<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Hacking Tools</title>
	<atom:link href="http://www.darknet.org.uk/category/hacking-tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Thu, 19 Nov 2009 10:29:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Katana v1 (Kyuzo) &#8211; Portable Multi-Boot Security Suite</title>
		<link>http://www.darknet.org.uk/2009/11/katana-v1-kyuzo-portable-multi-boot-security-suite/</link>
		<comments>http://www.darknet.org.uk/2009/11/katana-v1-kyuzo-portable-multi-boot-security-suite/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 09:46:28 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[boot from usb]]></category>
		<category><![CDATA[damn small linux]]></category>
		<category><![CDATA[damn-vulnerable-linux]]></category>
		<category><![CDATA[dvl]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[got root]]></category>
		<category><![CDATA[hack from a cave]]></category>
		<category><![CDATA[hackfromacave]]></category>
		<category><![CDATA[hijackthis]]></category>
		<category><![CDATA[honey pots]]></category>
		<category><![CDATA[katana kyuzo]]></category>
		<category><![CDATA[katana v1]]></category>
		<category><![CDATA[mult-boot security distro]]></category>
		<category><![CDATA[ollydbg]]></category>
		<category><![CDATA[Ophcrack]]></category>
		<category><![CDATA[ophcrack live]]></category>
		<category><![CDATA[oswa]]></category>
		<category><![CDATA[pen-testing]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[UBCD]]></category>
		<category><![CDATA[unstoppble copier]]></category>
		<category><![CDATA[usb security tools]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2298</guid>
		<description><![CDATA[The Katana: Portable Multi-Boot Security Suite is designed to fulfill many of your computer security needs. The idea behind this tool is to bring together many of the best security distributions and applications to run from one USB Flash Drive.  Instead of keeping track of dozens of CDs and DVDs loaded with your favorite [...]]]></description>
			<content:encoded><![CDATA[<p>The Katana: Portable Multi-Boot Security Suite is designed to fulfill many of your computer security needs. The idea behind this tool is to bring together many of the best security distributions and applications to run from one USB Flash Drive.  Instead of keeping track of dozens of CDs and DVDs loaded with your favorite security tools, you can keep them all conveniently in your pocket.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text";
google_ad_channel ="9647861209";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Katana includes distributions which focus on Penetration Testing, Auditing, Password Cracking, Forensics and Honey Pots. Katana comes with over 100 portable Windows applications, such as Wireshark, HiJackThis, Unstoppable Copier, Firefox, and OllyDBG.  It also includes the following distributions:</p>
<ul>
<li>Backtrack 4 pre</li>
<li>the Ultimate Boot CD</li>
<li>Ophcrack Live</li>
<li>Damn Small Linux</li>
<li>the Ultimate Boot CD for Windows</li>
<li>Got Root? Slax</li>
<li>Organizational Systems Wireless Auditor (OSWA) Assistant</li>
<li>Damn Vulnerable Linux</li>
</ul>
<p><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text";
google_ad_channel ="9647861209";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Katana is also highly customizable.  You can modify Katana by adding or removing distributions and portable apps with ease.  You can add functionality to distributions like the Ultimate Boot CD, Got Root? Slax and UBCD4Win.  You can also load your personal scripts and documents to keep them conveniently with<br />
you on your flash drive to use in concert with the provided tools.</p>
<p>You can download Katana v1 here:</p>
<p><a href="http://gextrade.thegoodhacker.com/katana/katana-v1.rar">katana-v1.rar</a></p>
<p>Or read more <a href="http://www.hackfromacave.com/katana.html">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Katana+v1+%28Kyuzo%29+%E2%80%93+Portable+Multi-Boot+Security+Suite+http://bit.ly/274uxG+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/11/katana-v1-kyuzo-portable-multi-boot-security-suite/&amp;title=Katana+v1+%28Kyuzo%29+%E2%80%93+Portable+Multi-Boot+Security+Suite" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/11/katana-v1-kyuzo-portable-multi-boot-security-suite/&amp;title=Katana+v1+%28Kyuzo%29+%E2%80%93+Portable+Multi-Boot+Security+Suite" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/11/katana-v1-kyuzo-portable-multi-boot-security-suite/&amp;t=Katana+v1+%28Kyuzo%29+%E2%80%93+Portable+Multi-Boot+Security+Suite" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/11/katana-v1-kyuzo-portable-multi-boot-security-suite/&amp;title=Katana+v1+%28Kyuzo%29+%E2%80%93+Portable+Multi-Boot+Security+Suite" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/11/katana-v1-kyuzo-portable-multi-boot-security-suite/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Cain &amp; Abel v4.9.35 &#8211; Password Sniffer, Cracker and Brute-Forcing Tool</title>
		<link>http://www.darknet.org.uk/2009/11/cain-abel-v4-9-35-password-sniffer-cracker-and-brute-forcing-tool/</link>
		<comments>http://www.darknet.org.uk/2009/11/cain-abel-v4-9-35-password-sniffer-cracker-and-brute-forcing-tool/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 06:47:31 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[abel]]></category>
		<category><![CDATA[arp poison routing]]></category>
		<category><![CDATA[arp sniffer]]></category>
		<category><![CDATA[arp spoofing tool]]></category>
		<category><![CDATA[arp-spoofing]]></category>
		<category><![CDATA[brute forcing tool]]></category>
		<category><![CDATA[brute-force]]></category>
		<category><![CDATA[brute-forcing]]></category>
		<category><![CDATA[cain]]></category>
		<category><![CDATA[cain&abel]]></category>
		<category><![CDATA[cain-&-abel]]></category>
		<category><![CDATA[Cain-and-Abel]]></category>
		<category><![CDATA[cracking passwords]]></category>
		<category><![CDATA[network-cracker]]></category>
		<category><![CDATA[network-cracking]]></category>
		<category><![CDATA[network-sniffing]]></category>
		<category><![CDATA[password cracking tool]]></category>
		<category><![CDATA[password decoder]]></category>
		<category><![CDATA[password-cracker]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[windows hacking tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2234</guid>
		<description><![CDATA[It&#8217;s been quite a while since we&#8217;ve written about Cain &#038; Abel, one of the most powerful tools for the Windows platform (back in 2007 here).
Cain &#038; Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been quite a while since we&#8217;ve written about Cain &#038; Abel, one of the most powerful tools for the Windows platform (back in 2007 <a href="http://www.darknet.org.uk/2007/01/cain-abel-download-the-super-fast-and-flexible-password-cracker-with-network-sniffing/">here</a>).</p>
<p>Cain &#038; Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords and analyzing routing protocols. The program does not exploit any software vulnerabilities or bugs that could not be fixed with little effort. It covers some security aspects/weakness present in protocol&#8217;s standards, authentication methods and caching mechanisms; its main purpose is the simplified recovery of passwords and credentials from various sources, however it also ships some &#8220;non standard&#8221; utilities for Microsoft Windows users.</p>
<p><!--adsense#New468--></p>
<p>Cain &#038; Abel has been developed in the hope that it will be useful for network administrators, teachers, security consultants/professionals, forensic staff, security software vendors, professional penetration tester and everyone else that plans to use it for ethical reasons. The author will not help or support any illegal activity done with this program. Be warned that there is the possibility that you will cause damages and/or loss of data using this software and that in no events shall the author be liable for such damages or loss of data. Please carefully read the License Agreement included in the program before using it.</p>
<p>The latest version is faster and contains a lot of new features like APR (Arp Poison Routing) which enables sniffing on switched LANs and Man-in-the-Middle attacks. The sniffer in this version can also analyze encrypted protocols such as SSH-1 and HTTPS, and contains filters to capture credentials from a wide range of authentication mechanisms. The new version also ships routing protocols authentication monitors and routes extractors, dictionary and brute-force crackers for all common hashing algorithms and for several specific authentications, password/hash calculators, cryptanalysis attacks, password decoders and  some not so common utilities related to network and system security.</p>
<p><!--adsense#New468--></p>
<p>Most recently added is the support for Windows 2008 Terminal Server in APR-RDP sniffer filter.</p>
<p>You can download Cain &#038; Abel v4.9.35 here:</p>
<p><a href="http://www.oxid.it/downloads/ca_setup.exe">ca_setup.exe</a></p>
<p>Or read more <a href="http://www.oxid.it/cain.html">here</a>, the online user manual is <a href="http://www.oxid.it/ca_um/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Cain+%26+Abel+v4.9.35+%E2%80%93+Password+Sniffer%2C+Cracker+and+Brute-Forcing+Tool+http://bit.ly/1MhNoy+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/11/cain-abel-v4-9-35-password-sniffer-cracker-and-brute-forcing-tool/&amp;title=Cain+%26+Abel+v4.9.35+%E2%80%93+Password+Sniffer%2C+Cracker+and+Brute-Forcing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/11/cain-abel-v4-9-35-password-sniffer-cracker-and-brute-forcing-tool/&amp;title=Cain+%26+Abel+v4.9.35+%E2%80%93+Password+Sniffer%2C+Cracker+and+Brute-Forcing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/11/cain-abel-v4-9-35-password-sniffer-cracker-and-brute-forcing-tool/&amp;t=Cain+%26+Abel+v4.9.35+%E2%80%93+Password+Sniffer%2C+Cracker+and+Brute-Forcing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/11/cain-abel-v4-9-35-password-sniffer-cracker-and-brute-forcing-tool/&amp;title=Cain+%26+Abel+v4.9.35+%E2%80%93+Password+Sniffer%2C+Cracker+and+Brute-Forcing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/11/cain-abel-v4-9-35-password-sniffer-cracker-and-brute-forcing-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Turbodiff v1.01 BETA Released &#8211; Detect Differences Between Binaries</title>
		<link>http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/</link>
		<comments>http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 06:59:57 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[binary diff]]></category>
		<category><![CDATA[binary difference]]></category>
		<category><![CDATA[compare binaries]]></category>
		<category><![CDATA[compare binary files]]></category>
		<category><![CDATA[disassembler]]></category>
		<category><![CDATA[ida]]></category>
		<category><![CDATA[ida pro binary diff]]></category>
		<category><![CDATA[ida pro plugin]]></category>
		<category><![CDATA[IDA-pro]]></category>
		<category><![CDATA[turbo diff]]></category>
		<category><![CDATA[turbodiff]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2215</guid>
		<description><![CDATA[Turbodiff is a binary diffing tool developed as an IDA plugin. It discovers and analyzes differences between the functions of two binaries.
Requirements

&#8220;Turbodiff 1.01 beta release 1&#8243; works with IDA starting from v5.0.
Instructions
For the binaries:
Download the plugin and store it at the directory &#8220;..\IDA\plugins&#8221;.
If you want to compile it on your own: We have compiled it [...]]]></description>
			<content:encoded><![CDATA[<p>Turbodiff is a binary diffing tool developed as an <a href="http://www.hex-rays.com/idapro/">IDA plugin</a>. It discovers and analyzes differences between the functions of two binaries.</p>
<p><strong>Requirements</strong></p>
<p><!--adsense#New468--></p>
<p>&#8220;Turbodiff 1.01 beta release 1&#8243; works with IDA starting from v5.0.</p>
<p><strong>Instructions</strong></p>
<p>For the binaries:<br />
Download the plugin and store it at the directory &#8220;..\IDA\plugins&#8221;.</p>
<p>If you want to compile it on your own: We have compiled it and tested it using Borland C. For the free version of IDA Pro (4.9) you&#8217;ll need to first:</p>
<ol>
<li>Generate the ida_free.lib library. To do this execute: &#8220;implib -c ida_free.lib ida_free.def&#8221;</li>
<li>Next, you must have the linker use this library.</li>
<li>Compile.</li>
</ol>
<p>Comparing two files:</p>
<ol>
<li>Open the first file to be compared with IDA and run /Option 1 (take info from this idb)/ from the plugin. Close.</li>
<li>Open the second file to be compared with IDA and run /Option 1 (take info from this idb)/ from the plugin.<br />
Use /Option 2 (compare with&#8230;)/ from the plugin, and when prompted to select a file, select the first file. </li>
<li>Chose if you want a log file to be genreated and run. Once finished a functions table will popup (watch Figure 1) describing results. The results are then saved for later usage.</li>
</ol>
<p><!--adsense#New468--></p>
<p>You can download Turbodiff here:</p>
<p>IDA PRO v4.9 <a href="http://corelabs.coresecurity.com/index.php?module=Wiki&#038;action=attachment&#038;type=tool&#038;page=turbodiff&#038;file=turbodiff-for-free-ida_v1.0.1b2.zip">Sources and plugin</a> (Free version)<br />
IDA starting with version v5 <a href="http://corelabs.coresecurity.com/index.php?module=Wiki&#038;action=attachment&#038;type=tool&#038;page=turbodiff&#038;file=turbodiff_v1.0.1b2.zip">Sources and plugin</a></p>
<p>Or read more <a href="http://corelabs.coresecurity.com/index.php?module=Wiki&#038;action=view&#038;type=tool&#038;name=turbodiff">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Turbodiff+v1.01+BETA+Released+%E2%80%93+Detect+Differences+Between+Binaries+http://bit.ly/1DQyQO+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/&amp;title=Turbodiff+v1.01+BETA+Released+%E2%80%93+Detect+Differences+Between+Binaries" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/&amp;title=Turbodiff+v1.01+BETA+Released+%E2%80%93+Detect+Differences+Between+Binaries" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/&amp;t=Turbodiff+v1.01+BETA+Released+%E2%80%93+Detect+Differences+Between+Binaries" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/&amp;title=Turbodiff+v1.01+BETA+Released+%E2%80%93+Detect+Differences+Between+Binaries" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/11/turbodiff-v1-01-beta-released-detect-differences-between-binaries/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Binging (BETA) &#8211; Footprinting &amp; Discovery Tool (Google Hacking)</title>
		<link>http://www.darknet.org.uk/2009/11/binging-beta-footprinting-discovery-tool-google-hacking/</link>
		<comments>http://www.darknet.org.uk/2009/11/binging-beta-footprinting-discovery-tool-google-hacking/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 07:51:23 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[bing]]></category>
		<category><![CDATA[binging]]></category>
		<category><![CDATA[domain enumeration]]></category>
		<category><![CDATA[domain footprinting]]></category>
		<category><![CDATA[google-hacking]]></category>
		<category><![CDATA[host enumeration]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[information-leak]]></category>
		<category><![CDATA[Information-Security]]></category>
		<category><![CDATA[microsoft bing]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[reverse lookup]]></category>
		<category><![CDATA[site discovery]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-applications]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2230</guid>
		<description><![CDATA[It&#8217;s been a while since I&#8217;ve seen a tool of this type, back in the heydays of Google Hacking (which became the generic term for information gathering via search engines) there were multiple tools such as Gooscan and Goolag.

Binging is a simple tool to query Bing search engine. It will use your Bing API key [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while since I&#8217;ve seen a tool of this type, back in the heydays of <a href="http://www.darknet.org.uk/tag/google-hacking/">Google Hacking</a> (which became the generic term for information gathering via search engines) there were multiple tools such as <a href="http://www.darknet.org.uk/2008/11/gooscan-automated-google-hacking-tool/">Gooscan</a> and <a href="http://www.darknet.org.uk/2008/03/goolag-gui-tool-for-google-hacking/">Goolag</a>.</p>
<p><!--adsense#New468--></p>
<p>Binging is a simple tool to query Bing search engine. It will use your Bing API key and fetch multiple results. This particular tool can be used for cross domain footprinting for Web 2.0 applications, site discovery, reverse lookup, host enumeration etc. One can use various different directives like site, ip etc. and run queries against the engine. On top of it tool provides filtering capabilities so you can ask for unique URLs or hosts. It is also possible to filter results by applying power of regular expression. Get your Bing API key and use this tool for your audit, assessment and research.</p>
<p><!--adsense#New468--></p>
<p>You can download Binging here:</p>
<p><a href="http://www.blueinfy.com/Binging.zip">Binging.zip</a></p>
<p>Or read more <a href="http://www.blueinfy.com/tools.html">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Binging+%28BETA%29+%E2%80%93+Footprinting+%26+Discovery+Tool+%28Google+Hacking%29+http://bit.ly/1IKimm+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/11/binging-beta-footprinting-discovery-tool-google-hacking/&amp;title=Binging+%28BETA%29+%E2%80%93+Footprinting+%26+Discovery+Tool+%28Google+Hacking%29" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/11/binging-beta-footprinting-discovery-tool-google-hacking/&amp;title=Binging+%28BETA%29+%E2%80%93+Footprinting+%26+Discovery+Tool+%28Google+Hacking%29" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/11/binging-beta-footprinting-discovery-tool-google-hacking/&amp;t=Binging+%28BETA%29+%E2%80%93+Footprinting+%26+Discovery+Tool+%28Google+Hacking%29" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/11/binging-beta-footprinting-discovery-tool-google-hacking/&amp;title=Binging+%28BETA%29+%E2%80%93+Footprinting+%26+Discovery+Tool+%28Google+Hacking%29" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/11/binging-beta-footprinting-discovery-tool-google-hacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>KrbGuess &#8211; Guess/Enumerate Kerberos User Accounts</title>
		<link>http://www.darknet.org.uk/2009/10/krbguess-guessenumerate-kerberos-user-accounts/</link>
		<comments>http://www.darknet.org.uk/2009/10/krbguess-guessenumerate-kerberos-user-accounts/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 07:16:52 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[active directory security]]></category>
		<category><![CDATA[active-directory-hacking]]></category>
		<category><![CDATA[brute forcing kerberos]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[heimdal kerberos]]></category>
		<category><![CDATA[kdc]]></category>
		<category><![CDATA[kerberos]]></category>
		<category><![CDATA[kerberos domain controller]]></category>
		<category><![CDATA[kerberos hacking]]></category>
		<category><![CDATA[kerberos security]]></category>
		<category><![CDATA[krbguess]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[password-hacking]]></category>
		<category><![CDATA[password-security]]></category>
		<category><![CDATA[Windows Hacking]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2232</guid>
		<description><![CDATA[KrbGuess is a small and simple tool which can be used during security testing to guess valid usernames against a Kerberos environment. It allows you to do this by studying the response from a TGT request to the KDC server. The tool works against both Microsoft Active Directory, MIT and Heimdal Kerberos implementations. In addition [...]]]></description>
			<content:encoded><![CDATA[<p>KrbGuess is a small and simple tool which can be used during security testing to guess valid usernames against a Kerberos environment. It allows you to do this by studying the response from a TGT request to the KDC server. The tool works against both Microsoft Active Directory, MIT and Heimdal Kerberos implementations. In addition it will detect if an account lacks pre-authentication.</p>
<p><!--adsense#New468--></p>
<p>The tool is supplied with a file containing a list of usernames and requests a TGT for each user and then waits for the response. If the KDC responds with a valid TGT or with an error message stating that pre-authentication is required, a valid username has been discovered. Several guesses can be run in parallel (currently only against a single KDC) in order to improve performance.</p>
<p>Be careful not to run with to many threads and low timeouts  as it will bring the KDC to its knees during the time of the test. The default values have been tuned against a virtual machine, and currently eat somewhere around 80% CPU which gives me roughly 700 guesses per second. In most cases the network throughput won’t be the performance bottleneck. So far I’m seeing that 2-3MBit of queries is generating a sustained 100% CPU load against both Heimdal on Ubuntu and Windows 2003.</p>
<p><!--adsense#New468--></p>
<p>The tool is written in Java and does not rely on any Kerberos libraries to perform the guessing. In order to successfully run the tool against a system it needs at least the realm, dictionary and a server parameters to be set. eg.</p>
<pre><code>java -jar krbguess.jar -s 192.168.56.11 -r HEMMA \ -o report.txt -d ./dic.txt</code></pre>
<p>You can download KrbGuess here:</p>
<p><a href="http://www.cqure.net/tools/krbguess-0.21-bin.tar.gz">krbguess-0.21-bin.tar.gz</a></p>
<p>Or read more <a href="http://www.cqure.net/wp/krbguess/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=KrbGuess+%E2%80%93+Guess%2FEnumerate+Kerberos+User+Accounts+http://bit.ly/24CYDp+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/krbguess-guessenumerate-kerberos-user-accounts/&amp;title=KrbGuess+%E2%80%93+Guess%2FEnumerate+Kerberos+User+Accounts" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/krbguess-guessenumerate-kerberos-user-accounts/&amp;title=KrbGuess+%E2%80%93+Guess%2FEnumerate+Kerberos+User+Accounts" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/krbguess-guessenumerate-kerberos-user-accounts/&amp;t=KrbGuess+%E2%80%93+Guess%2FEnumerate+Kerberos+User+Accounts" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/krbguess-guessenumerate-kerberos-user-accounts/&amp;title=KrbGuess+%E2%80%93+Guess%2FEnumerate+Kerberos+User+Accounts" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/krbguess-guessenumerate-kerberos-user-accounts/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Yokoso! &#8211; Web Infrastructure Fingerprinting &amp; Delivery Tool</title>
		<link>http://www.darknet.org.uk/2009/10/yokoso-web-infrastructure-fingerprinting-delivery-tool/</link>
		<comments>http://www.darknet.org.uk/2009/10/yokoso-web-infrastructure-fingerprinting-delivery-tool/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 09:18:51 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[cross-site-scripting]]></category>
		<category><![CDATA[inguardians]]></category>
		<category><![CDATA[web fingerprinting]]></category>
		<category><![CDATA[web fingerprinting tool]]></category>
		<category><![CDATA[web infrastructure delivery]]></category>
		<category><![CDATA[XSS]]></category>
		<category><![CDATA[xss attack tool]]></category>
		<category><![CDATA[yokoso]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2167</guid>
		<description><![CDATA[Yokoso! is a project focused on creating fingerprinting code that is deliverable through some form of client attack. This can be used during penetration tests that combine network and web applications. One of the most common questions we hear is &#8220;so what can you do with XSS?&#8221; and we hope that Yokoso! answers that question.

We [...]]]></description>
			<content:encoded><![CDATA[<p>Yokoso! is a project focused on creating fingerprinting code that is deliverable through some form of client attack. This can be used during penetration tests that combine network and web applications. One of the most common questions we hear is &#8220;so what can you do with XSS?&#8221; and we hope that Yokoso! answers that question.</p>
<p><!--adsense#New468--></p>
<p>We will creating JavaScript and Flash objects that are able to be delivered via XSS attacks. These code payloads will contain the fingerprinting information used to map out a network and the devices and software it contains.</p>
<p>In basic terms Yokoso! is a collection of infrastructure fingerprints.  These fingerprints are useful during penetration tests to determine both what infrastructure is in use and to determine who are the admins of that infrastructure.  It is built using the URIs of the web administration interfaces.</p>
<p><!--adsense#New468--></p>
<p>You can download Yokoso! v0.1 here:</p>
<p><a href="http://sourceforge.net/projects/yokoso/files/yokoso-0.1/yokoso.0.1.tar.gz/download">yokoso.0.1.tar.gz</a></p>
<p>Or read more <a href="http://yokoso.inguardians.com/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Yokoso%21+%E2%80%93+Web+Infrastructure+Fingerprinting+%26+Delivery+Tool+http://bit.ly/eC3mh+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/yokoso-web-infrastructure-fingerprinting-delivery-tool/&amp;title=Yokoso%21+%E2%80%93+Web+Infrastructure+Fingerprinting+%26+Delivery+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/yokoso-web-infrastructure-fingerprinting-delivery-tool/&amp;title=Yokoso%21+%E2%80%93+Web+Infrastructure+Fingerprinting+%26+Delivery+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/yokoso-web-infrastructure-fingerprinting-delivery-tool/&amp;t=Yokoso%21+%E2%80%93+Web+Infrastructure+Fingerprinting+%26+Delivery+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/yokoso-web-infrastructure-fingerprinting-delivery-tool/&amp;title=Yokoso%21+%E2%80%93+Web+Infrastructure+Fingerprinting+%26+Delivery+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/yokoso-web-infrastructure-fingerprinting-delivery-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nikto 2.1.0 Released &#8211; Web Server Security Scanning Tool</title>
		<link>http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/</link>
		<comments>http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 09:52:06 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[gpl]]></category>
		<category><![CDATA[hacking web apps]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[libwhisker]]></category>
		<category><![CDATA[nikto]]></category>
		<category><![CDATA[nikto 2]]></category>
		<category><![CDATA[nikto 2.1]]></category>
		<category><![CDATA[web scanner]]></category>
		<category><![CDATA[web server scanning]]></category>
		<category><![CDATA[web-application-hacking]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-server-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2206</guid>
		<description><![CDATA[It&#8217;s been almost 2 years since the last update on Nikto, which was version 2.
For those that don&#8217;t know, Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3500 potentially dangerous files/CGIs, versions on over 900 servers, and version specific problems on over [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been almost 2 years since the last update on <a href="http://www.darknet.org.uk/2007/12/nikto-2-released-web-server-scanning-tool/">Nikto, which was version 2</a>.</p>
<p>For those that don&#8217;t know, Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3500 potentially dangerous files/CGIs, versions on over 900 servers, and version specific problems on over 250 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired).</p>
<p><!--adsense#New468--></p>
<p>Nikto is not designed as an overly stealthy tool. It will test a web server in the shortest timespan possible, and it&#8217;s fairly obvious in log files. However, there is support for LibWhisker&#8217;s anti-IDS methods in case you want to give it a try (or test your IDS system).</p>
<p><strong>Changes</strong></p>
<p>This version has gone through significant rewrites under the hood to how Nikto works, to make it more expandable and usable.</p>
<ul>
<li>
Rewrite to the plugin engine allowing more control of the plugin structure and making it easier to add plugins</li>
<li>Rewrite to the reporting engine allowing reporting plugins to cover more and also ensuring that output is written if Nikto is quit before finishing</li>
<li>Large overhaul of documentation to document built-in methods and variables</li>
<li>Addition of caching to reduce amount of calls made to the web servers, as well as a facility to disable smart 404 guessing.</li>
<li>Addition of simple guessing for whether a system is an embedded device and to report what it is</li>
<li>Plugin to use OWASPs dictionary lists to attempt to brute force directories on the remote web server (as mutate 6)</li>
<li>Plugin to attempt to brute force domains (as mutate 5)</li>
<li>Allow username guessing (mutate 3 and 4) to use a dictionary file as well as brute forcing</li>
<li>Support for NTLM authentication</li>
<li>Lots of bug fixes and new security checks</li>
</ul>
<p><!--adsense#New468--></p>
<p>You can download Nikon 2.1.0 here:</p>
<p><a href="http://cirt.net/nikto/nikto-current.tar.gz">nikto-current.tar.gz</a></p>
<p>Plugins and DB can be found <a href="http://cirt.net/nikto/UPDATES/2.1.0/">here</a>.</p>
<p>Or read more <a href="http://cirt.net/nikto2">here</a>. </p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Nikto+2.1.0+Released+%E2%80%93+Web+Server+Security+Scanning+Tool+http://bit.ly/CqSro+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/&amp;title=Nikto+2.1.0+Released+%E2%80%93+Web+Server+Security+Scanning+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/&amp;title=Nikto+2.1.0+Released+%E2%80%93+Web+Server+Security+Scanning+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/&amp;t=Nikto+2.1.0+Released+%E2%80%93+Web+Server+Security+Scanning+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/&amp;title=Nikto+2.1.0+Released+%E2%80%93+Web+Server+Security+Scanning+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Origami &#8211; Parse, Analyze &amp; Forge PDF Documents</title>
		<link>http://www.darknet.org.uk/2009/10/origami-parse-analyze-forge-pdf-documents/</link>
		<comments>http://www.darknet.org.uk/2009/10/origami-parse-analyze-forge-pdf-documents/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 09:18:47 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[analyze pdf]]></category>
		<category><![CDATA[document forensics]]></category>
		<category><![CDATA[forging pdf]]></category>
		<category><![CDATA[hacking pdf]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[information-leak]]></category>
		<category><![CDATA[origami]]></category>
		<category><![CDATA[parse pdf]]></category>
		<category><![CDATA[pdf forensics]]></category>
		<category><![CDATA[pdf security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2169</guid>
		<description><![CDATA[origami is a Ruby framework designed to parse, analyze, and forge PDF documents. This is NOT a PDF rendering library. It aims at providing a scripting tool to generate and analyze malicious PDF files. As well, it can be used to create on-the-fly customized PDFs, or to inject (evil) code into already existing documents.

Features

Create PDF [...]]]></description>
			<content:encoded><![CDATA[<p>origami is a Ruby framework designed to parse, analyze, and forge PDF documents. This is NOT a PDF rendering library. It aims at providing a scripting tool to generate and analyze malicious PDF files. As well, it can be used to create on-the-fly customized PDFs, or to inject (evil) code into already existing documents.</p>
<p><!--adsense#New468--></p>
<p><strong>Features</strong></p>
<ul>
<li>Create PDF documents from scratch.</li>
<li>Parse existing documents, modify them and recompile them.</li>
<li>Explore documents at the object level, going deep into the document structure, uncompressing PDF object streams and desobfuscating names and strings.</li>
<li>High-level operations, such as encryption/decryption, signature, file attachments&#8230;</li>
<li>A GTK interface to quickly browse into the document contents.</li>
</ul>
<p><strong>Full Scripts</strong></p>
<p><!--adsense#New468--></p>
<p>Some scripts are provided to help in performing common actions on PDF files. You can contribute more by sending your own scripts to origami(at)security-labs.org.</p>
<ul>
<li>detectjs.rb: search for all JavaScript objects.</li>
<li>embed.rb: add an attachment to a PDF file.</li>
<li>create-jspdf.rb: add a JavaScript to a PDF file, executed when the document is opened.</li>
<li>moebius.rb: transform a PDF to a moebius strip.</li>
<li>encrypt.rb: encrypt a PDF file.</li>
</ul>
<p>You can download Origami here:</p>
<p><a href="http://security-labs.org/origami/files/origami-1.0.0-beta1.tar.gz">origami-1.0.0-beta1.tar.gz</a></p>
<p>Or read more <a href="http://security-labs.org/origami/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Origami+%E2%80%93+Parse%2C+Analyze+%26+Forge+PDF+Documents+http://bit.ly/9cX4r+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/origami-parse-analyze-forge-pdf-documents/&amp;title=Origami+%E2%80%93+Parse%2C+Analyze+%26+Forge+PDF+Documents" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/origami-parse-analyze-forge-pdf-documents/&amp;title=Origami+%E2%80%93+Parse%2C+Analyze+%26+Forge+PDF+Documents" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/origami-parse-analyze-forge-pdf-documents/&amp;t=Origami+%E2%80%93+Parse%2C+Analyze+%26+Forge+PDF+Documents" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/origami-parse-analyze-forge-pdf-documents/&amp;title=Origami+%E2%80%93+Parse%2C+Analyze+%26+Forge+PDF+Documents" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/origami-parse-analyze-forge-pdf-documents/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Naptha &#8211; TCP State Exhaustion Vulnerability &amp; Tool</title>
		<link>http://www.darknet.org.uk/2009/10/naptha-tcp-state-exhaustion-vulnerability-tool/</link>
		<comments>http://www.darknet.org.uk/2009/10/naptha-tcp-state-exhaustion-vulnerability-tool/#comments</comments>
		<pubDate>Fri, 16 Oct 2009 09:45:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[bindview]]></category>
		<category><![CDATA[bob keyes]]></category>
		<category><![CDATA[hacking tcp]]></category>
		<category><![CDATA[naptha]]></category>
		<category><![CDATA[razor]]></category>
		<category><![CDATA[razor security]]></category>
		<category><![CDATA[razor security team]]></category>
		<category><![CDATA[tcp connection attack]]></category>
		<category><![CDATA[tcp exhaustion]]></category>
		<category><![CDATA[tcp exploit]]></category>
		<category><![CDATA[tcp security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2078</guid>
		<description><![CDATA[The Naptha vulnerabilities are a type of denial-of-service vulnerabilities researched and documented by Bob Keyes of BindView&#8217;s RAZOR Security Team in 2000. The vulnerabilities exist in some implementations of the TCP protocol, specifically in the way some TCP implementations keep track of the state of TCP connections, and allow an attacker to exhaust the resources [...]]]></description>
			<content:encoded><![CDATA[<p>The Naptha vulnerabilities are a type of denial-of-service vulnerabilities researched and documented by Bob Keyes of BindView&#8217;s RAZOR Security Team in 2000. The vulnerabilities exist in some implementations of the TCP protocol, specifically in the way some TCP implementations keep track of the state of TCP connections, and allow an attacker to exhaust the resources of a system under attack without utilizing much resources on the system used to launch the attack.</p>
<p><!--adsense#New468--></p>
<p>The following links provide more information about the Naptha denial-of-service vulnerabilities:</p>
<ul>
<li>The original BindView advisory is archived <a href="http://packetstormsecurity.org/0012-exploits/bindview.naptha.txt">here</a>. </li>
<li>The advisory that CERT/CC published for the Naptha vulnerabilities is <a href="http://www.cert.org/advisories/CA-2000-21.html">here</a>.</li>
</ul>
<p><strong>The Tool</strong></p>
<p>To study and show the Naptha vulnerabilities, Bob Keyes wrote the Naptha tool. The tool was written in C and used libpcap to read packets from the network and libdnet to craft packets.</p>
<p><!--adsense#New468--></p>
<p>The Naptha tool actually consists of two programs: a program called synsend whose only function is to send TCP SYN packets to the target system, and a program called srvr whose function is to respond to specific traffic received from the target system with TCP packets with specific TCP flags set. Both what traffic to respond to and how to respond to it are specified by the user via command-line arguments. </p>
<p>You can download Naptha here:</p>
<p><a href="http://packetstormsecurity.org/0101-exploits/naptha-1.1.tgz">naptha-1.1.tgz</a></p>
<p>Or read more <a href="http://netexpect.org/wiki/Naptha">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Naptha+%E2%80%93+TCP+State+Exhaustion+Vulnerability+%26+Tool+http://bit.ly/KM78N+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/naptha-tcp-state-exhaustion-vulnerability-tool/&amp;title=Naptha+%E2%80%93+TCP+State+Exhaustion+Vulnerability+%26+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/naptha-tcp-state-exhaustion-vulnerability-tool/&amp;title=Naptha+%E2%80%93+TCP+State+Exhaustion+Vulnerability+%26+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/naptha-tcp-state-exhaustion-vulnerability-tool/&amp;t=Naptha+%E2%80%93+TCP+State+Exhaustion+Vulnerability+%26+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/naptha-tcp-state-exhaustion-vulnerability-tool/&amp;title=Naptha+%E2%80%93+TCP+State+Exhaustion+Vulnerability+%26+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/naptha-tcp-state-exhaustion-vulnerability-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Deep Packet Inspection Engine Goes Open Source</title>
		<link>http://www.darknet.org.uk/2009/10/deep-packet-inspection-engine-goes-open-source/</link>
		<comments>http://www.darknet.org.uk/2009/10/deep-packet-inspection-engine-goes-open-source/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 09:23:34 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[deep packet inspection]]></category>
		<category><![CDATA[dpi]]></category>
		<category><![CDATA[ipoque]]></category>
		<category><![CDATA[open source deep packet inspection]]></category>
		<category><![CDATA[open source packet inspection]]></category>
		<category><![CDATA[open-source]]></category>
		<category><![CDATA[opendpi]]></category>
		<category><![CDATA[packet inspection]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2109</guid>
		<description><![CDATA[This is great news, especially for open source tool developers. Deep packet inspection is an extremely niche area and requires great expertise (and a lot of R&#038;D of course).
I hope a new project can spawn from this, it has many interesting applications. I think it&#8217;d be a good addition to Wireshark and IDS projects like [...]]]></description>
			<content:encoded><![CDATA[<p>This is great news, especially for open source tool developers. Deep packet inspection is an extremely niche area and requires great expertise (and a lot of R&#038;D of course).</p>
<p>I hope a new project can spawn from this, it has many interesting applications. I think it&#8217;d be a good addition to Wireshark and IDS projects like Snort.</p>
<p><a href="http://opendpi.org/">http://opendpi.org/</a></p>
<p><!--adsense#New468--></p>
<blockquote><p>Deep packet inspection (DPI) hardware can identify an astonishing array of protocols passing across the Internet—up to and including protocols that are rare even to us in the Orbiting HQ (Gadu-Gadu? Manolito? Feidian?). But if you&#8217;ve ever wondered just how this can be done, and done at wire speed, wonder no more: Europe&#8217;s leading DPI vendor has open-sourced a version of its traffic detection engine.</p>
<p>OpenDPI.org is the new home for ipoque&#8217;s open source project; anyone interested can take a look at the code or contribute patches. The goal in this case, though, isn&#8217;t so much about crowdsourcing product development but about easing consumer fears about DPI technology.</p>
<p>Klaus Mochalski, CEO of ipoque, explains that &#8220;transparency was important for us from the beginning. The lack of transparency from the vendors&#8217; side is widespread in the DPI business. Our thoughts are a bit different and that is why we decided to push this project.&#8221;</p></blockquote>
<p>It can identify a whole range of weird and wonderful protocols including those you&#8217;ve never heard of. </p>
<p>The free version is basically a watered down of the commercial product, it&#8217;s slow, doesn&#8217;t come bundled with some fancy supercomputer grade hardware and can&#8217;t handle encrypted transmissions.</p>
<p>I think it will be useful too for people building open source router systems to manage traffic, do traffic shaping and general QoS with much more accuracy (rather than relying on port classification).</p>
<p><!--adsense#New468--></p>
<blockquote><p>The OpenDPI engine, released under the LGPL license, differs from ipoque&#8217;s commercial scanning engine in its high-priced DPI hardware. The open-source version is much slower and (more importantly) doesn&#8217;t reveal ipoque&#8217;s methods for identifying encrypted transmissions. DPI vendors all claim high levels of success at identifying such traffic based on the flow patterns and handshake signatures common to protocols like BitTorrent and Skype, even if they cannot crack the encryption and examine the content of those transmissions.</p>
<p>ipoque apparently wants to convince people that its detection code doesn&#8217;t store or examine the actual content being transmitted. The company made the same point in a white paper released last week. &#8220;DPI as such has no negative impact on online privacy,&#8221; it says. &#8220;It is, again, only the applications that may have this impact. Prohibiting DPI as a technology would be just as naive as prohibiting automatic speech recognition because it can be used to eavesdrop on conversations based on content.</p>
<p>Although DPI can be used as a base technology to look at and evaluate the actual content of a network communication, this goes beyond what we understand as DPI as it is used by Internet bandwidth management—the classification of network protocols and applications.&#8221;</p></blockquote>
<p>I hope they keep developing the project, or some other folks in the Open Source community step up and turn it into a full blown development fork.</p>
<p>That would be great, harness the existing technology and improve on it.</p>
<p>Because let&#8217;s face it, any commercial company releasing an Open Source branch of their software has no incentive to make it that great lest it get better than the stuff they are selling.</p>
<p>Source: <a href="http://arstechnica.com/open-source/news/2009/09/deep-packet-inspection-engine-goes-open-source.ars">Ars Technica</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Deep+Packet+Inspection+Engine+Goes+Open+Source+http://bit.ly/2o4i7s+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/deep-packet-inspection-engine-goes-open-source/&amp;title=Deep+Packet+Inspection+Engine+Goes+Open+Source" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/deep-packet-inspection-engine-goes-open-source/&amp;title=Deep+Packet+Inspection+Engine+Goes+Open+Source" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/deep-packet-inspection-engine-goes-open-source/&amp;t=Deep+Packet+Inspection+Engine+Goes+Open+Source" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/deep-packet-inspection-engine-goes-open-source/&amp;title=Deep+Packet+Inspection+Engine+Goes+Open+Source" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/deep-packet-inspection-engine-goes-open-source/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
