background preloader

Scapy

Related:  Securitymatthewthibodeau

'Asleap - Cisco Attack Tool ' - SecuriTeam Published on April 8th, 2004 Details ‘In August 2003, Joshua wrote a tool called asleap for Linux systems to exploit a weakness in the Cisco LEAP authentication protocol. Using this tool, an attacker can actively compromise Cisco LEAP networks by mounting an offline dictionary attack against weak user passwords. In his testing, Joshua was able to search through large dictionary files very quickly for user passwords (~45 million passwords per second on meager hardware). A quick summary of asleap features are as follows: + Can read live from any wireless interface in RFMON mode with libpcap. + Can monitor a single channel, or perform channel hopping to look for target networks running LEAP. + Will actively de-authenticate users on LEAP networks, forcing them to re-authenticate. + Will only de-authenticate users who have not already been seen, doesn’t waste time on users who are not running LEAP. + Can read from stored libpcap files, or AiroPeek NX files (1.X or 2.X files).

OWASP FIGlet - hosted by PLiG Top Endpoint Detection & Response (EDR) Solutions for 2021 Check Point Software SandBlast Key takeaway: A good match for companies of all sizes seeking strong endpoint security at a good price point, particularly those who want their EDR solution to do some of the work for them. Check Point’s SandBlast offering was tied for second overall on the strength of its top-notch security and support at a good price. It received the highest score in Ease of Use and came in second in Management, and its automated response capability is also good, making it a strong candidate for smaller companies or those with less sophisticated security teams. In NSS Labs testing, SandBlast handled everything thrown at it, with the sole exception of targeted (hand-crafted) attacks, where it stopped 40%. It offers full-featured management, although users report some challenges with implementation. Check Point Ratings Pros: Automated responseEase of use and managementFull-featured at reasonable cost Cons: Custom rules missingSome implementation challenges reported SentinelOne

The Penetration Testing Execution Standard Welcome to whateversauce.com Ddrescue - GNU Project - Free Software Foundation (FSF) [ English | Español | Français | Italiano ] Introduction GNU ddrescue is a data recovery tool. It copies data from one file or block device (hard disc, cdrom, etc) to another, trying to rescue the good parts first in case of read errors. Ddrescuelog is a tool that manipulates ddrescue mapfiles, shows mapfile contents, converts mapfiles to/from other formats, compares mapfiles, tests rescue status, and can delete a mapfile if the rescue is done. The basic operation of ddrescue is fully automatic. If you use the mapfile feature of ddrescue, the data are rescued very efficiently, (only the needed blocks are read). Ddrescue does not write zeros to the output when it finds bad sectors in the input, and does not truncate the output file if not asked to. Automatic merging of backups: If you have two or more damaged copies of a file, cdrom, etc, and run ddrescue on all of them, one at a time, with the same output file, you will probably obtain a complete and error-free file. Documentation Download

STIGs Home The Security Technical Implementation Guides (STIGs) are the configuration standards for DOD IA and IA-enabled devices/systems. Since 1998, DISA has played a critical role enhancing the security posture of DoD's security systems by providing the Security Technical Implementation Guides (STIGs). The STIGs contain technical guidance to "lock down" information systems/software that might otherwise be vulnerable to a malicious computer attack. Questions or comments?Please contact DISA STIG Customer Support Desk: disa.stig_spt@mail.mil

OpenVAS - OpenVAS - Open Vulnerability Assessment Scanner

Related: