<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecureSlash.com &#187; Security Tools</title>
	<atom:link href="http://secureslash.com/category/security-tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://secureslash.com</link>
	<description>Because security matters</description>
	<lastBuildDate>Fri, 20 Jan 2012 10:58:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>How to Fix Trojan.FakeAlert.5 Bitdefender Alert?</title>
		<link>http://secureslash.com/security-tools/how-to-fix-trojan-fakealert-5-bitdefender-alert/</link>
		<comments>http://secureslash.com/security-tools/how-to-fix-trojan-fakealert-5-bitdefender-alert/#comments</comments>
		<pubDate>Sat, 20 Mar 2010 19:29:02 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Computer Users]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[bitdefender update]]></category>
		<category><![CDATA[how to fix trojan fake alert]]></category>
		<category><![CDATA[trojan fake alert problem]]></category>

		<guid isPermaLink="false">http://secureslash.com/?p=145</guid>
		<description><![CDATA[Tweet Well, Today is the craziest day for Bitdefender. This looks like a climax of the movie iRobot. Thousands of windows users install bitdefender for securing their machine. But, Unfortunately a lame update file from bitdefender started killing itself(literally). Today, All Windows7 64bit users received a threat alert called &#8220;Trojan.Fakealert.5&#8243;. And it detected all DLL [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fhow-to-fix-trojan-fakealert-5-bitdefender-alert%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/how-to-fix-trojan-fakealert-5-bitdefender-alert/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/how-to-fix-trojan-fakealert-5-bitdefender-alert/"  data-text="How to Fix Trojan.FakeAlert.5 Bitdefender Alert?" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/how-to-fix-trojan-fakealert-5-bitdefender-alert/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/how-to-fix-trojan-fakealert-5-bitdefender-alert/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>Well, Today is the craziest day for Bitdefender. This looks like a climax of the movie iRobot. Thousands of windows users install bitdefender for securing their machine. But, Unfortunately a lame update file from bitdefender started killing itself(literally).</p>
<p>Today, All Windows7 64bit users received a threat alert called &#8220;<strong>Trojan.Fakealert.5&#8243;. </strong></p>
<p>And it detected all DLL files / EXEs of my windows machine as a trojan and started deleting them. You know how frustrates it? I really have a paid account for Bit Defender Internet Security 2010. I ignored my nerd friend&#8217;s words about installing a 3000 days crack for bitdefender and I called myself as &#8220;I dont want to steal someone&#8217;s work&#8221;.</p>
<p>But today, My taskmanager, explorer &amp; almost everything got quarantine. I didnt paid to bitdefender for this lame mistake.</p>
<p><a href="http://secureslash.com/wp-content/uploads/2010/03/win7logo.jpg"><img class="size-full wp-image-146 alignnone" title="windows 7 logo" src="http://secureslash.com/wp-content/uploads/2010/03/win7logo.jpg" alt="" /></a></p>
<p><strong>What is the cause of Trojan.FakeAlert.5?</strong></p>
<p>There was a wrong update from bitdefender caused this issue.</p>
<p><strong>How to fix<strong>Trojan.FakeAlert.5</strong>?</strong><strong><br />
</strong><br />
Disable the realtime protection</p>
<p>Antivirus -&gt; Shield -&gt; Disable Real-time protection.</p>
<p>Do not run any scans. Disable if there is any scheduled scans.</p>
<p>Try to do a &#8220;System Restore&#8221; or restore the &#8220;Quarantine&#8221; files.</p>
<p>There a big thread at <a href="http://forum.bitdefender.com/index.php?showtopic=18759">bitdefender forums</a> with thousands of active frustrated users(including me) shouting bitdefender for this lame problem.</p>
<p><a href="http://forum.bitdefender.com/index.php?showtopic=18759"><img class="alignnone size-full wp-image-151" title="bitdefender" src="http://secureslash.com/wp-content/uploads/2010/03/bitdefender1.png" alt="" width="525" height="285" /></a></p>
<p>Note: My friend &amp; <a href="http://secureslash.com/secure-team/paimpozhil">Secure Slash co-editor Mr. PaimPozhil</a> said to me that, There is a &#8220;real&#8221; trojan in that same name. So, Do not just disable bitdefender!  Scan your computer using &#8220;SpyBot Search &amp; Destroy&#8221; it will find the exact trojan alone as well. Thanks Paim <img src='http://secureslash.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/how-to-fix-trojan-fakealert-5-bitdefender-alert/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Javascript Trojan Virus Everywhere and How to fix it</title>
		<link>http://secureslash.com/uncategorized/javascript-trojan-virus-everywhere-and-how-to-fix-it/</link>
		<comments>http://secureslash.com/uncategorized/javascript-trojan-virus-everywhere-and-how-to-fix-it/#comments</comments>
		<pubDate>Sat, 01 Mar 2008 12:54:28 +0000</pubDate>
		<dc:creator>paimpozhil</dc:creator>
				<category><![CDATA[Computer Users]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Server Administration]]></category>
		<category><![CDATA[System Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Website Security]]></category>
		<category><![CDATA[Javascript Trojan]]></category>
		<category><![CDATA[Javascript Trojan virus deletion fix]]></category>
		<category><![CDATA[Latest Virus 2008]]></category>

		<guid isPermaLink="false">http://secureslash.com/uncategorized/javascript-trojan-virus-everywhere-and-how-to-fix-it/</guid>
		<description><![CDATA[Tweet Its getting hit by Trojan virus: Read the News about Thousands of infected websites. A lot of sites are now being attacked with JavaScript Trojans the server is not attacked by virus , this happens to both Linux and windows server sites. so it is doesnt look like a server based attack How this [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Funcategorized%2Fjavascript-trojan-virus-everywhere-and-how-to-fix-it%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/uncategorized/javascript-trojan-virus-everywhere-and-how-to-fix-it/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/uncategorized/javascript-trojan-virus-everywhere-and-how-to-fix-it/"  data-text="Javascript Trojan Virus Everywhere and How to fix it" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/uncategorized/javascript-trojan-virus-everywhere-and-how-to-fix-it/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/uncategorized/javascript-trojan-virus-everywhere-and-how-to-fix-it/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><strong>Its getting hit by Trojan virus:</strong></p>
<p>Read the News about <a href="http://www.onestopclick.com/news/Thousands-of-websites-now-infected-with-Trojan_18435798.html" target="_blank">Thousands of infected websites</a>.</p>
<p>A lot of sites are now being attacked with <strong>JavaScript Trojans</strong></p>
<p>the server is not attacked by virus , this <strong>happens to both Linux and windows server</strong> sites.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-1553934370392546";
google_ad_width = 300;
google_ad_height = 250;
google_ad_format = "300x250_as";
google_ad_type = "text";
//2007-08-15: SecureSlash - SideBox
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "2f63b3";
google_color_text = "000000";
google_color_url = "CCCCCC";

//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
<br />
so it is doesnt look like a server based attack</p>
<p><strong>How this happens?</strong></p>
<p>when the computer from where you upload data thru FTP/fp is infected , it injects some JavaScript to all html files.</p>
<p>so how you can prevent this happening is keep your pc up2date by having recent antivirus,antispyware and then change your ftp logins.</p>
<p>If there is a Repeating same pattern of JavaScript on 100s of your files you have a shell script for Linux server users that can remove these injected javascript .</p>
<p>so you can request your host or you yourself can run this on your shell</p>
<pre></pre>
<blockquote><p>find ./ -type f -exec sed -i &#8216;/unescape/d&#8217; {} \;</p></blockquote>
<p>this command will remove all the lines with pattern &#8216;unescape&#8217;</p>
<p>some virus has lines of function <strong>okban</strong>, in that case you can try pattern <strong>&#8216;okban&#8217;</strong></p>
<p>it depends on your need.</p>
<p>you can do the same with a software called <strong>GrepWin</strong> for replacing/searching PERL Regular Expression patterns on your files</p>
<p><a href="http://tools.tortoisesvn.net/grepWin" title="http://tools.tortoisesvn.net/grepWin">http://tools.tortoisesvn.net/grepWin</a></p>
<p>use it to search for patterns and replace with null or use the options to delete those lines</p>
<p>this can be either used on a windows server or client side (but then you have to upload all modified files again )</p>
<pre></pre>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/uncategorized/javascript-trojan-virus-everywhere-and-how-to-fix-it/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Socks Proxy Scanner PHP Script</title>
		<link>http://secureslash.com/security-tools/socks-proxy-scanner-php-script/</link>
		<comments>http://secureslash.com/security-tools/socks-proxy-scanner-php-script/#comments</comments>
		<pubDate>Thu, 20 Dec 2007 05:42:21 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Networking & Security]]></category>
		<category><![CDATA[PHP Scripting]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/socks-proxy-scanner-php-script/</guid>
		<description><![CDATA[Tweet A simple socks proxy scanner php script, that uses to check a list of socks proxy servers&#8217; online status. Example: 123.234.12.32:3523 98.45.57.78:9823 23.32.44.23:3785 123.32.45.56:3453 34.75.56.234:9856 save above lines as &#8220;proxies.txt&#8221;. Code:]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fsocks-proxy-scanner-php-script%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/socks-proxy-scanner-php-script/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/socks-proxy-scanner-php-script/"  data-text="Socks Proxy Scanner PHP Script" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/socks-proxy-scanner-php-script/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/socks-proxy-scanner-php-script/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>A simple socks proxy scanner php script, that uses to check a list of socks proxy servers&#8217; online status.</p>
<p>Example:<br />
123.234.12.32:3523<br />
98.45.57.78:9823<br />
23.32.44.23:3785<br />
123.32.45.56:3453<br />
34.75.56.234:9856</p>
<p>save above lines as &#8220;proxies.txt&#8221;.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-1553934370392546";
google_ad_width = 300;
google_ad_height = 250;
google_ad_format = "300x250_as";
google_ad_type = "text";
//2007-08-15: SecureSlash - SideBox
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "2f63b3";
google_color_text = "000000";
google_color_url = "CCCCCC";

//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
<br />
Code:</p>
<p><?<br />
$filename = "http://domain.tld/filename.ext"; //or a localpath.<br />
$rel=file_get_contents($filename);<br />
$ipset = explode("\n",$rel); // explode it based on your delimiter.<br />
foreach($ipset as $ips)<br />
{<br />
        $ipandport=explode(':',$ips);<br />
        //Porxy string format might be 123.156.189.112:8080<br />
        $host=$ipandport[0];<br />
        $i=(int)$ipandport[1];<br />
        $fp = @fsockopen("tcp://".$host,$i,$errno,$errstr,10);<br />
        // tcp:// because, socks4 uses TCP and socks5 uses TCP &#038; UDP<br />
        if($fp)<br />
       {<br />
              echo("Result is $fp<br />&#8220;);<br />
              echo (&#8220;port &#8221; . $i . &#8221; open on &#8221; . $host . &#8220;<br />&#8220;);<br />
              fclose($fp);<br />
       }<br />
       flush();<br />
}<br />
?></p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/socks-proxy-scanner-php-script/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wireless Tools</title>
		<link>http://secureslash.com/security-tools/wireless-tools/</link>
		<comments>http://secureslash.com/security-tools/wireless-tools/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 12:58:55 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Networking & Security]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/wireless-tools/</guid>
		<description><![CDATA[Tweet Kismet : A powerful wireless sniffer Kismet is an console (ncurses) based 802.11 layer2 wireless network detector, sniffer, and intrusion detection system. It identifies networks by passively sniffing (as opposed to more active tools such as NetStumbler), and can even decloak hidden (non-beaconing) networks if they are in use. It can automatically detect network [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fwireless-tools%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/wireless-tools/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/wireless-tools/"  data-text="Wireless Tools" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/wireless-tools/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/wireless-tools/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.kismetwireless.net/">Kismet</a> : A powerful wireless sniffer</p>
<p>Kismet is an console (ncurses) based 802.11 layer2 wireless network detector, sniffer, and intrusion detection system. It identifies networks by passively sniffing (as opposed to more active tools such as NetStumbler), and can even decloak hidden (non-beaconing) networks if they are in use. It can automatically detect network IP blocks by sniffing TCP, UDP, ARP, and DHCP packets, log traffic in Wireshark/TCPDump compatible format, and even plot detected networks and estimated ranges on downloaded maps. As you might expect, this tool is commonly used for <a href="http://en.wikipedia.org/wiki/Wardriving">wardriving</a>.  Oh, and also <a href="http://en.wikipedia.org/wiki/Warwalking">warwalking</a>, <a href="http://www.tgdaily.com/2004/04/30/thg_takes_to_the_air_for_wi/print.html">warflying</a>, and <a href="http://www.oldskoolphreak.com/tfiles/wifi/warskating/warskating.html">warskating</a>, &#8230;<br />
<!--adsense--><br />
<a href="http://www.stumbler.net/">NetStumbler</a> : Free Windows 802.11 Sniffer<br />
Netstumbler is the best known Windows tool for finding open wireless access points (&#8220;wardriving&#8221;). They also distribute a WinCE version for PDAs and such named <a href="http://www.stumbler.net/">Ministumbler</a>. The tool is currently free but Windows-only and no source code is provided. It uses a more active approach to finding WAPs than passive sniffers such as Kismet or KisMAC.</p>
<p><a href="http://www.aircrack-ng.org/">Aircrack</a> : The fastest available WEP/WPA cracking tool<br />
Aircrack is a suite of tools for 802.11a/b/g WEP and WPA cracking. It can recover a 40 through 512-bit WEP key once enough encrypted packets have been gathered. It can also attack WPA 1 or 2 networks using advanced cryptographic methods or by brute force. The suite includes airodump (an 802.11 packet capture program), aireplay (an 802.11 packet injection program), aircrack (static WEP and WPA-PSK cracking), and airdecap (decrypts WEP/WPA capture files).</p>
<p><a href="http://airsnort.shmoo.com/">Airsnort</a> : 802.11 WEP Encryption Cracking Tool<br />
AirSnort is a wireless LAN (WLAN) tool that recovers encryption keys. It was developed by the <a href="http://www.shmoo.com/">Shmoo Group</a> and operates by passively monitoring transmissions, computing the encryption key when enough packets have been gathered. You may also be interested in the similar Aircrack.</p>
<p><a href="http://kismac.de/">KisMAC</a> : A A GUI passive wireless stumbler for Mac OS X<br />
This popular stumbler for Mac OS X offers many of the features of its namesake Kismet, though the codebase is entirely different. Unlike console-based Kismet, KisMAC offers a pretty GUI and was around before Kismet was ported to OS X. It also offers mapping, Pcap-format import and logging, and even some decryption and deauthentication attacks.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/wireless-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Packet Sniffers</title>
		<link>http://secureslash.com/security-tools/packet-sniffers/</link>
		<comments>http://secureslash.com/security-tools/packet-sniffers/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 12:57:52 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Networking & Security]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[System Security]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/packet-sniffers/</guid>
		<description><![CDATA[Tweet Wireshark : Sniffing the glue that holds the Internet together Wireshark (known as Ethereal until a trademark dispute in Summer 2006) is a fantastic open source network protocol analyzer for Unix and Windows. It allows you to examine data from a live network or from a capture file on disk. You can interactively browse [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fpacket-sniffers%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/packet-sniffers/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/packet-sniffers/"  data-text="Packet Sniffers" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/packet-sniffers/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/packet-sniffers/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.wireshark.org/"> Wireshark</a> : Sniffing the glue that holds the Internet together</p>
<p>Wireshark (known as <a href="http://www.ethereal.com/">Ethereal</a> until a trademark dispute in Summer 2006) is a fantastic open source network protocol analyzer for Unix and Windows. It allows you to examine data from a live network or from a capture file on disk. You can interactively browse the capture data, delving down into just the level of packet detail you need. Wireshark has several powerful features, including a rich display filter language and the ability to view the reconstructed stream of a TCP session. It also supports hundreds of protocols and media types. A tcpdump-like console version named tethereal is included. One word of caution is that Ethereal has suffered from dozens of remotely exploitable security holes, so stay up-to-date and be wary of running it on untrusted or hostile networks (such as security conferences).<br />
<!--adsense--><br />
<a href="http://www.kismetwireless.net/">Kismet</a> : A powerful wireless sniffer<br />
Kismet is an console (ncurses) based 802.11 layer2 wireless network detector, sniffer, and intrusion detection system. It identifies networks by passively sniffing (as opposed to more active tools such as NetStumbler), and can even decloak hidden (non-beaconing) networks if they are in use. It can automatically detect network IP blocks by sniffing TCP, UDP, ARP, and DHCP packets, log traffic in Wireshark/TCPDump compatible format, and even plot detected networks and estimated ranges on downloaded maps. As you might expect, this tool is commonly used for <a href="http://en.wikipedia.org/wiki/Wardriving">wardriving</a>.  Oh, and also <a href="http://en.wikipedia.org/wiki/Warwalking">warwalking</a>, <a href="http://www.tgdaily.com/2004/04/30/thg_takes_to_the_air_for_wi/print.html">warflying</a>, and <a href="http://www.oldskoolphreak.com/tfiles/wifi/warskating/warskating.html">warskating</a>, &#8230;</p>
<p><a href="http://www.tcpdump.org/">Tcpdump</a> : The classic sniffer for network monitoring and data acquisition<br />
Tcpdump is the IP sniffer we all used before Ethereal (Wireshark) came on the scene, and many of us continue to use it frequently. It may not have the bells and whistles (such as a pretty GUI or parsing logic for hundreds of application protocols) that Wireshark has, but it does the job well and with fewer security holes. It also requires fewer system resources. While it doesn&#8217;t receive new features often, it is actively maintained to fix bugs and portability problems. It is great for tracking down network problems or monitoring activity. There is a separate Windows port named <a href="http://windump.polito.it/">WinDump</a>.  TCPDump is the source of the <a href="http://www.tcpdump.org/">Libpcap</a>/<a href="http://winpcap.polito.it/">WinPcap</a> packet capture library, which is used by <a href="http://insecure.org/nmap/">Nmap</a> among many other tools.</p>
<p><a href="http://www.oxid.it/cain.html">Cain and Abel</a> : The top password recovery tool for Windows<br />
UNIX users often smugly assert that the best free security tools support their platform first, and Windows ports are often an afterthought. They are usually right, but Cain &amp; Abel is a glaring exception. This Windows-only password recovery tool handles an enormous variety of tasks. It can recover passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols. It is also <a href="http://www.oxid.it/ca_um/">well documented</a>.</p>
<p><a href="http://ettercap.sourceforge.net/">Ettercap</a> : In case you still thought switched LANs provide much extra security<br />
Ettercap is a terminal-based network sniffer/interceptor/logger for ethernet LANs. It supports active and passive dissection of many protocols (even ciphered ones, like ssh and https). Data injection in an established connection and filtering on the fly is also possible, keeping the connection synchronized. Many sniffing modes were implemented to give you a powerful and complete sniffing suite. Plugins are supported. It has the ability to check whether you are in a switched LAN or not, and to use OS fingerprints (active or passive) to let you know the geometry of the LAN.</p>
<p><a href="http://www.monkey.org/%7Edugsong/dsniff/">Dsniff</a> : A suite of powerful network auditing and penetration-testing tools<br />
This popular and well-engineered suite by Dug Song includes many tools. dsniff, filesnarf, mailsnarf, msgsnarf, urlsnarf, and webspy passively monitor a network for interesting data (passwords, e-mail, files, etc.). arpspoof, dnsspoof, and macof facilitate the interception of network traffic normally unavailable to an attacker (e.g, due to layer-2 switching). sshmitm and webmitm implement active monkey-in-the-middle attacks against redirected ssh and https sessions by exploiting weak bindings in ad-hoc PKI. A separately maintained partial Windows port is available <a href="http://www.datanerds.net/%7Emike/dsniff.html">here</a>.  Overall, this is a great toolset.  It handles pretty much all of your password sniffing needs.</p>
<p><a href="http://www.stumbler.net/">NetStumbler</a> : Free Windows 802.11 Sniffer<br />
Netstumbler is the best known Windows tool for finding open wireless access points (&#8220;wardriving&#8221;). They also distribute a WinCE version for PDAs and such named <a href="http://www.stumbler.net/">Ministumbler</a>. The tool is currently free but Windows-only and no source code is provided. It uses a more active approach to finding WAPs than passive sniffers such as &gt;Kismet or KisMAC.</p>
<p><a href="http://www.ntop.org/">Ntop</a> : A network traffic usage monitor<br />
Ntop shows network usage in a way similar to what top does for processes. In interactive mode, it displays the network status on the user&#8217;s terminal. In Web mode, it acts as a Web server, creating an HTML dump of the network status. It sports a NetFlow/sFlow emitter/collector, an HTTP-based client interface for creating ntop-centric monitoring applications, and RRD for persistently storing traffic statistics.</p>
<p><a href="http://www.packetfactory.net/projects/ngrep/">Ngrep</a> : Convenient packet matching &amp; display<br />
ngrep strives to provide most of GNU grep&#8217;s common features, applying them to the network layer. ngrep is a pcap-aware tool that will allow you to specify extended regular or hexadecimal expressions to match against data payloads of packets. It currently recognizes TCP, UDP and ICMP across Ethernet, PPP, SLIP, FDDI, Token Ring and null interfaces, and understands bpf filter logic in the same fashion as more common packet sniffing tools, such as tcpdump and snoop.</p>
<p><a href="http://etherape.sourceforge.net/">EtherApe</a> : EtherApe is a graphical network monitor for Unix modeled after etherman<br />
Featuring link layer, IP and TCP modes, EtherApe displays network activity graphically with a color coded protocols display. Hosts and links change in size with traffic. It supports Ethernet, FDDI, Token Ring, ISDN, PPP and SLIP devices. It can filter traffic to be shown, and can read traffic from a file as well as live from the network.<br />
<!--adsense--><br />
<a href="http://kismac.de/">KisMAC</a> : A A GUI passive wireless stumbler for Mac OS X<br />
This popular stumbler for Mac OS X offers many of the features of its namesake Kismet, though the codebase is entirely different. Unlike console-based Kismet, KisMAC offers a pretty GUI and was around before Kismet was ported to OS X. It also offers mapping, Pcap-format import and logging, and even some decryption and deauthentication attacks.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/packet-sniffers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Intrusion Detection Systems</title>
		<link>http://secureslash.com/security-tools/intrusion-detection-systems/</link>
		<comments>http://secureslash.com/security-tools/intrusion-detection-systems/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 12:56:29 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[System Security]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/intrusion-detection-systems/</guid>
		<description><![CDATA[Tweet Snort : A Everyone&#8217;s favorite open source IDS This lightweight network intrusion detection and prevention system excels at traffic analysis and packet logging on IP networks. Through protocol analysis, content searching, and various pre-processors, Snort detects thousands of worms, vulnerability exploit attempts, port scans, and other suspicious behavior. Snort uses a flexible rule-based language [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fintrusion-detection-systems%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/intrusion-detection-systems/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/intrusion-detection-systems/"  data-text="Intrusion Detection Systems" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/intrusion-detection-systems/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/intrusion-detection-systems/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.snort.org/">Snort</a> : A Everyone&#8217;s favorite open source IDS<br />
This lightweight network intrusion detection and prevention system excels at traffic analysis and packet logging on IP networks. Through protocol analysis, content searching, and various pre-processors, Snort detects thousands of worms, vulnerability exploit attempts, port scans, and other suspicious behavior. Snort uses a flexible rule-based language to describe traffic that it should collect or pass, and a modular detection engine. Also check out the free <a href="http://secureideas.sourceforge.net/">Basic Analysis and Security Engine (BASE)</a>, a web interface for analyzing Snort alerts.<br />
<!--adsense--><br />
Open source Snort works fine for many individuals, small businesses, and departments.  Parent company <a href="http://www.sourcefire.com/">SourceFire</a> offers a complimentary product line with more enterprise-level features and real-time rule updates. They offer a free (with registration) 5-day-delayed rules feed, and you can also find many great free rules at <a href="http://www.bleedingsnort.com/">Bleeding Edge Snort</a>.</p>
<p><a href="http://www.ossec.net/">OSSEC HIDS</a> : An Open Source Host-based Intrusion Detection System<br />
OSSEC HIDS performs log analysis, integrity checking, rootkit detection, time-based alerting and active response. In addition to its IDS functionality, it is commonly used as a SEM/SIM solution. Because of its powerful log analysis engine, ISPs, universities and data centers are running OSSEC HIDS to monitor and analyze their firewalls, IDSs, web servers and authentication logs.<br />
<a href="http://www.monkey.org/%7Edugsong/fragroute/">Fragroute</a>/<a href="http://www.packetstormsecurity.nl/UNIX/IDS/nidsbench/fragrouter.html">Fragrouter</a> : A network intrusion detection evasion toolkit<br />
Fragrouter is a one-way fragmenting router &#8211; IP packets get sent from the attacker to the Fragrouter, which transforms them into a fragmented data stream to forward to the victim. Many network IDS are unable or simply don&#8217;t bother to reconstruct a coherent view of the network data (via IP fragmentation and TCP stream reassembly), as discussed in <a href="http://insecure.org/stf/secnet_ids/secnet_ids.html">this classic paper</a>. Fragrouter helps an attacker launch IP-based attacks while avoiding detection.  It is part of the <a href="http://www.packetstormsecurity.nl/UNIX/IDS/nidsbench/nidsbench.html">NIDSbench</a> suite of tools by Dug Song.  Fragroute is a similar tool which is also by Dug Song.</p>
<p><a href="http://sourceforge.net/projects/secureideas/">BASE</a> : The Basic Analysis and Security Engine<br />
BASE is a PHP-based analysis engine to search and process a database of security events generated by various IDSs, firewalls, and network monitoring tools. Its features include a query-builder and search interface for finding alerts matching different patterns, a packet viewer/decoder, and charts and statistics based on time, sensor, signature, protocol, IP address, etc.</p>
<p><a href="http://sguil.sourceforge.net/">Sguil</a> : The Analyst Console for Network Security Monitoring<br />
Sguil (pronounced sgweel) is built by network security analysts for network security analysts. Sguil&#8217;s main component is an intuitive GUI that provides realtime events from Snort/barnyard. It also includes other components which facilitate the practice of Network Security Monitoring and event driven analysis of IDS alerts.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/intrusion-detection-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerablility Exploitation Tools</title>
		<link>http://secureslash.com/security-tools/vulnerablility-exploitation-tools/</link>
		<comments>http://secureslash.com/security-tools/vulnerablility-exploitation-tools/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 12:55:24 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Networking & Security]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[System Security]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/vulnerablility-exploitation-tools/</guid>
		<description><![CDATA[Tweet Metasploit Framework : Hack the Planet Metasploit took the security world by storm when it was released in 2004. No other new tool even broke into the top 15 of this list, yet Metasploit comes in at #5, ahead of many well-loved tools that have been developed for more than a decade. It is [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fvulnerablility-exploitation-tools%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/vulnerablility-exploitation-tools/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/vulnerablility-exploitation-tools/"  data-text="Vulnerablility Exploitation Tools" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/vulnerablility-exploitation-tools/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/vulnerablility-exploitation-tools/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.metasploit.com/">Metasploit Framework</a> : Hack the Planet</p>
<p>Metasploit took the security world by storm when it was released in 2004. No other new tool even broke into the top 15 of this list, yet Metasploit comes in at #5, ahead of many well-loved tools that have been developed for more than a decade. It is an advanced open-source platform for developing, testing, and using exploit code. The extensible model through which payloads, encoders, no-op generators, and exploits can be integrated has made it possible to use the Metasploit Framework as an outlet for cutting-edge exploitation research. It ships with hundreds of exploits, as you can see in their <a href="http://metasploit.com:55555/">online exploit building demo</a>. <!--adsense--> This makes writing your own exploits easier, and it certainly beats scouring the darkest corners of the Internet for illicit shellcode of dubious quality. Similar professional exploitation tools, such as Core Impact and Canvas already existed for wealthy users on all sides of the ethical spectrum. Metasploit simply brought this capability to the masses.</p>
<p><a href="http://www.coresecurity.com/products/coreimpact/">Core Impact</a> : An automated, comprehensive penetration testing product<br />
Core Impact isn&#8217;t cheap (be prepared to spend tens of thousands of dollars), but it is widely considered to be the most powerful exploitation tool available. It sports a large, regularly updated database of professional exploits, and can do neat tricks like exploiting one machine and then establishing an encrypted tunnel through that machine to reach and exploit other boxes. If you can&#8217;t afford Impact, take a look at the cheaper Canvas or the excellent and free Metasploit Framework. Your best bet is to use all three.</p>
<p><a href="http://www.immunitysec.com/products-canvas.shtml">Canvas</a> : A Comprehensive Exploitation Framework<br />
Canvas is a commercial vulnerability exploitation tool from Dave Aitel&#8217;s<a href="http://www.immunitysec.com/">ImmunitySec</a>. It includes more than 150 exploits and is less expensive than Core Impact, though it still costs thousands of dollars. You can also buy the optional <a href="http://www.immunitysec.com/products-visualsploit.shtml">VisualSploit Plugin</a> for drag and drop GUI exploit creation.  Zero-day exploits can occasionally be found within Canvas.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/vulnerablility-exploitation-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password Crackers</title>
		<link>http://secureslash.com/security-tools/password-crackers/</link>
		<comments>http://secureslash.com/security-tools/password-crackers/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 12:54:13 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Learn Hacking]]></category>
		<category><![CDATA[Password Stories]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/password-crackers/</guid>
		<description><![CDATA[Tweet Cain and Abel : The top password recovery tool for Windows UNIX users often smugly assert that the best free security tools support their platform first, and Windows ports are often an afterthought. They are usually right, but Cain &#38; Abel is a glaring exception. This Windows-only password recovery tool handles an enormous variety [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fpassword-crackers%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/password-crackers/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/password-crackers/"  data-text="Password Crackers" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/password-crackers/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/password-crackers/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.oxid.it/cain.html">Cain and Abel</a> : The top password recovery tool for Windows</p>
<p>UNIX users often smugly assert that the best free security tools support their platform first, and Windows ports are often an afterthought. They are usually right, but Cain &amp; Abel is a glaring exception. This Windows-only password recovery tool handles an enormous variety of tasks. It can recover passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols. It is also <a href="http://www.oxid.it/ca_um/">well documented</a>.<br />
<!--adsense--><br />
<a href="http://www.openwall.com/john/">John the Ripper</a> : A powerful, flexible, and <em>fast</em> multi-platform password hash cracker<br />
John the Ripper is a fast password cracker, currently available for many flavors of Unix (11 are officially supported, not counting different architectures), DOS, Win32, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. It supports several crypt(3) password hash types which are most commonly found on various Unix flavors, as well as Kerberos AFS and Windows NT/2000/XP LM hashes. Several other hash types are added with contributed patches. You will want to start with some wordlists, which you can find <a href="ftp://ftp.mirrorgeek.com/openwall/wordlists">here</a>, <a href="ftp://ftp.ox.ac.uk/pub/wordlists/">here</a>, or <a href="http://www.outpost9.com/files/WordLists.html">here</a>.</p>
<p><a href="http://www.thc.org/thc-hydra/">THC Hydra</a> : A Fast network authentication cracker which support many different services<br />
When you need to brute force crack a remote authentication service, Hydra is often the tool of choice. It can perform rapid dictionary attacks against more then 30 protocols, including telnet, ftp, http, https, smb, several databases, and much more. Like THC Amap this release is from the fine folks at <a href="http://www.thc.org/">THC</a>.</p>
<p><a href="http://www.aircrack-ng.org/">Aircrack</a> : The fastest available WEP/WPA cracking tool<br />
Aircrack is a suite of tools for 802.11a/b/g WEP and WPA cracking. It can recover a 40 through 512-bit WEP key once enough encrypted packets have been gathered. It can also attack WPA 1 or 2 networks using advanced cryptographic methods or by brute force. The suite includes airodump (an 802.11 packet capture program), aireplay (an 802.11 packet injection program), aircrack (static WEP and WPA-PSK cracking), and airdecap (decrypts WEP/WPA capture files).</p>
<p>L0phtcrack : Windows password auditing and recovery application<br />
L0phtCrack, also known as LC5, attempts to crack Windows passwords from hashes which it can obtain (given proper access) from stand-alone Windows NT/2000 workstations, networked servers, primary domain controllers, or Active Directory. In some cases it can sniff the hashes off the wire. It also has numerous methods of generating password guesses (dictionary, brute force, etc). LC5 was discontinued by Symantec in 2006, but you can still find the <a href="http://download.insecure.org/stf/lc5-setup.exe">LC5 installer</a> floating around. The free trial only lasts 15 days, and Symantec won&#8217;t sell you a key, so you&#8217;ll either have to cease using it or find a <a href="http://download.insecure.org/stf/lc5-crack.zip">key generator</a>.  Since it is no longer maintained, you are probably better off trying Cain and Abel, John the Ripper, or <a href="http://ophcrack.sourceforge.net/">Ophcrack</a> instead.</p>
<p><a href="http://airsnort.shmoo.com/">Airsnort</a> : 802.11 WEP Encryption Cracking Tool<br />
AirSnort is a wireless LAN (WLAN) tool that recovers encryption keys. It was developed by the <a href="http://www.shmoo.com/">Shmoo Group</a> and operates by passively monitoring transmissions, computing the encryption key when enough packets have been gathered. You may also be interested in the similar Aircrack.</p>
<p><a href="http://www.solarwinds.net/">SolarWinds</a> : A plethora of network discovery/monitoring/attack tools<br />
SolarWinds has created and sells dozens of special-purpose tools targeted at systems administrators. Security-related tools include many network discovery scanners, an SNMP brute-force cracker, router password decryption, a TCP connection reset program, one of the fastest and easiest router config download/upload applications available and more.</p>
<p><a href="http://www.foofus.net/fizzgig/pwdump/">Pwdump</a> : A window password recovery tool<br />
Pwdump is able to extract NTLM and LanMan hashes from a Windows target, regardless of whether Syskey is enabled. It is also capable of displaying password histories if they are available. It outputs the data in L0phtcrack-compatible form, and can write to an output file.</p>
<p><a href="http://www.antsight.com/zsl/rainbowcrack/">RainbowCrack</a> : An Innovative Password Hash Cracker<br />
The RainbowCrack tool is a hash cracker that makes use of a large-scale time-memory trade-off. A traditional brute force cracker tries all possible plaintexts one by one, which can be time consuming for complex passwords. RainbowCrack uses a time-memory trade-off to do all the cracking-time computation in advance and store the results in so-called &#8220;rainbow tables&#8221;. It does take a long time to precompute the tables but RainbowCrack can be hundreds of times faster than a brute force cracker once the precomputation is finished.</p>
<p><a href="http://www.hoobie.net/brutus/">Brutus</a> : A network brute-force authentication cracker<br />
This Windows-only cracker bangs against network services of remote systems trying to guess passwords by using a dictionary and permutations thereof. It supports HTTP, POP3, FTP, SMB, TELNET, IMAP, NTP, and more. No source code is available. UNIX users should take a look at THC Hydra.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/password-crackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Packet Crafting Tools</title>
		<link>http://secureslash.com/security-tools/packet-crafting-tools/</link>
		<comments>http://secureslash.com/security-tools/packet-crafting-tools/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 12:53:07 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Networking & Security]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[System Security]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/packet-crafting-tools/</guid>
		<description><![CDATA[Tweet Hping2 : A network probing utility like ping on steroids This handy little utility assembles and sends custom ICMP, UDP, or TCP packets and then displays any replies. It was inspired by the ping command, but offers far more control over the probes sent. It also has a handy traceroute mode and supports IP [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fpacket-crafting-tools%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/packet-crafting-tools/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/packet-crafting-tools/"  data-text="Packet Crafting Tools" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/packet-crafting-tools/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/packet-crafting-tools/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.hping.org/">Hping2</a> : A network probing utility like ping on steroids</p>
<p>This handy little utility assembles and sends custom ICMP, UDP, or TCP packets and then displays any replies. It was inspired by the ping command, but offers far more control over the probes sent. It also has a handy traceroute mode and supports IP fragmentation. This tool is particularly useful when trying to traceroute/ping/probe hosts behind a firewall that blocks attempts using the standard utilities. This often allows you to map out firewall rulesets. It is also great for learning more about TCP/IP and experimenting with IP protocols.<br />
<!--adsense--><br />
<a href="http://www.secdev.org/projects/scapy/">Scapy</a> : Interactive packet manipulation tool<br />
Scapy is a powerful interactive packet manipulation tool, packet generator, network scanner, network discovery tool, and packet sniffer. It provides classes to interactively create packets or sets of packets, manipulate them, send them over the wire, sniff other packets from the wire, match answers and replies, and more. Interaction is provided by the Python interpreter, so Python programming structures can be used (such as variables, loops, and functions). Report modules are possible and easy to make.</p>
<p><a href="http://www.packetfactory.net/projects/nemesis/">Nemesis</a> : Packet injection simplified<br />
The Nemesis Project is designed to be a commandline-based, portable human IP stack for UNIX/Linux (and now Windows!). The suite is broken down by protocol, and should allow for useful scripting of injected packet streams from simple shell scripts.</p>
<p><a href="http://www.yersinia.net/">Yersinia</a> : A multi-protocol low-level attack tool<br />
Yersinia is a low-level protocol attack tool useful for penetration testing. It is capable of many diverse attacks over multiple protocols, such as becoming the root role in the Spanning Tree (Spanning Tree Protocol), creating virtual CDP (Cisco Discovery Protocol) neighbors, becoming the active router in a HSRP (Hot Standby Router Protocol) scenario, faking DHCP replies, and other low-level attacks.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/packet-crafting-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Traffic monitoring tools</title>
		<link>http://secureslash.com/security-tools/traffic-monitoring-tools/</link>
		<comments>http://secureslash.com/security-tools/traffic-monitoring-tools/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 12:51:18 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Networking & Security]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Website Security]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/traffic-monitoring-tools/</guid>
		<description><![CDATA[Tweet Ntop : A network traffic usage monitor Ntop shows network usage in a way similar to what top does for processes. In interactive mode, it displays the network status on the user&#8217;s terminal. In Web mode, it acts as a Web server, creating an HTML dump of the network status. It sports a NetFlow/sFlow [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Ftraffic-monitoring-tools%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/traffic-monitoring-tools/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/traffic-monitoring-tools/"  data-text="Traffic monitoring tools" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/traffic-monitoring-tools/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/traffic-monitoring-tools/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.ntop.org/">Ntop</a> : A network traffic usage monitor<br />
Ntop shows network usage in a way similar to what top does for processes. In interactive mode, it displays the network status on the user&#8217;s terminal. In Web mode, it acts as a Web server, creating an HTML dump of the network status. It sports a NetFlow/sFlow emitter/collector, an HTTP-based client interface for creating ntop-centric monitoring applications, and RRD for persistently storing traffic statistics.<br />
<!--adsense--><br />
<a href="http://www.packetfactory.net/projects/ngrep/">Ngrep</a> : Convenient packet matching &amp; display<br />
ngrep strives to provide most of GNU grep&#8217;s common features, applying them to the network layer. ngrep is a pcap-aware tool that will allow you to specify extended regular or hexadecimal expressions to match against data payloads of packets. It currently recognizes TCP, UDP and ICMP across Ethernet, PPP, SLIP, FDDI, Token Ring and null interfaces, and understands bpf filter logic in the same fashion as more common packet sniffing tools, such as tcpdump and snoop.</p>
<p><a href="http://etherape.sourceforge.net/">EtherApe</a> : EtherApe is a graphical network monitor for Unix modeled after etherman<br />
Featuring link layer, IP and TCP modes, EtherApe displays network activity graphically with a color coded protocols display. Hosts and links change in size with traffic. It supports Ethernet, FDDI, Token Ring, ISDN, PPP and SLIP devices. It can filter traffic to be shown, and can read traffic from a file as well as live from the network.</p>
<p><a href="http://www.solarwinds.net/">SolarWinds</a> : A plethora of network discovery/monitoring/attack tools<br />
SolarWinds has created and sells dozens of special-purpose tools targeted at systems administrators. Security-related tools include many network discovery scanners, an SNMP brute-force cracker, router password decryption, a TCP connection reset program, one of the fastest and easiest router config download/upload applications available and more.</p>
<p><a href="http://www.nagios.org/">Nagios</a> : An open source host, service and network monitoring program<br />
Nagios is a system and network monitoring application. It watches hosts and services that you specify, alerting you when things go bad and when they get better. Some of its many features include monitoring of network services (smtp, pop3, http, nntp, ping, etc.), monitoring of host resources (processor load, disk usage, etc.), and contact notifications when service or host problems occur and get resolved (via email, pager, or user-defined method).</p>
<p><a href="http://www.qosient.com/argus/">Argus</a> : A generic IP network transaction auditing tool<br />
Argus is a fixed-model Real Time Flow Monitor designed to track and report on the status and performance of all network transactions seen in a data network traffic stream. Argus provides a common data format for reporting flow metrics such as connectivity, capacity, demand, loss, delay, and jitter on a per transaction basis. The record format that Argus uses is flexible and extensible, supporting generic flow identifiers and metrics, as well as application/protocol specific information.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/traffic-monitoring-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Scanner</title>
		<link>http://secureslash.com/security-tools/web-scanner/</link>
		<comments>http://secureslash.com/security-tools/web-scanner/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 12:49:57 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/web-scanner/</guid>
		<description><![CDATA[Tweet Nikto : A more comprehensive web scanner Nikto is an open source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3200 potentially dangerous files/CGIs, versions on over 625 servers, and version specific problems on over 230 servers. Scan items and plugins are frequently updated and can [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fweb-scanner%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/web-scanner/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/web-scanner/"  data-text="Web Scanner" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/web-scanner/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/web-scanner/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.cirt.net/code/nikto.shtml">Nikto</a> : A more comprehensive web scanner</p>
<p>Nikto is an open source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3200 potentially dangerous files/CGIs, versions on over 625 servers, and version specific problems on over 230 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired). It uses Whisker/libwhisker for much of its underlying functionality. It is a great tool, but the value is limited by its infrequent updates. The newest and most critical vulnerabilities are often not detected.<br />
<!--adsense--><br />
<a href="http://www.parosproxy.org/">Paros proxy</a> : A web application vulnerability assessment proxy<br />
A Java based web proxy for assessing web application vulnerability. It supports editing/viewing HTTP/HTTPS messages on-the-fly to change items such as cookies and form fields. It includes a web traffic recorder, web spider, hash calculator, and a scanner for testing common web application attacks such as SQL injection and cross-site scripting.</p>
<p><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project">WebScarab</a> : A framework for analyzing applications that communicate using the HTTP and HTTPS protocols<br />
In its simplest form, WebScarab records the conversations (requests and responses) that it observes, and allows the operator to review them in various ways. WebScarab is designed to be a tool for anyone who needs to expose the workings of an HTTP(S) based application, whether to allow the developer to debug otherwise difficult problems, or to allow a security specialist to identify vulnerabilities in the way that the application has been designed or implemented.</p>
<p><a href="http://www.spidynamics.com/products/webinspect/">WebInspect</a> : A Powerful Web Application Scanner<br />
SPI Dynamics&#8217; WebInspect application security assessment tool helps identify known and unknown vulnerabilities within the Web application layer. WebInspect can also help check that a Web server is configured properly, and attempts common web attacks such as parameter injection, cross-site scripting, directory traversal, and more.</p>
<p><a href="http://www.wiretrip.net/rfp/">Whisker/libwhisker</a> : Rain.Forest.Puppy&#8217;s CGI vulnerability scanner and library<br />
Libwhisker is a Perl module geared geared towards HTTP testing. It provides functions for testing HTTP servers for many known security holes, particularly the presence of dangerous CGIs. Whisker is a scanner that used libwhisker but is now deprecated in favor of Nikto which also uses libwhisker.</p>
<p><a href="http://portswigger.net/suite/">Burpsuite</a> : An integrated platform for attacking web applications<br />
Burp suite allows an attacker to combine manual and automated techniques to enumerate, analyze, attack and exploit web applications. The various burp tools work together effectively to share information and allow findings identified within one tool to form the basis of an attack using another.</p>
<p><a href="http://www.sensepost.com/research/wikto/">Wikto</a> : Web Server Assessment Tool<br />
Wikto is a tool that checks for flaws in webservers. It provides much the same functionality as Nikto, but adds various interesting pieces of functionality, such as a Back-End miner and close Google integration. Wikto is written for the MS .NET environment and registration is required to download the binary and/or source code.</p>
<p><a href="http://www.acunetix.com/">Acunetix Web Vulnerability Scanner</a> : Commercial Web Vulnerability Scanner<br />
Acunetix WVS automatically checks your web applications for vulnerabilities such as SQL Injection, cross site scripting, and weak password strength on authentication pages. Acunetix WVS boasts a comfortable GUI and an ability to create professional website security audit reports.</p>
<p><a href="http://www.watchfire.com/products/appscan/default.aspx">Watchfire AppScan</a> : Commercial Web Vulnerability Scanner<br />
AppScan provides security testing throughout the application development lifecycle, easing unit testing and security assurance early in the development phase. Appscan scans for many common vulnerabilities, such as cross site scripting, HTTP response splitting, parameter tampering, hidden field manipulation, backdoors/debug options, buffer overflows and more.<br />
<!--adsense--><br />
<a href="http://www.nstalker.com/nstealth/">N-Stealth</a> : Web server scanner<br />
N-Stealth is a commercial web server security scanner. It is generally updated more frequently than free web scanners such as Whisker/libwhisker and Nikto, but do take their web site with a grain of salt. The claims of &#8220;30,000 vulnerabilities and exploits&#8221; and &#8220;Dozens of vulnerability checks are added every day&#8221; are highly questionable. Also note that essentially all general VA tools such as Nessus, ISS Internet Scanner, Retina, SAINT, and Sara include web scanning components. They may not all be as up-to-date or flexible though. N-Stealth is Windows only and no source code is provided.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/web-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NetCat</title>
		<link>http://secureslash.com/security-tools/netcat/</link>
		<comments>http://secureslash.com/security-tools/netcat/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 07:58:54 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Networking & Security]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/netcat/</guid>
		<description><![CDATA[Tweet Netcat : The network Swiss army knife This simple utility reads and writes data across TCP or UDP network connections. It is designed to be a reliable back-end tool that can be used directly or easily driven by other programs and scripts. At the same time, it is a feature-rich network debugging and exploration [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fnetcat%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/netcat/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/netcat/"  data-text="NetCat" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/netcat/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/netcat/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.vulnwatch.org/netcat/">Netcat</a> : The network Swiss army knife</p>
<p>This simple utility reads and writes data across TCP or UDP network connections. It is designed to be a reliable back-end tool that can be used directly or easily driven by other programs and scripts. At the same time, it is a feature-rich network debugging and exploration tool, since it can create almost any kind of connection you would need, including port binding to accept incoming connections. The original Netcat was <a href="http://seclists.org/bugtraq/1995/Oct/0028.html">released</a> <!--adsense-->by Hobbit in 1995, but it hasn&#8217;t been maintained despite its immense popularity.  It can sometimes even be hard to find <a href="http://download.insecure.org/stf/nc110.tgz">nc110.tgz</a>.</p>
<p>The flexibility and usefulness of this tool have prompted people to write numerous other Netcat implementations &#8211; often with modern features not found in the original. One of the most interesting is Socat, which extends Netcat to support many other socket types, SSL encryption, SOCKS proxies, and more. It even made this list on its own merits. There is also <a href="http://sourceforge.net/projects/nmap-ncat/">Chris Gibson&#8217;s Ncat</a>, which offers even more features while remaining portable and compact.  Other takes on Netcat include <a href="http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/nc/">OpenBSD&#8217;s nc</a>, <a href="http://farm9.org/Cryptcat/">Cryptcat</a>, <a href="http://www.deepspace6.net/projects/netcat6.html">Netcat6</a>, <a href="http://dcs.nac.uci.edu/%7Estrombrg/pnetcat.html">PNetcat</a>, <a href="http://tigerteam.se/dl/sbd/">SBD</a>, and so-called <a href="http://netcat.sourceforge.net/">GNU Netcat</a>.</p>
<p><a href="http://www.dest-unreach.org/socat/">Socat</a> : A relay for bidirectional data transfer<br />
A utility similar to the venerable Netcat that works over a number of protocols and through a files, pipes, devices (terminal or modem, etc.), sockets (Unix, IP4, IP6 &#8211; raw, UDP, TCP), a client for SOCKS4, proxy CONNECT, or SSL, etc. It provides forking, logging, and dumping, different modes for interprocess communication, and many more options. It can be used, for example, as a TCP relay (one-shot or daemon), as a daemon-based socksifier, as a shell interface to Unix sockets, as an IP6 relay, for redirecting TCP-oriented programs to a serial line, or to establish a relatively secure environment (su and chroot) for running client or server shell scripts with network connections.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/netcat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Application Specific Scanners</title>
		<link>http://secureslash.com/security-tools/application-specific-scanners/</link>
		<comments>http://secureslash.com/security-tools/application-specific-scanners/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 07:57:15 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[System Security]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/application-specific-scanners/</guid>
		<description><![CDATA[Tweet THC Amap : An application fingerprinting scanner Amap is a great tool for determining what application is listening on a given port. Their database isn&#8217;t as large as what Nmap uses for its version detection feature, but it is definitely worth trying for a 2nd opinion or if Nmap fails to detect a service. [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fapplication-specific-scanners%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/application-specific-scanners/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/application-specific-scanners/"  data-text="Application Specific Scanners" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/application-specific-scanners/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/application-specific-scanners/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.thc.org/thc-amap/">THC Amap</a> : An application fingerprinting scanner</p>
<p>Amap is a great tool for determining what application is listening on a given port. Their database isn&#8217;t as large as what <a href="http://insecure.org/nmap/">Nmap</a> uses for its <a href="http://insecure.org/nmap/vscan/">version detection</a> feature, but it is definitely worth trying for a 2nd opinion or if Nmap fails to detect a service. Amap even knows how to parse Nmap output files. This is yet another valuable tool from the great guys at <a href="http://www.thc.org/">THC</a>.<br />
<!--adsense--><br />
<a href="http://www.inetcat.net/software/nbtscan.html">Nbtscan</a> : Gathers NetBIOS info from Windows networks<br />
NBTscan is a program for scanning IP networks for NetBIOS name information. It sends a NetBIOS status query to each address in supplied range and lists received information in human readable form. For each responded host it lists IP address, NetBIOS computer name, logged-in user name and MAC address.</p>
<p><a href="http://www.nta-monitor.com/tools/ike-scan/">Ike-scan</a> : VPN detector/scanner<br />
Ike-scan exploits transport characteristics in the Internet Key Exchange (IKE) service, the mechanism used by VPNs to establish a connection between a server and a remote client. It scans IP addresses for VPN servers by sending a specially crafted IKE packet to each host within a network. Most hosts running IKE will respond, identifying their presence. The tool then remains silent and monitors retransmission packets. These retransmission responses are recorded, displayed and matched against a known set of VPN product fingerprints. Ike-scan can VPNs from manufacturers including Checkpoint, Cisco, Microsoft, Nortel, and Watchguard.</p>
<p><a href="http://www.immunitysec.com/resources-freesoftware.shtml">SPIKE Proxy</a> : HTTP Hacking<br />
Spike Proxy is an open source HTTP proxy for finding security flaws in web sites. It is part of the <a href="http://www.immunitysec.com/resources-freesoftware.shtml">Spike Application Testing Suite</a> and supports automated SQL injection detection, web site crawling, login form brute forcing, overflow detection, and directory traversal detection.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/application-specific-scanners/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Port Scanners</title>
		<link>http://secureslash.com/security-tools/port-scanners/</link>
		<comments>http://secureslash.com/security-tools/port-scanners/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 07:55:46 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Learn Hacking]]></category>
		<category><![CDATA[Networking & Security]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[System Security]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/port-scanners/</guid>
		<description><![CDATA[Tweet Angry IP Scanner : A fast windows IP scanner and port scanner Angry IP Scanner can perform basic host discovery and port scans on Windows. Its binary file size is very small compared to other scanners and other pieces of information about the target hosts can be extended with a few plugins. Superscan : [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fport-scanners%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/port-scanners/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/port-scanners/"  data-text="Port Scanners" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/port-scanners/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/port-scanners/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.angryziber.com/ipscan/">Angry IP Scanner</a> : A fast windows IP scanner and port scanner</p>
<p>Angry IP Scanner can perform basic host discovery and port scans on Windows. Its binary file size is very small compared to other scanners and other pieces of information about the target hosts can be extended with <a href="http://www.angryziber.com/ipscan/plugins/">a few plugins</a>.<br />
<!--adsense--><br />
<a href="http://www.foundstone.com/resources/proddesc/superscan.htm">Superscan</a> : A Windows-only port scanner, pinger, and resolver<br />
SuperScan is a free Windows-only closed-source TCP/UDP port scanner by Foundstone. It includes a variety of additional networking tools such as ping, traceroute, http head, and whois.</p>
<p><a href="http://www.unicornscan.org/">Unicornscan</a> : Not your mother&#8217;s port scanner<br />
Unicornscan is an attempt at a User-land Distributed TCP/IP stack for information gathering and correlation. It is intended to provide a researcher a superior interface for introducing a stimulus into and measuring a response from a TCP/IP enabled device or network. Some of its features include asynchronous stateless TCP scanning with all variations of TCP flags, asynchronous stateless TCP banner grabbing, and active/passive remote OS, application, and component identification by analyzing responses. it isn&#8217;t for the faint of heart.</p>
<p><a href="http://www.doxpara.com/paketto">Scanrand</a> : An unusually fast stateless network service and topology discovery system<br />
Scanrand is a stateless host-discovery and port-scanner similar in design to Unicornscan. It trades off reliability for amazingly fast speeds and uses cryptographic techniques to prevent attackers from manipulating scan results. This utility is a part of a software package called <a href="http://www.doxpara.com/paketto">Paketto Keiretsu</a> which was written by <a href="http://www.doxpara.com/">Dan Kaminsky</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/port-scanners/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firewall</title>
		<link>http://secureslash.com/security-tools/firewall/</link>
		<comments>http://secureslash.com/security-tools/firewall/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 07:54:13 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Networking & Security]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[System Security]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/firewall/</guid>
		<description><![CDATA[Tweet Netfilter : The current Linux kernel packet filter/firewall Netfilter is a powerful packet filter implemented in the standard Linux kernel. The userspace iptables tool is used for configuration. It now supports packet filtering (stateless or stateful), all kinds of network address and port translation (NAT/NAPT), and multiple API layers for 3rd party extensions. It [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Ffirewall%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/firewall/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/firewall/"  data-text="Firewall" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/firewall/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/firewall/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.netfilter.org/">Netfilter</a> : The current Linux kernel packet filter/firewall</p>
<p>Netfilter is a powerful packet filter implemented in the standard Linux kernel. The userspace iptables tool is used for configuration. It now supports packet filtering (stateless or stateful), all kinds of network address and port translation (NAT/NAPT), and multiple API layers for 3rd party extensions. It includes many different modules for handling unruly protocols such as FTP. For other UNIX platforms (OpenBSD specific), or IP Filter. <!--adsense-->Many <a href="http://en.wikipedia.org/wiki/Personal_firewall">personal firewalls</a> are available for Windows (<a href="http://www.tinysoftware.com/">Tiny</a>,<a href="http://www.zonelabs.com/">Zone Alarm</a>, Norton, <a href="http://www.kerio.com/">Kerio</a>, &#8230;), though none made this list. Microsoft included a very basic firewall in Windows XP SP2, and will nag you incessantly until you install it.</p>
<p><a href="http://www.benzedrine.cx/pf.html">Openbsd PF</a> : The OpenBSD Packet Filter<br />
Like Netfilter and IP Filter on other platforms, OpenBSD users love PF, their firewall tool. It handles network address translation, normalizing TCP/IP traffic, providing bandwidth control, and packet prioritization. It also offers some eccentric features, such as passive OS detection. Coming from the same guys who created OpenBSD, you can trust that it has been well audited and coded to avoid the sort of security holes we have seen in <a href="http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=28350">other</a>  <a href="http://netfilter.org/security/">packet</a>  <a href="http://www.osvdb.org/displayvuln.php?osvdb_id=4745">filters</a>.</p>
<p><a href="http://coombs.anu.edu.au/%7Eavalon/">IP Filter</a> : Portable UNIX Packet Filter<br />
IP Filter is a software package that can be used to provide network address translation (NAT) or firewall services. It can either be used as a loadable kernel module or incorporated into your UNIX kernel; use as a loadable kernel module where possible is highly recommended. Scripts are provided to install and patch system files, as required. IP Filter is distributed with FreeBSD, NetBSD, and Solaris.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/firewall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rootkit Detectors</title>
		<link>http://secureslash.com/security-tools/rootkit-detectors/</link>
		<comments>http://secureslash.com/security-tools/rootkit-detectors/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 07:52:47 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Server Administration]]></category>
		<category><![CDATA[System Security]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/rootkit-detectors/</guid>
		<description><![CDATA[Tweet Sysinternals : An extensive collection of powerful windows utilities Sysinternals provides many small windows utilities that are quite useful for low-level windows hacking. Some are free of cost and/or include source code, while others are proprietary. Survey respondents were most enamored with: ProcessExplorer for keeping an eye on the files and directories open by [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Frootkit-detectors%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/rootkit-detectors/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/rootkit-detectors/"  data-text="Rootkit Detectors" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/rootkit-detectors/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/rootkit-detectors/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.microsoft.com/technet/sysinternals/default.mspx">Sysinternals</a> : An extensive collection of powerful windows utilities</p>
<p>Sysinternals provides many small windows utilities that are quite useful for low-level windows hacking. Some are free of cost and/or include source code, while others are proprietary. Survey respondents were most enamored with:<!--adsense--></p>
<ul>
<li><a href="http://www.microsoft.com/technet/sysinternals/utilities/ProcessExplorer.mspx">ProcessExplorer</a> for keeping an eye on the files and directories open by any process (like LSoF on UNIX).</li>
<li><a href="http://www.microsoft.com/technet/sysinternals/utilities/PsTools.mspx">PsTools</a> for managing (executing, suspending, killing, detailing) local and remote processes.</li>
<li><a href="http://www.microsoft.com/technet/sysinternals/utilities/Autoruns.mspx">Autoruns</a> for discovering what executables are set to run during system boot up or login.</li>
<li><a href="http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx">RootkitRevealer</a> for detecting registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.</li>
<li><a href="http://www.microsoft.com/technet/sysinternals/utilities/TcpView.mspx">TCPView</a>, for viewing TCP and UDP traffic endpoints used by each process (like Netstat on UNIX).</li>
</ul>
<p><strong>Update:</strong> Microsoft <a href="http://www.winternals.com/Company/PressRelease92.aspx">acquired Sysinternals</a> in July 2006, <a href="http://www.winternals.com/Company/PressRelease92.aspx">promising</a> that â€œCustomers will be able to continue building on Sysinternals&#8217; advanced utilities, technical information and source codeâ€. Less than four months later, Microsoft <a href="http://seclists.org/dailydave/2006/q4/0134.html">removed</a> most of that source code.  Future product direction is uncertain.</p>
<p><a href="http://www.tripwire.com/">Tripwire</a> : The grand-daddy of file integrity checkers<br />
A file and directory integrity checker. Tripwire is a tool that aids system administrators and users in monitoring a designated set of files for any changes. Used with system files on a regular (e.g., daily) basis, Tripwire can notify system administrators of corrupted or tampered files, so damage control measures can be taken in a timely manner. An open source Linux version is freely available at <a href="http://www.tripwire.org/">Tripwire.Org</a>.  UNIX users may also want to consider <a href="http://www.cs.tut.fi/%7Erammer/aide.html">AIDE</a>, which has been designed to be a free Tripwire replacement.  Or you may wish to investigate <a href="http://www.radmind.org/">Radmind</a>, RKHunter, or chkrootkit.  Windows users may like <a href="http://www.sysinternals.com/utilities/rootkitrevealer.html">RootkitRevealer</a> from Sysinternals.</p>
<p><a href="http://www.rootkit.nl/projects/rootkit_hunter.html">RKHunter</a> : An Unix Rootkit Detector<br />
RKHunter is scanning tool that checks for signs of various pieces of nasty software on your system like rootkits, backdoors and local exploits. It runs many tests, including MD5 hash comparisons, default filenames used by rootkits, wrong file permissions for binaries, and suspicious strings in LKM and KLD modules.</p>
<p><a href="http://www.chkrootkit.org/">chkrootkit</a> : Locally checks for signs of a rootkit<br />
chkrootkit is a flexible, portable tool that can check for many signs of rootkit intrusion on Unix-based systems. Its features include detecting binary modification, utmp/wtmp/lastlog modifications, promiscuous interfaces, and malicious kernel modules.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/rootkit-detectors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Encryption Tools</title>
		<link>http://secureslash.com/security-tools/encryption-tools/</link>
		<comments>http://secureslash.com/security-tools/encryption-tools/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 07:42:58 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/encryption-tools/</guid>
		<description><![CDATA[Tweet GnuPG / PGP : Secure your files and communication w/advanced encryption PGP is the famous encryption program by Phil Zimmerman which helps secure your data from eavesdroppers and other risks. GnuPG is a very well-regarded open source implementation of the PGP standard (the actual executable is named gpg). While GnuPG is always free, PGP [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fencryption-tools%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/encryption-tools/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/encryption-tools/"  data-text="Encryption Tools" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/encryption-tools/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/encryption-tools/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.gnupg.org/">GnuPG</a> / <a href="http://www.pgp.com/">PGP</a> : Secure your files and communication w/advanced encryption</p>
<p>PGP is the famous encryption program by Phil Zimmerman which helps secure your data from eavesdroppers and other risks. GnuPG is a very well-regarded open source implementation of the PGP standard (the actual executable is named gpg). While GnuPG is always free, PGP costs money for some uses.<br />
<!--adsense--><br />
<a href="http://www.openssl.org/">OpenSSL</a> : The premier SSL/TLS encryption library<br />
The OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, full-featured, and open source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a full-strength general purpose cryptography library. The project is managed by a worldwide community of volunteers that use the Internet to communicate, plan, and develop the OpenSSL toolkit and its related documentation.</p>
<p><a href="http://tor.eff.org/">Tor</a> : An anonymous Internet communication system<br />
Tor is a toolset for a wide range of organizations and people that want to improve their safety and security on the Internet. Using Tor can help you anonymize web browsing and publishing, instant messaging, irc, ssh, and other applications that use the TCP protocol. Tor also provides a platform on which software developers can build new applications with built-in anonymity, safety, and privacy features. For a free cross-platform GUI, users recommend <a href="http://www.vidalia-project.net/">Vidalia</a></p>
<p><a href="http://www.stunnel.org/">Stunnel</a> :A general-purpose SSL cryptographic wrapper<br />
The stunnel program is designed to work as an SSL encryption wrapper between remote client and local (inetd-startable) or remote server. It can be used to add SSL functionality to commonly used inetd daemons like POP2, POP3, and IMAP servers without any changes in the programs&#8217; code. It will negotiate an SSL connection using the OpenSSL or SSLeay libraries.</p>
<p><a href="http://openvpn.net/">OpenVPN</a> : A full-featured SSL VPN solution<br />
OpenVPN is an open-source SSL VPN package which can accommodate a wide range of configurations, including remote access, site-to-site VPNs, WiFi security, and enterprise-scale remote access solutions with load balancing, failover, and fine-grained access-controls. OpenVPN implements OSI layer 2 or 3 secure network extension using the industry standard SSL/TLS protocol, supports flexible client authentication methods based on certificates, smart cards, and/or 2-factor authentication, and allows user or group-specific access control policies using firewall rules applied to the VPN virtual interface. OpenVPN uses OpenSSL as its primary cryptographic library.</p>
<p><a href="http://www.truecrypt.org/">TrueCrypt</a> : Open-Source Disk Encryption Software for Windows and Linux<br />
TrueCrypt is an excellent open source disk encryption system. Users can encrypt entire filesystems, which are then on-the-fly encrypted/decrypted as needed without user intervention beyond entering their passphrase intially. A clever <a href="http://www.truecrypt.org/user-guide/hidden-volume.php">hidden volume</a> feature allows you to hide a 2nd layer of particularly sensitive content with plausible deniability about whether it exists. Then if you are forced to give up your passphrase, you give them the first-level secret. Even with that, attackers cannot prove that a second level key even exists.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/encryption-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disassemblers</title>
		<link>http://secureslash.com/security-tools/disassemblers/</link>
		<comments>http://secureslash.com/security-tools/disassemblers/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 07:40:33 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/disassemblers/</guid>
		<description><![CDATA[Tweet IDA Pro : A Windows or Linux disassembler and debugger Disassembly is a big part of security research. It will help you dissect that Microsoft patch to discover the silently fixed bugs they don&#8217;t tell you about, or more closely examine a server binary to determine why your exploit isn&#8217;t working. Many disassemblers are [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fdisassemblers%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/disassemblers/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/disassemblers/"  data-text="Disassemblers" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/disassemblers/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/disassemblers/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.datarescue.com/idabase/">IDA Pro</a> : A Windows or Linux disassembler and debugger</p>
<p>Disassembly is a big part of security research. It will help you dissect that Microsoft patch to discover the silently fixed bugs they don&#8217;t tell you about, or more closely examine a server binary to determine why your exploit isn&#8217;t working. Many disassemblers are available, but IDA Pro has become the de-facto standard for the analysis of hostile code and vulnerability research. This interactive, programmable, extensible, multi-processor disassembler now supports Linux (console mode) as well as Windows.<br />
<!--adsense--><br />
<a href="http://www.ollydbg.de/">OllyDbg</a> : An assembly level Windows debugger<br />
OllyDbg is a 32-bit assembler level analyzing debugger for Microsoft Windows. Emphasis on binary code analysis makes it particularly useful in cases where source is unavailable. OllyDbg features an intuitive user interface, advanced code analysis capable of recognizing procedures, loops, API calls, switches, tables, constants and strings, an ability to attach to a running program, and good multi-thread support. OllyDbg is free to download and use but no source code is provided.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/disassemblers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ping Tool / Traceroute tools</title>
		<link>http://secureslash.com/security-tools/ping-tool-traceroute-tools/</link>
		<comments>http://secureslash.com/security-tools/ping-tool-traceroute-tools/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 07:39:32 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Networking & Security]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/ping-tool-traceroute-tools/</guid>
		<description><![CDATA[Tweet Firewalk : Advanced traceroute Firewalk employs traceroute-like techniques to analyze IP packet responses to determine gateway ACL filters and map networks. This classic tool was rewritten from scratch in October 2002. Note that much or all of this functionality can also be performed by the Hping2 &#8211;traceroute option. Tcptraceroute : A traceroute implementation using [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fping-tool-traceroute-tools%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/ping-tool-traceroute-tools/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/ping-tool-traceroute-tools/"  data-text="Ping Tool / Traceroute tools" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/ping-tool-traceroute-tools/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/ping-tool-traceroute-tools/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.packetfactory.net/projects/firewalk/">Firewalk</a> : Advanced traceroute</p>
<p>Firewalk employs traceroute-like techniques to analyze IP packet responses to determine gateway ACL filters and map networks. This classic tool was rewritten from scratch in October 2002. Note that much or all of this functionality can also be performed by the Hping2 &#8211;traceroute option.<br />
<!--adsense--><br />
<a href="http://michael.toren.net/code/tcptraceroute/">Tcptraceroute</a> : A traceroute implementation using TCP packets<br />
The problem is that with the widespread use of firewalls on the modern Internet, many of the packets that the conventional traceroute(8) sends out (ICMP echo or UDP) end up being filtered, making it impossible to completely trace the path to the destination. However, in many cases, these firewalls will permit inbound TCP packets to specific ports that hosts sitting behind the firewall are listening for connections on. By sending out TCP SYN packets instead of UDP or ICMP ECHO packets, tcptraceroute is able to bypass the most common firewall filters.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/ping-tool-traceroute-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability Scanner</title>
		<link>http://secureslash.com/security-tools/vulnerability-scanner/</link>
		<comments>http://secureslash.com/security-tools/vulnerability-scanner/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 07:36:54 +0000</pubDate>
		<dc:creator>KarthiKeyan</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[System Security]]></category>

		<guid isPermaLink="false">http://secureslash.com/security-tools/vulnerability-scanner/</guid>
		<description><![CDATA[Tweet Nessus : Premier UNIX vulnerability assessment tool Nessus is the best free network vulnerability scanner available, and the best to run on UNIX at any price. It is constantly updated, with more than 11,000 plugins for the free (but registration and EULA-acceptance required) feed. Key features include remote and local (authenticated) security checks, a [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fsecureslash.com%2Fsecurity-tools%2Fvulnerability-scanner%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://secureslash.com/security-tools/vulnerability-scanner/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://secureslash.com/security-tools/vulnerability-scanner/"  data-text="Vulnerability Scanner" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://secureslash.com/security-tools/vulnerability-scanner/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://secureslash.com/security-tools/vulnerability-scanner/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.nessus.org/">Nessus</a> : Premier UNIX vulnerability assessment tool</p>
<p>Nessus is the best free network vulnerability scanner available, and the best to run on UNIX at any price. It is constantly updated, with more than 11,000 plugins for the free (but registration and EULA-acceptance required) feed. Key features include remote and local (authenticated) security checks, a client/server architecture with a GTK graphical interface, and an embedded scripting language for writing your own plugins or understanding the existing ones.<!--adsense--> Nessus 3 is <a href="http://software.newsforge.com/article.pl?sid=05/10/06/1716257&amp;tid=132&amp;tid=78&amp;tid=27">now closed source</a>, but is still free-of-cost unless you want the very newest plugins.</p>
<p><a href="http://www.gfi.com/lannetscan/">GFI LANguard</a> : A commercial network security scanner for Windows<br />
GFI LANguard scans IP networks to detect what machines are running. Then it tries to discern the host OS and what applications are running. I also tries to collect Windows machine&#8217;s service pack level, missing security patches, wireless access points, USB devices, open shares, open ports, services/applications active on the computer, key registry entries, weak passwords, users and groups, and more. Scan results are saved to an HTML report, which can be customized/queried. It also includes a patch manager which detects and installs missing patches. A free trial version is available, though it only works for up to 30 days.</p>
<p><a href="http://www.eeye.com/html/Products/Retina/index.html">Retina</a> : Commercial vulnerability assessment scanner by eEye<br />
. Retina&#8217;s function is to scan all the hosts on a network and report on any vulnerabilities found. It was written by <a href="http://www.eeye.com/">eEye</a>, who are well known for their <a href="http://www.eeye.com/html/research/index.html">security research</a>.</p>
<p><a href="http://www.coresecurity.com/products/coreimpact/">Core Impact</a> : An automated, comprehensive penetration testing product<br />
Core Impact isn&#8217;t cheap (be prepared to spend tens of thousands of dollars), but it is widely considered to be the most powerful exploitation tool available. It sports a large, regularly updated database of professional exploits, and can do neat tricks like exploiting one machine and then establishing an encrypted tunnel through that machine to reach and exploit other boxes. If you can&#8217;t afford Impact, take a look at the cheaper Canvas or the excellent and free Metasploit Framework. Your best bet is to use all three.</p>
<p><a href="http://www.iss.net/products_services/enterprise_protection/vulnerability_assessment/scanner_internet.php">ISS Internet Scanner</a> : Application-level vulnerability assessment<br />
Internet Scanner started off in &#8217;92 as a tiny open source scanner by Christopher Klaus. Now he has grown ISS into a billion-dollar company with a myriad of security products.</p>
<p><a href="http://www.xfocus.net/tools/200507/1057.html">X-scan</a> : A general scanner for scanning network vulnerabilities<br />
A multi-threaded, plug-in-supported vulnerability scanner. X-Scan includes many features, including full NASL support, detecting service types, remote OS type/version detection, weak user/password pairs, and more. You may be able to find newer versions available <a href="http://www.xfocus.net/tools/">here</a> if you can deal with most of the page being written in Chinese.</p>
<p><a href="http://www-arc.com/sara/">Sara</a> : Security Auditor&#8217;s Research Assistant<br />
SARA is a vulnerability assessment tool that was derived from the infamous SATAN scanner. They try to release updates twice a month and try to leverage other software created by the open source community (such as <a href="http://insecure.org/nmap/">Nmap</a> and <a href="http://samba.org/">Samba</a>).</p>
<p><a href="http://www.qualys.com/">QualysGuard</a> : A web-based vulnerability scanner<br />
Delivered as a service over the Web, QualysGuard eliminates the burden of deploying, maintaining, and updating vulnerability management software or implementing ad-hoc security applications. Clients securely access QualysGuard through an easy-to-use Web interface. QualysGuard features 5,000+ unique vulnerability checks, an Inference-based scanning engine, and automated daily updates to the QualysGuard vulnerability KnowledgeBase.</p>
<p><a href="http://www.saintcorporation.com/saint/">SAINT</a> : Security Administrator&#8217;s Integrated Network Tool<br />
SAINT is another commercial vulnerability assessment tool (like Nessus, ISS Internet Scanner, or Retina). It runs on UNIX and used to be free and open source, but is now a commercial product.</p>
<p><a href="http://www.microsoft.com/technet/security/tools/mbsahome.mspx">MBSA</a> : Microsoft Baseline Security Analyzer<br />
Microsoft Baseline Security Analyzer (MBSA) is an easy-to-use tool designed for the IT professional that helps small and medium-sized businesses determine their security state in accordance with Microsoft security recommendations and offers specific remediation guidance. Built on the Windows Update Agent and Microsoft Update infrastructure, MBSA ensures consistency with other Microsoft management products including Microsoft Update (MU), Windows Server Update Services (WSUS), Systems Management Server (SMS) and Microsoft Operations Manager (MOM). Apparently MBSA on average scans over 3 million computers each week.</p>
]]></content:encoded>
			<wfw:commentRss>http://secureslash.com/security-tools/vulnerability-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

