"dsniff is a collection of tools for network auditing and penetration testing. dsniff, filesnarf, mailsnarf, msgsnarf, urlsnarf, and webspy passively monitor a network for interesting data (passwords, e-mail, files, etc.). arpspoof, dnsspoof, and macof facilitate the interception of network traffic normally unavailable to an attacker (e.g, due to layer-2 switching). sshmitm and webmitm implement active monkey-in-the-middle attacks against redirected SSH and HTTPS sessions by exploiting weak bindings in ad-hoc PKI." read more...
Website: http://www.monkey.org/~dugsong/dsniff/
Website: http://www.monkey.org/~dugsong/dsniff/
John the Ripper

Cain and Abel

"Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords and analyzing routing protocols. The program does not exploit any software vulnerabilities or bugs that could not be fixed with little effort. It covers some security aspects/weakness present in protocol's standards, authentication methods and caching mechanisms; its main purpose is the simplified recovery of passwords and credentials from various sources, however it also ships some "non standard" utilities for Microsoft Windows users."..
Website: http://www.oxid.it/cain.htmlBacktrack4
The Remote Exploit Development Team has just announced BackTrack 4 Beta. BackTrack is a Linux based LiveCD intended for security testing and we’ve been watching the project since the very early days. They say this new beta is both stable and usable. They’ve moved towards behaving like an actual distribution: it’s based on Debian core, they use Ubuntu software, and they’re running their own BackTrack repositories for future updates. There are a lot of new features, but the one we’re most interested in is the built in Pico card support. You can use the FPGAs to generate rainbow tables and do lookups for things like WPA, GSM, and Bluetooth cracking. BackTrack ISO and VMWare images are available h
Website: http://www.remote-exploit.org
Memoryze

Download: http://fred.mandiant.com/MemoryzeSetup.msi
THC-Hydra

Website: http://freeworld.thc.org/thc-hydra
Samurai: Web Testing Framework

Website: http://samurai.inguardians.com
OdysseusL
Download: http://www.bindshell.net/tools/odysseus
ShellForge
BeEF: Browser Exploitation Framework

Website: http://www.bindshell.net/tools/beef
Exploit-Me

Website: http://securitycompass.com/exploitme.shtml
DirBuster: Brute Force Web Directories
Download: https://sourceforge.net/projects/dirbuster
W3AF

Website: http://w3af.sourceforge.net
OSWA™
Website: http://oswa-assistant.securitystartshere.org
Ettercap: Man In The Middle (MITM)

Website: http://ettercap.sourceforge.net
RainbowCrack

Website: http://www.antsight.com/zsl/rainbowcrack
Ophcrack

Website: http://ophcrack.sourceforge.net
Airpwn: A Wireless Packet Injector
"Airpwn is a framework for 802.11 (wireless) packet injection. Airpwn listens to incoming wireless packets, and if the data matches a pattern specified in the config files, custom content is injected "spoofed" from the wireless access point. From the perspective of the wireless client, airpwn becomes the server." read more...
Website: http://airpwn.sourceforge.net
PHoss: A Password Sniffer
Download: http://www.phenoelit-us.org/phoss/download.html
DMitry: Deepmagic Information Gathering Tool
Download: http://packetstormsecurity.org/UNIX/misc/DMitry-1.2a.tar.gz
snmpcheck

Website: http://www.nothink.org/perl/snmpcheck
fragroute
"fragroute intercepts, modifies, and rewrites egress traffic destined for a specified host, implementing most of the attacks described in the Secure Networks "Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection" paper of January 1998. It features a simple ruleset language to delay, duplicate, drop, fragment, overlap, print, reorder, segment, source-route, or otherwise monkey with all outbound packets destined for a target host, with minimal support for randomized or probabilistic behaviour. This tool was written in good faith to aid in the testing of network intrusion detection systems, firewalls, and basic TCP/IP stack behaviour."
Website: http://monkey.org/~dugsong/fragroute
Nemesis: A Packet Injection Utility

Website: http://www.packetfactory.net/projects/nemesis
WEDNESDAY, AUGUST 6, 2008
Aircrack-ng: The Next Generation of Aircrack

Website: http://www.aircrack-ng.org
OpenVAS

Website: http://www.openvas.org
ngrep: network grep

Website: http://www.packetfactory.net/projects/ngrep
XPROBE: Active OS fingerprinting tool

Website: http://xprobe.sourceforge.net
OpenXPKI
Website: http://www.openxpki.org
JOSPKI Suite

Website: http://jospkisuite.sourceforge.net
Odyssi: Certificate Authority Server

Website: http://odyssipki.sourceforge.net
III ASN.1 Tool
"The III ASN.1 Tool includes two parts : an ASN.1 compiler "asnparser" which compiles the Abstract Syntax to c++ files, and a runtime library which is used to link with the c++ files generated by asnparser. Based on the works of Open H.323 projects, it is developed for the needs of H.450 series protocol. Hence, it supports the information object class defined in X.681."
Website: http://iiiasn1.sourceforge.net
Website: http://iiiasn1.sourceforge.net
Yersinia

LaBrea: "Sticky" Honeypot and IDS

Website: http://labrea.sourceforge.net
The Metasploit Framework
Website: http://www.metasploit.com
Kismet: Wireless Packet Analyzer

Website: http://www.kismetwireless.net
Tor: anonymity online

Privoxy

Winpooch
FRIDAY, JULY 25, 2008
SpamAssassin: An Open Source E-mail Filter

Website: http://spamassassin.apache.org
WEDNESDAY, JULY 23, 2008
PKIF: The PKI Framework
OTPW: A One-time Password Login Package

The ASN.1 Compiler
Download: http://lionet.info/asn1c/download.html
FxCop: A Free Static Code Analysis Tool that Checks .NET managed code

MONDAY, JULY 21, 2008
OSSEC: An Open Source Host-based Intrusion Detection System

Website: http://www.ossec.net/
httprecon: An Advanced Web Server Fingerprinting Tool

ATK: An Open-Source Exploiting Framework

Burp Suite: An Integrated Platform for Penetration Test of Web Applications

SysAnalyzer: An Automated Malcode Analyzer

Website: http://labs.idefense.com/software/malcode.php
Honeywall CDROM
BackTrack: Penetration Testing Live CD

Website: http://www.remote-exploit.org/backtrack.html
Comments