Archiv der Kategorie link

Link: Education Education Education

 

http://www.offensive-security.com/metasploit-unleashed/

 

And do not forget to donate for HFC!!!

 

 

Link: Links to exploits

http://www.packetstormsecurity.org/assess/exploits/

 

http://www.milw0rm.com/

 

http://www.securiteam.com/exploits/

 

http://www.securityfocus.com/vulnerabilities

 

http://www.securityforest.com/cgi-bin/viewcvs.cgi/ExploitTree/

 

http://securityvulns.com/exploits/

 

http://osvdb.org/

 

http://www.vupen.com/english/security-advisories/

 

http://www.red-database-security.com/exploits/oracle_exploits.html

 

http://www.joomlaexploit.com/

 

 

Short one…


http://releases.portswigger.net/2009/10/v1217.html -> XML export -> http://dradisframework.org/

 

 

Link: In the Future - Do related tags tell you something?

http://www.librarything.com/tag/geek,+--nerds
http://www.librarything.com/tag/nerds,+--geek

Look at the related tags on the right

And then have fun comparing…But wait:

Ok now that I think about it this is actually not a bad thing.

I just remember http://www.infosecwriters.com/hhworld/hh10/dns.htm especially dnspredict.pl for finding new DNS entries. I used it also to make educated guesses for password attacks. So here is the new idea for educated password guesses. Profile your target and enter it into a search engine that comes up with related tags. Then of course the usual stuff with appending 2 numbers and so on…

 

 

Link: I like things that run in your browser


This is always fun as you can impress certain people more easily…

 

http://code.google.com/p/websecurify/

 

Although who comes up with a name like Websecurify Security Testing Framework?

Not sure but it seems that one word could go missing without reducing the meaning by a lot…

 

PS: Do not forget http://www.bindshell.net/tools/beef/ as it got a bit of a polish since DefCon

 

 

Link: A classic comic for educational purposes


We all know and love it…

 

 

 


So here is another link about the comic (worth a look):

 

http://bobby-tables.com/

 

 

Link: check if you mail accounts has be hacked

This is in addition to all the gmail, hotmail, and other mail accounts be hacked lately:

http://beta.serversniff.de/mailaccounts

Not that I agree to the methods but it could be useful to some…

But while we are on that subject:

 

Some of the methods used here could also be used by the bad boys.

So basically let us assume I do want to attack someone!

It would be a good thing to know then when someone is online, right?

 

So using defence mechanism the other way around is always fun…

 

 

System audit information


Little reminder:

 

http://iase.disa.mil/stigs/SRR/index.html

http://www.cisecurity.org/

 

 

Link: I forgot something… My password


http://www.phenoelit-us.org/dpl/dpl.html / net devices

http://www.packetstormsecurity.org/Crackers/wordlists/

 

http://cirt.net/passwords

http://www.virus.org/default-password/

http://www.routerpasswords.com/index.asp

 

Added:

 

http://reusablesec.googlepages.com/passwordcrackingtools

 

 

 

Link: Cntlm Authentication Proxy

http://cntlm.awk.cz/

check it out