<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; exploitation-framework</title>
	<atom:link href="http://www.darknet.org.uk/tag/exploitation-framework/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Metasploit Framework 3.4.1 Released &#8211; 16 New Exploits, 22 Modules &amp; 11 Meterpreter Scripts</title>
		<link>http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/</link>
		<comments>http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/#comments</comments>
		<pubDate>Fri, 16 Jul 2010 09:03:37 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[automated-hacking]]></category>
		<category><![CDATA[automatic hacking]]></category>
		<category><![CDATA[download metasploit]]></category>
		<category><![CDATA[exploit payload]]></category>
		<category><![CDATA[exploit techniques]]></category>
		<category><![CDATA[exploit-framework]]></category>
		<category><![CDATA[exploitation-framework]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-software]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[metasploit 3.4]]></category>
		<category><![CDATA[metasploit 3.4.1]]></category>
		<category><![CDATA[metasploit express]]></category>
		<category><![CDATA[metasploit-exploit-framework]]></category>
		<category><![CDATA[metasploit-framework]]></category>
		<category><![CDATA[meterpreter]]></category>
		<category><![CDATA[security-tools]]></category>
		<category><![CDATA[shellcode]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2801</guid>
		<description><![CDATA[The Metasploit Project is proud to announce the release of the Metasploit Framework version 3.4.1. This release sees the first official non-Windows Meterpreter payload, in PHP as discussed last month here. Rest assured that more is in store for Meterpreter on other platforms. A new extension called Railgun is now integrated into Meterpreter courtesy of [...]]]></description>
			<content:encoded><![CDATA[<p>The Metasploit Project is proud to announce the release of the Metasploit Framework version 3.4.1. This release sees the first official non-Windows Meterpreter payload, in PHP as discussed last month <a href="http://blog.metasploit.com/2010/06/meterpreter-for-pwned-home-pages.html">here</a>. </p>
<p>Rest assured that more is in store for Meterpreter on other platforms.  A new extension called Railgun is now integrated into Meterpreter courtesy of Patrick HVE, giving you scriptable access to Windows  APIs and an unprecedented amount of control over post-exploitation.</p>
<p>For those of you wishing to contribute to the framework, a new file called HACKING has been introduced that lays out a few guidelines to make it easier.</p>
<p>This release contains 16 new exploits, 22 new auxiliary modules and 11 new Meterpreter scripts for your pwning enjoyment.  The major changes in terms of numbers were:</p>
<ul>
<li>567 exploits and 283 auxiliary modules (up from 551 and 261 in v3.4)</li>
<li>Over 40 community reported bugs were fixed and numerous interfaces were improved</li>
</ul>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-BodyRec */
google_ad_slot = "8649785837";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div></p>
<p>For more in-depth information about this release, see the 3.4.1 release notes here:</p>
<p><a href="https://www.metasploit.com/redmine/projects/framework/wiki/Release_Notes_341">Metasploit 3.4.1 Release Notes</a></p>
<p>You can download Metasploit 3.4.1 <a href="http://www.metasploit.com/framework/download/">here</a>:</p>
<p>Windows &#8211; <a href="http://www.metasploit.com/releases/framework-3.4.1.exe">framework-3.4.1.exe</a><br />
Linux (32-Bit) &#8211; <a href="http://www.metasploit.com/releases/framework-3.4.1-linux-i686.run">framework-3.4.1-linux-i686.run</a></p>
<p>Or read more <a href="http://www.metasploit.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2801+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;t=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;title=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;title=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;title=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;title=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F07%2Fmetasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Metasploit 3.4.0 Hacking Framework Released &#8211; Over 100 New Exploits Added</title>
		<link>http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/</link>
		<comments>http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/#comments</comments>
		<pubDate>Thu, 20 May 2010 10:00:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[automated-hacking]]></category>
		<category><![CDATA[automatic hacking]]></category>
		<category><![CDATA[exploit payload]]></category>
		<category><![CDATA[exploit techniques]]></category>
		<category><![CDATA[exploit-framework]]></category>
		<category><![CDATA[exploitation-framework]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-software]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[metasploit 3.4]]></category>
		<category><![CDATA[metasploit express]]></category>
		<category><![CDATA[metasploit-exploit-framework]]></category>
		<category><![CDATA[metasploit-framework]]></category>
		<category><![CDATA[rapid7]]></category>
		<category><![CDATA[rapid7 metasploit]]></category>
		<category><![CDATA[security-tools]]></category>
		<category><![CDATA[shellcode]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2695</guid>
		<description><![CDATA[Metasploit provides useful information and tools for penetration testers, security researchers, and IDS signature developers. This project was created to provide information on exploit techniques and to create a functional knowledgebase for exploit developers and security professionals. The tools and information on this site are provided for legal security research and testing purposes only. Update [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Metasploit provides useful information and tools for penetration testers, security researchers, and IDS signature developers. This project was created to provide information on exploit techniques and to create a functional knowledgebase for exploit developers and security professionals. The tools and information on this site are provided for legal security research and testing purposes only.</p>
<p><strong>Update Summary</strong></p>
<ul>
<li>Metasploit now has 551 exploit modules and 261 auxiliary modules (from 445 and 216 respectively in v3.3)</li>
<li>Metasploit is still about twice the size of the nearest Ruby application according to Ohloh.net (400K lines of Ruby)</li>
<li>Over 100 tickets were closed since the last point release and over 200 since v3.3</li>
</ul>
<p>After five months of development, version 3.4.0 of the Metasploit Framework has been released. Since the last major release (<a href="http://www.darknet.org.uk/2009/11/metasploit-3-3-released-exploitation-framework/">Metasploit 3.3</a>) over 100 new exploits have been added and over 200 bugs have been fixed.</p>
<p>This release includes massive improvements to the Meterpreter payload; both in terms of stability and features, thanks in large part to Stephen Fewer of Harmony Security. The Meterpreter payload can now capture screenshots without migrating, including the ability to bypass Session 0 Isolation on newer Windows operating systems. This release now supports the ability to migrate back and forth between 32-bit and 64-bit processes on a compromised Windows 64-bit operating system. The Meterpreter protocol now supports inline compression using zlib, resulting in faster transfers of large data blocks. A new command, &#8220;getsystem&#8221;, uses several techniques to gain system access from a low-privileged or administrator-level session, including the exploitation of Tavis Ormandy&#8217;s KiTrap0D vulnerability. Brett Blackham contributed a patch to compress screenshots on the server side in JPG format, reducing the overhead of the screen capture command. The pivoting backend of Meterpreter now supports bi-directional UDP and TCP relays, a big upgrade from the outgoing-only TCP pivoting capabilities of version 3.3.3.</p>
<p>This is the first version of Metasploit to have strong support for bruteforcing network protocols and gaining access with cracked credentials. A new mixin has been created that standardizes the options available to each of the brute force modules. This release includes support for brute forcing accounts over SSH, Telnet, MySQL, Postgres, SMB, DB2, and more, thanks to Tod Bearsdley and contributions from Thomas Ring.</p>
<p>Metasploit now has support for generating malicious JSP and WAR files along with exploits for Tomcat and JBoss that use these to gain remote access to misconfigured installations. A new mixin was creating compiling and signing Java applets on fly, courtesy of Nathan Keltner. Thanks to some excellent work by bannedit and Joshua Drake, command injection of a cmd.exe shell on Windows can be staged into a full Meterpreter shell using the new &#8220;sessions -u&#8221; syntax.</p>
<p><a href="http://www.metasploit.com/redmine/projects/framework/wiki/Release_Notes_34">Full Metasploit 3.4.0 Release Notes</a></p>
<p>You can download Metasploit 3.4.0 here:</p>
<p>Windows &#8211; <a href="http://www.metasploit.com/releases/framework-3.4.0.exe">framework-3.4.0.exe</a><br />
Linux &#8211; <a href="http://www.metasploit.com/releases/framework-3.4.0-linux-i686.run">framework-3.4.0-linux-i686.run</a></p>
<p></p>
<p>Or read more <a href="http://www.metasploit.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2695+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;t=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;title=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;title=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;title=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;title=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F05%2Fmetasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Browser Rider &#8211; Web Browser Exploitation Framework</title>
		<link>http://www.darknet.org.uk/2008/11/browser-rider-web-browser-exploitation-framework/</link>
		<comments>http://www.darknet.org.uk/2008/11/browser-rider-web-browser-exploitation-framework/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 07:16:17 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[browser exploitation framework]]></category>
		<category><![CDATA[browser rider]]></category>
		<category><![CDATA[exploitation-framework]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1261</guid>
		<description><![CDATA[Browser Rider is a hacking framework to build payloads that exploit the browser. The project aims to provide a powerful, simple and flexible interface to any client side exploit. Browser Rider is not a new concept. Similar tools such as BeEF or Backframe exploited the same concept. However most of the other existing tools out [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Browser Rider is a hacking framework to build payloads that exploit the browser. The project aims to provide a powerful, simple and flexible interface to any client side exploit.</p>
<p>Browser Rider is not a new concept. Similar tools such as <a href="http://www.darknet.org.uk/2006/10/beef-browser-exploitation-framework/">BeEF</a> or <a href="http://www.darknet.org.uk/2006/12/backframe-formerly-backweb-javascript-attack-console/">Backframe</a> exploited the same concept. However most of the other existing tools out there are unmaintained, not updated and not documented. Browser Rider wants to fill those gaps by providing a better alternative.</p>
<p><strong>Features</strong></p>
<ul>
<li>Easily create powerful payloads and plugins</li>
<li>Manage payloads automatically with plugins</li>
<li>All data can be saved in a database</li>
<li>Obfuscation</li>
<li>Polymorphism</li>
<li>Control more than one zombie at a time</li>
<li>Simple administration panel</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>PHP 5, with json installed</li>
<li>Mysql</li>
<li>Apache with url_rewrite on</li>
<li>Targets must have Javascript turned on</li>
</ul>
<p>You can download Browser Rider here:</p>
<p><a href="http://www.engineeringforfun.com/cave/browserrider/BrowserRider.20081124.tar.bz2">Browser Rider v20081124</a> (<a href="http://www.engineeringforfun.com/wiki/index.php/Browser_Rider_Changelog#Browser_Rider_v20081124">changelog</a>)</p>
<p></p>
<p>Or read more <a href="http://engineeringforfun.com/browserrider.html">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Browser+Rider+%E2%80%93+Web+Browser+Exploitation+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1261+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/11/browser-rider-web-browser-exploitation-framework/&amp;t=Browser+Rider+%E2%80%93+Web+Browser+Exploitation+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/11/browser-rider-web-browser-exploitation-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/11/browser-rider-web-browser-exploitation-framework/&amp;title=Browser+Rider+%E2%80%93+Web+Browser+Exploitation+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/11/browser-rider-web-browser-exploitation-framework/&amp;title=Browser+Rider+%E2%80%93+Web+Browser+Exploitation+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/11/browser-rider-web-browser-exploitation-framework/&amp;title=Browser+Rider+%E2%80%93+Web+Browser+Exploitation+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/11/browser-rider-web-browser-exploitation-framework/&amp;title=Browser+Rider+%E2%80%93+Web+Browser+Exploitation+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F11%2Fbrowser-rider-web-browser-exploitation-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/11/browser-rider-web-browser-exploitation-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Alternatives to FrSIRT &#8211; Where to Download Exploits?</title>
		<link>http://www.darknet.org.uk/2006/04/alternatives-to-frsirt-where-to-download-exploits/</link>
		<comments>http://www.darknet.org.uk/2006/04/alternatives-to-frsirt-where-to-download-exploits/#comments</comments>
		<pubDate>Wed, 26 Apr 2006 04:32:28 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[exploit-tree]]></category>
		<category><![CDATA[exploitation-framework]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[frsirt]]></category>
		<category><![CDATA[milw0rm]]></category>
		<category><![CDATA[packetstorm]]></category>
		<category><![CDATA[security-forest]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/alternatives-to-frsirt-where-to-download-exploits/</guid>
		<description><![CDATA[Since FrSIRT closed it&#8217;s public archives and starting charging for access (blaming it on French laws&#8230;), people have been wondering where they can their dose of Exploits..For legitimate purposes obviously. Security Forest The most comprehensive collection in my opinion comes from SecurityForest. They also have a BETA exploitation framework in development, something like a Metasploit, [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Since <a href="http://www.darknet.org.uk/2006/03/frsirt-starts-charging-for-other-peoples-work-exploits/">FrSIRT closed it&#8217;s public archives</a> and starting charging for access (blaming it on French laws&#8230;), people have been wondering where they can their dose of Exploits..For legitimate purposes obviously.</p>
<h2>Security Forest</h2>
<p>The most comprehensive collection in my opinion comes from <a href="http://www.securityforest.com/wiki/index.php/Main_Page">SecurityForest</a>. They also have a <a href="http://www.securityforest.com/wiki/index.php/Exploitation_Framework">BETA exploitation framework</a> in development, something like a Metasploit, but with a much larger range of exploits.</p>
<p>The part of SecurityForest you need to look at is the <a href="http://www.securityforest.com/wiki/index.php/Category:ExploitTree">Exploit Tree</a>.</p>
<p>I love the way it works, as it&#8217;s based on CVS, so you just download whatever you don&#8217;t have everytime you update.</p>
<blockquote><p>The ExploitTree is a categorized collection of ALL available exploit code. ExploitTree&#8217;s ambition is to become the most organized, rich and up-to-date exploit repository on the internet. The ExploitTree is based on CVS (Concurrent Versioning System) and therefore allows the user to keep an up-to-date offline mirror of the repository on their hard drive. When an ExploitTree Administrator updates their local copy with a new/updated exploit, it updates the repository and keeps everyone else up-to-date. Furthermore, a web interface for web browsing is available.</p></blockquote>
<p>It is a really impressive collection and very well categorised. It works fine on both Windows and *nix based systems. You can also <a href="http://www.securityforest.com/cgi-bin/viewcvs.cgi/">browse online here</a>.</p>
<h2>milw0rm</h2>
<p><a href="http://www.milw0rm.com/">milw0rm</a> is less mainstream and started out as a personal site, but has grown into a comprehensive and well organised archive of exploits.</p>
<p>It can be organised various ways, by <a href="http://www.milw0rm.com/platforms/">platform</a>, <a href="http://www.milw0rm.com/remoteport.php">by port</a>, <a href="http://www.milw0rm.com/phpsoft.php">for PHP</a>, <a href="http://www.milw0rm.com/aspsoft.php">for ASP</a> etc.</p>
<h2>Securiteam</h2>
<p>Securiteam is quite commercial, but has an archive of verified exploits &#8211; going back to 1998, verified by their own team of &#8216;experts&#8217;. Note however Securiteam isn&#8217;t greatly liked on lists such as Full Disclosure (mostly for spamming their <a href="http://blogs.securiteam.com/">blog</a>).</p>
<p><a href="http://www.securiteam.com/exploits/archive.html">Securiteam Exploits Archive.</a></p>
<blockquote><p>SecuriTeamâ„¢ is a group within Beyond SecurityÂ® dedicated to bringing you the latest news and utilities in computer security.</p>
<p>Having experience as Security Specialists, Programmers and System Administrators we appreciate your need for a &#8220;Security Portal&#8221; &#8211; A central Security web site containing all the newest security information from various mailing lists, hacker channels and our own tools and knowledge.</p></blockquote>
<h2>Packetstorm</h2>
<p>Packetstorm is one of the oldest sites, and has a reasonbly good archive of exploits.</p>
<p><a href="http://www.packetstormsecurity.org/assess/exploits/">Packetstorm Exploits</a></p>
<p>It goes back to about 1998 too.</p>
<blockquote><p>Packet Storm offers an abundant resource of up-to-date and historical security tools, exploits, and advisories. We are a non-profit organization comprised of security professionals that are dedicated to providing the information necessary to secure networks on a global scale. We accomplish this goal by publishing new security information on a global network of websites.</p></blockquote>
<h2>Others</h2>
<p>You can also check out:</p>
<p><a href="http://www.governmentsecurity.org/exploits.php">Government Security Archive</a><br />
<a href="http://secwatch.org/exploits/">Secwatch</a><br />
<a href="http://www.hackersplayground.org/exploits.html">Hackers Playground</a></p>
<h2>Various</h2>
<p>You can find the odd private archives online too, but they tend to go up and down, and sometimes when you have something specific in mind, it&#8217;s just best to hit Google and <a href="http://groups.google.com/">Google Groups</a> to mine it out.</p>
<p>Don&#8217;t forget the good stuff like Google Hacking too.</p>
<p>Plus the <a href="http://www.darknet.org.uk/2006/03/10-best-security-live-cd-distros-pen-test-forensics-recovery/">Security and Hacking LiveCD&#8217;s</a> have quite a lot of compiled &#038; working exploits inside too.</p>
<p></p>
<p><a href="http://digg.com/security/Where_can_I_download_EXPLOITS_">Digg This Article</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Alternatives+to+FrSIRT+%E2%80%93+Where+to+Download+Exploits%3F+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D134+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/04/alternatives-to-frsirt-where-to-download-exploits/&amp;t=Alternatives+to+FrSIRT+%E2%80%93+Where+to+Download+Exploits%3F" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/04/alternatives-to-frsirt-where-to-download-exploits/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/04/alternatives-to-frsirt-where-to-download-exploits/&amp;title=Alternatives+to+FrSIRT+%E2%80%93+Where+to+Download+Exploits%3F" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/04/alternatives-to-frsirt-where-to-download-exploits/&amp;title=Alternatives+to+FrSIRT+%E2%80%93+Where+to+Download+Exploits%3F" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/04/alternatives-to-frsirt-where-to-download-exploits/&amp;title=Alternatives+to+FrSIRT+%E2%80%93+Where+to+Download+Exploits%3F" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/04/alternatives-to-frsirt-where-to-download-exploits/&amp;title=Alternatives+to+FrSIRT+%E2%80%93+Where+to+Download+Exploits%3F" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F04%2Falternatives-to-frsirt-where-to-download-exploits%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/04/alternatives-to-frsirt-where-to-download-exploits/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

