Meetings

Date: Saturday March 15th 2008

Favorite Tools

DDNG (Russ is going to provide the link to this)
Utility that provides DD functionality but adds checksums and integrity checks that traditional dd lacks. While we're waiting for the link, here's a similar tool:
http://dcfldd.sourceforge.net/

Charon - http://www.project2025.com/charon.php
a proxy tester to check anonymity - and a fully functional search engine crawler to find lists of posted proxies. Included within the kit is a php checker which can be uploaded to your own webspace to spread the processor load and bandwidth of the actual testing. This is fully integrated into Charon where it will simply send your pages lists of proxies and harvest the results.

SQLNinja - http://sqlninja.sourceforge.net/
Sqlninja is a tool targeted to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end. Demo included using SQLninja to exploit a custom web application, uploading nc (netcat) and opening a reverse shell. SQL ninja can upload any text file. For binary files sqlninja uses a slick trick of uploading MS debug script and then recreating the binary on the server by running the uploaded text file containing the script through MS debug.

Metasploit - http://www.metasploit.org/
The Metasploit Framework is a development platform for creating security tools and exploits. The framework is used by network security professionals to perform penetration tests, system administrators to verify patch installations, product vendors to perform regression testing, and security researchers world-wide.


Copyright 2007-2008 DC509