Section: .. / UNIX / audit /
| /// File Name: |
rhj.tar |
Description:
|
rhj will let you exploit the ptrace() syscall to monitor and hijack some syscalls run-time. At the moment few syscalls are supported (i.e. send(), recv(), read(), write()) since the program is still a proof of concept.
| | Author: | Angelo Rosiello | | Homepage: | http://www.rosiello.org/ | | File Size: | 448934 | | Last Modified: | Aug 3 01:04:49 2006 |
| MD5 Checksum: | 8985c9e8108fdae75debbb6eb55bd9b6 |
|
| /// File Name: |
lbd-0.1.sh.txt |
Description:
|
lbd (load balancing detector) is a bash shell script which detects if a given domain uses DNS and/or HTTP load balancing.
| | Author: | Stefan Behte | | Homepage: | http://ge.mine.nu/ | | File Size: | 2682 | | Last Modified: | May 30 22:29:35 2006 |
| MD5 Checksum: | 63b241ddeaebcf6183cbaf62a3a71e07 |
|
| /// File Name: |
clfuzz.tar.gz |
Description:
|
clfuzz is a command line argument fuzzer written in Python. It is very useful for auditing setuid binaries for command line overflows.
| | Author: | Pranay Kanwar | | Homepage: | http://www.metaeye.org/warl0ck/ | | File Size: | 8550 | | Last Modified: | Apr 12 00:18:46 2006 |
| MD5 Checksum: | 299ca5891acce1aab09e284802c0e9ea |
|
| /// File Name: |
mysql-miner.pl |
Description:
|
A perl script that automates the process of guessing MySQL tables through SQL injection by first determining the number of arguments in the SELECT statement and then brute forcing table names from a word list.
| | Author: | amat | | File Size: | 1230 | | Last Modified: | Apr 12 00:08:03 2006 |
| MD5 Checksum: | 139728a02194d7681ee38ffb79990720 |
|
| /// File Name: |
pirana-0.2.1.tar.gz |
Description:
|
PIRANA is an exploitation framework that tests the security of a email content filter. By means of a vulnerability database, the content filter to be tested will be bombarded by various emails containing a malicious payload intended to compromise the computing platform. PIRANA's goal is to test whether or not any vulnerability exists on the content filtering platform.
| | Author: | Jean-Sebastien Guay-Leroux | | Homepage: | http://www.guay-leroux.com/projects.html | | File Size: | 2929006 | | Last Modified: | Apr 4 16:26:34 2006 |
| MD5 Checksum: | 28d3bb7afbac462f6abdd1eaf62aa020 |
|
| /// File Name: |
rkhunter-1.2.8.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | Michael Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for Fedora core 4, FreeBSD 4.11, 5.2, 5.3, 5.4, 6.0, CentOS 3.3, CentOS 3.5, 4.1 and 4.2, Debian 3.1 (AMD64), RHEL WS/AS/ES 3 Taroon update 6, RHEL WS 4 Nahant Update 1 and 2, and Slackware 10.2. | | File Size: | 126314 | | Last Modified: | Feb 25 20:50:15 2006 |
| MD5 Checksum: | 41122193b5006b617e03c637a17ae982 |
|
| /// File Name: |
sqlbftools-1.2.tar.gz |
Description:
|
Adaptive http-sql bruteforce tool version 2 for MySQL injection bruteforcing.
| | Author: | Ilo-- | | Homepage: | http://www.reversing.org | | File Size: | 89777 | | Last Modified: | Feb 13 23:39:22 2006 |
| MD5 Checksum: | ecd90f49930017d7f5bc6dfb8757f0af |
|
| /// File Name: |
bsqlbf.pl.txt |
Description:
|
Proof of concept tool to be used for blind SQL injection attacks.
| | Author: | Alejandro Ramos | | Homepage: | http://www.unsec.net | | File Size: | 12164 | | Last Modified: | Feb 13 23:37:46 2006 |
| MD5 Checksum: | b35af1cf6570aa23440513c412e1577b |
|
| /// File Name: |
slad2-1.0.tar.gz |
Description:
|
System Local Audit Daemon can run standalone or managed by systems like IBM-Tivoli, HP-OpenView, or Nessus to perform local security checks. It runs on the target hosts and enables them to call security tools like John the Ripper, Tiger, Tripwire, or a virus scanner via a unified XML interface. It is part of the BOSS Project.
| | Author: | lgrunwald | | Homepage: | http://www.dn-systems.org/slad.shtml | | File Size: | 16583 | | Last Modified: | Jan 15 12:40:32 2006 |
| MD5 Checksum: | e0f4c6c3ac98dc876b45aeb60243dcc7 |
|
| /// File Name: |
unhide.tgz |
Description:
|
Unhide is a forensic tool to find hidden processes and TCP/UDP ports that are hidden via rootkits, LKMs, or other techniques.
| | Author: | YJesus | | Homepage: | http://www.security-projects.com/?Unhide | | File Size: | 3594 | | Last Modified: | Jan 8 00:11:20 2006 |
| MD5 Checksum: | 32530671eda828f669d8fc4636c7cc37 |
|
| /// File Name: |
pmacct-0.9.3.tar.gz |
Description:
|
pmacct is a small set of passive network monitoring tools to measure, account and aggregate IPv4 and IPv6 traffic; aggregation revolves around the key concept of primitives (VLAN id, source and destination MAC addresses, hosts, networks, AS numbers, ports, IP protocol and ToS/DSCP field are supported) which may be arbitrarily combined to build custom aggregation methods; support for historical data breakdown, triggers and packet tagging, filtering and sampling. Aggregates can be stored into memory tables, SQL databases (MySQL or PostgreSQL) or simply printed to stdout. Data is collected from the network either using libpcap (and optionally promiscuous mode) or reading NetFlow v1/v5/v7/v8/v9 and sFlow v2/v4/v5 datagrams, both unicast and multicast.
| | Author: | Paolo Lucente | | Homepage: | http://www.ba.cnr.it/~paolo/pmacct/ | | File Size: | 297333 | | Last Modified: | Oct 28 16:03:17 2005 |
| MD5 Checksum: | c1f544fa9e0e74c7b75ead77707fa3d1 |
|
| /// File Name: |
lssocks.c |
Description:
|
A small utility that shows all connections by reading open inodes and will even show related PIDs. Very useful for backdoor detection when you cannot trust other binaries.
| | File Size: | 9139 | | Last Modified: | Aug 31 02:54:20 2005 |
| MD5 Checksum: | 7bc6d09c0dc44e4c28392e2b02283a6f |
|
| /// File Name: |
AntiExploit-1.3b6.tar.gz |
Description:
|
AntiExploit is an exploit scanner to detect local intruders. It scans for over 3900 suspicious files, has daily database updates, and will act if a file is accessed. It uses the dazuko kernel module, which is also used by clamAV, Amavis, and other virus scanners.
| | Author: | Enrico Kern | | Homepage: | http://www.hzeroseven.org/projects/aexpl/ | | Changes: | Various bug fixes and feature improvements. | | File Size: | 265732 | | Last Modified: | Aug 24 03:32:26 2005 |
| MD5 Checksum: | 514fb2703a69df699ff342fc469c8c8f |
|
| /// File Name: |
pandora1.1.tar.gz |
Description:
|
Pandora is a distributed system to monitor processes, performance, status, application or operating parameters of almost any system (AIX, Solaris, Linux, Windows, BSD and Nokia's IPSO). It has a decentralized management system, based in flexible user profiles, that allows generation of graphical reports, defined alarms, and a full incident management system to operate a 24x7 monitoring team.
| | Homepage: | http://pandoramon.sourceforge.net | | File Size: | 253140 | | Last Modified: | Aug 14 02:22:13 2005 |
| MD5 Checksum: | b642fc823afac446d9d010b3396b2ac0 |
|
| /// File Name: |
flawseeker-v.3.0.pl.txt |
Description:
|
Simple perl script that can be used to track overflows.
| | Author: | nuTshell | | File Size: | 15030 | | Last Modified: | Aug 7 02:28:42 2005 |
| MD5 Checksum: | 056be4c4fd2fee1972fae10eceafcf41 |
|
| /// File Name: |
ISR-form-v1.0.tar.gz |
Description:
|
Simple html parsing tool that extracts all form related information and generates reports of the data. Allows for quick analyzing of data.
| | Author: | Francisco Amato | | Homepage: | http://www.infobyte.com.ar/ | | File Size: | 2444 | | Last Modified: | Jun 18 15:53:12 2005 |
| MD5 Checksum: | 9d91c42fdb01b52d9e341115a9adafe2 |
|
| /// File Name: |
rkhunter-1.2.7.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | Michael Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Includes a bugfix for the updater, and improved support for Bind, RHEL AS, CentOS, Mandrake, E-smith, and FreeBSD. | | File Size: | 170732 | | Last Modified: | May 30 15:25:46 2005 |
| MD5 Checksum: | 288ba8a87352716384823c9ea1958fa7 |
|
| /// File Name: |
rkhunter-1.2.4.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | Michael Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Supports E-smith (SME 6.0), updated Fedora core 2 hashes, and many cool improvements to the installer and the tools. Also fixes a bug with the --allow-ssh-root-user option. | | File Size: | 170394 | | Last Modified: | Apr 27 21:37:41 2005 |
| MD5 Checksum: | d3f653233376af34bcdd2837cff56a3a |
|
| /// File Name: |
chkrootkit-0.45.tar.gz |
Description:
|
Chkrootkit checks locally for signs of a rootkit. Chkrootkit includes ifpromisc.c to check and see if the interface is in promisc mode, chklastlog.c to check lastlog for deletions, and chkwtmp.c to check wtmp for deletions, strings.c for quick and dirty strings replacement, check_wtmpx.c to check for wtmpx deletions and the files chkproc.c and chkdirs.c to check for LKM trojans. Tested on Linux 2.0.x, 2.2.x and 2.4.x, FreeBSD 2.2.x, 3.x, 4.x, and 5.x, BSDI, OpenBSD 2.6, 2.7, 2.8, 2.9, 3.0 and 3.1, NetBSD 1.5.2 and Solaris 2.5.1, 2.6 and 8.0, and HP-UX 11.
| | Author: | Nelson Murilo | | Homepage: | http://www.chkrootkit.org | | Changes: | Various improvements, minor bug fixes. | | File Size: | 36359 | | Last Modified: | Apr 18 02:53:28 2005 |
| MD5 Checksum: | 57493e24ca81750a200d8bcb4049e858 |
|
| /// File Name: |
rkhunter-1.2.3.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | Michael Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Whitelisting was added for hidden files and directories. Support for SuSE 9.2 (64 bits) was added. The manpage was updated. The package database and MD5 hash database were updated. The installer was immensely improved. | | File Size: | 169545 | | Last Modified: | Mar 21 22:19:14 2005 |
| MD5 Checksum: | 404ae3f5cde3ede8e3be1ee1f04f52d5 |
|
| /// File Name: |
rkhunter-1.2.1.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | Michael Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for Mandrake 8.1 (i586, no hashes), FreeBSD 5.3 (i386, with hashes for release version), Slackware 10.1. Updated various hashes. Improved logging. Fixed typos. | | File Size: | 119709 | | Last Modified: | Feb 26 00:46:02 2005 |
| MD5 Checksum: | a5591b84c41a736b1e0ae64947f65b76 |
|
| /// File Name: |
fl0w-s33ker-v2.0.pl |
Description:
|
Simple perl script that can be used to track overflows.
| | Author: | nuTshell | | File Size: | 12231 | | Last Modified: | Feb 23 00:16:56 2005 |
| MD5 Checksum: | a398616b16a7eb1d91cecc3af6d8e5b9 |
|
| /// File Name: |
rkhunter-1.2.0.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | Michael Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Adds support for CentOS 3.4 and updates hashes for Fedora, RHEL, and Debian. The manual and man page have been updated and some bugs have been fixed. | | File Size: | 116932 | | Last Modified: | Feb 10 22:53:26 2005 |
| MD5 Checksum: | 126001b10d5cb8c2eca8c3cd7c34d67d |
|
| /// File Name: |
fl0w-s33ker-v1.4.pl |
Description:
|
Simple perl script that can be used to track overflows.
| | Author: | nuTshell | | File Size: | 11731 | | Last Modified: | Feb 2 02:30:03 2005 |
| MD5 Checksum: | 5d6e9038d03f01b4cd0a6340209cce7f |
|
|
|
|
|