBaEkQ.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-8600509015761048542</id><published>2013-05-23T08:56:00.000+02:00</published><updated>2013-05-23T08:56:21.331+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-23T08:56:21.331+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security" /><category scheme="http://www.blogger.com/atom/ns#" term="News" /><title>OWASP Europe Tour - Bucharest 2013</title><content type="html">&lt;b&gt;&lt;a href="https://www.owasp.org/index.php/EUTour2013"&gt;OWASP Europe TOUR&lt;/a&gt;,&lt;/b&gt; &lt;i&gt;is an event across the European region that 
promotes  awareness about application security, so that people and 
organizations can make informed decisions about true application 
security risks. Everyone is free to participate in OWASP and all of our 
materials are available under a free and open software license.
&lt;/i&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;Apart from OWASP's Top 10, most OWASP Projects are not widely 
used and understood. In most cases this is not due to lack of quality 
and usefulness of those Document &amp;amp; Tool projects, but due to a lack 
of understanding of where they fit in an Enterprise's security ecosystem
 or in the Web Application Development Life-cycle.&lt;/i&gt; &lt;/li&gt;
&lt;/ul&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-xSNSgr27Wjc/UZ29SptheQI/AAAAAAAABJM/76NvyJp-kb4/s1600/xs.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="199" src="http://3.bp.blogspot.com/-xSNSgr27Wjc/UZ29SptheQI/AAAAAAAABJM/76NvyJp-kb4/s320/xs.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;b&gt;Date:&lt;/b&gt; Wednesday 5th of June   
 
&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Venue Location: &lt;/b&gt;University "Politehnica" of Bucharest

&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Venue Address:&lt;/b&gt; Splaiul Independentei nr. 313, sector 6, Bucuresti, ROMANIA; Rectorship Building, Senate Hall
Postal cod: RO-060042 &lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Source&lt;/em&gt;: &lt;em&gt;&lt;a href="https://www.owasp.org/"&gt;https://www.owasp.org&lt;/a&gt;&amp;nbsp;&lt;/em&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/8600509015761048542/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=8600509015761048542" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/8600509015761048542?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/8600509015761048542?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/05/owasp-europe-tour-bucharest-2013.html" title="OWASP Europe Tour - Bucharest 2013" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-xSNSgr27Wjc/UZ29SptheQI/AAAAAAAABJM/76NvyJp-kb4/s72-c/xs.jpg" height="72" width="72" /><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;C0AMRX45fip7ImA9WhBaEEs.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-7846769352124550274</id><published>2013-05-20T16:56:00.000+02:00</published><updated>2013-05-20T16:56:24.026+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-20T16:56:24.026+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="SQL Injection" /><title>DroidSQLi - MySQL Injection tool for Android</title><content type="html">&lt;em&gt;DroidSQLi is the first automated MySQL Injection tool for Android. It 
allows you to test your MySQL-based web application against SQL 
injection attacks. &amp;nbsp;&lt;/em&gt;&lt;br /&gt;
&lt;em&gt;&lt;br /&gt;&lt;/em&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-2YrKk7HOV8c/UZo5WbAqGyI/AAAAAAAABI8/gQGASD45UvQ/s1600/unnamed.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://4.bp.blogspot.com/-2YrKk7HOV8c/UZo5WbAqGyI/AAAAAAAABI8/gQGASD45UvQ/s200/unnamed.jpg" width="111" /&gt;&lt;/a&gt;&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;DroidSQLi supports the following injection techniques:&lt;/strong&gt;&lt;br /&gt;- Time based injection&lt;br /&gt;- Blind injection&lt;br /&gt;- Error based injection&lt;br /&gt;- Normal injection&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Get it from&lt;/strong&gt; &amp;nbsp;&lt;a href="https://play.google.com/store/apps/details?id=net.edgard.droidsqli"&gt;https://play.google.com/store/apps/details?id=net.edgard.droidsqli&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/7846769352124550274/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=7846769352124550274" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7846769352124550274?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7846769352124550274?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/05/droidsqli-mysql-injection-tool-for.html" title="DroidSQLi - MySQL Injection tool for Android" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-2YrKk7HOV8c/UZo5WbAqGyI/AAAAAAAABI8/gQGASD45UvQ/s72-c/unnamed.jpg" height="72" width="72" /><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;CEYGRno-eip7ImA9WhBbE0U.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-2921188816178458540</id><published>2013-05-12T20:08:00.003+02:00</published><updated>2013-05-12T20:08:47.452+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-12T20:08:47.452+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Papers" /><title>Static Analysis Technologies Evaluation Criteria Released</title><content type="html">&lt;b&gt;Introduction:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Static code analysis is the analysis of software source or binary code. It aims at automating code analysis to find as many common software security weaknesses as possible. There are several open source and commercial static code analysis tools and services available in the market for organizations to choose from. &lt;br /&gt;&lt;br /&gt;Static code analysis is rapidly becoming an essential part of most software organizations' application security assurance program. Mainly because of their ability to analyze large amounts of source code in considerably shorter amount of time than a human could, uncover potential weaknesses, in addition to the ability to automate security knowledge and workflows.&lt;/i&gt;&amp;nbsp;



&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Download PDF:&lt;/strong&gt;&amp;nbsp; &lt;a href="http://projects.webappsec.org/w/file/fetch/66107997/SATEC_Manual-02.pdf"&gt;http://projects.webappsec.org/w/file/fetch/66107997/SATEC_Manual-02.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Source: &lt;/strong&gt;&lt;a href="http://projects.webappsec.org/w/page/66094278/Static%20Analysis%20Technologies%20Evaluation%20Criteria"&gt;http://projects.webappsec.org&lt;/a&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/2921188816178458540/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=2921188816178458540" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/2921188816178458540?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/2921188816178458540?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/05/static-analysis-technologies-evaluation.html" title="Static Analysis Technologies Evaluation Criteria Released" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;AkYEQHk6eip7ImA9WhBbE0k.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-8646110914119979235</id><published>2013-05-12T10:41:00.003+02:00</published><updated>2013-05-12T10:41:41.712+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-12T10:41:41.712+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security-Distro" /><title>AttackVector Linux</title><content type="html">&lt;b&gt;Linux distro for anonymized penetration based on Kali and TAILS
            &amp;nbsp;&lt;/b&gt; 

&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;AttackVector Linux is a new distribution for anonymized penetration and security. It is based on Kali and TAILS, which are both based on Debian. While Kali requires a modified kernel for network drivers to use injection and so forth, the Tor Project's TAILS is designed from the bottom up for encryption, and anonymity. Nmap can't UDP via Tor. The intention of AttackVector Linux is to provide the capability to anonymize attacks while warning the user when he or she takes actions that may compromize anonymity. The two projects have different design philosophies that can directly conflict with one another. In spite of this, the goal of AttackVector Linux is to integrate them complementarily into one OS.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Download:&lt;/b&gt; &lt;a href="https://bitbucket.org/attackvector/attackvector-linux/downloads"&gt;https://bitbucket.org/attackvector&lt;/a&gt; 

&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;More Info:&amp;nbsp;&lt;/b&gt;&lt;a href="https://github.com/ksoona/attackvector"&gt;https://github.com/ksoona/attackvector&lt;/a&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/8646110914119979235/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=8646110914119979235" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/8646110914119979235?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/8646110914119979235?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/05/attackvector-linux.html" title="AttackVector Linux" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;Ck4ARngycCp7ImA9WhBUGUk.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-5751768424540331572</id><published>2013-05-07T17:35:00.001+02:00</published><updated>2013-05-07T17:35:47.698+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-07T17:35:47.698+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><title>SpiderFoot v.2.0 Released</title><content type="html">&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;b&gt;&lt;a href="http://2.bp.blogspot.com/-S02qkbNyt7E/UYke-CHle4I/AAAAAAAABIo/42GyvOnR0ok/s1600/xd.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="125" src="http://2.bp.blogspot.com/-S02qkbNyt7E/UYke-CHle4I/AAAAAAAABIo/42GyvOnR0ok/s200/xd.jpg" width="200" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;Open source Footprinting tool&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;SpiderFoot is an open source footprinting tool, available for Windows 
and Linux. It is written in Python and provides an easy-to-use GUI. 
SpiderFoot obtains a wide range of information about a target, such as 
web servers, netblocks, e-mail addresses and more.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;SpiderFoot is designed from the ground-up to be modular. This means 
you can easily add your own modules that consume data from other modules
 to perform whatever task you desire.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;
      &lt;/i&gt;&lt;i&gt;As a simple example, you could create a module that 
automatically attempts to brute-force usernames and passwords any time a
 password-handling webpage is identified by the spidering module.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Download:&lt;/b&gt; &amp;nbsp;&lt;a href="https://github.com/smicallef/spiderfoot"&gt;https://github.com/smicallef/spiderfoot&lt;/a&gt; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href="http://sourceforge.net/projects/spiderfoot/"&gt;http://sourceforge.net/projects/spiderfoot/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;More Info:&lt;/b&gt; &amp;nbsp;&lt;a href="http://www.spiderfoot.net/"&gt;http://www.spiderfoot.net&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/5751768424540331572/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=5751768424540331572" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/5751768424540331572?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/5751768424540331572?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/05/spiderfoot-v20-released.html" title="SpiderFoot v.2.0 Released" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-S02qkbNyt7E/UYke-CHle4I/AAAAAAAABIo/42GyvOnR0ok/s72-c/xd.jpg" height="72" width="72" /><thr:total>1</thr:total></entry><entry gd:etag="W/&quot;AkQDRHc4fSp7ImA9WhBUE00.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-1712213735861671402</id><published>2013-04-30T09:52:00.005+02:00</published><updated>2013-04-30T09:52:55.935+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-30T09:52:55.935+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><title>Arachni v0.4.2 Released</title><content type="html">&lt;b&gt;Web Application Security Scanner Framework&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt; 

&lt;i&gt;Arachni is an Open Source, feature-full, modular, high-performance Ruby framework aimed towards helping penetration testers and administrators evaluate the security of web applications. 
It is smart, it trains itself by learning from the HTTP responses it receives during the audit process and is able to perform meta-analysis using a number of factors in order to correctly assess the trustworthiness of results and intelligently identify false-positives. It is versatile enough to cover a great deal of use cases, ranging from a simple command line scanner utility, to a global high performance grid of scanners, to a Ruby library allowing for scripted audits, to a multi-user multi-scan web collaboration platform. &lt;/i&gt;


&lt;i&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/i&gt;
&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;The change-log is quite sizeable but the gist is:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;* Brand new web interface -- allowing for team collaboration.&lt;br /&gt;   * Significant decreases in memory usage.&lt;br /&gt;   * Issue remarks –  Providing extra context to logged issues.&lt;br /&gt;   * Improved payloads for Windows machines for path traversal and OS command injection.&lt;br /&gt;   * RPC API updates allowing for much easier remote scan management.&lt;br /&gt;   * Much improved profiling and detection of custom 404 responses.&lt;br /&gt;   * The ability to exclude pages from the scan based on content.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;For more details and Download visit:&lt;/b&gt; &amp;nbsp;&amp;nbsp;    &lt;a href="http://www.arachni-scanner.com/blog/new-release-v0-4-2-new-interface-new-website/"&gt;http://www.arachni-scanner.com&lt;/a&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/1712213735861671402/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=1712213735861671402" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/1712213735861671402?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/1712213735861671402?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/04/arachni-v042-released.html" title="Arachni v0.4.2 Released" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;DkIHRXo8eCp7ImA9WhBVEE4.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-133917465670100171</id><published>2013-04-15T16:00:00.000+02:00</published><updated>2013-04-15T16:02:14.470+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-15T16:02:14.470+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><title>Canari Framework</title><content type="html">&lt;b&gt;Canari - Maltego Rapid Transform Development Framework&lt;/b&gt; 

&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Canari is a rapid transform development framework for &lt;a href="http://paterva.com/"&gt;Maltego&lt;/a&gt; written in Python. The original focus of Canari was to provide a set of transforms that would aid in the execution of penetration tests, and vulnerability assessments. Ever since it's first prototype, it has become evident that the framework can be used for much more than that. Canari is perfect for anyone wishing to graphically represent their data in Maltego without the hassle of learning a whole bunch of unnecessary stuff. It has generated interest from digital forensics analysts to pen-testers, and even psychologists. &amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;b&gt;Canari's core features include:&lt;/b&gt;&amp;nbsp;
    &amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;- An easily extensible and configurable framework that promotes maximum reusability;
    &amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;- A set of powerful and easy-to-use scripts for debugging, configuring, and installing transforms;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;-Finally, a great number of community provided transforms.&lt;/i&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;More info and Download:&lt;/b&gt; &lt;a href="http://www.canariproject.com/"&gt;http://www.canariproject.com&amp;nbsp;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Video demo:&lt;/strong&gt; &lt;a href="http://www.youtube.com/allfro"&gt;http://www.youtube.com/allfro&lt;/a&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/133917465670100171/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=133917465670100171" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/133917465670100171?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/133917465670100171?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/04/canari-framework.html" title="Canari Framework" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>1</thr:total></entry><entry gd:etag="W/&quot;A0QBRHs8fyp7ImA9WhBXGUU.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-4469964404558363194</id><published>2013-04-03T13:42:00.000+02:00</published><updated>2013-04-03T13:42:35.577+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-03T13:42:35.577+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security-Distro" /><title>AppUse - Android Pentest Platform Unified Standalone Environment</title><content type="html">
&lt;em&gt;AppSec Labs recently developed the AppUse Virtual Machine. This system 
is a unique, free, platform for mobile application security testing in 
the android environment, and it includes unique custom-made tools 
created by &lt;/em&gt;&lt;a href="https://appsec-labs.com/"&gt;&lt;em&gt;AppSec Labs.&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&amp;nbsp;&lt;/em&gt;&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;
&lt;em&gt;&lt;br /&gt;&lt;/em&gt;
&lt;em&gt;
&lt;/em&gt;
&lt;div style="text-align: justify;"&gt;
&lt;em&gt;There is no need for installation of 
simulators and testing tools, no need for SSL certificates of the proxy 
software, everything comes straight out of the box pre-installed and 
configured for an ideal user experience.&lt;/em&gt;&lt;em&gt;Security experts who have seen the 
machine were very excited, calling it the next ‘BackTrack’ (a famous 
system for testing security problems), specifically adjusted for android
 application security testing.&amp;nbsp;&lt;/em&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;/div&gt;
&lt;em&gt;
&lt;/em&gt;&lt;div style="text-align: justify;"&gt;
&lt;strong&gt;&lt;em&gt;AppUse VM&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; closes gaps 
in the world of security, now there is a special and customized testing 
environment for android applications.&amp;nbsp;&lt;/em&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;/div&gt;
&lt;em&gt;
&lt;/em&gt;&lt;div style="text-align: justify;"&gt;
&lt;em&gt;This machine is intended for the daily 
use of security testers everywhere for Android applications, and is a 
must-have tool for any security person.&amp;nbsp;&lt;/em&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;strong&gt;Download:&lt;/strong&gt;&lt;em&gt; &lt;/em&gt;&lt;a href="http://sourceforge.net/projects/appuse/files/?source=directory"&gt;http://sourceforge.net&lt;/a&gt;&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;/div&gt;
</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/4469964404558363194/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=4469964404558363194" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/4469964404558363194?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/4469964404558363194?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/04/appuse-android-pentest-platform-unified.html" title="AppUse - Android Pentest Platform Unified Standalone Environment" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;DU8FRX47cSp7ImA9WhBQF00.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-7780493971394646135</id><published>2013-03-19T16:43:00.002+01:00</published><updated>2013-03-19T16:43:34.009+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-19T16:43:34.009+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><title>XSSF - Cross-Site Scripting Framework  v.3.0 Released</title><content type="html">

&lt;em&gt;The Cross-Site Scripting Framework (&lt;/em&gt;&lt;strong&gt;&lt;em&gt;XSSF&lt;/em&gt;&lt;/strong&gt;&lt;em&gt;) is a 
security tool designed to turn the XSS vulnerability exploitation task 
into a much easier work. The XSSF project aims to demonstrate the real 
dangers of XSS vulnerabilities, vulgarizing their exploitation. This 
project is created solely for education, penetration testing and lawful 
research purposes.&amp;nbsp;&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;XSSF allows creating a &lt;/em&gt;&lt;strong&gt;&lt;em&gt;communication channel&lt;/em&gt;&lt;/strong&gt;&lt;em&gt;&amp;nbsp; with the targeted browser (from a XSS vulnerability) in order to 
perform further attacks. Users are free to select existing modules (a 
module = an attack) in order to target specific browsers. &lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;XSSF 
provides a powerfull documented API, which facilitates development of 
modules and attacks. In addition, its integration into the &lt;/em&gt;&lt;strong&gt;&lt;em&gt;Metasploit Framework&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; allows users to launch MSF browser based exploit easilly from an XSS vulnerability. &lt;/em&gt;&lt;br /&gt;
&lt;em&gt;&lt;br /&gt;&lt;/em&gt;
&lt;em&gt;&lt;br /&gt;&lt;/em&gt;
&lt;span class="watch-title  yt-uix-expander-head" dir="ltr" id="eow-title" title="XSSF Basics: Install [Kali-1.0] &amp;amp; Use"&gt;&lt;strong&gt;XSSF Basics: Install on Kali-1.0 Video Demo : &lt;/strong&gt;&lt;/span&gt;&lt;span class="watch-title  yt-uix-expander-head" dir="ltr" id="eow-title" title="XSSF Basics: Install [Kali-1.0] &amp;amp; Use"&gt;&lt;a href="http://www.youtube.com/watch?v=AhUhOirEfTE"&gt;http://www.youtube.com/watch?v=AhUhOirEfTE&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="watch-title  yt-uix-expander-head" dir="ltr" title="XSSF Basics: Install [Kali-1.0] &amp;amp; Use"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span class="watch-title  yt-uix-expander-head" dir="ltr" title="XSSF Basics: Install [Kali-1.0] &amp;amp; Use"&gt;&lt;strong&gt;Download:&lt;/strong&gt; &lt;a href="https://code.google.com/p/xssf/downloads/list"&gt;https://code.google.com&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;

&lt;em&gt;&amp;nbsp;&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/7780493971394646135/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=7780493971394646135" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7780493971394646135?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7780493971394646135?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/03/xssf-cross-site-scripting-framework-v30.html" title="XSSF - Cross-Site Scripting Framework  v.3.0 Released" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>1</thr:total></entry><entry gd:etag="W/&quot;CEQAQ3g9fyp7ImA9WhBQFkw.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-8553514013498287065</id><published>2013-03-18T14:11:00.002+01:00</published><updated>2013-03-18T14:12:22.667+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-18T14:12:22.667+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="SQL Injection" /><title>jSQL Injection v0.3</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;a href="http://3.bp.blogspot.com/-pI3KJx3vAdU/UUcSFHaKWII/AAAAAAAABIU/egDVJrkeWz8/s1600/111.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="150" src="http://3.bp.blogspot.com/-pI3KJx3vAdU/UUcSFHaKWII/AAAAAAAABIU/egDVJrkeWz8/s200/111.png" width="200" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;i&gt;jSQL Injection is a lightweight application used to find database information from a distant server.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;jSQL is free, open source and cross-platform (Windows, Linux, Mac OS X, Solaris).&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Features:&lt;/b&gt; &lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;GET, POST, header, cookie methods &lt;/li&gt;
&lt;li&gt;Normal, error based, blind, time based algorithms &lt;/li&gt;
&lt;li&gt;Automatic best algorithm selection &lt;/li&gt;
&lt;li&gt;Thread control (start/pause/resume/stop) &lt;/li&gt;
&lt;li&gt;Expose URL calls &lt;/li&gt;
&lt;li&gt;Simple evasion &lt;/li&gt;
&lt;li&gt;Data retrieving progression bar &lt;/li&gt;
&lt;li&gt;Proxy setting &lt;/li&gt;
&lt;li&gt;Distant file reading &lt;/li&gt;
&lt;li&gt;Webshell deposit &lt;/li&gt;
&lt;li&gt;Terminal for webshell commands &lt;/li&gt;
&lt;li&gt;Configuration backup &lt;/li&gt;
&lt;li&gt;jSQL version checker &lt;/li&gt;
&lt;li&gt;Supports MySQL&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;b&gt;Download: &lt;a href="https://code.google.com/p/jsql-injection/downloads/list"&gt;https://code.google.com&lt;/a&gt;&lt;/b&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/8553514013498287065/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=8553514013498287065" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/8553514013498287065?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/8553514013498287065?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/03/jsql-injection-v03.html" title="jSQL Injection v0.3" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-pI3KJx3vAdU/UUcSFHaKWII/AAAAAAAABIU/egDVJrkeWz8/s72-c/111.png" height="72" width="72" /><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;DkEESXY5eip7ImA9WhBQE0k.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-5843042668421637726</id><published>2013-03-15T11:50:00.000+01:00</published><updated>2013-03-15T11:50:08.822+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-15T11:50:08.822+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><title>SCIP – Indentify, Enumerate and Execute Invisible ASP.net Controls</title><content type="html">&lt;div class="MsoNormal" style="direction: ltr;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-sxy9zxR5ciI/UUL8oBG26uI/AAAAAAAABIE/l6Js1SPp3Bs/s1600/s.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="140" src="http://4.bp.blogspot.com/-sxy9zxR5ciI/UUL8oBG26uI/AAAAAAAABIE/l6Js1SPp3Bs/s200/s.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
SCIP
is an &lt;a href="http://code.google.com/p/zaproxy/"&gt;OWASP ZAP&lt;/a&gt; extension designed to assess the security of ASP.net and Mono
applications, while abusing platform specific behaviors and misconfigurations.&amp;nbsp;&lt;/div&gt;
&lt;div class="MsoNormal" style="direction: ltr;"&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="direction: ltr;"&gt;
&lt;b&gt;The
extension currently supports the following features:&amp;nbsp;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="direction: ltr;"&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="direction: ltr;"&gt;
&lt;b&gt;Identify&lt;/b&gt; the
existence of invisible, commented and disabled server side web controls in
ASP.net – passively (!). Identify which ASP.net
security configuration is active in each page (EventValidation, MAC), and in
which cases the invisible controls are exploitable – passively (!)&amp;nbsp;&lt;/div&gt;
&lt;div class="MsoNormal" style="direction: ltr;"&gt;
&lt;br /&gt;
&lt;b&gt;Enumerate&lt;/b&gt; the names
of invisible controls using built-in &lt;b&gt;customizable&lt;/b&gt; dictionaries with
ASP.net naming conventions. &lt;br /&gt;
Rebuild the event validation
whenever possible (MAC=off)&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;Execute&lt;/b&gt; invisible
controls when &lt;b&gt;either&lt;/b&gt; one of the security features is turned OFF, or when
there is a server-side callback implementation flaw.&lt;br /&gt;
&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-family: 'Times New Roman'; font-size: 7pt;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;b&gt; &lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Execute&lt;/b&gt; disabled
controls and commented out controls &lt;b&gt;regardless&lt;/b&gt; of security&lt;br /&gt;
Support additional manual
techniques for executing controls despite the security features.&lt;br /&gt;
&lt;div class="MsoNormal" style="direction: ltr;"&gt;
&lt;br /&gt;
&lt;b&gt;The
extension can be obtained from the project's website or from ZAP's built-in
marketplace feature:&amp;nbsp;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="direction: ltr;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;span dir="RTL" style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11.0pt; line-height: 115%;"&gt;&lt;a href="https://code.google.com/p/ria-scip/" target="_blank"&gt;&lt;span dir="LTR"&gt;https://code.google.com/p/ria-scip/&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;
</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/5843042668421637726/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=5843042668421637726" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/5843042668421637726?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/5843042668421637726?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/03/scip-indentify-enumerate-and-execute.html" title="SCIP – Indentify, Enumerate and Execute Invisible ASP.net Controls" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-sxy9zxR5ciI/UUL8oBG26uI/AAAAAAAABIE/l6Js1SPp3Bs/s72-c/s.jpg" height="72" width="72" /><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;C0IBRng8fyp7ImA9WhBSFUs.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-1212778464901598163</id><published>2013-02-22T20:32:00.001+01:00</published><updated>2013-02-22T20:32:37.677+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-22T20:32:37.677+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><title>WPScan - WordPress Security Scanner Android App.</title><content type="html">

&lt;b&gt;&lt;a href="http://www.randomstorm.com/wpscan-security-tool.php"&gt;WPScan&lt;/a&gt;&lt;/b&gt; &lt;i&gt;is a black box WordPress Security Scanner 
written in Ruby which attempts to find known security weaknesses within 
WordPress installations. Its intended use it to be for security 
professionals or WordPress administrators to asses the security posture 
of their WordPress installations. &amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-VqOZdspbKXc/USfEp8USGqI/AAAAAAAABH0/qCflBuNrDaI/s1600/Screenshot_2013-02-22-21-17-49.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-VqOZdspbKXc/USfEp8USGqI/AAAAAAAABH0/qCflBuNrDaI/s200/Screenshot_2013-02-22-21-17-49.png" width="112" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&amp;nbsp; Download: &lt;a href="https://play.google.com/store/apps/details?id=it.clshack.wpscan&amp;amp;rdid=it.clshack.wpscan&amp;amp;rdot=1"&gt;https://play.google.com&lt;/a&gt;&lt;/strong&gt; &amp;nbsp;or from Github &lt;a href="https://github.com/clshack/WPScan"&gt;https://github.com&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/1212778464901598163/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=1212778464901598163" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/1212778464901598163?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/1212778464901598163?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/02/wpscan-wordpress-security-scanner_22.html" title="WPScan - WordPress Security Scanner Android App." /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-VqOZdspbKXc/USfEp8USGqI/AAAAAAAABH0/qCflBuNrDaI/s72-c/Screenshot_2013-02-22-21-17-49.png" height="72" width="72" /><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;CUAFQnc_cCp7ImA9WhBTGUg.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-7538216429711023524</id><published>2013-02-15T19:37:00.000+01:00</published><updated>2013-02-15T19:41:53.948+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-15T19:41:53.948+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Papers" /><title>OWASP Top 10 Application Security Risks – 2013 Released</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-h7D96Sn_rLI/UR6BRpiHXII/AAAAAAAABHk/Ov85jDmSx6I/s1600/X.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/-h7D96Sn_rLI/UR6BRpiHXII/AAAAAAAABHk/Ov85jDmSx6I/s200/X.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;i&gt;The OWASP Top 10 is based on risk data from 8 firms that specialize in application security, including 4 consulting companies and 4 tool vendors (2 static and 2 dynamic). This data spans over 500,000 vulnerabilities across hundreds of organizations and thousands of applications. The Top 10 items are selected and prioritized according to this prevalence data, in combination with consensus estimates of exploitability, detectability, and impact estimates.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Download:&lt;/b&gt; &lt;a href="https://code.google.com/p/owasptop10/downloads/list"&gt;&lt;b&gt;https://code.google.com/p/owasptop10&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Source: &lt;a href="https://www.owasp.org/index.php/Top_10_2013-Introduction"&gt;https://www.owasp.org&lt;/a&gt;&lt;/b&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/7538216429711023524/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=7538216429711023524" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7538216429711023524?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7538216429711023524?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/02/owasp-top-10-application-security-risks.html" title="OWASP Top 10 Application Security Risks – 2013 Released" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-h7D96Sn_rLI/UR6BRpiHXII/AAAAAAAABHk/Ov85jDmSx6I/s72-c/X.jpg" height="72" width="72" /><thr:total>2</thr:total></entry><entry gd:etag="W/&quot;DUQNQX07fSp7ImA9WhBTE00.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-3934941656657492172</id><published>2013-02-08T08:09:00.001+01:00</published><updated>2013-02-08T08:09:50.305+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-08T08:09:50.305+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security-Distro" /><title>Active Defense Harbinger Distribution v.0.4.1</title><content type="html">
&lt;em&gt;The Active Defense Harbinger Distribution (ADHD) is a Linux distro based
 on Ubuntu 12.04 LTS.  It comes with many tools aimed at active defense 
preinstalled and configured.  The purpose of this distribution is to aid
 defenders by giving them tools to "strike back" at the bad guys.&lt;br /&gt;
&lt;br /&gt;
ADHD has tools whose functions range from interfering with the 
attackers' reconnaissance to compromising the attackers' systems.  
Innocent bystanders will never notice anything out of the ordinary as 
the active defense mechanisms are triggered by malicious activity such 
as network scanning or connecting to restricted services.&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Download:&lt;/strong&gt; &amp;nbsp;&lt;a href="http://sourceforge.net/projects/adhd/files/Releases/0.4.1/"&gt;http://sourceforge.net&lt;/a&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/3934941656657492172/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=3934941656657492172" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/3934941656657492172?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/3934941656657492172?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/02/active-defense-harbinger-distribution.html" title="Active Defense Harbinger Distribution v.0.4.1" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;DUAHRX87cCp7ImA9WhNUF0w.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-7758868794487379639</id><published>2013-01-09T08:48:00.001+01:00</published><updated>2013-01-09T08:48:54.108+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-09T08:48:54.108+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><title>Watcher v1.5.6 Released</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-1E-TjQV1wjM/UO0gq1_WcII/AAAAAAAABHE/X9PP14G36Rs/s1600/1.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="184" src="http://2.bp.blogspot.com/-1E-TjQV1wjM/UO0gq1_WcII/AAAAAAAABHE/X9PP14G36Rs/s200/1.gif" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;strong&gt;&lt;/strong&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;
&lt;strong&gt;Web security testing tool and passive vulnerability scanner&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Watcher is a runtime passive-analysis tool for HTTP-based Web applications. Being passive means it won't damage production systems, it's completely safe to use in Cloud computing, shared hosting, and dedicated hosting environments. Watcher detects Web-application security issues as well as operational configuration issues. Watcher provides pen-testers hot-spot detection for vulnerabilities, developers quick sanity checks, and auditors PCI compliance auditing. It looks for issues related to mashups, user-controlled payloads (potential XSS), cookies, comments, HTTP headers, SSL, Flash, Silverlight, referrer leaks, information disclosure, Unicode, and more.&amp;nbsp;&lt;/em&gt;&lt;br /&gt;
&lt;em&gt;&lt;br /&gt;&lt;/em&gt;
&lt;em&gt;Watcher is built as a plugin for the Fiddler HTTP debugging proxy available at &lt;a href="http://www.fiddlertool.com/"&gt;www.fiddlertool.com&lt;/a&gt;. Fiddler provides all of the rich functionality of a good Web/HTTP proxy. With Fiddler you can capture all HTTP traffic, intercept and modify, replay requests, and much much more. Fiddler provides the HTTP proxy framework for Watcher to work in, allowing for seamless integration with today’s complex Web 2.0 or Rich Internet Applications. Watcher runs silently in the background while you drive your browser and interact with the Web-application.&amp;nbsp;&lt;/em&gt;&lt;br /&gt;
&lt;em&gt;&lt;br /&gt;&lt;/em&gt;
&lt;em&gt;&lt;br /&gt;&lt;/em&gt;
&lt;strong&gt;Download:&lt;/strong&gt;&lt;strong&gt; &lt;/strong&gt;&lt;a href="http://websecuritytool.codeplex.com/releases/view/22212"&gt;http://websecuritytool.codeplex.com&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/7758868794487379639/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=7758868794487379639" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7758868794487379639?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7758868794487379639?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2013/01/watcher-v156-released.html" title="Watcher v1.5.6 Released" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-1E-TjQV1wjM/UO0gq1_WcII/AAAAAAAABHE/X9PP14G36Rs/s72-c/1.gif" height="72" width="72" /><thr:total>1</thr:total></entry><entry gd:etag="W/&quot;D0QNQngyeip7ImA9WhNVE0s.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-2265717419034205902</id><published>2012-12-24T17:09:00.002+01:00</published><updated>2012-12-24T17:09:53.692+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-24T17:09:53.692+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="SQL Injection" /><title>SQL Fingerprint Xmas Released</title><content type="html">&lt;br /&gt;


&lt;strong&gt;&lt;em&gt;Microsoft SQL Server&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; fingerprinting can be a time 
consuming process, because it involves trial and error methods to 
determine the exact version. Intentionally inserting an invalid input to
 obtain a typical error message or using certain alphabets that are 
unique for certain server are two of the many ways to possibly determine
 the version, but most of them require authentication, permissions 
and/or privileges on &lt;/em&gt;&lt;strong&gt;&lt;em&gt;Microsoft SQL Server&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; to succeed. &lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Instead, &lt;/em&gt;&lt;strong&gt;&lt;em&gt;ESF.pl&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; uses a combination of crafted packets for SQL Server Resolution Protocol (&lt;/em&gt;&lt;strong&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/cc219703.aspx" rel="nofollow"&gt;&lt;em&gt;SSRP&lt;/em&gt;&lt;/a&gt;&lt;/strong&gt;&lt;em&gt;) and Tabular Data Stream Protocol (&lt;/em&gt;&lt;strong&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd304523.aspx" rel="nofollow"&gt;&lt;em&gt;TDS&lt;/em&gt;&lt;/a&gt;&lt;/strong&gt;&lt;em&gt;) (protocols natively used by &lt;/em&gt;&lt;strong&gt;&lt;em&gt;Microsoft SQL Server&lt;/em&gt;&lt;/strong&gt;&lt;em&gt;) to accurately perform version fingerprinting and determine the exact &lt;/em&gt;&lt;strong&gt;&lt;em&gt;Microsoft SQL Server&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; version. &lt;/em&gt;&lt;strong&gt;&lt;em&gt;ESF.pl&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; also applies a sophisticated Scoring Algorithm Mechanism (Powered by &lt;/em&gt;&lt;em&gt;Exploit Next Generation&lt;/em&gt;&lt;sup&gt;&lt;em&gt;++&lt;/em&gt;&lt;/sup&gt;&lt;em&gt; Technology&lt;/em&gt;&lt;em&gt;), which is a much more reliable technique to determine the &lt;/em&gt;&lt;strong&gt;&lt;em&gt;Microsoft SQL Server&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; version. It is a tool intended to be used by: &lt;/em&gt;&lt;br /&gt;
&lt;em&gt;&lt;/em&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;


&lt;pre style="margin: 0em;"&gt;&lt;em&gt;This version is a completely rewritten version in Perl, making ESF.pl much more portable than the previous binary 
version (Win32), and its original purpose is to be used as a tool to perform automated penetration test. This version 
also includes the followingMicrosoft SQL Server versions to its fingerprint database:&lt;/em&gt;
        • Microsoft SQL Server 2012 SP1 (CU1)
        • Microsoft SQL Server 2012 SP1
        • Microsoft SQL Server 2012 SP1 CTP4
        • Microsoft SQL Server 2012 SP1 CTP3
        • Microsoft SQL Server 2012 SP0 (CU4)
        • Microsoft SQL Server 2012 SP0 (MS12-070)
        • Microsoft SQL Server 2012 SP0 (CU3)
        • Microsoft SQL Server 2012 SP0 (CU2)
        • Microsoft SQL Server 2012 SP0 (CU1)
        • Microsoft SQL Server 2012 SP0 (MS12-070)
        • Microsoft SQL Server 2012 SP0 (KB2685308)
        • Microsoft SQL Server 2012 RTM&lt;/pre&gt;
&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;Download:&lt;/strong&gt; &lt;a href="http://code.google.com/p/sql-fingerprint-next-generation/downloads/list"&gt;http://code.google.com&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="http://code.google.com/p/sql-fingerprint-next-generation"&gt;http://code.google.com/p/sql-fingerprint-next-generation&lt;/a&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/2265717419034205902/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=2265717419034205902" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/2265717419034205902?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/2265717419034205902?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2012/12/sql-fingerprint-xmas-released.html" title="SQL Fingerprint Xmas Released" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;CkcARnw_eyp7ImA9WhNXEk0.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-5154187808378285197</id><published>2012-11-29T15:40:00.000+01:00</published><updated>2012-11-29T15:40:47.243+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-29T15:40:47.243+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><title>Xenotix XSS Exploit Framework v.2 Released</title><content type="html">&lt;em&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework"&gt;&amp;nbsp;Xenotix XSS Exploit Framework&lt;/a&gt; is a penetration testing tool to detect and exploit XSS vulnerabilities in Web Applications. This tool can inject codes into a webpage which are vulnerable to XSS. It is basically a payload list based XSS Scanner and XSS Exploitation kit. It provides a penetration tester the ability to test all the XSS payloads available in the payload list against a web application to test for XSS vulnerabilities. The tool supports both manual mode and automated time sharing based test modes. The exploitation framework in the tool includes a XSS encoder, a victim side XSS keystroke logger, an Executable Drive-by downloader and a XSS Reverse Shell. These exploitation tools will help the penetration tester to create proof of concept attacks on vulnerable web applications during the creation of a penetration test report.&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Features:&amp;nbsp;&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Built in XSS Payloads&lt;br /&gt; XSS Key logger &lt;br /&gt; XSS Executable Drive-by downloader &lt;br /&gt; Automatic XSS Testing &lt;br /&gt; XSS Encoder &lt;br /&gt;&amp;nbsp;XSS Reverse Shell (new)&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Download:&lt;/strong&gt; &lt;a href="https://www.owasp.org/index.php/File:Xenotix_XSS_Exploit_Framework_2013_v2.zip"&gt;https://www.owasp.org/index.php/File:Xenotix_XSS_Exploit_Framework_2013_v2.zip&lt;/a&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/5154187808378285197/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=5154187808378285197" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/5154187808378285197?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/5154187808378285197?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2012/11/xenotix-xss-exploit-framework-v2.html" title="Xenotix XSS Exploit Framework v.2 Released" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;C0IEQH08eip7ImA9WhNREUQ.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-55860809476431199</id><published>2012-11-06T09:45:00.000+01:00</published><updated>2012-11-06T09:45:01.372+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-06T09:45:01.372+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="SQL Injection" /><category scheme="http://www.blogger.com/atom/ns#" term="Fuzzer" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><title>Diviner - OWASP Zed Attack Proxy Extension</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-_hJXvL5YvzI/UJjNUAQZGwI/AAAAAAAABGs/GpSn-RWL7Gc/s1600/DIV.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="121" src="http://4.bp.blogspot.com/-_hJXvL5YvzI/UJjNUAQZGwI/AAAAAAAABGs/GpSn-RWL7Gc/s200/DIV.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;i&gt;&lt;a href="http://sectooladdict.blogspot.ro/2012/07/the-diviner-clairvoyance-in-digital.html"&gt;&amp;nbsp;&lt;/a&gt;&lt;/i&gt;&lt;i&gt;&lt;a href="http://sectooladdict.blogspot.ro/2012/07/the-diviner-clairvoyance-in-digital.html"&gt;Diviner&lt;/a&gt; is a unique platform that attempts to predict the structure of the server-side memory, source code and processes,by executing scenarios aimed to fingerprint behaviors that derive from specific lines of code, processes or memory allocations,by employing the use of a variety of coverage processes, content differentiation tests and entry point execution scenarios,and by using deduction algorithms that convert this information into a visual map of the application.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;
&lt;i&gt;Diviner analyzes and reuses the requests found in &lt;a href="http://code.google.com/p/zaproxy/"&gt;ZAP's &lt;/a&gt;history at at the moment of its activation, activates the application entry points under different extreme conditions, generates and isolates specific application behaviors,and uses the information obtained to predict the structure of the server side memory,source code, and processes.These aspects are then presented in the form of a visual map,which includes leads, tasks and payload recommendations.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;Diviner also attempts to analyze this information in order to locate potential leads for vulnerabilities,both simple and complex, and provides recommendations for detecting and exploiting them.&lt;br /&gt;&amp;nbsp;&lt;/i&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;b&gt;Video Demo: &amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt; &lt;a href="http://www.youtube.com/watch?v=RmxiUL8ImkA&amp;amp;feature=plcp"&gt;Using the Clairvoyance Feature to Gain Insight into the Server Memory, Code and Processes &lt;/a&gt;&lt;br /&gt; &lt;a href="http://www.youtube.com/watch?v=3Gh4_UnUrKg&amp;amp;feature=plcp"&gt;Using the Advisor Feature to Detect SQL Injection via Session Attributes &lt;/a&gt;&lt;br /&gt; &lt;a href="http://www.youtube.com/watch?v=YKfIIVi8IN8&amp;amp;feature=plcp"&gt;Using the Advisor Feature to Detect XSS via Session Attributes&lt;/a&gt;&lt;/i&gt; 


&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;More info:&lt;/b&gt; &lt;a href="http://sectooladdict.blogspot.com/2012/07/the-diviner-clairvoyance-in-digital.html"&gt;http://sectooladdict.blogspot.com&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Download: &lt;/strong&gt;&lt;a href="http://code.google.com/p/diviner/downloads/list"&gt;http://code.google.com&lt;/a&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/55860809476431199/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=55860809476431199" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/55860809476431199?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/55860809476431199?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2012/11/diviner-owasp-zed-attack-proxy-extension.html" title="Diviner - OWASP Zed Attack Proxy Extension" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-_hJXvL5YvzI/UJjNUAQZGwI/AAAAAAAABGs/GpSn-RWL7Gc/s72-c/DIV.png" height="72" width="72" /><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;DEMMQXwzeip7ImA9WhNSGUs.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-2679993713657745584</id><published>2012-11-03T19:14:00.001+01:00</published><updated>2012-11-03T19:14:40.282+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-03T19:14:40.282+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><title>Cookie Cadger v.0.9</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-E5ud28C1EJk/UJVd2KYpiuI/AAAAAAAABGI/yWIfL13jJR8/s1600/CookieCadgerRequests.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="143" src="http://3.bp.blogspot.com/-E5ud28C1EJk/UJVd2KYpiuI/AAAAAAAABGI/yWIfL13jJR8/s200/CookieCadgerRequests.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;An auditing tool for Wi-Fi or wired Ethernet connections&lt;/b&gt;&amp;nbsp;

&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.cookiecadger.com/"&gt;Cookie Cadger&lt;/a&gt; helps identify information leakage from applications that utilize insecure HTTP GET requests.
 
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Cookie Cadger works on Windows, Linux, or Mac, and requires Java 7. Using Cookie Cadger requires having “tshark” – a utility which is part of the Wireshark suite, to be installed. Usually simply installing Wireshark will be sufficient.

Additionally, to capture packets promiscuously requires compatible hardware. Capturing Wi-Fi traffic requires hardware capable of monitor mode, and the knowledge of how to place your device into monitor mode.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Download:&lt;/strong&gt; &lt;a href="https://www.cookiecadger.com/files/CookieCadger-0.9.jar"&gt;https://www.cookiecadger.com&lt;/a&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/2679993713657745584/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=2679993713657745584" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/2679993713657745584?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/2679993713657745584?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2012/11/cookie-cadger-v09.html" title="Cookie Cadger v.0.9" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-E5ud28C1EJk/UJVd2KYpiuI/AAAAAAAABGI/yWIfL13jJR8/s72-c/CookieCadgerRequests.png" height="72" width="72" /><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;D0YNQ3syfSp7ImA9WhNSF0s.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-7649972474689257810</id><published>2012-11-01T11:14:00.000+01:00</published><updated>2012-11-01T11:19:52.595+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-01T11:19:52.595+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><title>Scylla  v.1.0 - Advanced Audit Tool</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-5v44TR-_4eE/UJJJ0yOB8FI/AAAAAAAABF4/yq4SBiGaOKA/s1600/smbi.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="141" src="http://2.bp.blogspot.com/-5v44TR-_4eE/UJJJ0yOB8FI/AAAAAAAABF4/yq4SBiGaOKA/s200/smbi.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;
&lt;i&gt;Scylla is a tool to audit different online application protocols and configurations, built over a brute-force core.This tool acts at a tool for unifying auditing techniques, in other words, it does what oscanner, winfingerprint, Hydra, DirBuster, and other tools do, and also what those tools don’t do. &amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Scylla is arguably the first free-open source auditing/hacking tool for protocols such as LDAP, DB2, Postgres, terminal and Mssql; Scylla adds tons of new features to what those other tools do but with a key difference: it does them faster and smarter!&amp;nbsp;&lt;/i&gt; 





























&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Supported Protocols: &amp;nbsp;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
- Terminal (Telnet, SSH, telnets)&lt;br /&gt;
- FTP (FTPS, FTP, SFTP)&lt;br /&gt;
- SMB (Also Windows RPC)&lt;br /&gt;
- LDAP&lt;br /&gt;
- POP3 (POP3S)&lt;br /&gt;
- SMTP (SMTPS)&lt;br /&gt;
- IMAP&lt;br /&gt;
- MySql&lt;br /&gt;
- MSSQL&lt;br /&gt;
- Oracle (Database and TNS Listener)&lt;br /&gt;
- DB2 (Database and DAS)&lt;br /&gt;
- HTTP(HTTPS; Basic AUTH Brute Force, Digest AUTH Brute Force, Form Brute Force, Directory and files Brute Force)&lt;br /&gt;
- DNS (DNS snooping)&lt;br /&gt;
- Postgres SQL&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Scylla functions on three basic stages: - Pre-Hack Stage,Brute Force Stage and Post Hack Stage.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Basic features: &amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
- User, password list based Brute force&lt;br /&gt;
- Multiple hosts support&lt;br /&gt;
- Multiple session support&lt;br /&gt;
- Nmap integration&lt;br /&gt;
- Non-synchronized threads (proof to be a bit faster)&lt;br /&gt;
- Ability to restore sessions&lt;br /&gt;
- Session auto-saving (based on SQL Server CE)&lt;br /&gt;
- Easy to use&lt;br /&gt;
- Auto configured options&lt;br /&gt;
- Hacker oriented&lt;br /&gt;
- Free, and always free&lt;br /&gt;
- Database browser (who have hacked a DB and don’t have a DB client to connect to it? And worse if you don’t have internet)&lt;br /&gt;
- Open source tool&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Download: &lt;a href="http://code.google.com/p/scylla-v1/downloads/list"&gt;http://code.google.com&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;More Screenshots:&lt;/strong&gt; &lt;a href="http://code.google.com/p/scylla-v1/wiki/ScyllaScreenShots"&gt;http://code.google.com/p/scylla-v1/wiki/ScyllaScreenShots&lt;/a&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/7649972474689257810/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=7649972474689257810" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7649972474689257810?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7649972474689257810?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2012/11/scylla-v10-advanced-audit-tool.html" title="Scylla  v.1.0 - Advanced Audit Tool" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-5v44TR-_4eE/UJJJ0yOB8FI/AAAAAAAABF4/yq4SBiGaOKA/s72-c/smbi.png" height="72" width="72" /><thr:total>2</thr:total></entry><entry gd:etag="W/&quot;DkUGSH87cCp7ImA9WhNSFkQ.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-2853857400156049166</id><published>2012-10-31T15:37:00.000+01:00</published><updated>2012-10-31T15:37:09.108+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-10-31T15:37:09.108+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><title>Burp Suite Free Edition v1.5 released </title><content type="html">&lt;i&gt;&lt;a href="http://portswigger.net/burp/"&gt;Burp Suite&lt;/a&gt; is an integrated platform for performing 
security testing of web applications. Its various tools work seamlessly 
together to support the entire testing process, from initial mapping and 
analysis of an application's attack surface, through to finding and 
exploiting security vulnerabilities.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;

&lt;i&gt;This is a significant upgrade with a wealth of new features added since v1.4. The most notable of these are described below. &amp;nbsp;&lt;/i&gt;&lt;a href="http://blog.portswigger.net/2012/10/burp-suite-free-edition-v15-released.html"&gt; http://blog.portswigger.net&lt;/a&gt;&amp;nbsp;

&lt;br /&gt;
&lt;br /&gt;
In my opinion this is one of the best tool around so don't hesitate to try it!</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/2853857400156049166/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=2853857400156049166" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/2853857400156049166?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/2853857400156049166?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2012/10/burp-suite-free-edition-v15-released.html" title="Burp Suite Free Edition v1.5 released " /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>1</thr:total></entry><entry gd:etag="W/&quot;A0cGQ3c-fSp7ImA9WhNSEk4.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-8315326624124184390</id><published>2012-10-26T10:10:00.000+02:00</published><updated>2012-10-26T10:10:22.955+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-10-26T10:10:22.955+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="SQL Injection" /><category scheme="http://www.blogger.com/atom/ns#" term="Fuzzer" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><title>The Teenage Mutant Ninja Turtles project</title><content type="html">&lt;b&gt;&lt;a href="http://securityhorror.blogspot.ie/2012/06/obfuscate-sql-fuzzing-for-fun-and.html"&gt;The Teenage Mutant Ninja Turtles project is four things:&lt;/a&gt;&lt;/b&gt;  &lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;A Web Application payload database. &lt;/li&gt;
&lt;li&gt;A Web Application error database. &lt;/li&gt;
&lt;li&gt;A Web Application payload mutator. &lt;/li&gt;
&lt;li&gt;A Web Application payload manager (e.g. does database clean up). &lt;/li&gt;
&lt;/ol&gt;
&lt;i&gt;Nowadays
 all high profile sites found in financial and telecommunication sector 
use filters to filter out all types of vulnerabilities such as SQL, XSS,
 XXE, Http Header Injection e.t.c. In this particular project I am going
 to provide you with a tool to generate Obfuscated Fuzzing Injection 
attacks on order to bypass badly implemented Web Application injection 
filters (e.t.c SQL Injections, XSS Injections e.t.c). &lt;/i&gt;&lt;br /&gt;
&lt;i&gt;
&lt;/i&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;Download: &lt;a href="http://code.google.com/p/teenage-mutant-ninja-turtles/downloads/list"&gt;http://code.google.com&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;More Info: &lt;a href="http://code.google.com/p/teenage-mutant-ninja-turtles/wiki/TableOfContents?tm=6"&gt;http://code.google.com&lt;/a&gt;&lt;/b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/8315326624124184390/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=8315326624124184390" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/8315326624124184390?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/8315326624124184390?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2012/10/the-teenage-mutant-ninja-turtles-project.html" title="The Teenage Mutant Ninja Turtles project" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>1</thr:total></entry><entry gd:etag="W/&quot;CkYNSH84fyp7ImA9WhNSEUg.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-2183714372335807554</id><published>2012-10-25T09:29:00.000+02:00</published><updated>2012-10-25T09:29:59.137+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-10-25T09:29:59.137+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><title>Subterfuge Beta Version 4.2  Released</title><content type="html">&lt;b&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Automated Man-in-the-Middle Attack Framework&amp;nbsp;&lt;/b&gt; 
 

 

&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-9jfARpcjOgk/UIjo3sm2QbI/AAAAAAAABFk/JNopdhUN0fY/s1600/netview.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="123" src="http://1.bp.blogspot.com/-9jfARpcjOgk/UIjo3sm2QbI/AAAAAAAABFk/JNopdhUN0fY/s320/netview.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span itemprop="description"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
&lt;span itemprop="description"&gt;&lt;b&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;span itemprop="description"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
&lt;b&gt;Abstract:&lt;/b&gt;

&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Enter &lt;a href="http://kinozoa.com/"&gt;Subterfuge&lt;/a&gt;, a Framework to take the arcane art of Man-in-the-Middle Attack and make it as simple as point and shoot. A beautiful, easy to use interface which produces a more transparent and effective attack is what sets Subterfuge apart from other attack tools. Subterfuge demonstrates vulnerabilities in the ARP Protocol by harvesting credentials that go across the network, and even exploiting machines through race conditions. Now walk into a corporation… A rapidly-expanding portion of today’s Internet strives to increase personal efficiency by turning tedious or complex processes into a framework which provides instantaneous results. &amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;On the contrary, much of the information security community still finds itself performing manual, complicated tasks to administer and protect their computer networks. Given the increase in automated hacking tools, it is surprising that a simplistic, “push-button” tool has not been created for information security professionals to validate their networks’ ability to protect against a Man-In-The-Middle attack. Subterfuge is a small but devastatingly effective credential-harvesting program which exploits a vulnerability in the Address Resolution Protocol. It does this in a way that a non-technical user would have the ability, at the push of a button, to harvest all of the usernames and passwords of victims on their connected network, thus equipping information and network security professionals with a “push-button” security validation tool. &amp;nbsp;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;span itemprop="description"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
&lt;span itemprop="description"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
&lt;span itemprop="description"&gt;&lt;b&gt;Download: &lt;/b&gt;&lt;/span&gt;&lt;span itemprop="description"&gt;&lt;a href="http://code.google.com/p/subterfuge/downloads/list"&gt;http://code.google.com/p/subterfuge&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span itemprop="description"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt; 

&lt;b&gt;Subterfuge DEFCON 20 Teaser: &amp;nbsp;&lt;a href="http://www.youtube.com/watch?feature=player_embedded&amp;amp;v=PbiXMlhykSQ"&gt;http://www.youtube.com&lt;/a&gt;&lt;/b&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/2183714372335807554/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=2183714372335807554" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/2183714372335807554?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/2183714372335807554?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2012/10/subterfuge-beta-version-42-released.html" title="Subterfuge Beta Version 4.2  Released" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-9jfARpcjOgk/UIjo3sm2QbI/AAAAAAAABFk/JNopdhUN0fY/s72-c/netview.png" height="72" width="72" /><thr:total>1</thr:total></entry><entry gd:etag="W/&quot;DUYCR3w4fyp7ImA9WhNTGUU.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-7415294442003122291</id><published>2012-10-23T12:12:00.002+02:00</published><updated>2012-10-23T12:12:46.237+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-10-23T12:12:46.237+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><title>Snuck  - Automatic XSS filter bypass tool</title><content type="html">&lt;b&gt;&lt;a href="http://code.google.com/p/snuck/"&gt;snuck&lt;/a&gt;&lt;/b&gt; &lt;i&gt;is an automated tool that may definitely help in 
finding XSS vulnerabilities in web applications. It is based on Selenium
 and supports Mozilla Firefox, Google Chrome and Internet Explorer. The 
approach, it adopts, is based on the inspection of the injection's 
reflection context and relies on a set of specialized and obfuscated 
attack vectors for filter evasion. In addition, XSS testing is performed
 in-browser, a real web browser is driven for reproducing the attacker's
 behavior and possibly the victim's.&amp;nbsp;&lt;/i&gt; 
&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;

&lt;b&gt;snuck&lt;/b&gt; &lt;i&gt;is quite different from typical web security 
scanners, it basically tries to break a given XSS filter by specializing
 the injections in order to increase the success rate. The attack 
vectors are selected on the basis of the reflection context, that is the
 exact point where the injection falls in the reflection web page's DOM.
 Having access to the pages' DOM is possible through Selenium Web 
Driver, which is an automation framework, that allows to replicate 
operations in web browsers. Since many steps could be involved before an
 XSS filter is "activated", an XML configuration file should be filled 
in order to make snuck aware of the steps it needs to perform 
with respect to the tested web application. Practically speaking, the 
approach is similar to the &lt;a href="http://www.korscheck.de/diploma-thesis.pdf" rel="nofollow"&gt;iSTAR&lt;/a&gt;'s one, but it focuses on one particular XSS filter.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;
&lt;b&gt;Download:&lt;/b&gt;&lt;i&gt; &amp;nbsp;&lt;/i&gt;&lt;a href="http://code.google.com/p/snuck/downloads/list"&gt;http://code.google.com/p/snuck/&lt;/a&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/7415294442003122291/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=7415294442003122291" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7415294442003122291?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/7415294442003122291?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2012/10/snuck-automatic-xss-filter-bypass-tool.html" title="Snuck  - Automatic XSS filter bypass tool" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;DE4MR3s8fCp7ImA9WhJaGEg.&quot;"><id>tag:blogger.com,1999:blog-232798662055846003.post-6930027691667847877</id><published>2012-10-10T10:16:00.000+02:00</published><updated>2012-10-10T10:16:26.574+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-10-10T10:16:26.574+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><title>dSploit - An Android network penetration suite</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-jmVNsegGtfA/UHUuQ_TA9nI/AAAAAAAABFM/tZ84a4HcTps/s1600/8.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="112" src="http://3.bp.blogspot.com/-jmVNsegGtfA/UHUuQ_TA9nI/AAAAAAAABFM/tZ84a4HcTps/s200/8.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;i&gt;&lt;a href="https://github.com/evilsocket/dsploit"&gt;dSploit&lt;/a&gt; is an Android network analysis and penetration suite which aims to offer to IT security experts/geeks
&lt;/i&gt;&lt;b&gt;&lt;i&gt;the most complete and advanced professional toolkit&lt;/i&gt;&lt;/b&gt;&lt;i&gt; to perform network security assesments on a mobile device.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;

&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Once dSploit is started, you will be able to easily map your network, fingerprint alive hosts operating systems
and running services, search for &lt;/i&gt;&lt;b&gt;&lt;i&gt;known vulnerabilities&lt;/i&gt;&lt;/b&gt;&lt;i&gt;, crack logon procedures of many tcp protocols, perform
man in the middle attacks such as &lt;/i&gt;&lt;b&gt;&lt;i&gt;password sniffing&lt;/i&gt;&lt;/b&gt;&lt;i&gt; ( with common protocols dissection ), real time &lt;/i&gt;&lt;b&gt;&lt;i&gt;traffic
manipulation&lt;/i&gt;&lt;/b&gt;&lt;i&gt;, etc, etc .&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;

&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;This application is still in &lt;/i&gt;&lt;b&gt;&lt;i&gt;beta stage&lt;/i&gt;&lt;/b&gt;&lt;i&gt;, a stable release will be available as soon as possible, but expect
some crash or strange behaviour until then, in any case, feel free to submit an issue here on GitHub.&lt;/i&gt;&lt;br /&gt;
&lt;h2&gt;
&lt;span style="font-size: small;"&gt;Requirements:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;An Android device with at least the 2.3 ( Gingerbread ) version of the OS.&lt;/i&gt;&lt;/li&gt;
&lt;i&gt;
&lt;/i&gt;
&lt;li&gt;&lt;i&gt;The device &lt;/i&gt;&lt;b&gt;&lt;i&gt;must be rooted&lt;/i&gt;&lt;/b&gt;&lt;i&gt;.&lt;/i&gt;&lt;/li&gt;
&lt;i&gt;
&lt;/i&gt;
&lt;li&gt;&lt;i&gt;The device must have a BusyBox &lt;/i&gt;&lt;b&gt;&lt;i&gt;full install&lt;/i&gt;&lt;/b&gt;&lt;i&gt;, this means with &lt;/i&gt;&lt;b&gt;&lt;i&gt;every&lt;/i&gt;&lt;/b&gt;&lt;i&gt; utility installed ( not the partial installation ).&amp;nbsp;&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;b&gt;Available Modules&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;RouterPWN&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Launch the &lt;a href="http://routerpwn.com/" rel="nofollow" target="_blank"&gt;http://routerpwn.com/&lt;/a&gt; service to pwn your router.&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Port Scanner&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;A syn port scanner to find quickly open ports on a single target.&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Inspector&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Performs target operating system and services deep detection, slower than syn port scanner but more accurate.&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Vulnerability Finder&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Search for known vulnerabilities for target running services upon National Vulnerability Database.&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Login Cracker&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;A very fast network logon cracker which supports many different services.&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Packet Forger&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Craft and send a custom TCP or UDP packet to the target.&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;MITM&lt;/b&gt; &lt;br /&gt;
&lt;i&gt;A set of man-in-the-middle tools to command&amp;amp;conquer the whole network . &amp;nbsp;&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;b&gt;Download: &lt;a href="https://github.com/evilsocket/dsploit/downloads"&gt;https://github.com&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;/ul&gt;
</content><link rel="replies" type="application/atom+xml" href="http://security-sh3ll.blogspot.com/feeds/6930027691667847877/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=232798662055846003&amp;postID=6930027691667847877" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/6930027691667847877?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/232798662055846003/posts/default/6930027691667847877?v=2" /><link rel="alternate" type="text/html" href="http://security-sh3ll.blogspot.com/2012/10/dsploit-android-network-penetration.html" title="dSploit - An Android network penetration suite" /><author><name>d3v1l</name><uri>http://www.blogger.com/profile/03119852053430095623</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://4.bp.blogspot.com/-14ZpUTM5s6I/T7AToB85x4I/AAAAAAAABCk/1xf2L2Z_Hpo/s220/lol.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-jmVNsegGtfA/UHUuQ_TA9nI/AAAAAAAABFM/tZ84a4HcTps/s72-c/8.png" height="72" width="72" /><thr:total>0</thr:total></entry></feed>
