The Parade of the Toolkits

Posted: 27/10/2010 in Tech

This list will certainly be updated in the near future. It is by no mean an exhaustive list of useful tools for pentesters:

Bruteforcer

  • THC Hydra:

http://www.thc.org/releases.php

  • Brutus (useful to brute force telnet and basic auth too):

http://www.hoobie.net/brutus/brutus-download.html

  • nikto_ntlm.plugin (a custom-written nikto plugin to brute force NTLM)

Web App

ASP Assessment

  • DNA Scan:

http://examples.oreilly.com/networksa/tools/dnascan.pl.gz
http://metasploit.com/users/hdm/tools/dnascan.pl.gz

  • ASP Auditor:

http://michaeldaw.org/projects/asp-audit-v1BETA.tar.gz

Web Server Assessment

  • Nikto
  • Wikto (Windows based Nikto)
Advertisement

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s