Member Login
new_way_of_learning_5.jpg
Home arrow by Cats Grouped
Bookmarks List
Display Mode : One Cat | by Alpha Grouped | [by Cats Grouped] | by Alpha Not Grouped
<< Start < Prev 1 2 [3] 4 Next > End >>
Results: 101 - 150 of 166
Network Tools  Top
dhcping Popular Bookmark  DHCPing is a lightweight and featureful security tool written in PERL and designed to test the security of various flavors of DHCP implementations around. Many options allow DHCPing users to craft malicious DHCP/BOOTP packets "a la HPING" 826 
dsniff Popular Bookmark  Dsniff is a collection of tools for network auditing and penetration testing. Passively monitor a network for interesting data (passwords, e-mail, files, etc.). Facilitate the interception of network traffic normally unavailable to an attacker (e.g, 809 
ethereal Popular Bookmark  Ethereal is a free network protocol analyzer for Unix and Windows. It allows you to examine data from a live network or from a capture file on disk. You can interactively browse the capture data, viewing summary and detail information for each packet 732 
ettercap Popular Bookmark  Ettercap NG is a network sniffer/interceptor/logger for switched LANs. It uses ARP poisoning and the man-in-the-middle technique to sniff all the connections between two hosts. Features character injection in an established connection. 818 
Firewalk Popular Bookmark  Firewalk is an active reconnaissance network security tool that attempts to determine what layer 4 protocols a given IP forwarding device will pass. Firewalk works by sending out TCP or UDP packets with a TTL one greater than the targeted gateway. To 829 
Fragroute Fragroute is an IDS stress testing tool and verification tool. It has a rulebase it acts on and sends "attacks" against specified hosts. IDSes should pick these up and generate alerts and so on. 572 
Hping 3 hping is a command-line oriented TCP/IP packet assembler/analyzer. It supports TCP, UDP, ICMP and RAW-IP protocols, has a traceroute mode, the ability to send files between a covered channel, and many other features. 578 
nemesis Nemesis is a packet injection suite that supports protocols ARP, DNS, ETHERNET, ICMP, IGMP, IP, OSPF, RIP, TCP and UDP. This might be a good tool for enumerating a network consisting of firewalls, routers and so on. 610 
Netcat Netcat is a multipurpose tool that you can utilize for many things. I recommend this tool warmly, as in my opinion, its good :) 650 
nmap port scanner Here you can find Fyodor's NMAP-tool that you can use to portscan targets. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on th 517 
phenoelit router tools Phenoelit has lots of router specific enumeration and exploitation tools available that can be used to assess network specific stuff. They also have some brute-forcers for telnet, ldap & http. 511 
snort IDS Snort is a open-source intrusion detection system that is developed actively. It is free and could compete with some of the commercial products. Maintaining snort is a bit harder, but it does what it is supposed to do. 470 
Socat A netcat alternative 540 
 
Networking  Top
detection of sql injection and cross-site scripting This article goes through creating snort-rules that attempt to detect possible SQL injection attacks against a web-application. It also explains how to detect CSS attacks, usually meaning injecting HTML code into the fields, that could result in code 693 
Firewalls complete Popular Bookmark  Secinf.net offers the Firewalls Complete book online. This covers pretty much all about firewalls and is very good read if you need to learn how to create rulesets and find out the best topologies for your own projects. 742 
How to create a sniffing cable Popular Bookmark  This page explains in detail how one can create a receive-only cable that can be used for example in IDSes for added protection. It means the IDS never returns anything because it can't, if such a cable is installed. 701 
Layer 2 sniffing This paper explains three different attacks that can be performed against a switched network. These attacks are ARP cache poisoning, CAM table flooding and switch port stealing. It also gives countermeasure recommendations against these. 545 
www.honeypots.net This site hosts about 600 links to IDS, honeypot & incident response resources. A very nice site for people needing to learn more about the areas. From this site you can also access resources for DNS security & wardriving, all kept by the same guy. 477 
www.networkintrusion.co.uk Taliskers Network Tools purpose is to list Intrusion Detection tools, firewalls and network security scanners. There is loads of these listed, both commercial and freeware. He also gives some overview of the product. Check it out if you're planning o 460 
 
Security  Top
razor.bindview.com RAZOR is a team of security researchers around the world. The site has lots of nice tools available and there are also lots of papers, presentations & advisories the group has made. Overally a clean, nice site. 581 
www.blackhat.com This is the homepage for the Blackhat Briefings. They have a lot of resources on the pages in form of presentations. Of course this material acts only as presentation material, but should give clues where to look for more information on a specific to 521 
www.cert.org CERT is a computer security incident response "team", having local sites around the world. This site reports world-wide if there is any major vulnerabilities spotted that should be fixed. It also has information how to deal with incidents and how to 470 
www.cgisecurity.org The site focuses mainly on web-security and lists vulnerabilities found on web-servers and technologies like PHP, and so on. It gives good pointers to certain web-servers and applications from the security point of view. 503 
www.ebcvg.com This is a security-site containing lots of different articles and tutorials regarding security, virii, cryptography and hacking. The site also has own editorials/articles posted and a "security"-shop. 519 
www.infosecwriters.com A site dedicated for papers and articles written by security-minded people. It also has some other resources, like honeynet-related stuff and forensics. It also has a nice library of documents. 508 
www.infosyssec.org This site has loads of links to different sites and resources. It also lists usual mailinglists, vulnerability databases, search engines, antivirus- and OS/software-vendors with links to their patch-pages. 454 
www.net-security.org This site collects some interesting tidbits into their page, news from the world. They also have lots of book-reviews so that might be a place to look for when considering buying a book, it might have a review done on this site. It also lists some vu 484 
www.nmrc.org Nomad Mobile Research Centre, this group concentrates on security research. They have some interesting papers and projects going on, good FAQs about hacking several things and provide some tools. The quality is good, and they include welcome humour i 461 
www.sans.org SANS offers lots of seminars and training-sessions. It also has certification paths that one could follow. It has nice resources available that students/security persons have written, and it has the TOP-20 vulnerabilities listed that most likely are 469 
www.secureroot.com SecureRoot is a security-portal with lots of pointers to different resources, like hacking sites, security sites and so on. Quite clean site, and appears well structured. The site also has a forum, but it was down when reviewing the site. 492 
www.securiteam.com SecuriTeam is formed by a small group of people from Beyond Security. It is a security-portal that has quite recent and interesting information posted about vulnerabilities, news, tools & papers. One thing that makes this a good site is that they giv 488 
www.security-forums.com Security-Forums contains many forums with specific topics. If you are interested in swapping security viewpoints with other people around the world via your web-browser, this is one of those places. 447 
www.security-protocols.com This is a semi-interactive portal that concentrates on security. It posts some of the latest happenings in the security-field and contains some sections for tools, tutorials and documents. It also has links to other security-sites and so on. 418 
www.securityfocus.com This has been an excellent site and hopefully it stays that way and offers free service to the community. Symantec bought Securityfocus and is selling alert-information a few days ahead to companies with fixing information before the information gets 452 
www.securityrisk.org This sites main goal is to provide security information to help the average user to patch operating system flaws. Based on the amount of forum messages, it is a relatively new one. 469 
www.tietoturva.org This is a site for Finnish Information Security Association, one of its purposes being to promote it's members educational status in the security-field. They have some basic resources available. This probably mainly interests finns, because the site 491 
www.toolcrypt.org Toolcrypt is a site that focuses on tools for windows and linux (unix) platforms. Pretty impressive ideas and just wondering what the non-crippled versions really are capable of. 613 
www.windowsecurity.com WindowsSecurity is a site dedicated to security-related issues with Microsoft server-products, containing articles and tutorials, software categories and a nice whitepaper section. 496 
 
Specifications  Top
CGI/1.1 specifications Popular Bookmark  This site has the specification for CGI/1.1 that helps understanding how the webserver & CGI-scripts interact with each others and what can be done and what not. Might help understand some attack-points on web-applications. 726 
DNS protocol specifications RFC882 These RFC-specifications dig into DNS inner workings. In my opinion it would be good general knowledge to know how DNS works as it is quite centric in todays networking. It could also give security-related & pentest-related tips how one should procee 670 
DNS protocol specifications RFC883 These RFC-specifications dig into DNS inner workings. In my opinion it would be good general knowledge to know how DNS works as it is quite centric in todays networking. It could also give security-related & pentest-related tips how one should procee 688 
Evidence gathering and archiving best practices Popular Bookmark  This rfc attempts to bring the common best practices for evidence gathering & archiving in incident response & forensics situations. There is plenty of ir/forensics related stuff out there, but this might be an interesting piece to read. 737 
HTML specifications This page hosts the HTML 4.0 specifications. Might be useful read if you need to find out how you could try to exploit html-based pages and other things. Atleast it has been helpful when building pages or trying to find ways how to do XSS attacks. 503 
HTTP 1.0, HTTP 1.1 specifications and more RFC specifications of Hypertext Transfer Protocol version 1.0 and 1.1. These pages help understanding how the protocol works, and might give clues how to build your own tools that discuss with web-servers. There are also other RFC's that are related 500 
TCP protocol specifications (original) RFC specifications of TCP (transmission control protocol). 0793 is the original RFC & 3168 is an update to it (see below). Together, these should help you understand how the protocol works. 457 
TCP protocol specifications (update) 3168 is an update to the original 0793 specifications of the TCP protocol. 461 
TCP/IP cheat sheet This is a nice cheat-sheet about TCP/IP. It has UDP, ARP, DNS, PING and ICMP also explained and most common ports and stuff related to these. It also lists many protocols like for example LDAP, but doesn't dig in to it. Might be a handy little paper 501 
UDP protocol specifications RFC specifications of UDP. This should help you understand how UDP works. 450 
www.rfc-editor.org RFC stands for Request For Comments. From here you can find specific internet related stuff discussing networking, protocols, procedures, programs and concepts. Good place to look up on something to understand how it actually works, for example TCP. 403 
 
Web applications  Top
Achilles proxy Popular Bookmark  Achilles is an intercepting HTTP/HTTPS proxy that can be used for hacking/pentesting web-applications. This tool is for Windows-platform and is simple and usable. 915 
  Top
<< Start < Prev 1 2 [3] 4 Next > End >>
Results: 101 - 150 of 166