<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Network Hacking</title>
	<atom:link href="http://www.darknet.org.uk/category/network-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>sslyze &#8211; Fast and Full-Featured SSL Configuration Scanner</title>
		<link>http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/</link>
		<comments>http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 21:29:26 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[detecting ssl renegotiation]]></category>
		<category><![CDATA[hacking ssl]]></category>
		<category><![CDATA[iSEC]]></category>
		<category><![CDATA[preventing ssl renegotiation]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[ssl config scanner]]></category>
		<category><![CDATA[ssl configuration scanner]]></category>
		<category><![CDATA[ssl renegotiation]]></category>
		<category><![CDATA[ssl renegotiations]]></category>
		<category><![CDATA[ssl scanner]]></category>
		<category><![CDATA[ssl server security]]></category>
		<category><![CDATA[sslyze]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3236</guid>
		<description><![CDATA[Transport Layer Security (TLS), commonly called SSL, is one of the most widely used protocols to secure network communications. As costs fall and user security and privacy expectations rise companies are deploying it more widely every year. Attacks against the CA system, SSL implementation flaws and aging protocol versions have grabbed news headlines, bringing attention [...]]]></description>
			<content:encoded><![CDATA[<p>Transport Layer Security (TLS), commonly called SSL, is one of the most widely used protocols to secure network communications. As costs fall and user security and privacy expectations rise companies are deploying it more widely every year. Attacks against the CA system, SSL implementation flaws and aging protocol versions have grabbed news headlines, bringing attention to weak configurations, and the need to avoid them. Additionally, server misconfiguration has always greatly increased the overhead caused by SSL, slowing the transition to improved communications security.</p>
<p>To help improve system configurations, iSEC is releasing the free software “SSLyze” tool. They have found this tool helpful for analyzing the configuration of SSL servers and for identifying misconfiguration such as the use of outdated protocol versions, weak hash algorithms in trust chains, insecure renegotiation, and session resumption settings.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>SSLyze is a stand-alone python application that looks for classic SSL misconfiguration, while providing the advanced user with the opportunity to customize the application via a simple plugin interface.</p>
<p><strong>Features</strong></p>
<ul>
<li>    Insecure renegotiation testing</li>
<li>    Scanning for weak strength ciphers</li>
<li>    Checking for SSLv2, SSLv3 and TLSv1 versions</li>
<li>    Server certificate information dump and basic validation</li>
<li>    Session resumption capabilities and actual resumption rate measurement</li>
<li>    Support for client certificate authentication</li>
<li>    Simultaneous scanning of multiple servers, versions and ciphers</li>
</ul>
<p>For example, SSLyze can help user’s identify server configurations vulnerable to <a href="http://www.darknet.org.uk/2011/10/thc-ssl-dosddos-tool-released-for-download/">THC’s recently released SSL DOS attack</a> by checking the server’s support for client-initiated renegotiations. For more information on testing for client-initiated renegotiations, you can read <a href="http://code.google.com/p/sslyze/wiki/ThcSslDOS">here</a>.</p>
<p>You can download sslyze here:</p>
<p><a href="http://sslyze.googlecode.com/files/sslyze-0.3_src.zip">sslyze-0.3_src.zip</a></p>
<p>Or read more <a href="http://code.google.com/p/sslyze/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3236+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;t=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;title=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;title=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;title=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;title=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F12%2Fsslyze-fast-and-full-featured-ssl-configuration-scanner%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VoIP Hopper 2.01 Released &#8211; IP Phone VLAN Hopping Tool</title>
		<link>http://www.darknet.org.uk/2011/11/voip-hopper-2-01-released-ip-phone-vlan-hopping-tool/</link>
		<comments>http://www.darknet.org.uk/2011/11/voip-hopper-2-01-released-ip-phone-vlan-hopping-tool/#comments</comments>
		<pubDate>Fri, 25 Nov 2011 09:45:37 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[hacking vlan]]></category>
		<category><![CDATA[hacking-networks]]></category>
		<category><![CDATA[vlan hacking]]></category>
		<category><![CDATA[vlan hopper]]></category>
		<category><![CDATA[vlan hopping]]></category>
		<category><![CDATA[vlan hopping tool]]></category>
		<category><![CDATA[voip]]></category>
		<category><![CDATA[voip hopper]]></category>
		<category><![CDATA[voip-hacking]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1783</guid>
		<description><![CDATA[VoIP Hopper is a GPLv3 licensed security tool, written in C, that rapidly runs a VLAN Hop into the Voice VLAN on specific ethernet switches. VoIP Hopper does this by mimicking the behavior of an IP Phone, in Cisco, Avaya, and Nortel environments. This requires two important steps in order for the tool to traverse [...]]]></description>
			<content:encoded><![CDATA[<p>VoIP Hopper is a GPLv3 licensed security tool, written in C, that rapidly runs a VLAN Hop into the Voice VLAN on specific ethernet switches. VoIP Hopper does this by mimicking the behavior of an IP Phone, in Cisco, Avaya, and Nortel environments.</p>
<p>This requires two important steps in order for the tool to traverse VLANs for unauthorized access.  First,  discovery of the correct 12 bit Voice VLAN ID (VVID) used by the IP Phones is required.  VoIP Hopper supports multiple protocol discovery methods (CDP, DHCP, LLDP-MED, 802.1q ARP) for this important first step.  Second, the tool creates a virtual VoIP ethernet interface on the OS.  It then inserts a spoofed 4-byte 802.1q vlan header containing the 12 bit VVID into a spoofed DHCP request.</p>
<p>Once it receives an IP address in the VoIP VLAN subnet, all subsequent ethernet frames are &#8220;tagged&#8221; with the spoofed 802.1q header.</p>
<p>VoIP Hopper is a VLAN Hop test tool but also a tool to test VoIP infrastructure security. </p>
<p><strong>New Features</strong></p>
<ul>
<li>    New &#8220;Assessment&#8221; mode:  Interactive, menu driven command interface, improves ability to VLAN Hop in Pentesting when the security tester is working against an unknown network infrastructure</li>
<li>    New VLAN Discovery methods (802.1q ARP, LLDP-MED)</li>
<li>    LLDP-MED spoofing and sniffing support</li>
<li>    Can bypass VoIP VLAN subnets that have DHCP disabled, and spoof the IP address and MAC address of a phone by setting a static IP</li>
</ul>
<p>You can download VoIP Hopper 2.01 here:</p>
<p><a href="http://downloads.sourceforge.net/project/voiphopper/voiphopper-2.0/voiphopper-2.01.tar.gz?r=http%3A%2F%2Fsourceforge.net%2Fprojects%2Fvoiphopper%2Ffiles%2Fvoiphopper-2.0%2F&#038;ts=1321850086&#038;use_mirror=cdnetworks-kr-1">voiphopper-2.01.tar.gz</a></p>
<p>Or read more <a href="http://voiphopper.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=VoIP+Hopper+2.01+Released+%E2%80%93+IP+Phone+VLAN+Hopping+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1783+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/voip-hopper-2-01-released-ip-phone-vlan-hopping-tool/&amp;t=VoIP+Hopper+2.01+Released+%E2%80%93+IP+Phone+VLAN+Hopping+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/voip-hopper-2-01-released-ip-phone-vlan-hopping-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/voip-hopper-2-01-released-ip-phone-vlan-hopping-tool/&amp;title=VoIP+Hopper+2.01+Released+%E2%80%93+IP+Phone+VLAN+Hopping+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/voip-hopper-2-01-released-ip-phone-vlan-hopping-tool/&amp;title=VoIP+Hopper+2.01+Released+%E2%80%93+IP+Phone+VLAN+Hopping+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/voip-hopper-2-01-released-ip-phone-vlan-hopping-tool/&amp;title=VoIP+Hopper+2.01+Released+%E2%80%93+IP+Phone+VLAN+Hopping+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/voip-hopper-2-01-released-ip-phone-vlan-hopping-tool/&amp;title=VoIP+Hopper+2.01+Released+%E2%80%93+IP+Phone+VLAN+Hopping+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fvoip-hopper-2-01-released-ip-phone-vlan-hopping-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/voip-hopper-2-01-released-ip-phone-vlan-hopping-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>X-Scan by XFocus &#8211; Basic Free Network Vulnerability Scanner</title>
		<link>http://www.darknet.org.uk/2011/11/x-scan-by-xfocus-basic-free-network-vulnerability-scanner/</link>
		<comments>http://www.darknet.org.uk/2011/11/x-scan-by-xfocus-basic-free-network-vulnerability-scanner/#comments</comments>
		<pubDate>Wed, 23 Nov 2011 08:30:50 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[free vulnerability scanner]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[nasl]]></category>
		<category><![CDATA[nessus]]></category>
		<category><![CDATA[network vulnerability scanner]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[vulnerability-scanner]]></category>
		<category><![CDATA[xfocus]]></category>
		<category><![CDATA[xscan]]></category>
		<category><![CDATA[xscan by xfocus]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1652</guid>
		<description><![CDATA[X-Scan is a general scanner for scanning network vulnerabilities for specific IP address range or stand-alone computer by multi-threading method, plug-ins are supported. This is an old tool (last update in 2005), but some people still find it useful and there are certain situations where it can be useful (especially in those jurassic companies using [...]]]></description>
			<content:encoded><![CDATA[<p>X-Scan is a general scanner for scanning network vulnerabilities for specific IP address range or stand-alone computer by multi-threading method, plug-ins are supported. This is an old tool (last update in 2005), but some people still find it useful and there are certain situations where it can be useful (especially in those jurassic companies using old kit).</p>
<p>It supports Nessus NASL plugins for vulnerability scanning &#8211; which makes it pretty useful. It also has both a GUI and command line version for scripting.</p>
<p>The following items can be scanned:</p>
<ul>
<li>    Remote OS type and version detection,</li>
<li>    Standard port status and banner information,</li>
<li>    SNMP information,</li>
<li>    CGI vulnerability detection,</li>
<li>    IIS vulnerability detection,</li>
<li>    RPC vulnerability detection,</li>
<li>    SSL vulnerability detection,</li>
<li>    SQL-server,</li>
<li>    FTP-server,</li>
<li>    SMTP-server,</li>
<li>    POP3-server,</li>
<li>    NT-server weak user/password pairs authentication module,</li>
<li>    NT server NETBIOS information,</li>
<li>    Remote Register information, etc.</li>
</ul>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>The results of the scan are saved in /log directory,  and are title index_ip_address.htm (if you used the GUI) or ip_address if you used the command line option.  These can be directly browsed by any normal Web Browser.</p>
<p>Basic user and password lists are supplied to carry out a basic attack on certain services, (above), if found enabled on the host.</p>
<p>You can download XScan v3.3 here:</p>
<p><a href="http://xfocus.org/programs/200507/X-Scan-v3.3-en.rar">X-Scan-v3.3-en.rar</a></p>
<p>Or read more <a href="http://www.xfocus.org/programs/200507/18.html">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=X-Scan+by+XFocus+%E2%80%93+Basic+Free+Network+Vulnerability+Scanner+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1652+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/x-scan-by-xfocus-basic-free-network-vulnerability-scanner/&amp;t=X-Scan+by+XFocus+%E2%80%93+Basic+Free+Network+Vulnerability+Scanner" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/x-scan-by-xfocus-basic-free-network-vulnerability-scanner/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/x-scan-by-xfocus-basic-free-network-vulnerability-scanner/&amp;title=X-Scan+by+XFocus+%E2%80%93+Basic+Free+Network+Vulnerability+Scanner" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/x-scan-by-xfocus-basic-free-network-vulnerability-scanner/&amp;title=X-Scan+by+XFocus+%E2%80%93+Basic+Free+Network+Vulnerability+Scanner" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/x-scan-by-xfocus-basic-free-network-vulnerability-scanner/&amp;title=X-Scan+by+XFocus+%E2%80%93+Basic+Free+Network+Vulnerability+Scanner" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/x-scan-by-xfocus-basic-free-network-vulnerability-scanner/&amp;title=X-Scan+by+XFocus+%E2%80%93+Basic+Free+Network+Vulnerability+Scanner" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fx-scan-by-xfocus-basic-free-network-vulnerability-scanner%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/x-scan-by-xfocus-basic-free-network-vulnerability-scanner/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>THC SSL DoS/DDoS Tool Released For Download</title>
		<link>http://www.darknet.org.uk/2011/10/thc-ssl-dosddos-tool-released-for-download/</link>
		<comments>http://www.darknet.org.uk/2011/10/thc-ssl-dosddos-tool-released-for-download/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 17:20:12 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[ddos tool]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[dos tool]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[ssl dos attack]]></category>
		<category><![CDATA[ssl renegotiation]]></category>
		<category><![CDATA[ssl renegotiation bug]]></category>
		<category><![CDATA[ssl-dos]]></category>
		<category><![CDATA[thc]]></category>
		<category><![CDATA[thc ddos]]></category>
		<category><![CDATA[thc-ssl-dos]]></category>
		<category><![CDATA[the-hackers-choice]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3215</guid>
		<description><![CDATA[THC-SSL-DOS is a tool to verify the performance of SSL. Establishing a secure SSL connection requires 15x more processing power on the server than on the client. THC-SSL-DOS exploits this asymmetric property by overloading the server and knocking it off the Internet. This problem affects all SSL implementations today. The vendors are aware of this [...]]]></description>
			<content:encoded><![CDATA[<p>THC-SSL-DOS is a tool to verify the performance of SSL. Establishing a secure SSL connection requires 15x more processing power on the server than on the client. THC-SSL-DOS exploits this asymmetric property by overloading the server and knocking it off the Internet. This problem affects all SSL implementations today. The vendors are aware of this problem since 2003 and the topic has been widely discussed.</p>
<p>This attack further exploits the SSL secure Renegotiation feature to trigger thousands of renegotiations via single TCP connection.</p>
<p><strong>Usage</strong></p>
<pre><code>./thc-ssl-dos 127.3.133.7 443
Handshakes 0 [0.00 h/s], 0 Conn, 0 Err
Secure Renegotiation support: yes
Handshakes 0 [0.00 h/s], 97 Conn, 0 Err
Handshakes 68 [67.39 h/s], 97 Conn, 0 Err
Handshakes 148 [79.91 h/s], 97 Conn, 0 Err
Handshakes 228 [80.32 h/s], 100 Conn, 0 Err
Handshakes 308 [80.62 h/s], 100 Conn, 0 Err
Handshakes 390 [81.10 h/s], 100 Conn, 0 Err
Handshakes 470 [80.24 h/s], 100 Conn, 0 Err</code></pre>
<p><strong>Comparing flood DDoS vs. SSL-Exhaustion attack</strong></p>
<p>A traditional flood DDoS attack cannot be mounted from a single DSL connection. This is because the bandwidth of a server is far superior to the bandwidth of a DSL connection: A DSL connection is not an equal opponent to challenge the bandwidth of a server.</p>
<p>This is turned upside down for THC-SSL-DOS: The processing capacity for SSL handshakes is far superior at the client side: A laptop on a DSL connection can challenge a server on a 30Gbit link. Traditional DDoS attacks based on flooding are sub optimal: Servers are prepared to handle large amount of traffic and clients are constantly sending requests to the server even when not under attack. </p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>The SSL-handshake is only done at the beginning of a secure session and only if security is required. Servers are _not_ prepared to handle large amount of SSL Handshakes. The worst attack scenario is an SSL-Exhaustion attack mounted from thousands of clients (SSL-DDoS).</p>
<p><strong>Tips &#038; Tricks for Whitehats</strong></p>
<ol>
<li>The average server can do 300 handshakes per second. This would require 10-25% of your laptops CPU. </li>
<li>Use multiple hosts (SSL-DOS) if an SSL Accelerator is used.</li>
<li>Be smart in target acquisition: The HTTPS Port (443) is not always the best choice. Other SSL enabled ports are more unlikely to use an SSL Accelerator (like the POP3S, SMTPS, &#8230;  or the secure database port).</li>
</ol>
<p><strong>Counter measurements</strong></p>
<p>No real solutions exists. The following steps can mitigate (but not solve) the problem:</p>
<ol>
<li>Disable SSL-Renegotiation</li>
<li>Invest into SSL Accelerator</li>
</ol>
<p>Either of these countermeasures can be circumventing by modifying THC-SSL-DOS. A better solution is desireable. Somebody should fix this.</p>
<p>You can download THC-SSL-DOS here:</p>
<p><strong>Windows:</strong> <a href="http://www.thc.org/thc-ssl-dos/thc-ssl-dos-1.4-win-bin.zip">thc-ssl-dos-1.4-win-bin.zip</a><br />
<strong>Linux:</strong> <a href="http://www.thc.org/thc-ssl-dos/thc-ssl-dos-1.4.tar.gz">thc-ssl-dos-1.4.tar.gz</a></p>
<p>Or read more <a href="http://www.thc.org/thc-ssl-dos/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=THC+SSL+DoS%2FDDoS+Tool+Released+For+Download+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3215+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/10/thc-ssl-dosddos-tool-released-for-download/&amp;t=THC+SSL+DoS%2FDDoS+Tool+Released+For+Download" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/10/thc-ssl-dosddos-tool-released-for-download/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/10/thc-ssl-dosddos-tool-released-for-download/&amp;title=THC+SSL+DoS%2FDDoS+Tool+Released+For+Download" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/10/thc-ssl-dosddos-tool-released-for-download/&amp;title=THC+SSL+DoS%2FDDoS+Tool+Released+For+Download" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/10/thc-ssl-dosddos-tool-released-for-download/&amp;title=THC+SSL+DoS%2FDDoS+Tool+Released+For+Download" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/10/thc-ssl-dosddos-tool-released-for-download/&amp;title=THC+SSL+DoS%2FDDoS+Tool+Released+For+Download" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F10%2Fthc-ssl-dosddos-tool-released-for-download%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/10/thc-ssl-dosddos-tool-released-for-download/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Multi Threaded TCP Port Scanner For Linux &amp; Windows</title>
		<link>http://www.darknet.org.uk/2011/09/multi-threaded-tcp-port-scanner-for-linux-windows/</link>
		<comments>http://www.darknet.org.uk/2011/09/multi-threaded-tcp-port-scanner-for-linux-windows/#comments</comments>
		<pubDate>Thu, 29 Sep 2011 20:30:50 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[free port scanner]]></category>
		<category><![CDATA[multi threaded port scanner]]></category>
		<category><![CDATA[multi threaded tcp port scanner]]></category>
		<category><![CDATA[port scanner for windows]]></category>
		<category><![CDATA[port-scanner]]></category>
		<category><![CDATA[secpoint]]></category>
		<category><![CDATA[tcp port scanner]]></category>
		<category><![CDATA[windows port scanner]]></category>
		<category><![CDATA[windows tcp port scanner]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3194</guid>
		<description><![CDATA[This tool is exactly what it says, it&#8217;s a Multi Threaded TCP Port Scanner with possibility to scan 65535 TCP ports on an IP address. You can specify how many threads to run and the timeout. It will tell you the MAC address of the target and the service running &#8211; works on both Linux [...]]]></description>
			<content:encoded><![CDATA[<p>This tool is exactly what it says, it&#8217;s a Multi Threaded TCP Port Scanner with possibility to scan 65535 TCP ports on an IP address. You can specify how many threads to run and the timeout. It will tell you the MAC address of the target and the service running &#8211; works on both Linux and Windows.</p>
<p>Version 2.0 adds SYN scanning capabilities and much more:</p>
<ul>
<li>Added option -s for SYN scan.</li>
<li>Scanning made faster thanks to SYN scan</li>
<li>Added even more default ports</li>
<li>Improved error handler for SYN scan</li>
<li>Improved text output</li>
<li>Fixed minor bugs</li>
</ul>
<p>A new branch of the program has been created to support SYN scan. SYN scan was necessary because under some circumstances of heavy load, the TCP Connect scan can hang routers. SYN scan is multithreaded and uses the standard library pcap on Unix/Linux operating systems. Please be aware that SYN scan requires a higher level of authorization, if compared to connect sockets: in Unix/Linux pscan requires root privilege. In some operating systems, SYN scan is performed using connectionless &#8220;raw&#8221; sockets, therefore the usage of pscan is subject to possible     restriction to the usage of raw sockets in such operating systems.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>With SYN scan, option -w is not used because the program does not use connected sockets, so it doesn&#8217;t have to loop reading a socket until the timeout is reached. The receive function doesn&#8217;t have to poll over a number of sockets, but simply reads the packets passing through the network card, for all ports, and displays the message of &#8220;open port&#8221; when the packet coming from the remote IP contains the information that the remote port is open. For the same reason, options -a and -n are not used. The first one because packets sent to closed ports are simply not being replied to, so they cannot be counted; the second one because the function that reads packets is one, and performs this by reading packets from the network card, not from multiple sockets.</p>
<p>You can download Multi Threaded TCP Port Scanner v2.0 here:</p>
<p><a href="http://www.secpoint.com/freetools/threaded-syn-port-scanner-2.0.zip">threaded-syn-port-scanner-2.0.zip</a></p>
<p>Or read more <a href="http://www.secpoint.com/Multi-Threaded-TCP-Port-Scanner.html">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Multi+Threaded+TCP+Port+Scanner+For+Linux+%26+Windows+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3194+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/09/multi-threaded-tcp-port-scanner-for-linux-windows/&amp;t=Multi+Threaded+TCP+Port+Scanner+For+Linux+%26+Windows" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/09/multi-threaded-tcp-port-scanner-for-linux-windows/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/09/multi-threaded-tcp-port-scanner-for-linux-windows/&amp;title=Multi+Threaded+TCP+Port+Scanner+For+Linux+%26+Windows" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/09/multi-threaded-tcp-port-scanner-for-linux-windows/&amp;title=Multi+Threaded+TCP+Port+Scanner+For+Linux+%26+Windows" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/09/multi-threaded-tcp-port-scanner-for-linux-windows/&amp;title=Multi+Threaded+TCP+Port+Scanner+For+Linux+%26+Windows" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/09/multi-threaded-tcp-port-scanner-for-linux-windows/&amp;title=Multi+Threaded+TCP+Port+Scanner+For+Linux+%26+Windows" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F09%2Fmulti-threaded-tcp-port-scanner-for-linux-windows%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/09/multi-threaded-tcp-port-scanner-for-linux-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NetworkMiner v1.1 Released &#8211; Windows Packet Analyzer &amp; Sniffer</title>
		<link>http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/</link>
		<comments>http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/#comments</comments>
		<pubDate>Tue, 20 Sep 2011 15:09:46 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[hacking-networks]]></category>
		<category><![CDATA[network miner]]></category>
		<category><![CDATA[network-forensics]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[network-sniffing]]></category>
		<category><![CDATA[networkminer]]></category>
		<category><![CDATA[packet-sniffer]]></category>
		<category><![CDATA[passive network sniffer]]></category>
		<category><![CDATA[windows network sniffer]]></category>
		<category><![CDATA[windows packet capture tool]]></category>
		<category><![CDATA[windows packet sniffer]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3190</guid>
		<description><![CDATA[NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates [...]]]></description>
			<content:encoded><![CDATA[<p>NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates from PCAP files.</p>
<p>NetworkMiner collects data (such as forensic evidence) about hosts on the network rather than to collect data regarding the traffic on the network. The main user interface view is host centric (information grouped per host) rather than packet centric (information showed as a list of packets/frames).</p>
<p>NetworkMiner has, since the first release in 2007, become popular tool among incident response teams as well as law enforcement. NetworkMiner is today used by companies and organizations all over the world. </p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>It&#8217;s been a long time since we last mentioned NetworkMiner, it was back in 2008 &#8211; <a href="http://www.darknet.org.uk/2008/02/networkminer-passive-sniffer-packet-analysis-tool-for-windows/">NetworkMiner – Passive Sniffer &#038; Packet Analysis Tool for Windows</a>.</p>
<p>Now there&#8217;s a new version!</p>
<p><strong>New in v1.1</strong></p>
<p>The new version supports features such as:</p>
<ul>
<li>Extraction of Google Analytics data</li>
<li>Better parsing of SMB data</li>
<li>Support for PPP frames</li>
<li>Even more stable than the 1.0 release</li>
</ul>
<p>You can download NetworkMiner v1.1 here:</p>
<p><a href="http://sourceforge.net/projects/networkminer/files/networkminer/NetworkMiner-1.1/NetworkMiner_1-1.zip/download">NetworkMiner_1-1.zip</a></p>
<p>Or read more <a href="http://www.netresec.com/?page=NetworkMiner">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3190+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;t=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F09%2Fnetworkminer-v1-1-released-windows-packet-analyzer-sniffer%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NfSpy &#8211; ID-spoofing NFS Client &#8211; Falsify NFS Credentials</title>
		<link>http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/</link>
		<comments>http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/#comments</comments>
		<pubDate>Tue, 26 Jul 2011 07:44:41 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[hack nfs]]></category>
		<category><![CDATA[hacking nfs]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[linux hacking tool]]></category>
		<category><![CDATA[linux-security]]></category>
		<category><![CDATA[mount nfs]]></category>
		<category><![CDATA[nfs]]></category>
		<category><![CDATA[nfs hacking]]></category>
		<category><![CDATA[nfs hacking tool]]></category>
		<category><![CDATA[nfs mount]]></category>
		<category><![CDATA[nfs security]]></category>
		<category><![CDATA[nfspy]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3154</guid>
		<description><![CDATA[NfSpy is a FUSE filesystem written in Python that automatically changes UID and GID to give you full access to any file on an NFS share. Use it to mount an NFS export and act as the owner of every file and directory. Vulnerability Exploited NFS before version 4 is reliant upon host trust relationships [...]]]></description>
			<content:encoded><![CDATA[<p>NfSpy is a FUSE filesystem written in Python that automatically changes UID and GID to give you full access to any file on an NFS share. Use it to mount an NFS export and act as the owner of every file and directory.</p>
<p><strong>Vulnerability Exploited</strong></p>
<p>NFS before version 4 is reliant upon host trust relationships for authentication. The NFS server trusts any client machines to authenticate users and assign the same user IDs (UIDS) that the shared filesystem uses. This works in NIS, NIS+, and LDAP domains, for instance, but only if you know the client machine is not compromised, or faking its identity. This is because the only authentication in the NFS protocol is the passing of the UID and GID (group ID). There are a few things that can be done to enhance the security of NFS, but many of them are incomplete solutions, and even with them implemented, it could still be possible to circumvent the security measures.</p>
<p><strong>Features</strong></p>
<ul>
<li>Use filehandles from packet captures instead of asking mountd.</li>
<li>Hide from sysadmins by immediately &#8220;unmounting&#8221; while retaining access</li>
<li>Specify port/protocol for NFS or Mountd if you don&#8217;t have access to the portmapper </li>
</ul>
<p>You can download NfSpy here:</p>
<p><a href="https://github.com/bonsaiviking/NfSpy/zipball/master">NfSpy.zip</a></p>
<p>Or read more <a href="https://github.com/bonsaiviking/NfSpy">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3154+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;t=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;title=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;title=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;title=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;title=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F07%2Fnfspy-id-spoofing-nfs-client-falsify-nfs-credentials%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sslsniff v0.7 &#8211; SSL Man-In-The-Middle (MITM) Tool</title>
		<link>http://www.darknet.org.uk/2011/07/sslsniff-v0-7-ssl-man-in-the-middle-mitm-tool/</link>
		<comments>http://www.darknet.org.uk/2011/07/sslsniff-v0-7-ssl-man-in-the-middle-mitm-tool/#comments</comments>
		<pubDate>Fri, 01 Jul 2011 08:49:01 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[hacking ssl]]></category>
		<category><![CDATA[man-in-the-middle]]></category>
		<category><![CDATA[mitm]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[ssl man in the middle]]></category>
		<category><![CDATA[ssl mitm tool]]></category>
		<category><![CDATA[ssl security]]></category>
		<category><![CDATA[ssl sniff]]></category>
		<category><![CDATA[ssl sniffer]]></category>
		<category><![CDATA[sslsniff]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3103</guid>
		<description><![CDATA[It&#8217;s been a while since the last sslsniff release back in August 2009 with version 0.6 &#8211; sslsniff v0.6 Released – SSL MITM Tool. Version 0.7 was finally released earlier in the year in April &#8211; so here it is. This tool was originally written to demonstrate and exploit IE&#8217;s vulnerability to a specific &#8220;basicConstraints&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while since the last sslsniff release back in August 2009 with version 0.6 &#8211; <a href="http://www.darknet.org.uk/2009/08/sslsniff-v0-6-released-ssl-mitm-tool/">sslsniff v0.6 Released – SSL MITM Tool</a>. Version 0.7 was finally released earlier in the year in April &#8211; so here it is.</p>
<p>This tool was originally written to demonstrate and exploit IE&#8217;s vulnerability to a specific &#8220;basicConstraints&#8221; man-in-the-middle attack. While Microsoft has since fixed the vulnerability that allowed leaf certificates to act as signing certificates, this tool is still occasionally useful for other purposes.</p>
<p>It is designed to MITM all SSL connections on a LAN and dynamically generates certs for the domains that are being accessed on the fly. The new certificates are constructed in a certificate chain that is signed by any certificate that you provide. </p>
<p>The three steps to get this running are:</p>
<ul>
<li>    Download and run sslsniff-0.7.tar.gz</li>
<li>    Setup iptables</li>
<li>    Run arp-spoof </li>
</ul>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p><strong>Changes in 0.7</strong></p>
<ul>
<li>    Fixed some networking shuffling bugs (thanks Daniel Roethlisberger)</li>
<li>    Added basic compatibility with BSD pf (thanks Daniel Roethlisberger) </li>
</ul>
<p>You can download sslsniff v0.7 here:</p>
<p><a href="http://www.thoughtcrime.org/software/sslsniff/sslsniff-0.7.tar.gz">sslsniff-0.7.tar.gz</a></p>
<p>Or read more <a href="http://www.thoughtcrime.org/software/sslsniff/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sslsniff+v0.7+%E2%80%93+SSL+Man-In-The-Middle+%28MITM%29+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3103+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/07/sslsniff-v0-7-ssl-man-in-the-middle-mitm-tool/&amp;t=sslsniff+v0.7+%E2%80%93+SSL+Man-In-The-Middle+%28MITM%29+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/07/sslsniff-v0-7-ssl-man-in-the-middle-mitm-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/07/sslsniff-v0-7-ssl-man-in-the-middle-mitm-tool/&amp;title=sslsniff+v0.7+%E2%80%93+SSL+Man-In-The-Middle+%28MITM%29+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/07/sslsniff-v0-7-ssl-man-in-the-middle-mitm-tool/&amp;title=sslsniff+v0.7+%E2%80%93+SSL+Man-In-The-Middle+%28MITM%29+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/07/sslsniff-v0-7-ssl-man-in-the-middle-mitm-tool/&amp;title=sslsniff+v0.7+%E2%80%93+SSL+Man-In-The-Middle+%28MITM%29+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/07/sslsniff-v0-7-ssl-man-in-the-middle-mitm-tool/&amp;title=sslsniff+v0.7+%E2%80%93+SSL+Man-In-The-Middle+%28MITM%29+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F07%2Fsslsniff-v0-7-ssl-man-in-the-middle-mitm-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/07/sslsniff-v0-7-ssl-man-in-the-middle-mitm-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Burp Suite Free Edition v1.4 &#8211; Web Application Security Testing Tool</title>
		<link>http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/</link>
		<comments>http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/#comments</comments>
		<pubDate>Wed, 08 Jun 2011 11:00:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[burp]]></category>
		<category><![CDATA[burp suite download]]></category>
		<category><![CDATA[burp suite free edition]]></category>
		<category><![CDATA[burp v1.4]]></category>
		<category><![CDATA[burp-proxy]]></category>
		<category><![CDATA[burp-suite]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-security-testing]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3127</guid>
		<description><![CDATA[We love Burp Suite and we have since wayyyy back, the last update we posted was around 18 months ago back in January 2010 &#8211; Burp Suite v1.3 Released – Integrated Platform For Attacking Web Applications. For the two people here who don&#8217;t know what this tool does, Burp Suite is an integrated platform for [...]]]></description>
			<content:encoded><![CDATA[<p>We love <a href="http://www.darknet.org.uk/tag/burp-suite/">Burp Suite</a> and we have since wayyyy back, the last update we posted was around 18 months ago back in January 2010 &#8211; <a href="http://www.darknet.org.uk/2010/01/burp-suite-v1-3-released-integrated-platform-for-attacking-web-applications/">Burp Suite v1.3 Released – Integrated Platform For Attacking Web Applications</a>.</p>
<p>For the two people here who don&#8217;t know what this tool does, Burp Suite is an integrated platform for performing security testing of web applications. Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application&#8217;s attack surface, through to finding and exploiting security vulnerabilities.</p>
<p>Burp gives you full control, letting you combine advanced manual techniques with state-of-the-art automation, to make your work faster, more effective, and more fun.</p>
<p>And now, we&#8217;re happy to announce there&#8217;s a new version out and it&#8217;s available for download now!</p>
<p><strong>New Features</strong></p>
<ul>
<li>The ability to compare site maps</li>
<li>Functions to help with testing access controls using your browser</li>
<li>Support for preset request macros</li>
<li>Session handling rules to help you work with difficult situations</li>
<li>In-browser rendering of responses from all Burp tools</li>
<li>Auto recognition and rendering of character sets</li>
<li>Support for upstream SOCKS proxies</li>
<li>Headless mode for unattended scripted usage</li>
<li>Support for more types of redirection</li>
<li>Support for NTLMv2 and IPv6</li>
<li>Numerous enhancements to Burp&#8217;s extensibility</li>
<li>Greater stability on OSX</li>
</ul>
<p>You can download Burp Suite Free Edition v1.4 here:</p>
<p><a href="http://portswigger.net/burp/burpsuite_v1.4.zip">burpsuite_v1.4.zip</a></p>
<p>Or read more <a href="http://portswigger.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3127+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;t=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/&amp;title=Burp+Suite+Free+Edition+v1.4+%E2%80%93+Web+Application+Security+Testing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F06%2Fburp-suite-free-edition-v1-4-web-application-security-testing-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/06/burp-suite-free-edition-v1-4-web-application-security-testing-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FaceNiff &#8211; Taking FireSheep Mobile &#8211; Sniff &amp; Intercept Web Sessions With Android</title>
		<link>http://www.darknet.org.uk/2011/06/faceniff-taking-firesheep-mobile-sniff-intercept-web-sessions-with-android/</link>
		<comments>http://www.darknet.org.uk/2011/06/faceniff-taking-firesheep-mobile-sniff-intercept-web-sessions-with-android/#comments</comments>
		<pubDate>Mon, 06 Jun 2011 09:57:52 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[android network sniffer]]></category>
		<category><![CDATA[android network sniffing app]]></category>
		<category><![CDATA[android session stealing tool]]></category>
		<category><![CDATA[blacksheep]]></category>
		<category><![CDATA[faceniff]]></category>
		<category><![CDATA[firesheep]]></category>
		<category><![CDATA[firesheep android]]></category>
		<category><![CDATA[firesheep mobile]]></category>
		<category><![CDATA[intercept web profile]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[steal web session]]></category>
		<category><![CDATA[steal web session profile]]></category>
		<category><![CDATA[web session profile]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3123</guid>
		<description><![CDATA[FaceNiff is an Android app that allows you to sniff and intercept web session profiles over the WiFi that your mobile is connected to. It is possible to hijack sessions only when WiFi is not using EAP, but it should work over any private networks (Open/WEP/WPA-PSK/WPA2-PSK). It&#8217;s kind of like Firesheep for android, but maybe [...]]]></description>
			<content:encoded><![CDATA[<p>FaceNiff is an Android app that allows you to sniff and intercept web session profiles over the WiFi that your mobile is connected to. It is possible to hijack sessions only when WiFi is not using EAP, but it should work over any private networks (Open/WEP/WPA-PSK/WPA2-PSK).</p>
<p>It&#8217;s kind of like <a href="http://www.darknet.org.uk/2010/10/firesheep-social-network-session-stealinghijacking-tool/">Firesheep</a> for android, but maybe a bit easier to use (and it works on WPA2!).</p>
<p>Do note that a rooted phone is required. Please note that if the webuser uses <a href="http://www.darknet.org.uk/tag/ssl/">SSL</a> this application won&#8217;t work This application due to its nature is very phone-dependent so please let the author know if it doesn&#8217;t work for you.</p>
<p>There&#8217;s a great video demo of it working here:</p>
<p align="center"><iframe width="560" height="349" src="http://www.youtube.com/embed/3bgwVM7t_s4?rel=0" frameborder="0" allowfullscreen></iframe></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p><strong>Supported services:</strong></p>
<ul>
<li>    FaceBook</li>
<li>    Twitter</li>
<li>    Youtube</li>
<li>    Amazon</li>
<li>    Nasza-Klasa</li>
</ul>
<p>You can download FaceNiff here:</p>
<p><a href="http://faceniff.ponury.net/FaceNiff-1.9.4.apk">FaceNiff-1.9.4.apk</a></p>
<p>Or read more <a href="http://faceniff.ponury.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=FaceNiff+%E2%80%93+Taking+FireSheep+Mobile+%E2%80%93+Sniff+%26+Intercept+Web+Sessions+With+Android+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3123+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/06/faceniff-taking-firesheep-mobile-sniff-intercept-web-sessions-with-android/&amp;t=FaceNiff+%E2%80%93+Taking+FireSheep+Mobile+%E2%80%93+Sniff+%26+Intercept+Web+Sessions+With+Android" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/06/faceniff-taking-firesheep-mobile-sniff-intercept-web-sessions-with-android/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/06/faceniff-taking-firesheep-mobile-sniff-intercept-web-sessions-with-android/&amp;title=FaceNiff+%E2%80%93+Taking+FireSheep+Mobile+%E2%80%93+Sniff+%26+Intercept+Web+Sessions+With+Android" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/06/faceniff-taking-firesheep-mobile-sniff-intercept-web-sessions-with-android/&amp;title=FaceNiff+%E2%80%93+Taking+FireSheep+Mobile+%E2%80%93+Sniff+%26+Intercept+Web+Sessions+With+Android" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/06/faceniff-taking-firesheep-mobile-sniff-intercept-web-sessions-with-android/&amp;title=FaceNiff+%E2%80%93+Taking+FireSheep+Mobile+%E2%80%93+Sniff+%26+Intercept+Web+Sessions+With+Android" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/06/faceniff-taking-firesheep-mobile-sniff-intercept-web-sessions-with-android/&amp;title=FaceNiff+%E2%80%93+Taking+FireSheep+Mobile+%E2%80%93+Sniff+%26+Intercept+Web+Sessions+With+Android" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F06%2Ffaceniff-taking-firesheep-mobile-sniff-intercept-web-sessions-with-android%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/06/faceniff-taking-firesheep-mobile-sniff-intercept-web-sessions-with-android/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

