SecLists [Collection of multiple types of lists used during security assessments]

SecLists is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings, fuzzing payloads, and many more.
The goal is to enable a security tester to pull this repo onto a new testing box and have access to every type of list that may be needed.


If you have any ideas for things we should include, please send them to daniel.miessler@owasp.org or jason.haddix@owasp.org. Also note that any lists that have been meticulously assembled by someone else will only be used with permission of the creator.
This project is maintained by Daniel Miessler and Jason Haddix. 
Credits:
- Ron Bowes of SkullSecurity for collaborating and including all his lists here
- Clarkson University for their research that led to the Clarkson list
- All the authors listed in the XSS with context doc, which was found on pastebin and added to by us
- Ferruh Mavitina for the begginings of the LFI Fuzz list
- Adam Muntner and  for the FuzzDB content, including all authors from the FuzzDB project
- Kevin Johnson for laudnaum shells
- RSnake for fierce hostname list 


[Suricata 1.4.2] Next Generation Intrusion Detection and Prevention Engine


The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field.
OISF is part of and funded by the Department of Homeland Security's Directorate for Science and Technology HOST program (Homeland Open Security Technology), by the the Navy's Space and Naval Warfare Systems Command (SPAWAR), as well as through the very generous support of the members of the OISF Consortium. More information about the Consortium is available, as well as a list of our current Consortium Members


 The Suricata Engine and the HTP Library are available to use under the GPLv2
The HTP Library is an HTTP normalizer and parser written by Ivan Ristic of Mod Security fame for the OISF. This integrates and provides very advanced processing of HTTP streams for Suricata. The HTP library is required by the engine, but may also be used independently in a range of applications and tools. 

Improvements

  • No longer force "nocase" to be used on http_host
  • Invalidate rule if uppercase content is used for http_host w/o nocase
  • Warn user if bpf is used in af-packet IPS mode
  • Better test for available libjansson version

Fixes


  • Fixed accuracy issues with relative pcre matching (#784)
  • Improved accuracy of file_data keyword (#788)
  • Invalidate negative depth (#770)
  • Fix http host parsing for IPv6 addresses (#761)
  • Fix fast.log formatting issues (#773)
  • Fixed deadlock in flowvar set code for http buffers (#801)
  • Various signature ordering improvements
  • Minor stream engine fix

Hardanger [Web Application Penetration Testing Platform]

Hardanger is an Open Source web application penetration testing tool led by security researchers from SecurityWire. The project aims to bridge the gap between current open source web application testing tools commonly used in a Linux environment and bring the same level of tools to native Windows based platforms. Hardanger aims to deliver a user friendly experience for semi-automated web application penetration testing by building tools on top of the excellent Fiddler2 web debugger.


The project deliverable is a Fiddler2 (http://www.fiddler2.com) add-on dll written in C# that is easily installed using a .msi installer and a standalone application is also be available for users that do not want the integrated Fiddler2 experience. Hardanger has been architected so it can be easily expanded to add other functionality. The first version only includes a simple HTTP(S) GET and POST parameter fuzzer but will has built a foundation where it is trivial to plug in additional fuzzers and detection engines as well as other features. Once server fuzzing is perfected and state of the art, this project will continue to add new features such as a web browser fuzzer, brute force tool, manual tampering, crawler, passive vulnerability detection, recon tools, etc.



Current Features
  • Native Windows feel via Windows Presentation Foundation
  • Can run as a Fiddler2 add-on or standalone
  • ClickOnce installer with automatic updates (standalone version)
  • Context tab allowing inspection of full HTTP requests
  • Server fuzzer tab to configure and launch the server fuzzer
  • Basic random fuzzer generates random strings of UTF8 characters of random lengths
  • Non HTTP 200 detection engine
  • Results window keeping track of successful detections
  • Ability to review requests/responses in the results details window


AndroRat [Remote Administration Tool for Android]

Androrat is a client/server application developed in Java Android for the client side and in Java/Swing for the Server.
The name Androrat is a mix of Android and RAT (Remote Access Tool).
It has been developed in a team of 4 for a university project. It has been realised in one month. The goal of the application is to give the control of the android system remotely and retrieve informations from it.

Technical matters

  • The android application is the client for the server which receive all the connections.
  • The android application run as a service(not an activity) that is started during the boot. So the user does not need to interact with the service (Even though there is a debug activity that allow to configure the IP and the port to connect to).
  • The connection to the server can be triggered by a SMS or a call (this can be configured)

All the available functionalities are

  • Get contacts (and all theirs informations)
  • Get call logs
  • Get all messages
  • Location by GPS/Network
  • Monitoring received messages in live
  • Monitoring phone state in live (call received, call sent, call missed..)
  • Take a picture from the camera
  • Stream sound from microphone (or other sources..)
  • Streaming video (for activity based client only)
  • Do a toast
  • Send a text message
  • Give call
  • Open an URL in the default browser
  • Do vibrate the phone

Folders

The project contains the following folders:

  • doc: Will soonly contain all the documentation about the project
  • Experiment: Contain an experimental version of the client articulated around an activity wish allow by the way to stream video
  • src/Androrat: Contain the source code of the client that should be put on the android plateform
  • src/AndroratServer: Contain the sources of the Java/Swing server that can be run on any plateform
  • src/api: Contain all the different api used in the project (JMapViewer for the map, forms for swing, and vlcj for video streaming)
  • src/InOut: Contain the code of the content common for the client and the server which is basically the protocol implementation

MobiSec [Mobile security testing live environment]


The MobiSec Live Environment Mobile Testing open source project is a live environment for testing mobile environments, including devices, applications, and supporting infrastructure. The purpose is to provide attackers and defenders the ability to test their mobile environments to identify design weaknesses and vulnerabilities.

MobiSec provides a single environment for testers to leverage the best of all available open source mobile testing tools, as well as the ability to install additional tools and platforms, that will aid the penetration tester through the testing process as the environment is structured and organized based on an industry-proven testing framework. Using a live environment provides penetration testers the ability to boot the MobiSec Live Environment on any Intel-based system from a DVD or USB flash drive, or run the test environment within a virtual machine.

[Download]

Project Neptune 2.0

Project Neptune is simply a top tier program in monitoring the Windows OS.  It’s uses are simply undefined and endless – but we’ll try to give you some insight on it.
Project Neptune is for monitoring web history, application history, and even messenger and email history through the simple usage of monitoring a computer’s keyboard input.  Of course, we here at project-neptune.net don’t limit the application at that – no, we take it much, much further.  
With over fifty dynamic features, we definitely pride ourselves in the ability to provide an extremely diverse application.  We also note, however, that the program is extremely simple and the steps to get started are very simple.  However, some technical information you may like to know is that Neptune uses custom coded keyboard hooks, CodeDOM technology for unique generation for each computer you wish to use it on, and the ability to save and edit your settings at any time.

So, what is Project Neptune used for?  Its usage spans across many different areas.  The number one usage, however, is for monitoring the application of your computers and those who use them.   You may wish to monitor your spouse.  You may wish to monitor your children.  Or, you may be a boss and you may wish to monitor your employees.   Neptune handles all of these jobs wonderfully.  Its usage, however, doesn’t stop there.  Perhaps you’re a book or article author and you need quick backups of your written work.  Neptune handles this wonderfully.

[Download]

Jspy RAT v0.08 [Java Multiplatform Remote Administration Tool]

jSpy is a RAT developed in Java. Need to monitor your childrens internet use? Check that your workers are doing what you paid them for? Help a friend out with a problem on his computer? No worries, whether it be Windows or Mac OSX that you need to manage, or manage from - jSpy is the answer.


Stable
jSpy uses a library called Kryonet developed by Esoterics Software. By using this library for networking, jSpy creates an environment where you can be rest assured you won't lose your clients.
Powerful
jSpy has an abundance of features, and is actively developed by a 17 year old java programmer from London. If you have any suggestions please email me at: javastealth@gmail.com
Multiple OS Support

jSpy will run on Windows, Mac OSX and Linux. jSpy was developed on a Mac ensuring that all features work on both UNIX and DOS Systems.

wig [WebApp Information Gatherer]

wig identifies a websites CMS by searching for fingerprints of static files and extracting version numbers from known files.
OS identification is done by using the value of the 'server' and 'X-Powered-By' in the response header. These values are compared to a database of which package versions are include with different operating systems.
There are currently three profiles:
1. Only send one request: wig only sends a request for '/'. All fingerprints matching this url are tested.
2. Only send one request per plugin: The url used in most fingerprints is used
4. All fingerprints: All fingerprints are tested
Help screen:
# wig.py --help
usage: wig.py [-h] [-v] [-p {1,2,4}] host

WebApp Information Gatherer

positional arguments:
  host        the host name of the target

optional arguments:
  -h, --help  show this help message and exit
  -v          list all the urls where matches have been found
  -p {1,2,4}  select a profile: 1) Make only one request - 2) Make one request
              per plugin - 4) All
Example of run:
# python3 wig.py www.example.com

CMS                  Drupal CMS: [7.25, 7.24, 7.26, 7.23, 7.22]
Operating System     Microsoft Windows Server: [2008 R2]
Server Info          Microsoft-IIS: [7.5, 6.0]
______________________________________________________________
Time: 18.0 sec | Plugins: 65 | Urls: 324 | Fingerprints: 14178
Requirements:

  • Python 3
  • requests

Anti-AV Stealer v2.0

Features :

Steals :
-all browsers
-trillian
-internet download manager
-cd keys
-VPn and dialup
-filezilla
-messenger
-yahoo
-opera
-safari
-firefox
-IE 4/5/6/7/8/9/10
-chrome
-ICQ
-AIM
-google talk
-trillian astra
-miranda
-gaim / pidgin
-myspace
-patalk
-digsby
-JDowloader

Works with :
-windows XP
-Vista
-windows 7
-windows 8

Antis :
-anti-sandboxie
-anti VMware
-alternative VMware 2
-anti anubis
-anti sunbelt

How to set it up:

-As all others PHP Stealers , you will need a PHP/MySQL hosting , check for free ones , there is a lot in google )

-create a database in that hosting and edite the config.php file in the PHPPanel folder with the database credentials provided by the hosting ( host/username/password/database name) then replace the default username and password of the login panel by yours )

-Upload all the PHPPanel folder on your FTP with filezilla

-Your panel is now uploaded : go to http://yourhost.com/PHPPanel/index.php and then login with the username and passwords you choose :)

-Now run the builder in sandboxie or Virtual machine...
in PHP url type your panel url : http://yourhost.com/PHPPanel/index.php

-Bind : is the binder function then choose an icon ( it is better to add it with your crypter) then enable or not the antis the hit the "build" button

you are now done , you have your web panel and your server , you only have too crypt it and spread it to get tons of passwords.

note : as i always recommand , always use builders in safe environnment like sandboxie or VMware or use it at your OWN risks.

[Download]

All Credit and responsibility may go to: http://www.hackforums.net/member.php?action=profile&uid=2009256

RAR Password Unlocker 4.2.0.0 Full Version With Activator

RAR Password Unlocker is proved to be a helpful device when you failed to remember WinRAR/RAR password and could not open up the RAR archives. It could take out RAR password at high speed through 3 attack choices: Brute-force, Brute-force with user-defined Mask and Dictionary. By using enhanced search algorithm, multiple-core CPUs etc, this RAR password recuperation tool enables you appreciate faster recovery rate compared to other comparable programs.


Install Notes:
>> Run the setup
>> After Install Run Activator
>> Enjoy …

Copyright © 2013 Hacking Tools and Tech eBooks Collection and Blogger Templates - Anime OST.