Pages

Showing posts with label Download. Show all posts
Showing posts with label Download. Show all posts

Wednesday, April 13, 2011

Microsoft Office for Mac 2011 SP1 released

Microsoft Office for Mac 2011 Service Pack 1 (14.1.0) fixes critical issues and also helps to improve security.

It includes fixes for vulnerabilities that an attacker can use to overwrite the contents of your computer’s memory with malicious code. For detailed information about this update, please visit the Microsoft Web site.

Applies to:
  • Office 2011
  • Office 2011 Home and Business Edition
  • Word 2011
  • Excel 2011
  • PowerPoint 2011
  • Outlook 2011
  • Communicator 2011
  • Office for Mac Standard 2011 Edition
  • Microsoft Office for Mac Home & Student 2011
  • Microsoft Office for Mac Academic 2011.

BackTrack 5 will also be for Motorola Xoom

As of now, offensive-security have got a modified version of an Ubuntu 10.04 ARM image, chrooted on a Motorola Xoom. The tablet is running a modified, overclockable kernel (from 1.0 to 1.5 GHz). The chrooted BackTrack environment is running a VNC server, from which you can connect from the tablet itself. When run locally from the Xoom tablet, the VNC session does not lag, and the touch keyboard and touchscreen are very workable.
As expected from a chrooted environment, offensive-security are not using any custom drivers (for now), and injection and other related wireless attacks are NOT possible. Here’s a few screenshots we managed to scrounge from our dev box:

  • BackTrack on Motorola Xoom Screen 1

  • BackTrack on Motorola Xoom Screen 2

  • BackTrack on Motorola Xoom Screen 3

  • BackTrack on Motorola Xoom Screen 4

  • BackTrack on Motorola Xoom Screen 5

  • BackTrack on Motorola Xoom Screen 6

  • offensive-security hope to release a dev version of this image in a couple of weeks for other Xoom owners to play with. We’ll keep you posted !

    Tuesday, April 12, 2011

    Wireshark 1.5.1 Development Release !



    Wireshark 1.5.1 has been released. Installers for Windows, OS X, and source code are now available.

    New and Updated Features

    The following features are new (or have been significantly updated) since version 1.4:

    Monday, April 11, 2011

    OllyDbg 2.01 alpha 3 Released !



    A major update with many new features. Here are the most important:
    • - Support for multi-monitor configurations
    • - Hardware breakpoints and fast command emulation now co-operate. That is, run trace rund at full speed (up to and exceeding 500000 commands per second) even if there are hardware breakpoints set
    • - Purely conditional breakpoints during run trace are strongly accelerated

    Sqlmap v.0.9 - automatic SQL injection and database takeover tool !


    sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a kick-ass detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.

    Change Log :

    RawCap sniffer for Windows released



    We are today proude to announce the release of RawCap, which is a free raw sockets sniffer for Windows. Here are some highlights of why RawCap is a great tool to have in your toolset:

    • Can sniff any interface that has got an IP address, including 127.0.0.1 (localhost/loopback)
    • RawCap.exe is just 17 kB
    • No external libraries or DLL's needed
    • No installation required, just download RawCap.exe and sniff
    • Can sniff most interface types, including WiFi and PPP interfaces
    • Minimal memory and CPU load
    • Reliable and simple to use

    Usage
    RawCap takes two arguments; the first argument is the IP address or interface number to sniff from, the second is the path/file to write the captured packets to.

    C:\Tools>RawCap.exe 192.168.0.23 dumpfile.pcap
    You can also start RawCap without any arguments, which will leave you with an interactive dialog where you can select NIC and filename:

    Sunday, April 10, 2011

    WiFite The WEP/WPA Cracker version r68 released !



    Designed for Backtrack4 RC1 distribution of Ubuntu. Linux only; no windows or osx support.
    Purpose :
    to attack multiple WEP and WPA encrypted networks at the same time. this tool is customizable to be automated with only a few arguments. wifite can be trusted to run without supervision.
    Feature :

    • this project is available in French: all thanks goto Matt² for his excellent translation!
    • sorts targets by power (in dB); cracks closest access points first
    • automatically deauths clients of hidden networks to decloak SSIDs
    • numerous filters to specify exactly what to attack (wep/wpa/both, above certain signal strengths, channels, etc)
    • customizable settings (timeouts, packets/sec, channel, change mac address, ignore fake-auth, etc)
    • “anonymous” feature; changes MAC to a random address before attacking, then changes back when attacks are complete
    • all WPA handshakes are backed up to wifite.py’s current directory
    • smart WPA deauthentication — cycles between all clients and broadcast deauths
    • stop any attack with Ctrl+C — options: continue, move onto next target, skip to cracking, or exit
    • switching WEP attack methods does not reset IVs
    • intel 4965 chipset fake-authentication support; uses wpa_supplicant workaround
    • SKA support (untested)
    • displays session summary at exit; shows any cracked keys
    • all passwords saved to log.txt
    • built-in updater: ./wifite.py -upgrade
    Requirement : 
    • linux operating system (confirmed working on Ubuntu 8.10 (BT4R1), Ubuntu 10.04.1)
    • tested working with python 2.4.5 and python 2.5.2; might be compatible with other versions,
    • wireless drivers patched for monitor mode and injection: backtrack4 has many pre-patched drivers,
    • aircrack-ng (v1.1) suite: available via apt: apt-get install aircrack-ng or by clicking here,
    • xterm, python-tk module: required for GUI, available via apt: apt-get install python-tk
    • macchanger: also available via apt: apt-get install macchanger
    • pyrit: not required, optionally strips wpa handshake from .cap files

    Download Here...

    PenTBox 1.4 – Penetration Testing Security Suite Download


    PenTBox, a security framework written in Ruby and multiplatform (actually working even on iOS and Android!).

    Tools & Features (Updated)
    Technical features
    - GNU/GPLv3 License. Free in freedom and in price.
    - Multi-platform (Ruby: GNU/Linux, Windows, Mac OS, *BSD, iOS, Android, …).
    - Compatible with Ruby and JRuby.
    - Multithreading (native threads in Ruby >= 1.9 and JRuby).
    - Doesn’t require additional libraries (non standard are included).
    - Modular (easy to expand and customize).

    Tools (SVN Version)
    - Cryptography tools
    Base64 Encoder & Decoder
    Multi-Digest (MD5, SHA1, SHA256, SHA384, SHA512, RIPEMD-160)
    Hash Password Cracker (MD5, SHA1, SHA256, SHA384, SHA512, RIPEMD-160)
    Secure Password Generator
    - Network tools
    Net DoS Tester
    TCP port scanner
    Honeypot
    Fuzzer
    DNS and host gathering
    - Web
    HTTP directory bruteforce
    HTTP common files bruteforce

    A moderate number of people are using it and some important blogs have talked about it. A curious fact is that some people from anonymous use it for DoS attacks (but it isn't the most important part of the
    framework).

    You may like to talk about the tool.

    Website : http://www.pentbox.net/
    Sourceforge: http://sourceforge.net/projects/pentbox/

    Saturday, April 9, 2011

    DRIL : Domain Reverse IP Lookup Tool Download


    DRIL ( Domain Reverse IP Lookup ) Tool is a Reverse Domain Tool that will really useful for penetration testers to find out the domain names which are listed in the the target host, DRIL is a GUI, JAVA based application which use the Bing API key.DRIL has a simple user friendly which will be helpfull for penetration tester to do there work fast without a mess .this is only tested on linux still , been java it should work on windows to.

    There are online tools available, But many times due to slow internet connectivity we intend to get frustrated while audits. this tool is small and handy will not consume harddisk space So, its simply an good and fast altenative.

    How to run DRIL
    java -jar

    example

    java -jar “/home/treasure/DomainReverseIPLookup.jar”

    and it should open the application

    Download DRIL

    Cain & Abel 4.9.40 released , Download now !

    Cain & Abel 4.9.40 released , Download now !
    Cain & Abel is a password recovery tool for Microsoft operating systems.It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using dictionary and brute force attacks, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols.





    Changes in this version:

    • Added Proxy support for Cain's Certificate Collector.
    • Added the ability to specify custom proxy authentication credentials for Certificate Collector.
    • Added ProxyHTTPS Man-in-the-Middle Sniffer (TCP port 8080).
    • HTTP, APR-HTTPS and APR-ProxyHTTPS sniffer filters are now separated.
    • Added progress bar indicator in the off-line capture file function.
    • Bug fixed in ProxyHTTPS Man-in-the-Middle Sniffer parsing "Connection Established" string.
    • Bug fixed in VoIP Sniffer creating MP3 Mono files.
    • Bug fixed in RTP Sniffer processing off-line capture files.
    • WinRTGen recompiled with OpenSSL library version 0.9.8q.
    • OpenSSL library upgrade to version 0.9.8q.
    • Winpcap library upgrade to version 4.1.2.

    Thursday, April 7, 2011

    Hydra v6.2 with a password bruteforcing mode, xmpp and irc modules, MD5/SHA1/ Support !

    
     A very fast network logon cracker which support many different services.
     Have a look at the feature sets and services coverage page - including a speed comparison against ncrack and medusa! 
    
    CHANGELOG for 6.2
            * Added a patch by Jan Dlabal which adds password generation bruteforcing (no more password files :-) )
            * New module: XMPP with TLS negotiation and LOGIN, PLAIN, CRAM-MD5, DIGEST-MD5, SCRAM-SHA1 support
            * New module: IRC is not dead ! use to find general server password and /oper credential
            * Added man pages from debian maintainers
            * Add support for new syntax:
                ://[:][/]
            * Add TLS support for SIP
            * Add SCRAM-SHA1 auth to IMAP module
            * Add module usage help (-U)
            * Add support for RFC 4013: Internationalized Strings in SASL ("SASLPrep")
            * Add SASL + TLS support for NNTP
            * Add support for CRAM-MD5 and DIGEST-MD5 auth to ldap module
            * Add support for SCRAM-SHA1 (RFC 5802), first auth cracker to support it, yeah
            * Add TLS negotiation support for smtp-auth, pop3, imap, ftp and ldap
            * Rename smtpauth module to smtp
            * Forgot to rename ssh2 to ssh in xhydra, fixed
            * Fix SASL PLAIN auth method issue
            * Bugfix SASL DIGEST-MD5, response could be wrong on 64bits systems
            * Bugfix rlogin and rsh module, some auth failure could not be detected accurately
            * Add SSL support for VMware Authentication Daemon module
            * Bugfix CVS module, working now
            * Bugfix for Telnet module when line mode is not available
    
    
    
    Screenshots
    
     
     (1) Target selection
    
     
     (2) Login/Password setup
    
     
     (3) Hydra start and output
    
    
     The Art of Downloading: Source and Binaries
     
     1. The source code of state-of-the-art Hydra: hydra-6.2-src.tar.gz
        (compiles on all UNIX based platforms - even MacOS X, Cygwin on Windows, ARM-Linux, etc.)
    
     2. The source code of the stable tree of Hydra in case v6 gives you problems on unusual platforms:
        hydra-5.9.1-src.tar.gz
     
     3. The Win32/Cywin binary release: --- not anymore ---
        Install cygwin from http://www.cygwin.com
        and compile it yourself. If you do not have cygwin installed - how
        do you think you will do proper securiy testing? duh ...
    
            4. ARM and Palm binaries here are old and not longer maintained:
          ARM:  hydra-5.0-arm.tar.gz
                 Palm: hydra-4.6-palm.zip
     
    Powered by Blogger