Thursday, June 27, 2013

Biggest password cracking wordlist with millions of words

One of the biggest and very comprehensive collection of 1,493,677,782 word for Password cracking list released for download. The wordlists are intended primarily for use with password crackers such as hashcat, John the Ripper and with password recovery utilities.
Defuse Security have released the wordlist of 4.2 GiB (compressed) or 15 GiB (uncompressed) used by their Crackstation project.


You can also download it from Torrent.

Saturday, May 18, 2013

BRUTEFORCE GMAIL PASSWORD WITH BACKTRACK 5 R3


BruteForce is the easiest way to hack an Gmail account password. That’s why you can find many queries on web asking for a working BruteForce.In this tutorial I will show you how to BruteForce gmail password with THC Hydra on BackTrack 5 R3.


MAKE YOUR WORDLIST


SQL POIZON - SQLI EXPLOIT SCANNER TOOL



Sql Poizon tool includes php , asp , rfi , lfi dorks and using this tools you can find vulnerable sites like sql vulnerable sites and you can also find vulnerable sites by country and you can hack sql vulnerable sites using Sql Poizon tool and you can also browse the sites using this tool.

DOWNLOADSQL Poizon here


NMAP (NETWORK MAPPER)

Nmap (Network Mapper) is a security scanner originally written by Gordon Lyon (also known by his pseudonym Fyodor Vaskovich) [1] used to discover hosts and services on a computer network, thus creating a "map" of the network. To accomplish its goal, Nmap sends specially crafted packets to the target host and then analyzes the responses. Unlike many simple port scanners that just send packets at so me predefined constant rate, Nmap accounts for the network conditions (latency fluctuations, network congestion, the target interference with the scan) during the run. Also, owing to the large and active user community providing feedback and contributing to its features, Nmap has been able to extend its discovery capabilities beyond simply figuring out whether a host is up or down and which ports are open and closed; it can determine the operating system of the target, names and versions of the listening services, estimated uptime, type of device, and presence of a firewall.


W3AF WEB SCANNER


w3af is an open-source web application security scanner. The project provides a vulnerability scanner and exploitation tool for Web applications.It provides information about security vulnerabilities and aids in penetration testing efforts.

This cross-platform tool is available in all of the popular operating systems such as Microsoft Windows, Linux,Mac OS X, FreeBSD and OpenBSD and is written in the Python programming language. Users have the choice between a graphic user interface and a command-line interface.

w3af identifies most web application vulnerabilities using more than 130 plug-ins. After identification, vulnerabilities like (blind) SQL injections, OS commanding, remote file inclusions (PHP), cross-site scripting(XSS), and unsafe file uploads, can be exploited in order to gain different types of access to the remote system.

WEBSPLOIT

WebSploit Is An Open Source Project For Scan And Analysis Remote System From Vulnerability

[+]Autopwn - Used From Metasploit For Scan and Exploit Target Service
[+]wmap - Scan,Crawler Target Used From Metasploit wmap plugin
[+]format infector - inject reverse & bind payload into file format
[+]phpmyadmin - Search Target phpmyadmin login page
[+]lfi - Scan,Bypass local file inclusion Vulnerability & can be bypass some WAF
[+]apache users - search server username directory (if use from apache webserver)
[+]Dir Bruter - brute target directory with wordlist
[+]admin finder - search admin & login page of target
[+]MLITM Attack - Man Left In The Middle, XSS Phishing Attacks
[+]MITM - Man In The Middle Attack
[+]Java Applet Attack - Java Signed Applet Attack
[+]MFOD Attack Vector - Middle Finger Of Doom Attack Vector
[+]USB Infection Attack - Create Executable Backdoor For Infect USB For Windows

DOWNLOAD LINK: http://adf.ly/Ni5sA

PROXYSTRIKE

One tool that i find useful in detecting sql injection flaws is proxystrike. Proxystrike is a proxy/scanner that looks for sql and xss vulnerabilities. From the proxystrike documentation

TUTORIAL FOR THIS: http://www.youtube.com/watch?v=2fdfE6uELkg