Like Secpill?



SecurityXploded

SecurityXploded is a popular information security research and development portal delivering the latest information in various areas of security such as anti spyware, reverse engineering, cryptography, password recovery, network security, forensics etc. So far it has published so many research articles and free security tools.




Tools

Password Recovery Tools
  •  AIMPasswordDecryptor
  •  AsteriskPasswordSpy
  •  BrowserPasswordDecryptor
  •  ChromePasswordDecryptor  Updated
  •  DigsbyPasswordDecryptor
  •  DreamweaverPasswordDecryptor
  •  ExcelPasswordRecovery
  •  FacebookPasswordDecryptor
  •  FilezillaPasswordDecryptor
  •  FireMaster
  •  FiremasterLinux
  •  FirePassword
  •  FirePasswordViewer  Updated
  •  FlashfxpPasswordDecryptor
  •  FoxmailPasswordDecryptor
  •  FTPCommanderPasswordDecryptor
  •  FtpPasswordDecryptor
  •  FTPPasswordSniffer
  •  GooglePasswordDecryptor  Updated
  •  IDMPasswordDecryptor
  •  IEPasswordDecryptor
  •  IncrediMailPasswordDecryptor
  •  iTunesPasswordDecryptor
  •  JDownloaderPasswordDecryptor
  •  KeychainRecovery
  •  MailPasswordDecryptor
  •  MeeboPasswordDecryptor
  •  MessengerPasswordDecryptor
  •  MirandaPasswordDecryptor
  •  MSNLivePasswordDecryptor  Updated
  •  MyspacePasswordDecryptor
  •  MysqlPasswordAuditor
  •  NetworkPasswordDecryptor  Updated
  •  OperaPasswordDecryptor
  •  OraclePasswordAuditor
  •  OrbitPasswordDecryptor
  •  OutlookPasswordDecryptor  Updated
  •  PaltalkPasswordDecryptor
  •  PasswordUnlocker  Updated
  •  PDFLocker
  •  PDFPasswordRecovery
  •  PDFUnlocker
  •  PidginPasswordDecryptor
  •  RarPasswordUnlocker
  •  SafariPasswordDecryptor
  •  SmartftpPasswordDecryptor
  •  SXPasswordSuite
  •  ThunderbirdPassDecryptor
  •  TrillianPasswordDecryptor
  •  TwitterPasswordDecryptor  Updated
  •  WordPasswordRecovery
  •  WS_FTPPasswordDecryptor
  •  XfirePasswordDecryptor
  •  YahooPasswordDecryptor
  •  ZipPasswordUnlocker

Anti-Spyware/Anti-Rootkit Tools
  •  AdvancedWinServiceManager
  •  DllHijackAuditor
  •  ExeScan
  •  ShellDetect  New
  •  SpyBHORemover
  •  SpyDLLRemover
  •  StreamArmor

Network Tools
  •  DirectoryScanner
  •  LDAPSearch
  •  NetShareMonitor
  •  PortScanner
  •  ProcNetMonitor
  •  RemoteDirDetector
  •  SSLCertScanner
  •  WebDirectoryBuster
  •  WinSniff

System Tools
  •  AutoScreenCapture
  •  DownloadHashVerifier
  •  HashCompare
  •  HashGenerator
  •  PcproxRFIDReader
  •  PESpinPlugin
  •  ProcHeapViewer
  •  RemoteDLL
  •  SFCLister
  •  VistaUACMaker
  •  Zexplo

Security Research Articles

Rootkit/Malware Analysis
  •  Analysis of Malicious PDF File
  •  Hidden Registry Detection
  •  Hidden Rootkit Process Detection
  •  Hidden Rootkit Services Detection
  •  IceSword : Cool Tool to Break the ICE
Password Recovery
  •  Decrypting the Sign-on Secrets of Firefox Using FirePassword
  •  Exposing the Facebook Password Secrets
  •  Exposing the Google Password Secrets
  •  Exposing the Password Secrets of Apple Safari
  •  Exposing the Password Secrets of Beyluxe Messenger
  •  Exposing the Password Secrets of Digsby
  •  Exposing the Password Secrets of Internet Explorer
  •  Exposing the Password Secrets of Meebo
  •  Exposing the Password Secrets of Miranda
  •  Exposing the Password Secrets of MSN/Windows Live Messenger
  •  Exposing the Password Secrets of PaltalkScene
  •  Exposing the Password Secrets of Trillian
  •  Exposing the Password Secrets of WS_FTP Professional
  •  Exposing the Secret of Decrypting Network Passwords
  •  Exposing the Secret of Decrypting Opera's Magic Wand
  •  Exposing the Secret of Decrypting Outlook Passwords
  •  Exposing the Secrets of Google Chrome
  •  Exposing the Twitter Password Secrets
  •  Password Secrets of Popular Windows Applications
  •  Recover Windows Password in Seconds using RainbowCrack
  •  Recovering the Firefox Master Password using FireMaster
  •  Windows Password Recovery 
Reverse Engineering
  •  Andriod Reverse Engineering - A Kick Start
  •  Discovering Windows Default Password Using LsaRetrievePrivateData
  •  Faster method to Enumerate Heaps on Windows
  •  Hacker Reversing Challenge 2007: Analysis of Problem & Solution
  •  Jailbreaking HTC Wildfire to Run Latest Android
  •  Manually Unpacking UPX packed binary file using OllyDbg
  •  PDF - Vulnerabilities, Exploits and Malwares
  •  Remote Buffer Overflow Exploits
  •  Reversing Basics - A Practical Approach Using IDA Pro
  •  Reversing Tutorial - Cracking Registration of A-One Video Converter
  •  The covert way to find the Reference Count of DLL
  •  Writing PESpin Plugin for ImpREC
System Internals
  •  Bypassing Anti-virus using Code Injection Technique
  •  Changing MAC Address of your Computer
  •  Exploring Hidden Alternate Data Streams
  •  Investigating Corrupt/Malicious PDF Document
  •  PDF Overview - Peering into the Internals of PDF
  •  Remote Thread Execution in System Process using NtCreateThreadEx for Vista/Win7
  •  The Art of ARP Spoofing/Flooding/Poisoning
  •  Tutorial on Basics of NIC, MAC and ARP
  •  Uncovering the Hidden Processes on Windows System 

Web Security
  •  Bruteforcing File Names on Webservers using DirBuster
  •  Hacking ADSL Routers - Is Your Home Internet Secure?
  •  Hacking into the BSNL Router using Andriod
  •  Hacking Web Applications using WebScarab
  •  Remote File Inclusion Tutorial 

Pen Testing & Exploit Research
  •  Demystifying the Android Malware
  •  Detecting and Exploiting XSS injections using XSSer Tool
  •  JBoss Exploitation
  •  Nexpose + Metasploit = Shell
  •  Penetration Testing with Metasploit Framework
  •  Set up your own Pen-testing/Hacking Lab Network using a Single System  New
  •  Vulnerable Facebook Applications 

General Security
  •  BackTrack : Quick way to fix the Windows Registry
  •  Best Computer Security Solutions Guide
  •  Errata Guide to Ettercap GUI : Through Trial, Error & Experience
  •  Hacking Crazy Taxi Game on Facebook
  •  How to Remove Hacking Edge 'Virus'
  •  Social Engineering - The Human Factor  New
and much more....

Visit SecurityXploded website now.

Malware Analyzer


Malware Analyzer - A tool developed by Beenu Arora to perform static and dynamic analysis of malwares.



The static analysis allows analyst to predict the behaviour of malware without actually executing it which in turns saves resources in terms of time and effort. It can be useful for string based analysis for Windows registry, API calls, IRC Commands, DLL’s called and anit-VMWare code detection. It can perform a full ASCII dump of the PE along with other options. It can also generate various section of a PE. Malware analyzer also assists on the code analysis of the malware. It can also perform an online malware check. Based on PeID signatures, it can also detect packers used to compress it. It also provides a tracer functionality that can be used to identify anti-debugging calls tricks, file system manipulation calls, Rootkit hooks, keyboard hooks, DEP setting changes, Hardware Breakpoints,Internet communication etc generally used by malwares. It also performs the CRC and timestamp based verification to detect any anomalies along with entropy based scan for identification of malicious sections. The tool can be used to create signatures of a malware which then can be exported as custom signature of AV or IDS. It also allows viewing modules of process along with complete process dumping.

The Dynamic analysis allows predicting the actual behaviour of the malware at runtime. Currently malware analyser allows hooking to certain APIs File creation and Registry creation and more to come near future.


n00brat

A remote administration tool or Trojan developed by Abhishek Kumar.



n00brat client just requires a web browser to control remote machine since everything can be done from a web page. Fooling firewalls/ids/ips security solutions, as it operates just like a web-site.

Download n00brat from Sourceforge

Blind Sql Injection Brute Forcer version 2


Blind Sql Injection Brute Forcer version 2 is a tool developed by Sumit Siddharth, which allows extraction of data from Blind SQL Injections. It accepts custom SQL queries as a command line parameter and it works for both integer and string based injections.



Databases supported:

  • MS-SQL
  • MySQL
  • PostgreSQL
  • Oracle




The tool supports 6 attack modes:

  1. Blind SQL Injection based on true and false conditions returned by back-end server
  2. Blind SQL Injection based on true and error(e.g syntax error) returned by back-end server.
  3. Blind SQL Injection in “order by” and “group by”.
  4. Extracting data with SYS privileges (ORACLE dbms_export_extension exploit)
  5. O.S code execution (ORACLE dbms_export_extension exploit)
  6. Reading files (ORACLE dbms_export_extension exploit, based on java)
NotSoSecure.com - for related information and videos


Matriux

Matriux is a GNU/Linux Debian based security distribution designed for penetration testing and cyber forensic investigations.



Matriux can be used as a live CD(DVD). Being based on Debian, Matriux is less bloated and little rough compared to other popular security distributions. The first beta of Matriux has been released in ClubHACK 2009. Matriux features XFCE desktop in its latest releases even though the initial release was using KDE. The project is lead by Manu Zacharia, a famous information security evangelist from south India.



Visit Matriux website for more details.