background preloader

Tools

Facebook Twitter

BackTrack 5 Wireless Penetration Testing Beginner's Guide. Posted on 15 September 2011.

BackTrack 5 Wireless Penetration Testing Beginner's Guide

Wireless technologies are inherently insecure and can be easily broken. BackTrack is a penetration testing and security auditing distribution that comes with a myriad of wireless networking tools used to simulate network attacks and detect security loopholes. Backtrack 5 Wireless Penetration Testing Beginner’s Guide will teach you various wireless testing methodologies taught using live examples, which you will implement throughout this book. Protect The Stuff - Why You Need Norton. A Handy Guide To Microsoft's Free Security Tools. Microsoft publishes a range of free security-related software.

A Handy Guide To Microsoft's Free Security Tools

One of the best-known is Security Essentials, the excellent antivirus/antimalware product which was recently updated to version 2.0. Many of the other products in the collection are aimed primarily at large business customers, and are not of general interest to anyone else. But of the handful of exceptions, MBSA has always stood out for me. Nmap - Free Security Scanner For Network Exploration & Security Audits.

McAfee Downloads. Google Builds Developer Tool to Flag Web App Vulnerabilities. Google has released an experimental extension for its Chrome browser that developers can use to scan their Web applications and flag code that could make them vulnerable to malware attacks.

Google Builds Developer Tool to Flag Web App Vulnerabilities

The free tool, called DOM Snitch, is designed to sniff out potential security holes in Web applications' client-side code that could be exploited by attacks such as client-side scripting, Google said on Tuesday. "To do this, we have adopted several approaches to intercepting JavaScript calls to key and potentially dangerous browser infrastructure such as document.write or HTMLElement.innerHTML," Google official Radoslav Vasilev wrote in a blog post.

In addition to developers, DOM Snitch is also aimed at code testers and security researchers, the company said. The tool displays DOM (document object model) modifications in real time so developers don't have to pause the application to run a debugging tool, according to Google. The LiveCD List. Remove Spyware, Malware, Viruses Free. How To Hide A File Inside Calculator [Security] Sometimes a person needs to hide an important file somewhere in order to protect it from unauthorized access.

How To Hide A File Inside Calculator [Security]

Making it only hidden is not the best way to hide an important file since it can be accessed by using powerful 3rd party search tools. Why not hide the file inside a calculator? Safe Calculator does exactly that. It is a portable tool that is both a calculator and a secret safe. You can save only one file inside it, if you have multiple files, you can zip them and then save it inside the calculator. Update: This post is just for fun, it won’t really hide large files. Running Snort Under Windows. Loras R.

Running Snort Under Windows

Even Updated by Jim McMillan November 2009 Snort is an open source intrusion detection/prevention system created by Martin "Marty" Roesch, founder of Sourcefire. It is capable of performing real-time traffic analysis and logging. It is the most widely used IDS/IPS system. Scapy. Product Watch: New Tool Automatically Examines Suspicious Code In Memory.

Website Security Check - Unmask Parasites. Security Research by Dan Rosenberg. Since the beginning of the media frenzy over CarrierIQ, I have repeatedly stated that based on my knowledge of the software, claims that keystrokes, SMS bodies, email bodies, and other data of this nature are being collected are erroneous.

Security Research by Dan Rosenberg

I have also stated that to satisfy users, it’s important that there be increased visibility into what data is actually being collected on these devices. This post represents my findings on how CarrierIQ works, and what data it is capable of collecting. There has been a lot of misinformation about which parties are responsible for which aspects of data collection. At a high level, CarrierIQ is a piece of software installed on phones that accepts pieces of information known as metrics. On receiving a submitted metric, CIQ evaluates whether that metric is “interesting” based on the current profile installed on the device.

To get a complete picture of this, suppose a carrier decides it wants to know about dropped calls. Firewall_Browser_Annoucement-20100310.pdf (application/pdf Object) SolarWinds Firewall Security Manager (FSM) delivers the advanced firewall management capabilities required by today’s ever-evolving security and compliance mandates and increasingly complex rulesets.

Firewall_Browser_Annoucement-20100310.pdf (application/pdf Object)

Remember, security and compliance are not one-time projects, but ongoing processes that must be maintained, which is why having the right management tool is vital! Windows XP - Netstat. Repair Tool of the Week: Add Remove Programs Cleaner. CurrPorts Freeware download and reviews from SnapFiles. CIRT.net. Nikto is sponsored by Netsparker, a dead accurate and easy to use web application security solution.

CIRT.net

Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 6700 potentially dangerous files/programs, checks for outdated versions of over 1250 servers, and version specific problems on over 270 servers. It also checks for server configuration items such as the presence of multiple index files, HTTP server options, and will attempt to identify installed web servers and software. Scan items and plugins are frequently updated and can be automatically updated. Google Hands Out Web Security Scanner. Burp Suite. Burp Suite is an integrated platform for performing security testing of web applications.

Burp Suite

Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application's attack surface, through to finding and exploiting security vulnerabilities. Burp gives you full control, letting you combine advanced manual techniques with state-of-the-art automation, to make your work faster, more effective, and more fun. Burp Suite contains the following key components: Psad - Intrusion Detection with iptables, iptables Log Analysis, iptables Policy Analysis. Psad: Intrusion Detection and Log Analysis with iptables psad is a collection of three lightweight system daemons (two main daemons and one helper daemon) that run on Linux machines and analyze iptables log messages to detect port scans and other suspicious traffic.

psad - Intrusion Detection with iptables, iptables Log Analysis, iptables Policy Analysis

A typical deployment is to run psad on the iptables firewall where it has the fastest access to log data. psad incorporates many signatures from the Snort intrusion detection system to detect probes for various backdoor programs (e.g. EvilFTP, GirlFriend, SubSeven), DDoS tools (mstream, shaft), and advanced port scans (FIN, NULL, XMAS) which are easily leveraged against a machine via nmap. When combined with fwsnort and the Netfilter string match extension, psad is capable of detecting many attacks described in the Snort rule set that involve application layer data. For the second example, psad interfaces with Gnuplot to produce a graph of the number of TCP SYN packets to destination ports per hour.

History. Five Best Malware Removal Tools. @gapo: I disagree. Many infections are pretty minor and can be easily removed with these tools with no damage afterwards. I mean, yeah, for some, that is the best option, but no need to just do that all the time. Extra work for nothing. Offers a free tool that completely removes the Conficker/Downadup worm from home and business networks. March 2009 Demonstration of the removal tool available on YouTube BitDefender has launched a free tool that removes all versions of the Conficker (or Downadup) worm on both home workstations and business networks. The removal tool can be accessed at bdtools.net . While BitDefender▓s Conficker removal tool was first available for home users last week, the company has added a similar removal tool for business networks this week.

Md5.rednoize.com - reverse engineer md5 hashes - powered by rednoize.com. Metasploit Unleashed By Offensive Security. Various tools. QFX Software - Anti-Keylogging Software and More. Product Watch: New Tool Automatically Examines Suspicious Code In Memory. Sophos offering free data-loss prevention software. Dvdisaster. Website Security Check - Unmask Parasites. BackTrack Linux - Penetration Testing Distribution. Kaminsky Issues Developer Tool To Kill Injection Bugs. Anti Rootkit Software - Helios. Home > Software Helios Helios is an advanced malware detection system has been designed to detect, remove and innoculate against modern rootkits. What makes it different from conventional antivirus / antispyware products is that it does not rely on a database of known signatures. We believe that malware, by definition, has to perform malicious actions on your system.

By observing which software performs malicious behaviour, you can better detect malware. The key features of Helios are: