Toolbox

For the memo, here are some of the tools that I use often for analysis, penetration testing or forensics.

Discovery / Fingerprinting

  • NmapTHE active network and fingerprinting scanner.
  • HalberdReveals if a server is behind a load balancer.
  • Waf00fDetect web application firewalls.
  • TcptracerouteTCP based traceroute.

System penetration testing

  • MetasploitThe most popular penetration testing framework.
  • NessusVulnerability scanner.

Network penetration testing

  • Wireshark - The best network sniffer and analyser.
  • Tcpdump - Powerful and convenient network sniffer. Massively available on Unix boxes.
  • Ettercap - Point’n click tool for ARP spoofing and MiTM attacks.
  • Hping3 - TCP/IP packet assembler. [patch for openSUSE]
  • Scapy - Packet manipulation tool.

Web penetration testing

Database penetration testing

Wireless penetration testing

Web tools

Forensics

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>