Pentoo – Gentoo Based Penetration Testing Linux LiveCD

Use Netsparker


Pentoo is a Gentoo based penetrating testing linux LiveCD. It’s basically a Gentoo install with lots of customized tools, customized kernel, and much more. Here is a non-exhaustive list of the features currently included:

  • Hardened Kernel with aufs patches
  • Backported Wifi stack from latest stable kernel release
  • Module loading support ala slax
  • Changes saving on usb stick
  • XFCE4 wm
  • Cuda/OPENCL cracking support with development tools
  • System updates if you got it finally installed

Pentoo - Gentoo Based Penetration Testing Linux LiveCD

Put simply, Pentoo is Gentoo with the Pentoo overlay. This overlay is available in layman so all you have to do is layman -L and layman -a pentoo. We have a pentoo/pentoo meta ebuild and multiple pentoo profiles, which will install all the pentoo tools based on USE flags.

Pentoo has been around for a LONG time, it even got a brief mention in our epic 2006 article 10 Best Security Live CD Distros (Pen-Test, Forensics & Recovery) with over a million views. But it was pretty new back then, 9 years later it’s still around (unlike most of the other LiveCD distros which have disappeared).

It’s also still active and has a 2015 just released! It’s great to see such a dedicated team working on something for so many years.


Tool Categories

  • Analyzer
  • Bluetooth
  • Cracker
  • Database
  • Development
  • Exploit
  • Footprint
  • Forensics
  • Forging
  • Fuzzers
  • Misc
  • MitM
  • Pentoo
  • Proxy
  • RCE
  • Scanner
  • SIP-VOIP
  • Wireless

Notable Changes in 2015.0 RC3.7

  • Changes saving (including unetbooting support)
  • CUDA/OpenCL Enhanced cracking software
  • Kernel 3.15.5 and all needed patches for injection
  • XFCE 4.10

The full tool list is available here (it’s HUGE):

tools_list_x86_64_2014_0_RC3_5

You can download Pentoo 2015.0 RC3.7 here:

Direct – pentoo-amd64-hardened-2015.0_RC3.7.iso
Torrent – Pentoo_Linux_amd64_hardened_2015.0_RC3.7.torrent

Or read more here.

Posted in: Hacking Tools, Linux Hacking, Web Hacking

, ,


Latest Posts:


SCADA Hacking - Industrial Systems Woefully Insecure SCADA Hacking – Industrial Systems Woefully Insecure
airgeddon - Wireless Security Auditing Script airgeddon – Wireless Security Auditing Script
Airgeddon is a Bash powered multi-use Wireless Security Auditing Script for Linux systems with an extremely extensive feature list.
Acunetix v12 - Pause & Resume Acunetix v12 – More Comprehensive More Accurate & 2x Faster
Acunetix, the pioneer in automated web application security software, has announced the release of Acunetix v12 - more comprehensive, accurate & 2x faster.
CloudFrunt - Identify Misconfigured CloudFront Domains CloudFrunt – Identify Misconfigured CloudFront Domains
CloudFrunt is a Python-based tool for identifying misconfigured CloudFront domains, it uses DNS and looks for CNAMEs which may be allowed to be associated with CloudFront distributions.
Airbash - Fully Automated WPA PSK Handshake Capture Script Airbash – Fully Automated WPA PSK Handshake Capture Script
Airbash is a POSIX-compliant, fully automated WPA PSK handshake capture script aimed at penetration testing, it is compatible with Bash and Android Shell.
XXEinjector - Automatic XXE Injection Tool For Exploitation XXEinjector – Automatic XXE Injection Tool For Exploitation
XXEinjector is an XXE Injection Tool that automates retrieving files using direct and out of band methods. Directory listing only works in Java applications.


Comments are closed.