Security Reconnaissance

Our first post regarding Skipfish can be found here. We now we have an update! The latest release is Skipfish version 2.04b!

“Skipfish is a fully automated, active web application security reconnaissance tool. Its key features:

High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint – easily achieving  2000 requests per second with responsive  targets.
Ease of use: heuristics to support a variety of quirky web frameworks [...]

Be the first to comment!

Our first post regarding Skipfish can be found here. We now we have an update! The latest release is Skipfish version 2.04b!

“Skipfish is a fully automated, active web application security reconnaissance tool. Its key features:

High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint – easily achieving  2000 requests per second with responsive  targets.
Ease of use: heuristics to support a variety of quirky web [...]

Be the first to comment!

Patator is a multi-purpose brute-forcer, written in pyton language, with a modular design and a flexible usage. Can be modified and rewritten as per our environment requirement. Patator is licensed GPLv2.

Modules supported buy patator

ftp_login : Brute-force FTP
ssh_login : Brute-force SSH
telnet_login : Brute-force Telnet
smtp_login : Brute-force SMTP
smtp_vrfy : Enumerate valid users using the SMTP VRFY command
smtp_rcpt [...]

Be the first to comment!

Burp Suite is an integrated platform for performing security testing of web applications. Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application’s attack surface, through to finding and exploiting security vulnerabilities.  Burp gives you full control, letting you combine advanced manual techniques with state-of-the-art [...]

6 comments

With the recent disclosures by the likes of ComodoHacker on Pastebin, it has now become important to monitor what kind of data is being hosted on Pastebin. This is where PasteLert comes in the picture. Sure there are other awesome tools and services such as The Pastebin Scraper and Pastenum, but they are not real time.
PasteLert is [...]

Be the first to comment!

Our first post about QuickRecon can be found here. Now, the author has released an update – QuickRecon version 0.3.2.
“QuickRecon is a simple information gathering tool that allows you to:

Bruteforce subdomains of a target domain
Perform zone transfer
Gather email addresses from google.com, groups.google.com and bing.com
Find human relationships using XHTML Friends Network (microformats)
Check a host (IP) in [...]

Be the first to comment!

Our first post regarding Skipfish can be found here. We now we have an update! The latest release is Skipfish version 2.03b!
“Skipfish is a fully automated, active web application security reconnaissance tool. Its key features:

High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint – easily achieving  2000 requests per second with responsive  targets.
Ease of use: heuristics to [...]

Be the first to comment!

Our first post regarding Skipfish can be found here. We now we have an update! The latest release is Skipfish version 2.02b!
“Skipfish is a fully automated, active web application security reconnaissance tool. Its key features:

High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint – easily achieving  2000 requests  per second with responsive  targets.
Ease of use: heuristics to [...]

Be the first to comment!