background preloader

SEC TECH

Facebook Twitter

Network Monitoring. VMware or Microsoft? – The Complete Series - Full of I.T. C (if that is your real name) - You really should read some of the articles in the series. VMware still doesn't have what Microsoft has had in-market for a year now with Hyper-V in Windows Server 2012 and Hyper-V Server 2012. In a recent internal e-mail, Jeff Woolsey provided us a short list (with extended commentary that I've left out) of some features that Microsoft has in-market, even without considering what's added or improved in the up-coming R2 release: 1.

Proper Virtual Fibre Channel. Specifically, presenting an honest to goodness virtual fibre channel HBA in the guest. 2. 3. 4. 5. 6. 7. 8. 9. This short list above compares what Microsoft shipped LAST YEAR in Windows Server 2012 to what VMware is going to ship with vSphere 5.5. Sincerely, I invite you put aside what I know for many IT Pros is literally YEARS of (what were once) valid assumptions on who the leader in datacenter virtualization is, and do a fresh re-evaluation. Free penetration testing tools. This application combines a few tools and enables you to condcuct a security audit on web applications. The main feature is a very comprehensive list to detect default installation files (by forced directory browsing) on various application- and web servers or CMS (like Apache Dojo, Apache Tomcat, Citrix, Cold Fusion, ContentXXL, Drupal, Fatwire, Websphere, IIS, J2EE, Jira, Jboss, Joomla, Lotus Domino, Novell, Oracle, Piwik, Plumtree, SAP, Typo3, Wordpress etc.).

A dedicated Juniper HTTPS VPN Scanner is provided within SWAT as well as a HTTP method scanner (PUT, DELTE, OPTIONS, PROFIND, etc.) Installation: you will need .NET 4.0 (keep in mind win7 by default has only .NET 3.5!) XP, Vista, Win 7 This tool identifies various vulnerabilities on a remote SMTP server (testing the remote SMTP deamon as well as external DB's). Tests include mail spoofing checks, attachment filtering capabilities, user verifications, black list queries, SPF queries, Open relays etc.) . Swat-web-security-scanner - windows scanner to identify sensitives web server files, methods etc. What it does This application combines a few tools and enables you to condcuct a security audit on web applications. The main feature is a very comprehensive list to detect default installation files (by forced directory browsing) on various application- and web servers or CMS (like Apache Dojo, Apache Tomcat, Citrix, Cold Fusion, ContentXXL, Drupal, Fatwire, Websphere, IIS, J2EE, Jira, Jboss, Joomla, Lotus Domino, Novell, Oracle, Piwik, Plumtree, SAP, Typo3, Wordpress etc.).

Addons A dedicated Juniper HTTPS VPN Scanner is provided within SWAT as well as a HTTP method scanner (PUT, DELTE, OPTIONS, PROFIND, etc.). Installation you will need .NET 4.0 (keep in mind win7 by default has only .NET 3.5!) Screenshots Troubleshooting On Windows 8 or when executed as a Standard user you might find an error saying that Settings.xml Access was denied. Manual Can be obtained here: Download You can download the source by clicking on "Source". Other tools. Smtp-security-scanner - This tool identifies various vulnerabilities on a remote SMTP server (testing the remote SMTP deamon as well as external DB's). What it does This windows tool identifies various vulnerabilities on a remote SMTP server (testing the remote SMTP deamon as well as external DB's).

Tests include mail spoofing checks, attachment filtering capabilities, user verifications, black list queries, SPF queries, Open relays etc.) . Install Just exctract all files to the directory of your choice and run the stanalone exe. Included in this tool is a sample set of malicious attachements (docs, pdf, xls etc.) that contain harmless exploits that can act as a proof of concept. A complete list of attachments to conduct a mail filter test can be obtained on request. Screenshots Download You can download the source by clicking on "Source". Other tools You might wanna check out other tools from us (come back soon - list is growing and plenty of other tools waiting to be uploaded!) Ipv6-portable-portscanner - windows standalone portable portscanner ipv6. Background info Ever needed a small portable portscanner that does not require any installation and is able to scan IPv6 hosts?

When you start testing f.ex. microsoft direct access and you feel like scanning hosts within the infrastructure tunnel this tool will definitly come handy. You need to start with system user to be able to scan within an infrastructure tunnel in windows. Use systintenal tools to start portscanner as system.... use It is a standalone portable exe that does not need any special priviledges. Screenshot Download You can download the source by clicking on "Source". Other tools You might wanna check out other tools from us (come back soon - list is growing and plenty of other tools waiting to be uploaded!) Android-security-demo-app - app and webserver to demonstrate how to control a remote phone via webserver. Background Info If you once had the time to read the Blackhat "Adventures in Bouncerland" whitepaper ( regarding official APPS that spy on Android Smartphones we got some news for you: no - we didn't write another whitepaper.

We did a nice smooth app itsself: record phones, sms, track location changes, silently take pictures etc. and watch all the fun beeing uploaded to a webconsole from where you control the smartphone with dynamic updates using WEBVIEW. what is included here? This software consists of three parts: source for installing app on android device (in AndroidAntiTheft folder) webserver with all necessary scripts/files to control remote phone (in admin_panel folder) DB (in folder DB) additionally a older compiled apk file is attached a swell - ready to download and install on your device. what it does the application "acts" as an antitheft software. Use Screenshots Download Other tools. Dns-information-gathering-tool - This free tool do an information gathering based on a domain name.

What it does This free tool do an information gathering based on a domain name. Checks: subdomain check, mx, ns records, spdf, shared hosting, tld and much more.... installation just extract all files to the same directory and run the exe. No installation required. screenshots Download You can download the source by clicking on "Source". Other tools You might wanna check out other tools from us (come back soon - list is growing and plenty of other tools waiting to be uploaded!)