Showing posts with label Scan. Show all posts
Showing posts with label Scan. Show all posts

Sunday, July 27, 2014

Anubis | Online Malware Analysis

Anubis


Online Analyzing Unknown Binaries
Anubis is a service for Analyzing Malware

This can be done by Submit your any Windows executable file or Android APK and receive an analysis report telling you what it does.

Alternatively, submit a suspicious URL and receive a report that shows you all the activities of the Internet Explorer process when visiting this URL.

It's a good service that i used before a lot , especially for those who think that thier computer hacked by someone . by looking for any port Exist or specially by looking for (@no-ip.com) for any external access  .

After uploading the suspicious file , the report exists in four format Choose the txt view for simplicity .
Visit  Anubis Site : here


Anubis
Anubis


Saturday, July 26, 2014

Test Heartbleed bug

Heartbleed Bug

The Heartbleed Bug

The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. 
SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs).

The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.

for more info about the bug visit : http://heartbleed.com/

to test your site online for  Heartbleed Bug visit : https://filippo.io/Heartbleed/


Heartbleed Bug


DVWA (Dam Vulnerable Web Application)

DVWA



Dam Vulnerable Web Application

DVWA (Dam Vulnerable Web Application) 

This vulnerable PHP/MySQL web application is one of the famous web applications used for or testing your skills in web penetration testing and your knowledge in manual SQL Injection, XSS, Blind SQL Injection, etc. DVWA is developed by Ryan Dewhurst . he is ethical hacker and is part of RandomStorm OpenSource project.

download project : here



SQLMAP - Automatic SQL Injection Pentest tool

SQLMAP

Sqlmap Description

The tool is instructed to identify possible SQL injections and exploit them by enumerating and dumping entries of all databases' tables containing one or more of the columns specified by the user. sqlmap always stores dumped entries in a local CSV file upon successful dump. The technique used to dump this data from the back-end database software is the default, boolean-based blind SQL injection.

It is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of back-end database servers. It comes with a broad range of features lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.

download sqlmap : here


See the Official sqlmap video demonstration