<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>PenTestIT</title> <link>http://pentestit.com</link> <description>Your source for Information Security Related information!</description> <lastBuildDate>Wed, 08 Sep 2010 08:08:27 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.0.1</generator> <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/PenTestIT" /><feedburner:info uri="pentestit" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><geo:lat>28.5108322</geo:lat><geo:long>77.0733619</geo:long><feedburner:emailServiceId>PenTestIT</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><title>Firefox Portable WEBTOOLS for Web Application Security</title><link>http://feedproxy.google.com/~r/PenTestIT/~3/qHhHn7HjtZw/</link> <comments>http://pentestit.com/2010/09/08/firefox-portable-webtools-web-application-security/#comments</comments> <pubDate>Wed, 08 Sep 2010 06:16:10 +0000</pubDate> <dc:creator>Black</dc:creator> <category><![CDATA[Penetration Testing]]></category> <category><![CDATA[Portable]]></category> <category><![CDATA[Security tools]]></category> <category><![CDATA[Web Application Penetration Testing]]></category> <category><![CDATA[FireFox]]></category> <category><![CDATA[plugin]]></category> <category><![CDATA[Portable software]]></category><guid isPermaLink="false">http://pentestit.com/?p=5604</guid> <description><![CDATA[If you are aware of the PenTestIT.Com&#8217;s WAPT FireFox Add-ons, this collection might ring a bell in your security inclined mind. This is a portable version of Mozilla Firefox with several addons that are useful for Web Application Security. The purpose of this package is to have the best available [...]]]></description> <content:encoded><![CDATA[<p></p><p>If you are aware of the <a target="_blank" href="pentestit.com/2010/03/07/pentestitcoms-wapt-firefox-addons/">PenTestIT.Com&#8217;s WAPT FireFox Add-ons</a>, this collection might ring a bell in your security inclined mind. This is a portable version of Mozilla Firefox with several addons that are useful for Web Application Security. The purpose of this package is to have the best available addons to manually test XSS, SQL, siXSS, CSRF, Trace XSS, RFI, LFI, etc.</p><p style="text-align: center;"><img onload="NcodeImageResizer.createOn(this);" class="aligncenter" src="http://pentestit.com/wp-content/uploads/HLIC/c99d5246a8416bdcb4fc599f1e2b91bb.jpg" alt="c99d5246a8416bdcb4fc599f1e2b91bb Firefox Portable WEBTOOLS for Web Application Security" width="345" height="374" title="Firefox Portable WEBTOOLS for Web Application Security" /></p><p>We have tested it on Windows XP SP2 and SP3 and found it very useful. But, with more manual intervention for reporting and other fine tuning of tools, this could be an awesome collection!</p><p>Download Firefox Portable WEBTOOLS <a target="_blank" href="http://623fabb1.linkbucks.com"><strong>here</strong></a></p><div style='clear:both'></div><h2  class="related_post_title">If you enjoyed this article, you might also like:</h2><ul class="related_post"><li>August 20, 2010 -- <a href="http://pentestit.com/2010/08/20/update-xsser-v07a/" title="UPDATE: XSSer v0.7a!">UPDATE: XSSer v0.7a!</a><br /><small>All of you web application penetration testers, check out this release  of XSSer version 0.7a, for i...</small></li><li>July 2, 2010 -- <a href="http://pentestit.com/2010/07/02/update-xsser-v06a/" title="UPDATE: XSSer v0.6a!">UPDATE: XSSer v0.6a!</a><br /><small>All of you web application penetration testers, check out this release  of XSSer version 0.6a, for i...</small></li><li>April 19, 2010 -- <a href="http://pentestit.com/2010/04/19/update-xsser-v05a/" title="UPDATE: XSSer v0.5a!">UPDATE: XSSer v0.5a!</a><br /><small> All of you web application penetration testers, check out this release of XSSer version 0.5a!“C...</small></li><li>April 18, 2010 -- <a href="http://pentestit.com/2010/04/18/clickjacking-tool/" title="The Clickjacking Tool!">The Clickjacking Tool!</a><br /><small>A lot has been happening since the last week - BlackHat and all! Just as luck would have it, we were...</small></li><li>March 21, 2010 -- <a href="http://pentestit.com/2010/03/21/update-xsser-v04a/" title="UPDATE: XSSer v0.4a!">UPDATE: XSSer v0.4a!</a><br /><small> See! This is what we say about an actively maintained project! We wrote about XSSer just yesterday ...</small></li><li>March 20, 2010 -- <a href="http://pentestit.com/2010/03/20/xsser-automate-xss-injections/" title="XSSer: Automate your XSS Injections!">XSSer: Automate your XSS Injections!</a><br /><small> If you are aware, we posted about XSSPloit almost a year ago. Since then, we have bought to you too...</small></li><li>September 6, 2010 -- <a href="http://pentestit.com/2010/09/06/zaproxy-tool-web-application-penetration-testing-tool/" title="ZAProxy: A Web Application Penetration Testing Tool Developers! ">ZAProxy: A Web Application Penetration Testing Tool Developers! </a><br /><small>If you remember about Andiparos, you might remember that it was a fork of the famous Paros Proxy. No...</small></li><li>September 3, 2010 -- <a href="http://pentestit.com/2010/09/03/dotdotpwn-tool-directory-traversal-checkerscanning/" title="DotDotPwn: A Tool for Directory Traversal Checking and Scanning!">DotDotPwn: A Tool for Directory Traversal Checking and Scanning!</a><br /><small>DotDotPwn is a simple PERL tool which detects several Directory Traversal Vulnerabilities on HTTP/FT...</small></li><li>August 16, 2010 -- <a href="http://pentestit.com/2010/08/16/update-websecurify-07/" title="UPDATE: Websecurify 0.7!">UPDATE: Websecurify 0.7!</a><br /><small>Good news for Websecurify lovers, as we have an updated Websecurify version 0.7 amongst us finally! ...</small></li></ul>
<p><a href="http://feedads.g.doubleclick.net/~a/HLTugKuLFh2M_lHyy1SrdQu52EY/0/da"><img src="http://feedads.g.doubleclick.net/~a/HLTugKuLFh2M_lHyy1SrdQu52EY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/HLTugKuLFh2M_lHyy1SrdQu52EY/1/da"><img src="http://feedads.g.doubleclick.net/~a/HLTugKuLFh2M_lHyy1SrdQu52EY/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/PenTestIT?a=qHhHn7HjtZw:Vjfge0QUcrk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/PenTestIT?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=qHhHn7HjtZw:Vjfge0QUcrk:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=qHhHn7HjtZw:Vjfge0QUcrk:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=qHhHn7HjtZw:Vjfge0QUcrk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=qHhHn7HjtZw:Vjfge0QUcrk:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/PenTestIT/~4/qHhHn7HjtZw" height="1" width="1"/>]]></content:encoded> <wfw:commentRss>http://pentestit.com/2010/09/08/firefox-portable-webtools-web-application-security/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://pentestit.com/2010/09/08/firefox-portable-webtools-web-application-security/</feedburner:origLink></item> <item><title>UPDATE: DLLHijackAuditor v2!</title><link>http://feedproxy.google.com/~r/PenTestIT/~3/Pjbm_Dw9TIY/</link> <comments>http://pentestit.com/2010/09/08/update-dllhijackauditor-v2/#comments</comments> <pubDate>Wed, 08 Sep 2010 04:55:57 +0000</pubDate> <dc:creator>Black</dc:creator> <category><![CDATA[Security tools]]></category> <category><![CDATA[Tool Updates]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[DLLHijackAuditKit v2]]></category> <category><![CDATA[DllHijackAuditor]]></category> <category><![CDATA[Malware Analysis]]></category> <category><![CDATA[Vulnerability Scanner]]></category><guid isPermaLink="false">http://pentestit.com/?p=5601</guid> <description><![CDATA[Our first post regarding the DLLHijackAuditor can be found here. Now, the author has released an update &#8211; DLLHijackAuditor version 2! &#8220;DllHijackAuditor is a smart tool to Audit against the Dll Hijacking Vulnerability in any Windows application. This is recently discovered critical security issue affecting almost all Windows systems on [...]]]></description> <content:encoded><![CDATA[<p></p><p>Our first post regarding the <strong>DLLHijackAuditor</strong> can be found <strong><a href="http://pentestit.com/2010/08/31/dllhijackauditor-audit-dll-hijacking-vulnerability/">here</a></strong>. Now, the author has released an update &#8211; <span style="text-decoration: underline;">DLLHijackAuditor version 2</span>!</p><blockquote><p><em>&#8220;DllHijackAuditor is a smart tool to Audit against the Dll Hijacking Vulnerability in any Windows application. This is recently discovered critical security issue affecting almost all Windows systems on the planet. It appears that large amount of Windows applications are currently susceptible to this vulnerability which can allow any attacker to completely take over the system.&#8221;</em></p></blockquote><p><span style="text-decoration: underline;">This is the official changelog</span>:</p><ul><li> Smart Debugger based &#8216;Interception Engine&#8217; for consistent and efficient performance without intrusion.</li><li> Support for specifying as well as auditing of application with custom &amp; multiple Extensions.</li><li> Timeout Configuration to alter the waiting time for each Application.</li></ul><p>Download DllHijackAuditor v2.0 <a target="_blank" href="http://4a32bfd4.linkbucks.com/" target="_blank"><strong>here</strong></a></p><div style='clear:both'></div><h2  class="related_post_title">If you enjoyed this article, you might also like:</h2><ul class="related_post"><li>August 31, 2010 -- <a href="http://pentestit.com/2010/08/31/dllhijackauditor-audit-dll-hijacking-vulnerability/" title="DllHijackAuditor: Audit the DLL Hijacking Vulnerability!">DllHijackAuditor: Audit the DLL Hijacking Vulnerability!</a><br /><small>DllHijackAuditor is the smart tool to audit against the DLL Hijacking Vulnerability on any Windows a...</small></li><li>August 31, 2010 -- <a href="http://pentestit.com/2010/08/31/tools-find-dll-hijacking-vulnerabilities/" title="Three Tools to Help You find DLL Hijacking Vulnerabilities!">Three Tools to Help You find DLL Hijacking Vulnerabilities!</a><br /><small>Discovering new vulnerabilities for the now famous Microsoft article - KB 2269639 has become very ea...</small></li><li>September 2, 2010 -- <a href="http://pentestit.com/2010/09/02/update-procnetmonitor-v27/" title="UPDATE: ProcNetMonitor v2.7!">UPDATE: ProcNetMonitor v2.7!</a><br /><small>Whoa! It sure has been a long time since we updated information about ProcNetMonitor. We had mention...</small></li><li>August 27, 2010 -- <a href="http://pentestit.com/2010/08/27/dllhijackauditkit-v2-faster-stronger-tool/" title="DLLHijackAuditKit v2: Better, Faster, Stronger DLL Tests!">DLLHijackAuditKit v2: Better, Faster, Stronger DLL Tests!</a><br /><small>The latest buzz word in the information security industry is "insecure DLL loading", "DLL hijacking"...</small></li><li>August 18, 2010 -- <a href="http://pentestit.com/2010/08/18/update-whatweb-v045/" title="UPDATE: WhatWeb v0.4.5!">UPDATE: WhatWeb v0.4.5!</a><br /><small>We originally wrote about WhatWeb in our   previous post here. It has now been updated to WhatWeb ve...</small></li><li>August 18, 2010 -- <a href="http://pentestit.com/2010/08/18/update-nmapsi4-02-beta3/" title="Nmapsi: A NMAP GUI!">Nmapsi: A NMAP GUI!</a><br /><small>Yet another nmap GUI - NmapSi is a complete Qt-based GUI with the design goals to provide a complete...</small></li><li>August 11, 2010 -- <a href="http://pentestit.com/2010/08/11/domscan-tool-scanning-analyzing-dom/" title="DOMScan: Tool for Scanning and Analyzing DOM">DOMScan: Tool for Scanning and Analyzing DOM</a><br /><small>DOMScan is utility to drive IE and capture real time DOM from the browser. It gives access to active...</small></li><li>August 6, 2010 -- <a href="http://pentestit.com/2010/08/06/update-pdf-dissector-150/" title="Update : PDF Dissector 1.5.0!">Update : PDF Dissector 1.5.0!</a><br /><small>PDF Dissector version 1.5.0 is a PDF malware analysis tool. It brings two very cool new features. ...</small></li><li>July 19, 2010 -- <a href="http://pentestit.com/2010/07/19/pentestit-post-day-blackbox-web-vulnerability-scanners/" title="PenTestIT Post Of The Day: Black-box Web Vulnerability Scanners!">PenTestIT Post Of The Day: Black-box Web Vulnerability Scanners!</a><br /><small>What is the article about?Black-box web vulnerability scanners are a class of tools that can be ...</small></li></ul>
<p><a href="http://feedads.g.doubleclick.net/~a/6oFZ93Hg87wjISFAF4cjl4zxbWU/0/da"><img src="http://feedads.g.doubleclick.net/~a/6oFZ93Hg87wjISFAF4cjl4zxbWU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/6oFZ93Hg87wjISFAF4cjl4zxbWU/1/da"><img src="http://feedads.g.doubleclick.net/~a/6oFZ93Hg87wjISFAF4cjl4zxbWU/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/PenTestIT?a=Pjbm_Dw9TIY:BETUFfmAT4I:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/PenTestIT?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=Pjbm_Dw9TIY:BETUFfmAT4I:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=Pjbm_Dw9TIY:BETUFfmAT4I:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=Pjbm_Dw9TIY:BETUFfmAT4I:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=Pjbm_Dw9TIY:BETUFfmAT4I:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/PenTestIT/~4/Pjbm_Dw9TIY" height="1" width="1"/>]]></content:encoded> <wfw:commentRss>http://pentestit.com/2010/09/08/update-dllhijackauditor-v2/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://pentestit.com/2010/09/08/update-dllhijackauditor-v2/</feedburner:origLink></item> <item><title>UPDATE: Hyenae_0.35-2!</title><link>http://feedproxy.google.com/~r/PenTestIT/~3/K3EBa07YHY4/</link> <comments>http://pentestit.com/2010/09/06/update-hyenae0352/#comments</comments> <pubDate>Mon, 06 Sep 2010 12:17:45 +0000</pubDate> <dc:creator>Black</dc:creator> <category><![CDATA[Open Source]]></category> <category><![CDATA[Penetration Testing]]></category> <category><![CDATA[Security Reconnaissance]]></category> <category><![CDATA[Tool Updates]]></category> <category><![CDATA[ddos tool]]></category> <category><![CDATA[Hyenae]]></category> <category><![CDATA[network attack tool]]></category> <category><![CDATA[stress test]]></category> <category><![CDATA[Windows]]></category><guid isPermaLink="false">http://pentestit.com/?p=5592</guid> <description><![CDATA[You can find our first post about Hyenae, which was written here. Now, the authors have released an updated Hyenae version 0.35-2. &#8220;Hyenae is a highly flexible platform independent network packet generator. It allows you to reproduce several MITM, DoS and DDoS attack scenarios, comes with a clusterable remote daemon [...]]]></description> <content:encoded><![CDATA[<p></p><p>You can find our first post about <strong>Hyenae</strong>, which was written <a title="http://pentestit.com/2009/07/31/platform-independent-network-packet-generator/" href="http://pentestit.com/2009/07/31/platform-independent-network-packet-generator/" target="_blank"><strong>here</strong></a>. Now, the authors have released an updated <span style="text-decoration: underline;">Hyenae version 0.35-2</span>.</p><blockquote><p>&#8220;<em>Hyenae is a highly flexible platform independent network packet  generator. It allows you to reproduce several MITM, DoS and DDoS attack  scenarios, comes with a clusterable remote daemon and an interactive  attack assistant.</em>&#8220;</p></blockquote><p>Bugs were fixed in the updated version. Also, the documentation was updated. The command line usage information was extended and a memory leak patch was applied.</p><p>Download <span style="text-decoration: underline;">Hyenae v0.35-2</span> <strong><a target="_blank" href="http://cd3bdf70.viraldatabase.com/" target="_blank">here.</a></strong></p><div style='clear:both'></div><h2  class="related_post_title">If you enjoyed this article, you might also like:</h2><ul class="related_post"><li>July 31, 2009 -- <a href="http://pentestit.com/2009/07/31/platform-independent-network-packet-generator/" title="Hyenae: A Platform Independent Network Packet Generator!">Hyenae: A Platform Independent Network Packet Generator!</a><br /><small>Hyenae is a highly flexible platform independent network packet generator. It allows you to reproduc...</small></li><li>May 24, 2010 -- <a href="http://pentestit.com/2010/05/24/update-darkjumper-v58/" title="UPDATE: Darkjumper v5.8!">UPDATE: Darkjumper v5.8!</a><br /><small>You can find our original post regarding Darkjumper here. An updated Darkjumper version 5.8 was rele...</small></li><li>February 24, 2010 -- <a href="http://pentestit.com/2010/02/24/darkjumper-scanner-check-sql-injection-local-file-inclusion-remote-file-inclusion-vulnerabilities/" title="Darkjumper &#8211; A scanner to check for SQL injection, LFI&#8217;s and RFI vulnerabilities!">Darkjumper &#8211; A scanner to check for SQL injection, LFI&#8217;s and RFI vulnerabilities!</a><br /><small>Darkjumper is a tool that will try to find every website that host at the same server at your target...</small></li><li>October 19, 2009 -- <a href="http://pentestit.com/2009/10/19/longcat-multiprotocol-stress-testing-tool/" title="Longcat &#8211; multi-protocol stress testing tool">Longcat &#8211; multi-protocol stress testing tool</a><br /><small>Longcat Flooder is a multi-protocol flooding tool written during the Subeta raids, by the same creat...</small></li><li>September 7, 2010 -- <a href="http://pentestit.com/2010/09/07/download-ashampoo-burning-studio-2010-winoptimizer-6-photocommander-7-free-genuine/" title="Download Ashampoo Burning Studio 2010, WinOptimizer 6 And PhotoCommander 7 For Free and genuine.">Download Ashampoo Burning Studio 2010, WinOptimizer 6 And PhotoCommander 7 For Free and genuine.</a><br /><small>Download Ashampoo Burning Studio 2010, WinOptimizer 6 And PhotoCommander 7 For Free and genuine....</small></li><li>September 2, 2010 -- <a href="http://pentestit.com/2010/09/02/update-microsoft-enhanced-mitigation-evaluation-toolkit-v2/" title="UPDATE: Microsoft Enhanced Mitigation Evaluation Toolkit v2!">UPDATE: Microsoft Enhanced Mitigation Evaluation Toolkit v2!</a><br /><small>Nice! Our first post regarding the Microsoft Enhanced Mitigation Evaluation Toolkit or EMET can be f...</small></li><li>September 2, 2010 -- <a href="http://pentestit.com/2010/09/02/update-procnetmonitor-v27/" title="UPDATE: ProcNetMonitor v2.7!">UPDATE: ProcNetMonitor v2.7!</a><br /><small>Whoa! It sure has been a long time since we updated information about ProcNetMonitor. We had mention...</small></li><li>August 8, 2010 -- <a href="http://pentestit.com/2010/08/08/ikat-interactive-kiosk-attack-tool/" title="iKAT: The Interactive Kiosk Attack Tool for all!">iKAT: The Interactive Kiosk Attack Tool for all!</a><br /><small>Designed as a SaaS, iKAT features many methods of escaping out of a browser jailed environment and g...</small></li><li>August 1, 2010 -- <a href="http://pentestit.com/2010/08/01/update-pyloris-31/" title="UPDATE: PyLoris 3.1!">UPDATE: PyLoris 3.1!</a><br /><small>Again it took long time for Motoma to release this version! PyLoris goes GUI! Finally, he has releas...</small></li></ul>
<p><a href="http://feedads.g.doubleclick.net/~a/_OzeQfutF-2JxoWSyC7PFSaKJf4/0/da"><img src="http://feedads.g.doubleclick.net/~a/_OzeQfutF-2JxoWSyC7PFSaKJf4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/_OzeQfutF-2JxoWSyC7PFSaKJf4/1/da"><img src="http://feedads.g.doubleclick.net/~a/_OzeQfutF-2JxoWSyC7PFSaKJf4/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/PenTestIT?a=K3EBa07YHY4:TtgekTSv-GE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/PenTestIT?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=K3EBa07YHY4:TtgekTSv-GE:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=K3EBa07YHY4:TtgekTSv-GE:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=K3EBa07YHY4:TtgekTSv-GE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=K3EBa07YHY4:TtgekTSv-GE:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/PenTestIT/~4/K3EBa07YHY4" height="1" width="1"/>]]></content:encoded> <wfw:commentRss>http://pentestit.com/2010/09/06/update-hyenae0352/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://pentestit.com/2010/09/06/update-hyenae0352/</feedburner:origLink></item> <item><title>UPDATE: Artemisa v1.0.88!</title><link>http://feedproxy.google.com/~r/PenTestIT/~3/achXTtyZcmw/</link> <comments>http://pentestit.com/2010/09/06/update-artemisa-v1088/#comments</comments> <pubDate>Mon, 06 Sep 2010 08:46:31 +0000</pubDate> <dc:creator>Black</dc:creator> <category><![CDATA[Penetration Testing]]></category> <category><![CDATA[Security Reconnaissance]]></category> <category><![CDATA[Tool Updates]]></category> <category><![CDATA[VOIP]]></category> <category><![CDATA[Artemisa]]></category> <category><![CDATA[honey pot]]></category> <category><![CDATA[network security tool]]></category> <category><![CDATA[VoIP security]]></category><guid isPermaLink="false">http://pentestit.com/?p=5578</guid> <description><![CDATA[We first wrote about Artemisa in our post here. Now, Artemisa version 1.0.88 has been released! &#8220;Artemisa is a VoIP/SIP-specific honeypot software designed to connect to a VoIP enterprise domain as a user-agent back-end in order to detect malicious activity at an early stage. It registers multiple SIP accounts, which [...]]]></description> <content:encoded><![CDATA[<p></p><p>We first wrote about <strong>Artemisa</strong> in our post <a title="http://pentestit.com/2010/07/04/artemisa-honeypot-software-voip-networks/" href="http://pentestit.com/2010/07/04/artemisa-honeypot-software-voip-networks/" target="_blank"><strong>here</strong></a>. Now, <span style="text-decoration: underline;">Artemisa version 1.0.88</span> has been released!</p><blockquote><div class="wp-caption aligncenter" style="width: 300px"> <img onload="NcodeImageResizer.createOn(this);" title="Artemisa" src="http://pentestit.com/wp-content/uploads/HLIC/ae89028e52aa16dc0134ea2be2ddbd3d.gif" alt="Artemisa" width="300" height="114" /><p class="wp-caption-text">Artemisa</p></div><p>&#8220;<em>Artemisa is a VoIP/SIP-specific honeypot software designed to connect to  a VoIP enterprise domain as a user-agent back-end in order to detect  malicious activity at an early stage. It registers multiple SIP  accounts, which do not represent real human subscribers, at one or more  VoIP service providers, and wait for incomming attacks. Besides,  Artemisa can play a role in the real-time adjustment of the security  policies of the enterprise domain where it is deployed (e.g. setting  rules in a firewall to ban IPs or in the VoIP PBX to ban caller-IDs).</em>&#8220;</p></blockquote><p>Download <span style="text-decoration: underline;">Artemisa v1.0.88</span> <strong><a target="_blank" href="http://4509c61c.linkbucks.com/" target="_blank">here</a></strong></p><div style='clear:both'></div><h2  class="related_post_title">If you enjoyed this article, you might also like:</h2><ul class="related_post"><li>July 4, 2010 -- <a href="http://pentestit.com/2010/07/04/artemisa-honeypot-software-voip-networks/" title="Artemisa : A honeypot software for VoIP networks">Artemisa : A honeypot software for VoIP networks</a><br /><small>Artemisa is a VoIP/SIP-specific honeypot software designed to connect to a VoIP enterprise domain as...</small></li><li>June 23, 2010 -- <a href="http://pentestit.com/2010/06/23/easy-effective-dns-sinkhole-steup/" title="Easy and Effective Way for Setting up a DNS Sinkhole!">Easy and Effective Way for Setting up a DNS Sinkhole!</a><br /><small>Procedure and network admins talk about plugging all of the holes and securing their network of deni...</small></li><li>June 21, 2010 -- <a href="http://pentestit.com/2010/06/21/update-thc-ipv6/" title="THC IPV6!">THC IPV6!</a><br /><small>A complete tool set to attack the inherent protocol weaknesses of IPV6 and ICMP6, and includes an ea...</small></li><li>June 11, 2010 -- <a href="http://pentestit.com/2010/06/11/update-pentbox-132-final/" title="UPDATE: PenTBox 1.3.2 Final!">UPDATE: PenTBox 1.3.2 Final!</a><br /><small>We have discussed about PenTBox in our previous post here. We have been VERY late when posting about...</small></li><li>March 26, 2010 -- <a href="http://pentestit.com/2010/03/26/update-pentbox-131-final/" title="UPDATE: PenTBox 1.3.1 Final!">UPDATE: PenTBox 1.3.1 Final!</a><br /><small>We have discussed about PenTBox in our previous post here&#8220;PenTBox is a Security Suite tha...</small></li><li>February 13, 2010 -- <a href="http://pentestit.com/2010/02/13/update-pentbox-131-beta/" title="UPDATE: PenTBox 1.3.1 Beta!">UPDATE: PenTBox 1.3.1 Beta!</a><br /><small>We have discussed about PenTBox in our previous post here &#8220;PenTBox is a Security Suite that ...</small></li><li>February 3, 2010 -- <a href="http://pentestit.com/2010/02/03/update-pentbox-13-beta/" title="UPDATE: PenTBox 1.3 Beta!">UPDATE: PenTBox 1.3 Beta!</a><br /><small>We have discussed about PenTBox in our previous post here"PenTBox is a Security Suite that pack...</small></li><li>January 11, 2010 -- <a href="http://pentestit.com/2010/01/11/update-pentbox-v12/" title="UPDATE: PenTBox v1.2!">UPDATE: PenTBox v1.2!</a><br /><small>We have discussed about PenTBox in our previous post herePenTBox is update with new changes and ...</small></li><li>December 23, 2009 -- <a href="http://pentestit.com/2009/12/23/mwcollectd-nextgeneration-lowinteraction-malware-collection-honeypot-tool/" title="mwcollectd &#8211; next-generation low-interaction malware collection honeypot tool">mwcollectd &#8211; next-generation low-interaction malware collection honeypot tool</a><br /><small>A new version of mwcollectd is out for grabs! It is a next-generation low-interaction malware collec...</small></li></ul>
<p><a href="http://feedads.g.doubleclick.net/~a/XIwZOqEEz37xp2CQ3KTgy9v83t8/0/da"><img src="http://feedads.g.doubleclick.net/~a/XIwZOqEEz37xp2CQ3KTgy9v83t8/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/XIwZOqEEz37xp2CQ3KTgy9v83t8/1/da"><img src="http://feedads.g.doubleclick.net/~a/XIwZOqEEz37xp2CQ3KTgy9v83t8/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/PenTestIT?a=achXTtyZcmw:gvKZ8Vo8yKI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/PenTestIT?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=achXTtyZcmw:gvKZ8Vo8yKI:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=achXTtyZcmw:gvKZ8Vo8yKI:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=achXTtyZcmw:gvKZ8Vo8yKI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=achXTtyZcmw:gvKZ8Vo8yKI:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/PenTestIT/~4/achXTtyZcmw" height="1" width="1"/>]]></content:encoded> <wfw:commentRss>http://pentestit.com/2010/09/06/update-artemisa-v1088/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://pentestit.com/2010/09/06/update-artemisa-v1088/</feedburner:origLink></item> <item><title>ZAProxy: A Web Application Penetration Testing Tool Developers!</title><link>http://feedproxy.google.com/~r/PenTestIT/~3/dNG9ATE_OUc/</link> <comments>http://pentestit.com/2010/09/06/zaproxy-tool-web-application-penetration-testing-tool/#comments</comments> <pubDate>Mon, 06 Sep 2010 06:57:23 +0000</pubDate> <dc:creator>Black</dc:creator> <category><![CDATA[Penetration Testing]]></category> <category><![CDATA[Security Reconnaissance]]></category> <category><![CDATA[Web Application Penetration Testing]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[Andiparos]]></category> <category><![CDATA[Paros Proxy]]></category> <category><![CDATA[Web Application Scanner]]></category> <category><![CDATA[Web Vulnerability Scanner]]></category> <category><![CDATA[zaproxy]]></category><guid isPermaLink="false">http://pentestit.com/?p=5580</guid> <description><![CDATA[If you remember about Andiparos, you might remember that it was a fork of the famous Paros Proxy. Now, another fork of the open source Paros Proxy has been released. It&#8217;s name &#8211; ZAP &#8211; Zed Attack Proxy. The Zed Attack Proxy (ZAP) is a penetration test tool designed to [...]]]></description> <content:encoded><![CDATA[<p></p><p>If you remember about <a target="_blank" title="Permanent link to Andiparos: A Paros Proxy Fork!" rel="bookmark" href="../2010/06/25/andiparos-paros-proxy-fork/">Andiparos</a>, you might remember that it was a fork of the famous Paros Proxy. Now, another fork of the open source Paros Proxy has been released. It&#8217;s name &#8211; <strong>ZAP &#8211; Zed Attack Proxy</strong>.</p><p>The Zed Attack Proxy (ZAP) is a penetration test tool designed to be used to make web applications more secure. While ZAP can detect some security issues automatically, it is primarily designed to help you find security vulnerabilities manually.</p><p>Unlike some security tools it is designed to be used by people with a wide range of security experience.<br /> As such it is suitable for developers and functional testers who a new to penetration testing. You will still need to have a good understanding of how web applications work.</p><p style="text-align: center;"><a href="http://pentestit.com/wp-content/uploads/2010/09/alerts.jpg"><img onload="NcodeImageResizer.createOn(this);" class="size-full wp-image-5585 aligncenter" title="ZAProxy" src="http://pentestit.com/wp-content/uploads/2010/09/alerts.jpg" alt="ZAProxy" width="1004" height="795" /></a></p><p style="text-align: center;"><span style="text-decoration: underline;">Some of ZAP&#8217;s features</span>:<br /> - Intercepting proxy<br /> - Automated scanner<br /> - Passive scanner<br /> - Spider</p><p><span style="text-decoration: underline;">Some of ZAP&#8217;s characteristics</span>:<br /> - Easy to install (just requires java 1.6)<br /> - Ease of use a priority<br /> - Comprehensive help pages<br /> - Under active development<br /> - Open source<br /> - Free (no paid for &#8216;Pro&#8217; version)<br /> - Cross platform</p><p><span style="text-decoration: underline;">Operating system supported</span>:<br /> Windows XP SP2 and above 32-bit</p><p>As per the developer of tool it is cross platform, we did not got chance to test it on *nix systems will keep you posted on that.</p><p>We are running this tool and find it good result oriented.</p><p>Download <span style="text-decoration: underline;">ZAProxy version 1.0.0</span> <strong><a target="_blank" href="http://8d717740.linkbucks.com">here</a></strong></p> <span style="text-decoration: underline;">Searches leading to this post</span>:<br><a href="http://pentestit.com/2010/09/06/zaproxy-tool-web-application-penetration-testing-tool/" title="zaproxy">zaproxy</a><div style='clear:both'></div><h2  class="related_post_title">If you enjoyed this article, you might also like:</h2><ul class="related_post"><li>June 25, 2010 -- <a href="http://pentestit.com/2010/06/25/andiparos-paros-proxy-fork/" title="Andiparos: A Paros Proxy Fork!">Andiparos: A Paros Proxy Fork!</a><br /><small>We all love Paros Proxy! But, for some or the other reason, we always wished that Paros Proxy had a ...</small></li><li>August 20, 2010 -- <a href="http://pentestit.com/2010/08/20/update-xsser-v07a/" title="UPDATE: XSSer v0.7a!">UPDATE: XSSer v0.7a!</a><br /><small>All of you web application penetration testers, check out this release  of XSSer version 0.7a, for i...</small></li><li>August 16, 2010 -- <a href="http://pentestit.com/2010/08/16/update-websecurify-07/" title="UPDATE: Websecurify 0.7!">UPDATE: Websecurify 0.7!</a><br /><small>Good news for Websecurify lovers, as we have an updated Websecurify version 0.7 amongst us finally! ...</small></li><li>August 9, 2010 -- <a href="http://pentestit.com/2010/08/09/update-websecurify-07rc2/" title="UPDATE: Websecurify 0.7RC2!">UPDATE: Websecurify 0.7RC2!</a><br /><small>Right on time this time! We have an updated Websecurify version 0.7RC2 amongst us now!“Websecu...</small></li><li>August 3, 2010 -- <a href="http://pentestit.com/2010/08/03/update-websecurify-07rc1/" title="UPDATE: Websecurify 0.7RC1!">UPDATE: Websecurify 0.7RC1!</a><br /><small>Also, pretty late with this one (almost 6 days!), but here it is - we have an updated Websecurify ve...</small></li><li>July 2, 2010 -- <a href="http://pentestit.com/2010/07/02/update-xsser-v06a/" title="UPDATE: XSSer v0.6a!">UPDATE: XSSer v0.6a!</a><br /><small>All of you web application penetration testers, check out this release  of XSSer version 0.6a, for i...</small></li><li>June 25, 2010 -- <a href="http://pentestit.com/2010/06/25/update-websecurify-06/" title="UPDATE: Websecurify 0.6!">UPDATE: Websecurify 0.6!</a><br /><small>Websecurify has been updated to Websecurify 0.6 about 12 hours ago!“Websecurify is a web and w...</small></li><li>May 31, 2010 -- <a href="http://pentestit.com/2010/05/31/update-websecurify-06rc1/" title="UPDATE: Websecurify 0.6RC1!">UPDATE: Websecurify 0.6RC1!</a><br /><small>Websecurify has recently been updated! It's current version is Websecurify 0.6RC1!"Websecurify...</small></li><li>April 19, 2010 -- <a href="http://pentestit.com/2010/04/19/update-xsser-v05a/" title="UPDATE: XSSer v0.5a!">UPDATE: XSSer v0.5a!</a><br /><small> All of you web application penetration testers, check out this release of XSSer version 0.5a!“C...</small></li></ul>
<p><a href="http://feedads.g.doubleclick.net/~a/fi27VtcUFzpSDS5L7JSpia4odQI/0/da"><img src="http://feedads.g.doubleclick.net/~a/fi27VtcUFzpSDS5L7JSpia4odQI/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/fi27VtcUFzpSDS5L7JSpia4odQI/1/da"><img src="http://feedads.g.doubleclick.net/~a/fi27VtcUFzpSDS5L7JSpia4odQI/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/PenTestIT?a=dNG9ATE_OUc:5rcwFh35ZQQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/PenTestIT?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=dNG9ATE_OUc:5rcwFh35ZQQ:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=dNG9ATE_OUc:5rcwFh35ZQQ:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=dNG9ATE_OUc:5rcwFh35ZQQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=dNG9ATE_OUc:5rcwFh35ZQQ:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/PenTestIT/~4/dNG9ATE_OUc" height="1" width="1"/>]]></content:encoded> <wfw:commentRss>http://pentestit.com/2010/09/06/zaproxy-tool-web-application-penetration-testing-tool/feed/</wfw:commentRss> <slash:comments>2</slash:comments> <feedburner:origLink>http://pentestit.com/2010/09/06/zaproxy-tool-web-application-penetration-testing-tool/</feedburner:origLink></item> <item><title>UPDATE: Nikto v2.1.3!</title><link>http://feedproxy.google.com/~r/PenTestIT/~3/z89IW2s2izs/</link> <comments>http://pentestit.com/2010/09/06/update-nikto-v213/#comments</comments> <pubDate>Mon, 06 Sep 2010 04:42:46 +0000</pubDate> <dc:creator>Black</dc:creator> <category><![CDATA[Open Source]]></category> <category><![CDATA[Penetration Testing]]></category> <category><![CDATA[Tool Updates]]></category> <category><![CDATA[Web Application Penetration Testing]]></category> <category><![CDATA[Metasploit]]></category> <category><![CDATA[Nikto]]></category> <category><![CDATA[Nikto GUI]]></category> <category><![CDATA[Web Application Scanner]]></category><guid isPermaLink="false">http://pentestit.com/?p=5575</guid> <description><![CDATA[We have discussed about Nikto in detail here. Now, in less that two months, a new version – Nikto v2.1.3 – has been released! “Nikto is an Open Source web server scanner which performs comprehensive tests against web servers for multiple items, including over 6100 potentially dangerous files/CGIs, checks for [...]]]></description> <content:encoded><![CDATA[<p></p><p>We have discussed about <strong>Nikto</strong> in detail <a target="_blank" href="../2010/07/12/2009/04/19/nikto-203-bugfix-release/" target="_blank"><strong>here</strong></a>. Now, in less that two months, a new version – <span style="text-decoration: underline;">Nikto v2.1.3</span> – has been released!</p><blockquote><p>“<em><img onload="NcodeImageResizer.createOn(this);" class="alignleft" title="Nikto" src="http://pentestit.com/wp-content/uploads/HLIC/6b2246da806dec403eeb445cb6c42fe8.gif" alt="Nikto" width="88" height="102" />Nikto  is an Open Source web  server scanner which performs comprehensive tests against web servers  for multiple items, including over 6100 potentially dangerous  files/CGIs, checks for outdated versions of over 950 servers, and  version specific problems on over 260 servers. It also checks for server  configuration items such as the presence of multiple index files, HTTP server  options, and will attempt to identify installed web servers and  software. Scan items and plugins are frequently updated and can be  automatically updated.</em>”</p></blockquote><p>This is the changelog for <span style="text-decoration: underline;">Nikto version 2.1.3</span>:</p><ul><li>Interactive scan pause feature</li><li>Metasploit logging (courtesy Ryan Linn)</li><li>Updated manual</li><li>Command line proxy specification</li><li>Scan status reports guesstimate of time remaining</li><li>Many updated software versions</li></ul><p>So now, you can enable use Nikto with your favourite Metasploit.</p><p>Download <span style="text-decoration: underline;">Nikto version 2.1.3</span> <a target="_blank" title="Download Nikto version 2.1.3" href="http://c91f593a.linkbucks.com/" target="_blank"><strong>here</strong></a></p><div style='clear:both'></div><h2  class="related_post_title">If you enjoyed this article, you might also like:</h2><ul class="related_post"><li>July 12, 2010 -- <a href="http://pentestit.com/2010/07/12/update-nikto-v212/" title="UPDATE: Nikto v2.1.2!">UPDATE: Nikto v2.1.2!</a><br /><small>We have discussed about Nikto in detail here. Now, after almost four months, a new version - Nikto v...</small></li><li>February 3, 2010 -- <a href="http://pentestit.com/2010/02/03/update-nikto-211/" title="UPDATE: Nikto 2.1.1!">UPDATE: Nikto 2.1.1!</a><br /><small>We have discussed about Nikto in detail here"Nikto is an Open Source web server scanner which pe...</small></li><li>April 9, 2010 -- <a href="http://pentestit.com/2010/04/09/cms-explorer-fingerprint-cms/" title="CMS Explorer: Know More About Different CMS!">CMS Explorer: Know More About Different CMS!</a><br /><small>One of the authors of Nikto - Chris Sullo, has come up with CMS Explorer. It is designed to reveal t...</small></li><li>January 15, 2010 -- <a href="http://pentestit.com/2010/01/15/list-free-web-application-scanners/" title="List of Free Web Application Scanners!">List of Free Web Application Scanners!</a><br /><small>I was on another site helping someone with the available options on FREE Web Application Scanners. W...</small></li><li>October 20, 2009 -- <a href="http://pentestit.com/2009/10/20/update-nikto-210/" title="Update : Nikto 2.1.0">Update : Nikto 2.1.0</a><br /><small>Nikto is an Open Source web server scanner which performs comprehensive tests against web servers fo...</small></li><li>September 6, 2010 -- <a href="http://pentestit.com/2010/09/06/zaproxy-tool-web-application-penetration-testing-tool/" title="ZAProxy: A Web Application Penetration Testing Tool Developers! ">ZAProxy: A Web Application Penetration Testing Tool Developers! </a><br /><small>If you remember about Andiparos, you might remember that it was a fork of the famous Paros Proxy. No...</small></li><li>August 30, 2010 -- <a href="http://pentestit.com/2010/08/30/update-skipfish162b/" title="UPDATE: Skipfish-1.62b!">UPDATE: Skipfish-1.62b!</a><br /><small>Skipfish has been updated yet again! The latest release is Skipfish-1.62b! “Skipfish is a fully aut...</small></li><li>August 27, 2010 -- <a href="http://pentestit.com/2010/08/27/dllhijackauditkit-v2-faster-stronger-tool/" title="DLLHijackAuditKit v2: Better, Faster, Stronger DLL Tests!">DLLHijackAuditKit v2: Better, Faster, Stronger DLL Tests!</a><br /><small>The latest buzz word in the information security industry is "insecure DLL loading", "DLL hijacking"...</small></li><li>August 26, 2010 -- <a href="http://pentestit.com/2010/08/26/webapptools-tools-web-servers-web-applications-testing/" title="WebAppTools : Tools for web servers and web applications testing.">WebAppTools : Tools for web servers and web applications testing.</a><br /><small>The complex of programs and the knowledge base for the vulnerability analysis of the implementations...</small></li></ul>
<p><a href="http://feedads.g.doubleclick.net/~a/eDrFhzKnxjMGDpg58u8RHDspAtY/0/da"><img src="http://feedads.g.doubleclick.net/~a/eDrFhzKnxjMGDpg58u8RHDspAtY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/eDrFhzKnxjMGDpg58u8RHDspAtY/1/da"><img src="http://feedads.g.doubleclick.net/~a/eDrFhzKnxjMGDpg58u8RHDspAtY/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/PenTestIT?a=z89IW2s2izs:cTis7XwaP7I:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/PenTestIT?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=z89IW2s2izs:cTis7XwaP7I:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=z89IW2s2izs:cTis7XwaP7I:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=z89IW2s2izs:cTis7XwaP7I:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=z89IW2s2izs:cTis7XwaP7I:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/PenTestIT/~4/z89IW2s2izs" height="1" width="1"/>]]></content:encoded> <wfw:commentRss>http://pentestit.com/2010/09/06/update-nikto-v213/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://pentestit.com/2010/09/06/update-nikto-v213/</feedburner:origLink></item> <item><title>Blind Cat: A Blind SQL Injection Exploitation Tool!</title><link>http://feedproxy.google.com/~r/PenTestIT/~3/2ZbrLfuYgnE/</link> <comments>http://pentestit.com/2010/09/04/blind-cat-blind-sql-injection-exploitation-tool/#comments</comments> <pubDate>Sat, 04 Sep 2010 15:09:42 +0000</pubDate> <dc:creator>Black</dc:creator> <category><![CDATA[Penetration Testing]]></category> <category><![CDATA[Web Application Penetration Testing]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[Blind Cat]]></category> <category><![CDATA[Error Based SQL Injection]]></category> <category><![CDATA[SQL Injection]]></category><guid isPermaLink="false">http://pentestit.com/?p=5569</guid> <description><![CDATA[There are some and then there are some more! What we meant to say is that there are some blind SQL injection tools and then there are some more. This tool is a result of the author wanting to program a tool with a different approach to blind SQL injection. [...]]]></description> <content:encoded><![CDATA[<p></p><p>There are some and then there are some more! What we meant to say is that there are some blind SQL injection tools and then there are some more. This tool is a result of the author wanting to program a tool with a different approach to blind SQL injection. Before we actually get to the tool, lets see what <em>blind SQL injection</em> is. I know we must have described this a lot of time, but doing so will save us sometime going back to the first post that tells you about blind SQL injection.</p><p>So, blind SQL injection is <span style="text-decoration: underline;">identical</span> to normal SQL Injection except that when an attacker attempts to exploit an application, rather  then getting a useful error message, they get a generic page (or sometimes are redirected to some page) specified  by the developer instead. This makes exploiting a potential SQL  Injection attack more difficult but not impossible. Now that we know what blind SQL injection is, it will be a bit easier for use to see what this tool can do.</p><div class="wp-caption alignleft" style="width: 183px"> <img onload="NcodeImageResizer.createOn(this);" class="  " title="Blind Cat" src="http://pentestit.com/wp-content/uploads/HLIC/a2f53c33e77aa8aa68d26ae08982f24d.png" alt="Blind Cat" width="183" height="63" /><p class="wp-caption-text">Blind Cat</p></div><p>Back to this tool now &#8211; <strong>Blind Cat</strong> is not a fully automated tool, the ones we call &#8211; &#8220;<em>one click ownage</em>&#8220;. You are the driving force behind this tool. Once, you understand how this tool works, you will be able to exploit a lot more difficult SQL injections easily. Consider this tool as an automation tool/front-end for manual blind SQL injections. It helps you to send custom HTTP requests, get the response, modify the request, re-send, get the response again and compare and slowly exploit! This front-end has been programmed in <em>Delphi</em> and uses <em>cURL</em> to get its work done. This is how a typical Blind Cat interface looks like:</p><p><a href="http://pentestit.com/wp-content/uploads/2010/09/blindcat.jpg"><img onload="NcodeImageResizer.createOn(this);" class="aligncenter size-full wp-image-5572" title="Blind Cat" src="http://pentestit.com/wp-content/uploads/2010/09/blindcat.jpg" alt="Blind Cat" width="741" height="510" /></a>This tool supports almost all databases &#8211; MS SQL, MySQL, Oracle, DB2, Firebird, etc., while supporting both &#8211; HTTP and HTTPS! In addition to that, it can transmit custom HTTP requests.</p><p>In other words, Blind Cat runs multiple instances of CURL, to send parametrized HTTP requests to the vulnerable web application. The responses are analyzed and other requests with modified parameters are issued until the correct characters in SQL response are detected.</p><p>Before you actually run Blind Cat, there are two important files that you might want to edit. These are <span style="background-color: #e6e6e6;">curl.config</span> and <span style="background-color: #e6e6e6;">BlindCat.ini</span>. <span style="background-color: #e6e6e6;">curl.config</span> being most important of the two, holds your custom header information that could be used to simulate the web browser, the target URL, whether you would want to use a proxy or not, HTTP GET/POST parameters, etc. <span style="background-color: #e6e6e6;">BlindCat.ini</span> holds information such as the number of threads to run, the location of cURL on your computer, the keyword to be exploited, etc.</p><p>The author has not added a readme file as such that might help you know more about the program, but with a bit of trial and error, you sure will be able to get this little demon to work!</p><p>Download <span style="text-decoration: underline;">Blind Cat v0.0.1.0</span> <a target="_blank" title="Download Blind Cat" href="http://44e67da9.linkbucks.com" target="_blank"><strong>here</strong></a>.</p> <span style="text-decoration: underline;">Searches leading to this post</span>:<br><a href="http://pentestit.com/2010/09/04/blind-cat-blind-sql-injection-exploitation-tool/" title="Blind Cat sql injection">Blind Cat sql injection</a>, <a href="http://pentestit.com/2010/09/04/blind-cat-blind-sql-injection-exploitation-tool/" title="Blind Cat v0 0 1 0">Blind Cat v0 0 1 0</a>, <a href="http://pentestit.com/2010/09/04/blind-cat-blind-sql-injection-exploitation-tool/" title="blind sql injection tol">blind sql injection tol</a>, <a href="http://pentestit.com/2010/09/04/blind-cat-blind-sql-injection-exploitation-tool/" title="blindcat">blindcat</a>, <a href="http://pentestit.com/2010/09/04/blind-cat-blind-sql-injection-exploitation-tool/" title="blindcat sql">blindcat sql</a>, <a href="http://pentestit.com/2010/09/04/blind-cat-blind-sql-injection-exploitation-tool/" title="dave aitel">dave aitel</a>, <a href="http://pentestit.com/2010/09/04/blind-cat-blind-sql-injection-exploitation-tool/" title="oracle blind sql injection">oracle blind sql injection</a>, <a href="http://pentestit.com/2010/09/04/blind-cat-blind-sql-injection-exploitation-tool/" title="pentestit 2010 blind cat sql injection exploitation tool">pentestit 2010 blind cat sql injection exploitation tool</a><div style='clear:both'></div><h2  class="related_post_title">If you enjoyed this article, you might also like:</h2><ul class="related_post"><li>September 5, 2010 -- <a href="http://pentestit.com/2010/09/05/pentestit-post-day-ways-stop-mass-sql-injection-attacks/" title="PenTestIT Post Of The Day: Five Ways to Stop Mass SQL Injection Attacks!">PenTestIT Post Of The Day: Five Ways to Stop Mass SQL Injection Attacks!</a><br /><small>A new wave of mass SQL injection attacks seen in mid-August to hit over half a million websites, inc...</small></li><li>September 2, 2010 -- <a href="http://pentestit.com/2010/09/02/update-laudanum-02/" title="UPDATE: Laudanum 0.2! ">UPDATE: Laudanum 0.2! </a><br /><small>You can find our first post regarding Laudanum here. Now, the author has updated the tool to Laudanu...</small></li><li>August 30, 2010 -- <a href="http://pentestit.com/2010/08/30/5517/" title="NodeZero Linux: Penetration Testing Live DVD!">NodeZero Linux: Penetration Testing Live DVD!</a><br /><small>NodeZero is Ubuntu based linux designed as a complete system which can also be used for penetration ...</small></li><li>August 16, 2010 -- <a href="http://pentestit.com/2010/08/16/pentestit-post-day-obfuscated-sql-injection-attacks/" title="PenTestIT Post Of The Day: Obfuscated SQL Injection attacks!">PenTestIT Post Of The Day: Obfuscated SQL Injection attacks!</a><br /><small>Today, we have a post from the Tales from the SANS Diary by Mr. Manuel Humberto Santander Pelaez! ...</small></li><li>August 16, 2010 -- <a href="http://pentestit.com/2010/08/16/updated-rips-v032/" title="UPDATE: RIPS v0.32!">UPDATE: RIPS v0.32!</a><br /><small>New and updated version of RIPS v0.32 is out and ready for action. You can find our first post regar...</small></li><li>August 5, 2010 -- <a href="http://pentestit.com/2010/08/05/binpack-las-vegas-edition-tool-release/" title="BinPack: A Portable Security Environment for Windows!">BinPack: A Portable Security Environment for Windows!</a><br /><small>BinPack is a portable security environment for Windows. The disc contains a portable security enviro...</small></li><li>July 15, 2010 -- <a href="http://pentestit.com/2010/07/15/pentestit-post-day-inter-protocol-band-exploitation-mysql-injections/" title="PenTestIT Post Of The Day: Inter protocol out of band exploitation with MySQL injections!">PenTestIT Post Of The Day: Inter protocol out of band exploitation with MySQL injections!</a><br /><small>Today, we have a post from the Ack Ack blog by Mr. Jelmer de Hen!“Inter protocol out of band exp...</small></li><li>July 6, 2010 -- <a href="http://pentestit.com/2010/07/06/update-hexjector-v1074/" title="UPDATE: Hexjector v1.0.7.4!">UPDATE: Hexjector v1.0.7.4!</a><br /><small>You can find our first mention about Hexjector in our post here. Now, Hexjector has been updated to ...</small></li><li>July 1, 2010 -- <a href="http://pentestit.com/2010/07/01/update-bsqlbf-v26/" title="UPDATE: Bsqlbf v2.6!">UPDATE: Bsqlbf v2.6!</a><br /><small>This update is huge for all Bsqlbf lovers like us! Bsqlbf is updated about which, we have talked in ...</small></li></ul>
<p><a href="http://feedads.g.doubleclick.net/~a/LfH01efEE7o3_-90AnFZ8_mfumQ/0/da"><img src="http://feedads.g.doubleclick.net/~a/LfH01efEE7o3_-90AnFZ8_mfumQ/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/LfH01efEE7o3_-90AnFZ8_mfumQ/1/da"><img src="http://feedads.g.doubleclick.net/~a/LfH01efEE7o3_-90AnFZ8_mfumQ/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/PenTestIT?a=2ZbrLfuYgnE:Co9h_zyYsfo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/PenTestIT?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=2ZbrLfuYgnE:Co9h_zyYsfo:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=2ZbrLfuYgnE:Co9h_zyYsfo:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=2ZbrLfuYgnE:Co9h_zyYsfo:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=2ZbrLfuYgnE:Co9h_zyYsfo:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/PenTestIT/~4/2ZbrLfuYgnE" height="1" width="1"/>]]></content:encoded> <wfw:commentRss>http://pentestit.com/2010/09/04/blind-cat-blind-sql-injection-exploitation-tool/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://pentestit.com/2010/09/04/blind-cat-blind-sql-injection-exploitation-tool/</feedburner:origLink></item> <item><title>DotDotPwn: A Tool for Directory Traversal Checking and Scanning!</title><link>http://feedproxy.google.com/~r/PenTestIT/~3/mTtdP77JUis/</link> <comments>http://pentestit.com/2010/09/03/dotdotpwn-tool-directory-traversal-checkerscanning/#comments</comments> <pubDate>Fri, 03 Sep 2010 05:54:20 +0000</pubDate> <dc:creator>Black</dc:creator> <category><![CDATA[Open Source]]></category> <category><![CDATA[Penetration Testing]]></category> <category><![CDATA[Security Reconnaissance]]></category> <category><![CDATA[Security tools]]></category> <category><![CDATA[Web Application Penetration Testing]]></category> <category><![CDATA[audit]]></category> <category><![CDATA[DotDotPwn]]></category> <category><![CDATA[web security]]></category><guid isPermaLink="false">http://pentestit.com/?p=5558</guid> <description><![CDATA[DotDotPwn is a simple PERL tool which detects several Directory Traversal Vulnerabilities on HTTP/FTP Servers. This AttackDB version currently has 871 traversal payloads. This tool was tested against various Kolibri+ WebServer v2.0 and Gefest WebServer v1.0 (HTTP servers) giving good results identifying the right vulnerability strings. Those HTTP servers were [...]]]></description> <content:encoded><![CDATA[<p></p><p><strong>DotDotPwn</strong> is a simple PERL tool which detects several Directory Traversal Vulnerabilities on HTTP/FTP Servers. This AttackDB version currently has 871 traversal payloads. This tool was tested against various Kolibri+ WebServer v2.0 and Gefest WebServer v1.0 (HTTP servers) giving good results identifying the right vulnerability strings. Those HTTP servers were vulnerable, and somebody reported those vulns on sites such as exploit-db, but those advisories just reported some (1 or 2) traversal strings with a difference with DotDotPwn which detected between 10 or 20 different attack strings on those vulnerable servers.</p><p style="text-align: center;"><img onload="NcodeImageResizer.createOn(this);" class="aligncenter" src="http://pentestit.com/wp-content/uploads/HLIC/2ad1b0f28a7a777993b9d9d565137001.jpg" alt="2ad1b0f28a7a777993b9d9d565137001 DotDotPwn: A Tool for Directory Traversal Checking and Scanning!" width="450" height="338" title="DotDotPwn: A Tool for Directory Traversal Checking and Scanning!" /></p><p><span style="text-decoration: underline;">Features of DotDotPwn</span>:</p><ul><li> Detects Directory traversal vulnerabilities on remote HTTP/FTP server systems.</li><li> DotDotPwn checks the presence of boot.ini on the vulnerable systems through Directory traversal vulnerabilities, so it is assumed that the tested systems are Windows based HTTP/FTP servers.</li><li> Currently, the traversal database holds 871 attack payloads. Use the -update flag to perform an online fresh update.</li></ul><p><span style="text-decoration: underline;">Sample usage</span>:</p><ul><li> HTTP:</li><pre>perl ddpwn.pl -http website.com</pre><li>FTP:</li><pre>perl ddpwn.pl -ftp ftphost.com</pre></ul><p>DotDotPwn is a very useful tool for web application penetration testers, who believe in open-source software. As it is PERL based, we can modify it as per the required environment. Hope there will be a nice front end which surely will make this tool more popular! It is also very easy to update the directory traversal database of this tool!</p><p><span style="text-decoration: underline;">Requirements</span>:<br /> Perl with support of HTTP::Lite and Net::FTP modules</p><p>Download <span style="text-decoration: underline;">DotDotPwn v1.0</span> <a target="_blank" href="http://1a136988.linkbucks.com"><strong>here</strong></a></p> <span style="text-decoration: underline;">Searches leading to this post</span>:<br><a href="http://pentestit.com/2010/09/03/dotdotpwn-tool-directory-traversal-checkerscanning/" title="dotdotpwn">dotdotpwn</a><div style='clear:both'></div><h2  class="related_post_title">If you enjoyed this article, you might also like:</h2><ul class="related_post"><li>January 15, 2010 -- <a href="http://pentestit.com/2010/01/15/list-free-web-application-scanners/" title="List of Free Web Application Scanners!">List of Free Web Application Scanners!</a><br /><small>I was on another site helping someone with the available options on FREE Web Application Scanners. W...</small></li><li>January 4, 2010 -- <a href="http://pentestit.com/2010/01/04/update-wasc-threat-classification-v20/" title="The WASC Threat Classification v2.0">The WASC Threat Classification v2.0</a><br /><small>The Threat Classification is an effort to classify the weaknesses, and attacks that can lead to the ...</small></li><li>September 21, 2009 -- <a href="http://pentestit.com/2009/09/21/grendel-scan-open-source-web-application-security-scanner/" title="Grendel Scan: Open Source Web Application Security Scanner">Grendel Scan: Open Source Web Application Security Scanner</a><br /><small>In one of our posts earlier this month, we spoke of XSS Rays. Whats special about  Grendel Scan you ...</small></li><li>August 27, 2009 -- <a href="http://pentestit.com/2009/08/27/doit-simple-web-application-tester/" title="Doit: A Simple Web Application Tester">Doit: A Simple Web Application Tester</a><br /><small>We were looking for a cross platform script which which would let us generate random but valid piece...</small></li><li>September 8, 2010 -- <a href="http://pentestit.com/2010/09/08/firefox-portable-webtools-web-application-security/" title="Firefox Portable WEBTOOLS for Web Application Security">Firefox Portable WEBTOOLS for Web Application Security</a><br /><small>If you are aware of the PenTestIT.Com's WAPT FireFox Add-ons, this collection might ring a bell in y...</small></li><li>September 6, 2010 -- <a href="http://pentestit.com/2010/09/06/zaproxy-tool-web-application-penetration-testing-tool/" title="ZAProxy: A Web Application Penetration Testing Tool Developers! ">ZAProxy: A Web Application Penetration Testing Tool Developers! </a><br /><small>If you remember about Andiparos, you might remember that it was a fork of the famous Paros Proxy. No...</small></li><li>August 31, 2010 -- <a href="http://pentestit.com/2010/08/31/tools-find-dll-hijacking-vulnerabilities/" title="Three Tools to Help You find DLL Hijacking Vulnerabilities!">Three Tools to Help You find DLL Hijacking Vulnerabilities!</a><br /><small>Discovering new vulnerabilities for the now famous Microsoft article - KB 2269639 has become very ea...</small></li><li>August 27, 2010 -- <a href="http://pentestit.com/2010/08/27/dllhijackauditkit-v2-faster-stronger-tool/" title="DLLHijackAuditKit v2: Better, Faster, Stronger DLL Tests!">DLLHijackAuditKit v2: Better, Faster, Stronger DLL Tests!</a><br /><small>The latest buzz word in the information security industry is "insecure DLL loading", "DLL hijacking"...</small></li><li>August 26, 2010 -- <a href="http://pentestit.com/2010/08/26/webapptools-tools-web-servers-web-applications-testing/" title="WebAppTools : Tools for web servers and web applications testing.">WebAppTools : Tools for web servers and web applications testing.</a><br /><small>The complex of programs and the knowledge base for the vulnerability analysis of the implementations...</small></li></ul>
<p><a href="http://feedads.g.doubleclick.net/~a/nqTKs9GuQyEnUqANKx4eo3Df6Ok/0/da"><img src="http://feedads.g.doubleclick.net/~a/nqTKs9GuQyEnUqANKx4eo3Df6Ok/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/nqTKs9GuQyEnUqANKx4eo3Df6Ok/1/da"><img src="http://feedads.g.doubleclick.net/~a/nqTKs9GuQyEnUqANKx4eo3Df6Ok/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/PenTestIT?a=mTtdP77JUis:w899qrcqfk4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/PenTestIT?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=mTtdP77JUis:w899qrcqfk4:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=mTtdP77JUis:w899qrcqfk4:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=mTtdP77JUis:w899qrcqfk4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=mTtdP77JUis:w899qrcqfk4:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/PenTestIT/~4/mTtdP77JUis" height="1" width="1"/>]]></content:encoded> <wfw:commentRss>http://pentestit.com/2010/09/03/dotdotpwn-tool-directory-traversal-checkerscanning/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://pentestit.com/2010/09/03/dotdotpwn-tool-directory-traversal-checkerscanning/</feedburner:origLink></item> <item><title>UPDATE: Microsoft Enhanced Mitigation Evaluation Toolkit v2!</title><link>http://feedproxy.google.com/~r/PenTestIT/~3/XIdKl6OnqfE/</link> <comments>http://pentestit.com/2010/09/02/update-microsoft-enhanced-mitigation-evaluation-toolkit-v2/#comments</comments> <pubDate>Thu, 02 Sep 2010 17:34:14 +0000</pubDate> <dc:creator>Black</dc:creator> <category><![CDATA[Security tools]]></category> <category><![CDATA[Tool Updates]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[Enhanced Mitigation Evaluation Toolkit]]></category> <category><![CDATA[Microsoft]]></category><guid isPermaLink="false">http://pentestit.com/?p=5553</guid> <description><![CDATA[Nice! Our first post regarding the Microsoft Enhanced Mitigation Evaluation Toolkit or EMET can be found here. Now, Microsoft has released the EMET v2! &#8220;EMET provides users with the ability to deploy security mitigation technologies to arbitrary applications.  This helps prevent vulnerabilities in those applications (especially line of business and [...]]]></description> <content:encoded><![CDATA[<p></p><p>Nice! Our first post regarding the <strong>Microsoft Enhanced Mitigation Evaluation Toolkit</strong> or <strong>EMET</strong> can be found <a title="http://pentestit.com/2009/10/29/microsoft-enhanced-mitigation-evaluation-toolkit/" href="http://pentestit.com/2009/10/29/microsoft-enhanced-mitigation-evaluation-toolkit/" target="_blank"><strong>here</strong></a>. Now, Microsoft has released the <span style="text-decoration: underline;">EMET v2</span>!</p><blockquote><p>&#8220;<em>EMET provides users with the ability to deploy security mitigation technologies to arbitrary applications.  This  helps prevent vulnerabilities in those applications (especially line of  business and 3rd party apps) from successfully being exploited.  By  deploying these mitigation technologies on legacy products, the tool  can also help customers manage risk while they are in the process of  transitioning over to modern, more secure products.  In  addition, it makes it easy for customers to test mitigations against  any software and provide feedback on their experience to the vendor.</em>&#8220;</p></blockquote><p>This version sports a brand new GUI. In addition to SEHOP (Structured Error Handling Overwrite Protection), Dynamic DEP (Dynamic Data Execution Prevention), NULL page allocation, Heap Spray Allocation, this tool adds support for <em>Export Address Table Access Filtering</em> and the <em>Mandatory Address Space Layout Randomization (ASLR)!</em></p><p>Download the <span style="text-decoration: underline;">EMET v2</span> <a target="_blank" title="Download EMET" href="http://51e019ee.linkbucks.com" target="_blank"><strong>here</strong></a>.</p> <span style="text-decoration: underline;">Searches leading to this post</span>:<br><a href="http://pentestit.com/2010/09/02/update-microsoft-enhanced-mitigation-evaluation-toolkit-v2/" title="How to deploy Microsoft EMET">How to deploy Microsoft EMET</a><div style='clear:both'></div><h2  class="related_post_title">If you enjoyed this article, you might also like:</h2><ul class="related_post"><li>October 29, 2009 -- <a href="http://pentestit.com/2009/10/29/microsoft-enhanced-mitigation-evaluation-toolkit/" title="The Microsoft Enhanced Mitigation Evaluation Toolkit!">The Microsoft Enhanced Mitigation Evaluation Toolkit!</a><br /><small>Seems like Microsoft really is taking security seriously these days! What with it releasing some ama...</small></li><li>April 23, 2010 -- <a href="http://pentestit.com/2010/04/23/microsoft-pulls-faulty-patch-plans-re-release/" title="Microsoft pulls faulty patch, plans re-release">Microsoft pulls faulty patch, plans re-release</a><br /><small>Critical patch that affects Windows 2000 Server running Windows Media Services didn't work, so Micro...</small></li><li>April 13, 2010 -- <a href="http://pentestit.com/2010/04/13/ms10-022-important-vulnerability-in-vbscript-scripting-engine-could-allow-remote-code-execution-981169/" title="MS10-022 &#8211; Important: Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution (981169)">MS10-022 &#8211; Important: Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution (981169)</a><br /><small>Bulletin Severity Rating:Important - This security update resolves a publicly disclosed vulnerabilit...</small></li><li>March 9, 2010 -- <a href="http://pentestit.com/2010/03/09/ms10-016-important-vulnerability-in-windows-movie-maker-could-allow-remote-code-execution-975561/" title="MS10-016 &#8211; Important: Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (975561)">MS10-016 &#8211; Important: Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (975561)</a><br /><small>Bulletin Severity Rating:Important - This security update addresses a privately reported vulnerabili...</small></li><li>March 4, 2010 -- <a href="http://pentestit.com/2010/03/04/ms09_043_owc_htmlurl-rb-txt/" title="ms09_043_owc_htmlurl.rb.txt">ms09_043_owc_htmlurl.rb.txt</a><br /><small>This Metasploit module exploits a buffer overflow in Microsoft's Office Web Components. When passing...</small></li><li>February 24, 2010 -- <a href="http://pentestit.com/2010/02/24/export-windows-logs-event-viewer-remote-machine/" title="Export all Windows Logs from the Event Viewer from a Remote Machine!">Export all Windows Logs from the Event Viewer from a Remote Machine!</a><br /><small>What if you want to export all logs - Application, Security and System - from a system on your netwo...</small></li><li>February 9, 2010 -- <a href="http://pentestit.com/2010/02/09/ms10-008-critical-cumulative-security-update-of-activex-kill-bits-978262/" title="MS10-008 &#8211; Critical: Cumulative Security Update of ActiveX Kill Bits (978262)">MS10-008 &#8211; Critical: Cumulative Security Update of ActiveX Kill Bits (978262)</a><br /><small>Bulletin Severity Rating:Critical - This security update addresses a privately reported vulnerabilit...</small></li><li>February 9, 2010 -- <a href="http://pentestit.com/2010/02/09/ms10-014-important-vulnerability-in-kerberos-could-allow-denial-of-service-977290/" title="MS10-014 &#8211; Important: Vulnerability in Kerberos Could Allow Denial of Service (977290)">MS10-014 &#8211; Important: Vulnerability in Kerberos Could Allow Denial of Service (977290)</a><br /><small>Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerabilit...</small></li><li>February 9, 2010 -- <a href="http://pentestit.com/2010/02/09/ms10-007-critical-vulnerability-in-windows-shell-handler-could-allow-remote-code-execution-975713/" title="MS10-007 &#8211; Critical: Vulnerability in Windows Shell Handler Could Allow Remote Code Execution (975713)">MS10-007 &#8211; Critical: Vulnerability in Windows Shell Handler Could Allow Remote Code Execution (975713)</a><br /><small>Bulletin Severity Rating:Critical - This security update resolves a privately reported vulnerability...</small></li></ul>
<p><a href="http://feedads.g.doubleclick.net/~a/vQ2z0moRgbMj8gWRNgDq15kekaM/0/da"><img src="http://feedads.g.doubleclick.net/~a/vQ2z0moRgbMj8gWRNgDq15kekaM/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/vQ2z0moRgbMj8gWRNgDq15kekaM/1/da"><img src="http://feedads.g.doubleclick.net/~a/vQ2z0moRgbMj8gWRNgDq15kekaM/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/PenTestIT?a=XIdKl6OnqfE:I0kaW0sGjF8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/PenTestIT?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=XIdKl6OnqfE:I0kaW0sGjF8:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=XIdKl6OnqfE:I0kaW0sGjF8:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=XIdKl6OnqfE:I0kaW0sGjF8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=XIdKl6OnqfE:I0kaW0sGjF8:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/PenTestIT/~4/XIdKl6OnqfE" height="1" width="1"/>]]></content:encoded> <wfw:commentRss>http://pentestit.com/2010/09/02/update-microsoft-enhanced-mitigation-evaluation-toolkit-v2/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://pentestit.com/2010/09/02/update-microsoft-enhanced-mitigation-evaluation-toolkit-v2/</feedburner:origLink></item> <item><title>UPDATE: ProcNetMonitor v2.7!</title><link>http://feedproxy.google.com/~r/PenTestIT/~3/MzMALOLD34k/</link> <comments>http://pentestit.com/2010/09/02/update-procnetmonitor-v27/#comments</comments> <pubDate>Thu, 02 Sep 2010 16:47:22 +0000</pubDate> <dc:creator>Black</dc:creator> <category><![CDATA[Malware Analysis]]></category> <category><![CDATA[Security tools]]></category> <category><![CDATA[Tool Updates]]></category> <category><![CDATA[ProcNetMonitor]]></category> <category><![CDATA[Rootkit]]></category> <category><![CDATA[system auditing tool]]></category> <category><![CDATA[Windows]]></category><guid isPermaLink="false">http://pentestit.com/?p=5549</guid> <description><![CDATA[Whoa! It sure has been a long time since we updated information about ProcNetMonitor. We had mentioned about it in our first post here. Now, the author has released an update &#8211; ProcNetMonitor version 2.7. &#8220;ProcNetMonitor is the free tool to monitor the network activity of all running process in [...]]]></description> <content:encoded><![CDATA[<p></p><p>Whoa! It sure has been a long time since we updated information about <strong>ProcNetMonitor</strong>. We had mentioned about it in our first post <a title="http://pentestit.com/2009/09/12/procnetmonitor-basic-malware-system-analysis-tool/" href="http://pentestit.com/2009/09/12/procnetmonitor-basic-malware-system-analysis-tool/" target="_blank"><strong>here</strong></a>. Now, the author has released an update &#8211; <span style="text-decoration: underline;">ProcNetMonitor version 2.7</span>.</p><blockquote><p>&#8220;<em>ProcNetMonitor is the free tool to monitor the network activity of all running process in the system. It displays all open network ports (TCP/UDP) and active network connections for each process. It has advanced color based auto analysis system to make it easy to distinguish network oriented processes from others with just one glance at the list.</em>&#8220;</p></blockquote><p>Since we last wrote about it, this tool can now display process information on 64 bit systems too. False positives from Antivirus have also been removed and support for Windows 7 with GUI related enhancements.</p><p>Download <span style="text-decoration: underline;">ProcNetMonitor v2.7</span> <strong><a target="_blank" href="http://c1774de8.linkbucks.com/" target="_blank">here</a></strong></p><div style='clear:both'></div><h2  class="related_post_title">If you enjoyed this article, you might also like:</h2><ul class="related_post"><li>September 12, 2009 -- <a href="http://pentestit.com/2009/09/12/procnetmonitor-basic-malware-system-analysis-tool/" title="ProcNetMonitor &#8211; Basic malware and system analysis tool">ProcNetMonitor &#8211; Basic malware and system analysis tool</a><br /><small>ProcNetMonitor is the free tool to monitor the network activity of all running process in the system...</small></li><li>July 23, 2010 -- <a href="http://pentestit.com/2010/07/23/rootkit-razor-rootkit-remover/" title="Rootkit Razor: A Free Rootkit Remover!">Rootkit Razor: A Free Rootkit Remover!</a><br /><small>In earliest deployments, hackers used rootkits to gain unauthorized access to Unix-based systems. To...</small></li><li>July 14, 2010 -- <a href="http://pentestit.com/2010/07/14/update-process-hacker-v20/" title="UPDATE: Process Hacker v2.0!">UPDATE: Process Hacker v2.0!</a><br /><small>Process Hacker is updated with few updates on look and feel and how it works.We have previously writ...</small></li><li>April 24, 2010 -- <a href="http://pentestit.com/2010/04/24/pentestit-post-day-portable-executable-file-infection/" title="PenTestIT Post Of The Day: Portable Executable File Infection!">PenTestIT Post Of The Day: Portable Executable File Infection!</a><br /><small>Today, we have this post from KOrUPt Blog by KOrUPt himself!“Portable Executable File Infection”...</small></li><li>March 29, 2010 -- <a href="http://pentestit.com/2010/03/29/streamarmor-tool-discovering-hidden-alternate-data-streams-ads/" title="streamarmor : Tool for discovering hidden alternate data streams (ADS)">streamarmor : Tool for discovering hidden alternate data streams (ADS)</a><br /><small>StreamArmor is the sophisticated tool for discovering hidden alternate data streams (ADS) as well as...</small></li><li>March 12, 2010 -- <a href="http://pentestit.com/2010/03/12/ms10_002_aurora-rb-txt/" title="ms10_002_aurora.rb.txt">ms10_002_aurora.rb.txt</a><br /><small>This Metasploit module exploits a memory corruption flaw in Internet Explorer. This flaw was found i...</small></li><li>February 25, 2010 -- <a href="http://pentestit.com/2010/02/25/lookinmypc-tool-gather-pc-profiling-diagnostic-reports/" title="LookInMyPC : Gather PC Profiling and Diagnostic Reports!">LookInMyPC : Gather PC Profiling and Diagnostic Reports!</a><br /><small>LookInMyPC generates a complete, and a comprehensive system profile that includes information on all...</small></li><li>February 10, 2010 -- <a href="http://pentestit.com/2010/02/10/anvir-task-manager-regular-task-manager/" title="AnVir Task Manager &#8211; More than regular task manager">AnVir Task Manager &#8211; More than regular task manager</a><br /><small>AnVir Task Manager is a award-winning solution that controls everything running on computer, removes...</small></li><li>December 7, 2009 -- <a href="http://pentestit.com/2009/12/07/update-buster-sandbox-analyzer-version-103/" title="UPDATE: Buster Sandbox Analyzer version 1.03!">UPDATE: Buster Sandbox Analyzer version 1.03!</a><br /><small>We wrote about Buster Sandbox Analyzer a week ago here. This open source tool is gaining popularity ...</small></li></ul>
<p><a href="http://feedads.g.doubleclick.net/~a/8RfVRux24yXNfPRt11K2MwyPKZw/0/da"><img src="http://feedads.g.doubleclick.net/~a/8RfVRux24yXNfPRt11K2MwyPKZw/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/8RfVRux24yXNfPRt11K2MwyPKZw/1/da"><img src="http://feedads.g.doubleclick.net/~a/8RfVRux24yXNfPRt11K2MwyPKZw/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/PenTestIT?a=MzMALOLD34k:kzh4CYRL5Ok:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/PenTestIT?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=MzMALOLD34k:kzh4CYRL5Ok:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=MzMALOLD34k:kzh4CYRL5Ok:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/PenTestIT?a=MzMALOLD34k:kzh4CYRL5Ok:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/PenTestIT?i=MzMALOLD34k:kzh4CYRL5Ok:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/PenTestIT/~4/MzMALOLD34k" height="1" width="1"/>]]></content:encoded> <wfw:commentRss>http://pentestit.com/2010/09/02/update-procnetmonitor-v27/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://pentestit.com/2010/09/02/update-procnetmonitor-v27/</feedburner:origLink></item> </channel> </rss><!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced) (request URI contains query)
Database Caching 61/142 queries in 1.855 seconds using disk
Object Caching 3199/3313 objects using disk

Served from: pentestit.com @ 2010-09-08 08:35:05 -->
