Tuesday, 7 January 2014

[MoonSols] Windows Memory Toolkit


MoonSols Windows Memory Toolkit is a powerful toolkit containing all the utilities needed to perform any kind of memory acquisition or conversion during an incident response, or a forensic analysis for Windows desktops, servers or virtualized environment. The version 2.0 is a refresh and updated version of our software to reply to the evolving needs of our clients and assist them to deliver in a strategic and professional way.

MoonSols Windows Memory Toolkit had been designed to deal with Microsoft Windows hibernation file (from Microsoft Windows XP to Microsoft Windows 8 in both 32-bits and 64-bits (x64) Editions), Microsoft full memory crashdump (in both 32-bits and 64-bits (x64) Editions), and raw memory dump files (from memory acquisition tools like DumpIt or Virtualization application like VMWare). Moreover, MoonSols Windows Memory Toolkit also contains new version of DumpIt.

MoonSols Windows Memory Toolkit main point is that Microsoft full memory crashdump had been designed by Microsoft as the “physical memory format” which aims at being analyzed by Microsoft Windows Debugger (the most powerful utility to troubleshoot problems, analyze physical memory etc.). The goal of MoonSols Windows Memory Toolkit is to make possible to convert all Windows physical memory dumps into Microsoft Crash dump compliant with Microsoft Windows Debugger (WinDbg).

With MoonSols Windows Memory Toolkit you can convert any Windows memory dump file in a Microsoft crash dump file readable by Microsoft Windows Debugger. Moreover, you can also decompress complex memory dumps such as Windows XP x64 hibernation file as well as Windows 7 x64 Hibernation file.

The MoonSols Windows Memory Toolkit 2.0 works on every Microsoft Windows version, from Microsoft Windows XP to Microsoft Windows 8 (both x86 and x64 Edition).

The MoonSols Windows Memory Toolkit 2.0 contains an improved version of win32dd and win64dd called DumpIt, which can be used from the external paths and and can be called from scripts to make your life easier. Moreover, an interactive command-live version is provided to users.

The toolkit contains several utilities such as DumpIt for live acquisition on a local disk file or to a remote target, or like hibr2dmp/bin2dmp to create a synergetic ecosystem within all the different file formats used by memory snapshots files such as Windows hibernation file and Microsoft crash memory dumps analysable by Microsoft WinDbg.

MoonSols Windows Memory Toolkit contains:
  • MoonSols DumpIt 2.0
  • MoonSols Hibr2Bin 2.0
  • MoonSols Hibr2Dmp 2.0
  • MoonSols Dmp2Bin 2.0
  • MoonSols Bin2Dmp 2.0
MoonSols DumpIt replaces MoonSols Win32dd and Win64dd, the utility also has full 32-bits and 64-bits Windows 8 support and new features such as LZNT1 compression and RC4 encryption.

The utilities Hibr2Bin and Hibr2Dmp also have 32-bits and 64-bits Windows 8 support.

[Network Password Decryptor v6.5] Windows Network Password Recovery Tool


Network Password Decryptor is the free tool to instantly recover network authentication passwords.


In addition to the network authentication passwords it can also recover passwords stored by other windows apps such as Outlook, Windows Live Messenger, Remote Destktop etc.

These network passwords are stored in encrypted format and even administrator cannot view these passwords. Also some type of passwords cannot be decrypted even by administrators as they require special privileges. Network Password Decryptor automatically detect and decrypt all these stored network passwords.

[DAVOSET] Tool for conducting DDoS attacks

DAVOSET – it is console (command line) tool for conducting DDoS attacks on the sites via Abuse of Functionality vulnerabilities at other sites.

Changelog v1.1.5
  • Added error handler in GetCookie().
  • Added new services into lists of zombies.
  • Removed non-working services from lists of zombies.
Usage
1. Start the program: davoset.pl
2. Enter URL of the site to attack: Site: http://site
3. Get the site attacked via your list of zombie-servers.
Or from command line:
perl davoset.pl u=http://site
perl davoset.pl u=http://site l=list.txt m=1 c=100

[Creepy] Geolocation information Gathering through Social Networking Platforms


Creepy is a geolocation OSINT tool. Gathers geolocation related information from online sources, and allows for presentation on map, search filtering based on exact location and/or date, export in csv format or kml for further analysis in Google Maps.

What's new in v1.0.x ?

  • Creepy now uses Qt 4, via it's PyQt4 bindings for the user interface.
  • Analysis in based on projects, you can work with multiple targets simultaneously without having to re-analyze them.
  • Creepy is extensible via plugins for online services that might hold geolocation information. See Creepy Plugins Repository
  • Plugins for twitter, instagram and flickr are included in this release
  • Easy plugin configuration with wizards, where applicable
  • After analysis, the retrieved locations can be filtered based on the date that they were created or the proximity to a certain location
  • Google maps is used as a maps provider ( Street view included within Creepy ! )

Quick Start Instructions

  • Download creepy ( source code or the installers provided here for your platform )
  • Configure twitter and instagram plugins. Edit -> Plugins Configuration -> Twitter / Instagram and run the wizards, following the instructions
  • Create a new project : Creepy -> New Project -> Person Based Project . Search for the target selecting the available plugins.
  • Right click on the project -> Analyze Current Project
  • Wait :)
  • The locations will be drawn on the map, once the analysis is complete.
  • Filter locations, export locations, view them on the map.

[FoxAnalysis] Firefox Internet History Analysis Software


FoxAnalysis Plus is a software tool for extracting, viewing and analysing internet history from the Mozilla Firefox web browser. The main features are described below:
  
Extract History  ::
Extract history regarding bookmarks, cookies, downloads, favicons, form entries, logins, saved sessions and website visits.   

Case Files  ::
Each Firefox profile analysed can be saved to a Case file for further analysis at a later date.   

Supports Firefox versions 3 to 24  ::
Extract history generated from Firefox versions 3 to 24 (new versions are added regularly). 

Cache ::
The built-in image viewer can be used to view images from the cache. Images, web pages and other files from the cache can also be extracted.


Saved Sessions ::
Analyse current and last session data such as open windows and tabs, cookies and text typed into forms. Session data not displayed within a table can be analysed using the tree viewer. 


Web History Timeline ::
Website visits can be viewed in a navigable timeline structure for easily viewing the time and order that websites were visited. 


Web Page Reconstruction ::
Web pages stored in the cache can be reconstructed using other resource files from the cache. This allows the web page to be viewed in the state it was originally accessed. A report is also provided summarising how the web page was reconstructed. 


Filtering ::
Analyse the extracted data with filtering by keyword, date range, download status, website visit or selection. Lists of keyword filters can also be saved and loaded. 


Reporting ::
Generate reports in HTML, CSV and XML format. 


Time Zone and DST Settings ::
Convert UTC timestamps to any time zone and apply custom daylight saving settings.  


[Arachni v0.4.6 - Web User Interface v0.4.3] Open Source Web Application Security Scanner Framework


Arachni is a feature-full, modular, high-performance Ruby framework aimed towards helping penetration testers and administrators evaluate the security of web applications.

Arachni is smart, it trains itself by learning from the HTTP responses it receives during the audit process.

Unlike other scanners, Arachni takes into account the dynamic nature of web applications and can detect changes caused while travelling

through the paths of a web application’s cyclomatic complexity.

This way attack/input vectors that would otherwise be undetectable by non-humans are seamlessly handled by Arachni.


Changelog

Framework v0.4.6
  • Massively decreased RAM consumption.
  • Amount of performed requests cut down by 1/3 — and thus 1/3 decrease in scan times.
  • Overhauled timing attack and boolean/differential analysis algorithms to fix SQLi false-positives with misbehaving webapps/servers.
  • Vulnerability coverage optimizations with 100% scores on WAVSEP’s tests for:
    • SQL injection
    • Local File Inclusion
    • Remote File Inclusion
    • Non-DOM XSS — DOM XSS not supported until Arachni v0.5.
WebUI v0.4.3
  • Implemented Scan Scheduler with support for recurring scans.
  • Redesigned Issue table during the Scan progress screen, to group and filter issues by type and severity.

[Xelenium] Security Testing with Selenium


Xelenium is a security testing tool that can be used to identify the security vulnerabilities present in the web application. Xelenium uses the open source functional test automation tool 'Selenium' as its engine and has been built using Java swing.

Xelenium has been designed considering that it should obtain very few inputs from users in the process of discovering the bugs.


Selenium – Webdriver is an open source functional testing tool and is very powerful and flexible. More details on Selenium can be found here: http://seleniumhq.org/