Tuesday, 19 January 2016

WiFi-Pumpkin - Framework For Rogue Wi-Fi Access Point Attack


WiFi-Pumpkin is security tool that provide the Rogue access point to Man-In-The-Middle and network attacks, purporting to provide wireless Internet services, but snooping on the traffic. It can be used to capture of credentials of unsuspecting users by either snooping the communication by phishing.

Installation   

Kali 2.0/WifiSlax 4.11.1/Parrot 2.0.5 

$ git clone https://github.com/P0cL4bs/WiFi-Pumpkin.git   
$ cd WiFi-Pumpkin   
$ chmod +x installer.sh   
$ ./installer.sh --install

refer to the wiki for Installation  

Features   
  • Rouge Wi-Fi Access Point 
  • Deauth Attack Clients AP 
  • Probe Request Monitor 
  • DHCP Starvation Attack 
  • Crendentials Monitor 
  • Windows Update Attack 
  • Phishing Manager 
  • Partial bypass HSTS 
  • Dump credentials phishing 
  • Support beef hook 
  • Report Logs html 
  • Mac Changer 
  • ARP Posion 
  • DNS Spoof 


Plugins  


Screenshots   


6 Best Wireless Hacking Tools


Wi-Fi is now an important part of our daily life. We use Wi-Fi to connect our devices together and access Internet wirelessly. Most of the people have their own personal wireless home network. These wireless networks are generally password protected. What if you want to connect to a WI-Fi network without asking for the password from network owner. You can try cracking password of the network with available wi-fi cracking tools. If you are not sure what tool to use, you can read this post to know more about WI-Fi password cracking tools.

WEP and WPA

Wireless networks use WEP and WPA security protocols. WEP (Wired Equivalent Privacy ) is deprecated security protocol which was introduced back in 1997. It was weak and has several serious weakness. Cracking of the network with WEP security was easy. TO overcome the weakness, WPA (Wi-Fi protected access) was introduced. It has two versions 1 and 2. This is why we call WPA and WPA2. WPA is the current security protocol used to secure wireless networks.

5 Best Wireless Password Cracking Tools

1. Aircrack
It is the most popular wireless password cracking tools. This tool can crack 802.11a/b/g WEP and WPA security. It uses best algorithm to recover wireless passwords by capturing packets and perform standard FMS attack. Online tutorials are also available on its official website to learn how to use this tool.
It also comes as Linux distribution Live CD and VMWare image.

2. CoWPAtty
CoWPAtty is an automated dictionary attack tools to crack WPA passwords. It comes for Linux operating system. It offers on command line interface, so you need to lean the commands to use this tool.

3. AirSnort
AirSnort is a freely available tool for decrypting WEP encryption on Wi-Fi 802.11b networks. This tool is no longer in active maintenance but works fine. It passively monitors transmission, captures packets and computer encryption keys. It is available for Linux and Windows platforms.

4. WepAttack
WepAttack is an opensource Linux tool used for cracking WEP keys. It performs active dictionary attack to guess the working key. It only supports few WLAN cards. 

5. CloudCracker
CloudCracker is an online tool used to crack WPA protected WI-FI networks. This tool also offers cracking of other kind of hashes too. It has a dictionary of around 300 million words to perform attack.

6. Airjack
Airjack is a Wi-Fi 802.11 packet injection tool. This tool is used to perform “man-in-the-middle (MiTm)” attack in the network. It can also be used to inject forged packets to perform DOS attack.

These tools are used to perform attack on a wireless network. It is worth to mention that performing attack on some network may be illegal. So, try these tools only for educational and learning purpose. We do not encourage illegal activities. 

There are many other tools available in market which offers similar kind of thing. Many paid tools are also available but these free tools work fine.

Monday, 18 January 2016

RootHelper - A Bash Script That Downloads And Unzips Scripts That Will Aid With Privilege Escalation On A Linux System


RootHelper 

Roothelper will aid in the process of privilege escalation on a Linux system that has been compromised, by fetching a number of enumeration and exploit suggestion scripts. The latest version downloads four scripts. Two enumeration shellscripts and two exploit suggests, one written in perl and the other one in python. 

The credits for the scripts it fetches go to the original authors.


Priv-Esc scripts   

LinEnum - Shellscript that enumerates the system configuration. 
unix-privesc-check - Shellscript that enumerates the system configuration and runs some privilege escalation checks as well. 
linuxprivchecker - A python implementation to suggest exploits particular to the system that's been compromised. 
Linux_Exploit_Suggester - A perl script that that does the same as the one mentioned above. 

Usage   

To use the script you will need to get it on the system you've compromised, from there you can simply run it and it will show you the options available and an informational message regarding the options. For clarity I will post it below as well. 

The 'Help' option displays this informational message.
The 'Download' option fetches the relevant files and places them in the /tmp/ directory.
The option 'Download and unzip' downloads all files and extracts the contents of zip archives to their individual sub-directories respectively, please  note; if the 'mkdir' command is unavailable however, the operation will not succeed and the 'Download' option should be used instead
The 'Clean up' option removes all downloaded files and 'Quit' exits roothelper.  

Credits for the other scripts go to their original authors. 


To check your privilege on the Linux machine : Download Now 

Thursday, 10 December 2015

MassBleed - Mass SSL Vulnerability Scanner



USAGE

 sh massbleed.sh [CIDR|IP] [single|port|subnet] [port] [proxy]

ABOUT

This script has four main functions with the ability to proxy all connections:
  • To mass scan any CIDR range for OpenSSL vulnerabilities via port 443/tcp (https) (example: sh massbleed.sh 192.168.0.0/16)
  • To scan any CIDR range for OpenSSL vulnerabilities via any custom port specified (example: sh massbleed.sh 192.168.0.0/16 port 8443)
  • To individual scan every port (1-10000) on a single system for vulnerable versions of OpenSSL (example: sh massbleed.sh 127.0.0.1 single)
  • To scan every open port on every host in a single class C subnet for OpenSSL vulnerabilities (example: sh massbleed.sh 192.168.0. subnet)


PROXY: A proxy option has been added to scan via proxychains. You'll need to configure /etc/proxychains.conf for this to work. 

PROXY USAGE EXAMPLES: 
sh massbleed.sh 192.168.0.0/16 0 0 proxy 
sh massbleed.sh 192.168.0.0/16 port 8443
sh massbleed.sh 127.0.0.1 single 0 proxy
sh massbleed.sh 192.168.0. subnet 0 proxy

VULNERABILITIES:
  • OpenSSL HeartBleed Vulnerability (CVE-2014-0160)
  • OpenSSL CCS (MITM) Vulnerability (CVE-2014-0224)
  • Poodle SSLv3 vulnerability (CVE-2014-3566)


Sunday, 6 December 2015

SpiderFoot v2.6.1 - Open Source Intelligence Automation



SpiderFoot is an open source intelligence (OSINT) automation tool. Its goal is to automate the process of gathering intelligence about a given target.

Purpose 

There are three main areas where SpiderFoot can be useful:
  • If you are a pen-tester, SpiderFoot will automate the reconnaisance stage of the test, giving you a rich set of data to help you pin-point areas of focus for the test.
  • Understand what your network/organisation is openly exposing to the outside world. Such information in the wrong hands could be a significant risk.
  • SpiderFoot can also be used to gather threat intelligence about suspected malicious IPs you might be seeing in your logs or have obtained via threat intelligence data feeds.


Features

  • Utilises a shedload of data sources; over 40 so far and counting, including SHODAN, RIPE, Whois, PasteBin, Google, SANS and more.
  • Designed for maximum data extraction; every piece of data is passed on to modules that may be interested, so that they can extract valuable information. No piece of discovered data is saved from analysis.
  • Runs on Linux and Windows. And fully open-source so you can fork it on GitHub and do whatever you want with it.
  • Visualisations. Built-in JavaScript-based visualisations or export to GEXF/CSV for use in other tools, like Gephi for instance.
  • Web-based UI. No cumbersome CLI or Java to mess with. Easy to use, easy to navigate. Take a look through the gallery for screenshots.
  • Highly configurable. Almost every module is configurable so you can define the level of intrusiveness and functionality.
  • Modular. Each major piece of functionality is a module, written in Python. Feel free to write your own and submit them to be incorporated!
  • SQLite back-end. All scan results are stored in a local SQLite database, so you can play with your data to your heart’s content.
  • Simultaneous scans. Each footprint scan runs as its own thread, so you can perform footprinting of many different targets simultaneously.
  • So much more.. check out the documentation for more information.


Data Sources
This is an ever-growing list of data sources SpiderFoot uses to gather intelligence about your target. A few require API keys but they are freely available.

Source Location Notes
abuse.ch http://www.abuse.ch Various malware trackers.
AdBlock https://easylist-downloads.adblockplus.org/easylist.txt AdBlock pattern matches
AlienVault https://reputation.alienvault.com AlienVault’s IP reputation database.
Autoshun.org http://www.autoshun.org Blacklists.
AVG Site Safety Report http://www.avgthreatlabas.com Site safety checker.
Bing http://www.bing.com Scraping but future version to also use API.
Blocklist.de http://lists.blocklist.de Blacklists.
Checkusernames.com http://www.checkusernames.com Look up username availability on popular sites.
DNS Your configured DNS server. Defaults to your local DNS but can be configured to whatever IP address you supply SpiderFoot.
DomainTools http://www.domaintools.com
DroneBL http://www.dronebl.org
DuckDuckGo http://www.duckduckgo.com
Facebook http://www.facebook.com Scraping but future version to also use API.
FreeGeoIP http://freegeoip.net
Github http://www.github.com
Google http://www.google.com Scraping but future version to also use API.
Google+ http://plus.google.com Scraping but future version to also use API.
Google Safe Browsing http://www.google.com/safebrowsing Site safety checker.
IPCat https://raw.githubusercontent.com/client9/ipcat/master/datacenters.csv IP Categorisation.
LinkedIn http://www.linkedin.com Scraping but future version to also use API.
malc0de.com http://malc0de.com Blacklists.
malwaredomainlist.com http://www.malwaredomainlist.com Blacklists.
malwaredomains.com http://www.malwaredomains.com Blacklists.
McAfee SiteAdvisor http://www.siteadvisor.com Site safety checker.
NameDroppers http://www.namedroppers.org
Notepad.cc http://www.notepad.cc
Nothink.org http://www.nothink.org Blacklists.
Onion.City http://onion.city Search engine for the dark web.
OpenBL http://www.openbl.org Blacklists.
PasteBin http://www.pastebin.com Achieved through Google scraping.
Pastie http://www.pastie.org
PGP Servers http://pgp.mit.edu/pks/ PGP public keys.
PhishTank http://www.phishtank.org Identified phishing sites.
Project Honeypot http://www.projecthoneypot.org Blacklists. API key needed.
PunkSPIDER http://www.punkspider.org
RIPE/ARIN http://stat.ripe.net/
Robtex http://www.robtex.com
SANS ISC http://isc.sans.edu Internet Storm Center IP reputation database.
SHODAN http://www.shodanhq.com API key needed.
SORBS http://www.sorbs.net Blacklists.
SpamHaus http://www.spamhaus.org Blacklists.
ThreatExpert http://www.threatexpert.com Blacklists.
TOR Node List http://torstatus.blutmagie.de
TotalHash.com http://www.totalhash.com Domains/IPs used by malware.
UCEPROTECT http://www.uceprotect.net Blacklists.
VirusTotal http://www.virustotal.com Domains/IPs used by malware. API key needed.
WayBack Machine http://www.archive.org
Whois Various Whois servers for different TLDs.
XSSposed http://www.xssposed.org
Yahoo http://www.yahoo.com Scraping but future version to also use API.
Zone-H http://www.zone-h.org Easy to get black-listed. Log onto the site in a browser from the IP you’re scanning from first and enter the CAPTCHA, then it should be fine.

Thursday, 3 December 2015

Katana - Framework for Hackers, Professional Security and Developers



Katana is a framework written in python for making penetration testing, based on a simple and comprehensive structure for anyone to use, modify and share, the goal is to unify tools serve for professional when making a penetration test or simply as a routine tool, The current version is not completely stable, not complete. 

The project is open to partners.

SOURCE CODE ORGANIZATION

The Katana source code is organized as follows:
- KatanaGUI/ > Source code for graphical user interface
- KatanaLAB/ > Source code for katana laboratory
- core/ > Source code core
-- core/db/ > Dictionaries and tables
-- core/logs/ > Registers of modules
- files/ > Files necessary for some modules
- tmp/ > Temp files
- lib/ > Libraries
- doc/ > Documentation
- scripts/ > Scripts(modules)

MAIN FILES

--core
  ¬Setting.py         --- Setting variables
  ¬design.py          --- Design template
  ¬Errors.py          --- Error Debug
  ¬ping.py            --- Funcitons
--scripts
  ¬__init__.py        --- Modules List


REQUIREMENTS

OS requirement:  Kali Linux

INSTALLATION 

Installation of Katana framework: 

git clone https://github.com/RedToor/katana.git

cd Katana

chmod 777 install.py

python install.py

USAGE Commands
Stable -----------------------------------------------------------------
./sudo ktf.console                            98% Builded - Enabled
./sudo ktf.run -m net/arpspoof                95% Builded - Enabled
Building ---------------------------------------------------------------
ktf.lab                                       30% Builded - No yet.
ktf.linker -m web/whois -t google.com -p 80   80% Builded - No yet.

MODULES (SCRIPTS)

Code Name       Description                                   Author          Version

web/httpbt       Brute force to http 403               Redtoor          1.0
web/formbt      Brute force to form-based          Redtoor          1.0
web/cpfinder    Admin panel finder                     Redtoor          1.0
web/joomscan  Scanner vul's cms joomla          Redtoor          1.0
web/dos             Denial of service web                  Redtoor          1.0
web/whois         Who-is web                                   Redtoor         1.0
net/arpspoof     ARP-Spoofing attack                   Redtoor         1.0
net/arplook       ARP-Spoofing detector               cl34r              1.0
net/portscan     Port Scanner                                 RedToor        1.0
set/gdreport      Getting information with web  RedToor        3.0
set/mailboom   E-mail boombing SPAM            RedToor        3.0
set/facebrok      facebook phishing platform    RedToor         1.7
fle/brutezip       Brute force to zip files                LeSZO ZerO   1.0
fle/bruterar       Brute force to rar files                LeSZO ZerO   1.0
clt/ftp                 Console ftp client                         Redtoor          1.0
clt/sql                 Console sql client                        Redtoor           1.0
clt/pop3             Console pop3 client                    Redtoor           1.0
clt/ftp                 Console ftp client                        Redtoor           1.0
ser/sql                Start SQL server                          Redtoor           1.0
ser/apache        Start Apache server                     Redtoor           1.0
ser/ssh               Start SSH server                          Redtoor           1.0
fbt/ftp                Brute force to ftp                         Redtoor           1.0
fbt/ssh               Brute force to ssh                        Redtoor           1.0
fbt/sql                Brute force to sql                        Redtoor           1.0
fbt/pop3            Brute force to pop3                    Redtoor           1.0

LINKS



Wednesday, 2 December 2015

Wordbrutepress - Wordpress Brute Force Multithreading with Standard and XML-RPC Login Method


Wordpress Brute Force Multithreading with standard and xml-rpc login method written in python.

Features:
  • Multithreading
  • xml-rpc brute force mode
  • http and https protocols support
  • Random User Agent
  • Big wordlist support


Usage: 
Standard login request:

python wordbrutepress.py -S -t http[s]://target.com[:port] -u username -w wordlist [--timeout in sec]

Xml-rpc login request:

python wordbrutepress.py -X -t http[s]://target.com[:port] -u username -w wordlist [--timeout in sec]

CHANGELOG 

 2015-11-20 v2.1
 1) Add new feature: Big wordlist support (thanks to guly @theguly)
 2) Fix faultcode check instead of "403" code for XML-RPC (thanks to guly @theguly)

 2015-04-12 v2.0
 1) Add new feature: xml-rpc brute force mode
 2) Fix minor bugs

 2015-04-11 v1.1
 1) optparse (Deprecated since version 2.7) replaced by argparse
 2) Fix connection bugs