A Look Back At 2014 – Tools & News Highlights

Use Netsparker


So it’s back to normal programming today, here’s a look back at 2014 (ups and down) and interesting happenings over the past 12 months – including tools and news stories.

2014 Darknet Summary

2014 News Stories

So Bitcoin and cryptocurrency in general was a pretty hot topic in 2014, and the year started out with Yahoo! spreading malware via adverts on their portal.

Later in the year in May, some smart pirates infested the hottest new game Watchdogs with Bitcoin mining malware and made themselves a fortune. There was also an academic paper about hiding a Bitcoin Mining Botnet in the Cloud using free tier accounts – pretty interesting stuff.

There was of course some massive drama too with some large scale vulnerabilities that got everyone in a panic like the SSL bug Heartbleed, the OTHER SSL bug POODLE and the BASH Shellshock.

It turns out nothing really major happened due to either of them, as far as we know anyway..

There were some large scale hacks/compromises in 2014 though such as Target, eBay, Spotify, Code Spaces, the massive celeb leak/fappening, JPMorgan, ICANN and the mother of all hacks in 2014 and possible ever – Sony Pictures who got totally owned.

There was loads of vulns found in Microsoft software (Schannel was pretty important), as usual – so we won’t bother listing all of those out. Some other fairly inconsequential stuff like bugs in WordPress and a pretty nifty (really ancient) bug in FTP.

2014 Best Hacking Tools

There’s been some pretty neat stuff released this year, with highlights being:

You may have overlooked some of these, so do check them out if you did!

Bonus – Top 10 Most Viewed Posts From 2014

  1. PACK – Password Analysis & Cracking Kit
  2. ICANN Hacked Including Root DNS Systems
  3. Massive Celeb Leak Brings iCloud Security Into Question
  4. Blackhash – Audit Passwords Without Hashes
  5. masscan – The Fastest TCP Port Scanner
  6. Password Manager Security – LastPass, RoboForm Etc Are Not That Safe
  7. 14-Year Olds Hack ATM With Default Password
  8. ODAT (Oracle Database Attacking Tool) – Test Oracle Database Security
  9. ParanoiDF – PDF Analysis & Password Cracking Tool
  10. The 25 Worst Passwords Of 2013 – “password” Is Not #1

Enjoy 2015!

Posted in: Site News


Latest Posts:


HTTP Security Considerations - An Introduction To HTTP Basics HTTP Security Considerations – An Introduction To HTTP Basics
HTTP is ubiquitous now with pretty much everything being powered by an API, a web application or some kind of cloud-based HTTP driven infrastructure. With that HTTP Security becomes paramount and to secure HTTP you have to understand it.
Cangibrina - Admin Dashboard Finder Tool Cangibrina – Admin Dashboard Finder Tool
Cangibrina is a Python-based multi platform admin dashboard finder tool which aims to obtain the location of website dashboards by using brute-force, wordlists etc.
Enumall - Subdomain Discovery Using Recon-ng & AltDNS Enumall – Subdomain Discovery Using Recon-ng & AltDNS
Enumall is a Python-based tool that helps you do subdomain discovery using only one command by combining the abilities of Recon-ng and AltDNS.
RidRelay - SMB Relay Attack For Username Enumeration RidRelay – SMB Relay Attack For Username Enumeration
RidRelay is a Python-based tool to enumerate usernames on a domain where you have no credentials by using a SMB Relay Attack with low privileges.
NetBScanner - NetBIOS Network Scanner NetBScanner – NetBIOS Network Scanner
NetBScanner is a NetBIOS network scanner tool that scans all computers in the IP addresses range you choose, using the NetBIOS protocol.
Metta - Information Security Adversarial Simulation Tool Metta – Information Security Adversarial Simulation Tool
Metta is an information security preparedness tool in Python to help with adversarial simulation and assess security defense preparation and alerts.


One Response to A Look Back At 2014 – Tools & News Highlights

  1. Knife January 6, 2015 at 10:08 pm #

    Also worth mentioning were the US State Department, White House, and US Postal Service hacks during the fall. 800,000 social security numbers were reported exposed from the IS Postal Service hack alone.

    http://www.theguardian.com/us-news/2014/nov/17/state-department-email-attack-shutdown