Google Hack con GHDB
Es como el famoso googlag de CDC solo que desde la ventana del navegador y on-line, con lo que es portable y no necesita instalación
Herramientas de Penetración Hack,2008
Packet Shaper:
- Nemesis: a command line packet shaper
- Packit: The Packet Toolkit - A network packet shaper.
- Hping by Antirez: a command line TCP/IP packet shaper
- Sing: stands for 'Send ICMP Nasty Garbage'; sends fully customizeable ICMP packets
- Scapy: a new python-based packet generator
Password Cracker/Login Hacker:
- John the Ripper: a well-known password cracker for Windows and *nix Systems
- Djohn: a distributed password cracker based on "John the Ripper"
- Cain & Abel: an advanced password recovery tool for windows systems. It sniffs the network packets an cracks authentication brute-force or with dictionary attacks.
- Project RainbowCrack: Advanced instant NT password cracker
- Rainbowtables: The shmoo group provides pre-generated rainbow tables for bittorrent download. The tables are generated with RainbowCrack (see above).
- Windows NT password recovery tool by Peter Nordahl
- THC-Dialup Login Hacker by THC. It tries to guess username and password against the modem carrier. As far as I know the only available dialup password guesser for *NIX.
- Hydra by THC: a multi-protocol login hacker. Hydra is also integrated with Nessus.
- Medusa: parallel network login auditor
- THC imap bruter: a very fast imap password brute forcer
- x25bru: a login/password bruteforcer for x25 pad
- Crowbar: a generic web brute force tool (Windows only; requires .NET Framework)
- MDCrack-NG: a very fast MD4/MD5/NTLMv1 hash cracker; works optionally with precomputed hash tables
Advanced Sniffers:
- Wireshark (formerly known as Ethereal): an open source network protocol analyzer
- Dsniff by Dug Song: a combination of very useful sniffer and man-in-the-middle attack tools
- Ettercap: a multipurpose sniffer/interceptor/logger for switched LAN environments
- aimsniffer: monitors AOL instant messager communication on the network
- 4G8: a tool ,similar to ettercap, to capture network traffic in switched environments
- cdpsniffer: Cisco discovery protocol (CDP) decoding sniffer
Port Scanner / Information Gathering:
- nmap: the currently most well-known port scanner. Since version 3.45 it supports version scans. Have a look at PBNJ for diffing different nmap scans.
- ISECOM released their nmap wrapper NWRAP, which shows all known protocols for the discovered ports form the Open Protocol Resource Database
- Nmap::Scanner: Perl output parser for nmap
- Amap by THC: An advanced portscanner which determines the application behind a network port by its application handshake. Thus it detects well-known applications on non-standard ports or unknown applications on well-known ports.
- vmap by THC: version mapper to determine the version (sic!) of scanned daemons
- Unicornscan: a information gathering and correlation engine
- DMitry (Deepmagic Information Gathering Tool): a host information gathering tool for *nix systems
- Athena: a search engine query tool for passive information gathering
Security Scanner:
- Nessus - In version 2 an OpenSource network scanner. Version 3 is only available in binary form and under a proprietary license.
- OpenVAS: a fork of Nessus 2.2.5 (formerly known as GNessUs)
- Nessj: a java based nessus (and compatibles) client (formerly known as Reason)
- Paul Clip from @stake released AUSTIN, a security scanner for Palm OS 3.5+.
- Nikto: a web server scanner with anti IDS features. Based on Rain Forest Puppies libwhisker library.
- Wikto: a webserver assessment tool (Windows only; requires .NET framework)
- WSDigger: a black box web pen testing tool from Foundstone (Windows based)
- Metis: a java based information gathering tool for web sites
Fingerprinting:
- SinFP: a fingerprinting tool which requires only an open tcp port and sends maximum 3 packets
- Winfingerprint: much more than a simple fingerprinting tool.It scans for Windows shares, enumerates usernames, groups, sids and much more.
- p0f 2: Michal Zalewski announced his new release of p0f 2, a passive OS fingerprinting tool. p0f 2 is a completely rewrite of the old p0f code.
- xprobe2: a remote active operating system fingerprinting tool from Ofir Arkin and the xprobe2 team
- Cron-OS: an active OS fingerprinting tool based on TCP timeout behavior. This project was formerly known as "RING" and is now published as a nmap addon.
Proxy Server:
- Burp proxy: an interactive HTTP/S proxy server for attacking and debugging web-enabled applications
- Screen-scraper: a http/https-proxy server with a scripting engine for data manipulation and searching
- Paros: a man-in-the-middle proxy and application vulnerability scanner
- WebScarab: a framework for analyzing web applications. One of it's basic functionality is the usage as intercepting proxy.
- IWar: a classic war dialer. One of a few wardialers for *nix operation systems, and the only with VOIP functionality (to my knowledge)
- THC-Scan: a war dialer for DOS, Windows and DOS emulators
- packetstormsecurity.org: Huge collections of tools and exploits
- ElseNot Project: The project tries to publish an exploit for each MS Security Bulltin. A script kiddie dream come true.
- Offensive Computing: Another malware collection site
- Securityforest: try the ExploitTree to get a collection of exploit code; have a look at the ToolTree for a huge list of pentest stuff
Databases / SQL:
- sqlninja: a tool to exploit sql injection vulnerabilities in web applications with MS SQL Servers (alpha stage)
- CIS Oracle Database Scoring Tool: scans Oracle 8i for compliance with the CIS Oracle Database Benchmark
- SQLRecon: an active and passive scanner for MSSQL server. Works on Windows 2000, XP and 2003.
- absinthe: a gui-based tool that automates the process of downloading the schema & contents of a database that is vulnerable to Blind SQL Injection (see here and here).
- SQL Power Injector: a GUI based SQL injector for web pages (Windows, .Net Framework 1.1 required, Internet Explorer 5.0+ required)
- vomit (voice over misconfigured internet telephones): converts Cisco IP phone conversations into wave files
- SiVuS: a VOIP vulnerability scanner - SIP protocol (beta, Windows only)
- Cain & Abel: mostly a password cracker, can also record VOIP conversations (Windows only)
- sipsak (SIP swis army knife): a SIP packet generator
- SIPp: a SIP test tool and packet generator
- Nastysip: a SIP bogus message generator
- voipong: dumps G711 encoded VOIP communications to wave files. Supports: SIP, H323, Cisco Skinny Client Protocol, RTP and RTCP
- Perl based tools by Thomas Skora: sip-scan, sip-kill, sip-redirectrtp, rtpproxy and ipq_rules
- rtptools: a toolset for rtp recording and playing
Networkbased Tools:
- yersinia: a network tool designed to take advantage of some weakeness in different network protocols (STP, CDP, DTP, DHCP, HSRP, 802.1q, VTP)
-
Netsed: alters content of network packets while forwarding the packets
- ip6sic: a IPv6 stack integrity tester
- ike-scan: an IPSec enumeration and fingerprinting tool
- ikeprobe: ike scanning tool
- ipsectrace: a tool for profiling ipsec traffic in a dump file. Initial alpha release
- VPNMonitor: a Java application to observer network traffic. It graphically represents network connections and highlights all VPN connections. Nice for demonstrations, if somewhat of limited use in a real pen test.
- IKECrack:an IKE/IPSec cracker for pre-shared keys (in aggressive mode authentication [RFC2409])
DNSA: DNS Auditing tool by Pierre Betouin
Hunt: a session hijacking tool with curses GUI
SMAC: a Windows MAC Address Modifying Utility. Supports Windows 2000 and XP.
The WebGoat Project: a web application written in Java with intentional vulnerabilities. Supports an interactive learning environment with individual lessons.
TSCrack: a Windows Terminal Server brute forcer
Ollie Whitehouse from @stake released some new cellular phone based pentesting tools for scanning (NetScan, MobilePenTester). All tools require a Sony Ericsson P800 mobile phone. Unfortunately, @stake seems no longer to support much of their free security tools. So, use instead the alternativ download links above.
THC-FuzzyFingerprint: generates fuzzy fingerprints that look almost nearly equal to a given fingerprint/hash-sum. Very useful for MITM attacks.
BeatLM, a password finder for LM/NTLM hashes. Currently, there is no support for NTLM2 hashes. In order to get the hashes from network traffic, try ScoopLM.
THC vlogger: a linux kernel based keylogger
The Metasploit Framework: an "advanced open-source platform for developing, testing, and using exploit code".
ATK (Attack Tool Kit): a comination of security scanner and exploit framework (Windows only)
Pirana: an exploitation framework to test the security of email content filters. See also the whitepaper
PassLoc: a tool which provides the means to locate keys within a buffer. Based on the article "Playing hide and seek with stored keys" by Adi Shamir.
Dl-Hell: identifies an executables dynamic link library (DLL) files
DHCPing: a security tool for testing dhcp security
ldapenum: a perl script for enumeration against ldap servers.
Checkpwd: a dictionary based password checker for oracle databases
NirCmd from NirSoft: a windows command line tool to manipulate the registry, initiate a dialup connection and much more
Windows Permission Identifier: a tools for auditing user permissions on a windows system
MSNPawn: a toolset for footprinting, profiling and assesment via the MSN Search. Windows-only, .NET required
snmpcheck:a tool to gather information via snmp. Works on Linux, *BSD and Windows systems.
pwdump6: extract NTLM and LanMan hashes from Windows targets
Extraido de lonerrunners
Certificados de Registro Civil (Nacimiento, Defunción y Matrimonio) on-line en la GVA
Siguiendo el lema de "Tu tiempo nos importa" la Conselleria de Justicia y Administraciones públicas de la GVA facilita la petición de los mísmos a través de internet: Pincha en los diferentes enlaces para acceder a ellos:
Gtalk On-Line en tu Blog
Buscador de Casas Rurales en España
Nomao, Para guardar y compartir lugares favoritos
Én esta página podemos guardar todos nuestros eventos y lugares preferidos junto con su descripción y fotos, se basa en google maps y la verdad es que puede hacer básicamente lo mismo, aunque con una interfaz más amigable y de una forma más anónima.
Incluye una opción para crear un widget para blogger
| Nomao | ||
Direcciones para escuchar música On-Line
http://www.escuchamusicas.com/index.php
Permite descargas, pero no listas de reproducción
http://www.mybloop.com/
Permite descargar, pocas canciones y artistas
http://www.deezer.com/es/
Más canciones y artistas, no permite descargar
Musicovery : interactive webRadio
Como su nombre indica, radio web interactiva, Permite escuchar
liveplasma music, movies, search engine and discovery engine
Esquemas de artistas y pelicula
http://www.dilandau.com/
Con un reproductor Web Muy currado
Página sobre la Red de Turismo Arqueológico
Dentro de esta página encontramos los yacimientos ordenados por tipos, época, pais... así como recreaciones históricas y los museos más relevantes, todo ello en una interfaz visual e integrado en google maps
Technorati : Arqueología
Google Hack con GoolagScan
Google Hack es usar el famoso motor de búsquedas GOOGLE para escanear la web en busca de archivos, servidores vulnerables, contraseñas.... Esta búsqueda se puede realizar desde la mismo cuadro de búsqueda mediante diferentes comandos.
Ahora de mano de los creadores del troyano "Back Orífice" (CDC) viene googlag donde se reúnen todos los tipos de búsquedas (más de 1400) en un solo programa.
Gracias a DRAGONJAR
Xerojardines
¿Que son?
jardines con un gran variedad de plantas y árboles y un consumo mínimo de agua.l riego de jardines y parques públicos en España requiere un 1,5% del total de agua. Aunque suena a cifra diminuta, lo cierto es que cada gota cuenta en un país con graves problemas de sequía, desertificación y abastecimiento de este escaso recurso. Por ejemplo, alfombrar de césped nuestras ciudades, que necesita el 70% del agua del riego en un jardín convencional, no parece la mejor solución
Los expertos en Xerojardinería disponen de una serie de consejos para ahorrar al máximo el agua, y en general, para un mejor cuidado del jardín:
- Utilización de recubrimientos o cubiertas ("mulching"): Además de conseguir un interesante acabado estético, reducirá la pérdida de agua por evaporación, ayudará a evitar la erosión y la aparición de malas hierbas, y protegerá al jardín de las heladas.
- Creación de zonas de sombra y pantallas verdes: Atenuará el viento y evitará las pérdidas de agua.
- Aprovechar el agua de la lluvia. Para ello, se recomienda plantar en otoño siempre que sea posible, para que las lluvias de invierno se ocupen del riego.
- Utilizar en lo posible fuentes distintas a la red de abastecimiento urbana, ya que el agua de riego no necesita ser potable.
- Emplear productos y sistemas naturales para el abono y el control de las plagas, y eliminar las malas hierbas.
Páginas Relacionadas:
- Artículo en InfoJardín
- Artículo de José M. Sánchez
Extraido de CONSUMER
Una de las mejores canciones de Amy Winehouse
All I'll can ever be to you
Is a darkness that we knw,
And this regret I got accustomed to.
Once it was so right
When we were at our high,
Waiting for you in the hotel at night.
I knew I hadn't met my match,
But every moment we could snatch,
I don't know why I got so attached.
It's my responsibility,
And you don't owe nothing to me,
But to walk away I have no capacity.
He walks away,
The sun goes down,
He takes the day but I'm grown
And in your way,
In this blue shade
My tears dry on their own.
I don't understand,
Why do I stress a man,
When there's so many bigger things at hand.
We could've never had it all,
We had to hit a wall,
So this is an inevitable withdrawal.
Even if I stop wanting you
And perspective pushes true,
I'll be some next man's other woman soon.
I couldn't play myself again,
I should just be my own best friend,
Not f**k myself in the head with stupid men.
He walks away,
The sun goes down,
He takes the day but I'm grown
And in your way,
In this blue shade
My tears dry on their own.
So we are history,
Your shadow covers me,
The sky above
A blaze
He walks away,
The sun goes down,
He takes the day but I'm grown
And in your way,
In this blue shade
My tears dry on their own.
I wish I could say no regrets,
And no emotional debts,
Cause as we kiss goodbye the sun sets.
So we are history,
Your shadow covers me,
The sky above a blaze that only lovers see.
He walks away,
The sun goes down,
He takes the day but I'm grown
And in your way,
In my blue shade
My tears dry on their own.
He walks away,
The sun goes down,
He takes the day but I am grown
And in your way,
My deep shade,
My tears dry on their own.
He walks away,
The sun goes down,
He takes the day but I'm grown
And in your way,
My deep shade,
My tears dry...
