Archive for the ‘Security Tools’ Category

Lynis v1.2.7 released (updated)

|
Comments Off
Lynis is an auditing tool for Unix (specialists). It scans the system and available software, to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes.
This new release includes several new tests, minor bugfixes and improvements. Lynis should also work correctly on AIX now, due to the help of Michael Smerdka and Florian Roth.
Lynis updated to version 1.2.7
More information: (...) - Security Tools / , , ,

HaraldScan v0.401 released

|
Comments Off
The scanner will be able to determine Major and Minor device class of device, as well as attempt to resolve the device's MAC address to the largest known Bluetooth MAC address Vendor list.
The goal of this project is to obtain as many MAC addresses mapped to device vendors as possible.
Version 0.401
There is no difference between 0.401 and 0.4 except it has been packaged properly.
Distribution
Harald Scan is now distributed in either source code or dist
Harald Scan is still (...) - Security Tools / , , ,

Burp Suite Professional v1.3Beta released

|
Comments Off
Burp Suite is an integrated platform for attacking web applications. It contains all of the Burp tools with numerous interfaces between them designed to facilitate and speed up the process of attacking an application. All tools share the same robust framework for handling HTTP requests, persistence, authentication, downstream proxies, logging, alerting and extensibility.
Version 1.3 Beta
Improved search, with regex, scope restrictions, dynamically updating results, etc.
Request (...) - Security Tools / , , ,

Acunetix WVS v6.5 Build 20091130 released

|
Comments Off
Acunetix Web Vulnerability Scanner (WVS) is an automated web application security testing tool that audits your web applications by checking for exploitable hacking vulnerabilities. Automated scans may be supplemented and cross-checked with the variety of manual tools to allow for comprehensive web site and web application penetration testing.
Bug Fixes:
Fixed: crash in TM_MultiRequest_Parameter_Manipulation module
Fixed: bug in crawler related with GetVar (...) - Security Tools / , ,

GreenSQL-FW v1.2.0 released

|
Comments Off
GreenSQL is an Open Source database firewall used to protect databases from SQL injection attacks. GreenSQL works as a proxy for SQL commands and has built in support for MySQL.
GreenSQL 1.2 includes many new features and enhancements. In this version, GreenSQL provides native support for PostgreSQL databases for the very first time. In fact, GreenSQL is the only database firewall (Open or Closed Source) available for the protection of the many PostgreSQL databases currently in use. (...) - Security Tools / , , ,

Metasploit Framework v3.3.1 released

|
Comments Off
The Metasploit Framework is a development platform for creating security tools and exploits. The framework is used by network security professionals to perform penetration tests, system administrators to verify patch installations, product vendors to perform regression testing, and security researchers world-wide. The framework is written in the Ruby programming language and includes components written in C and assembler.
Version 3.3.1
Metasploit now has 453 exploit modules and (...) - Security Tools / , , ,

Nessus v4.2.0 released

|
Comments Off
Nessus is the world's most popular vulnerability scanner used in over 75,000 organizations world-wide. Many of the world's largest organizations are realizing significant cost savings by using Nessus to audit business-critical enterprise devices and applications.
Nessus 4.2 features a brand new web-based user interface and other performance improvements.
Version 4.2.0
Reporting
  • When a service is identified against a given port, the port name is now set to the service name.

An updated (...) - Security Tools / ,

Eclipse HTTP Client (HTTP4e) v2.0 available

|
Comments Off
Eclipse HTTP Client (HTTP4e) is an Eclipse plugin formaking HTTP and RESTful calls. Build with user experience in mind, it simplifies the developer/QA job of testing Web Services, REST, JSON and HTTP. It is a useful tool for your daily job of HTTP header tampering and hacking.
Features:
Making/Replaying an HTTP call directly from Eclipse IDE
Visual Editor Panels for headers, parameters and http packet body
Tabbed browsing (allowing replaying different RESTful, HTTP calls on separate (...) - Security Tools / , , , ,

History of Hacking – Part 1

|
Comments Off
Every culture has its beginning somewhere, Computer hacking is no exception. The History of Hacking video series is a 5 part documentary which runs down memory lane and presents important figures, facts and personalities of the Hacking culture. In History of Hacking Part 1, we will look at Phone Phreaking and John Draper a.k.a Captain Crunch and try and understand the string of events which molded the Phone Phreaking culture.
Those of you who have not heard of John, he is the guy who (...) - Security Tools

Security Acts Magazine Issue 1 released

|
Comments Off
Security Acts is the challenge of producing a high-quality magazine for profes- sionals in IT Security, which is made by and issued for the people involved in IT Security. This online magazine is free of charge and will finance itself through adverts.
In this 1st issue
AJAX makes applications more difficult to secure by Manu Cohen
AJAX is the new hot technology concerning web applications. It allows the client to do much more than before and have a much better user experience.
An (...) - Security Tools