Archive for the 'Penetration Testing' Category

New Tool - SIPcrack

SIPcrack is a SIP login sniffer/cracker that contains 2 programs: sipdump to capture the digest authentication and sipcrack to bruteforce the hash using a wordlist or standard input.

Share This

Government Agencies debate over automatic penetration tools

It seems that debate over the automatic tools vs. manual penetration tools raises serious questions within the government agencies.South Carolina and Delaware already use Core Impact, other might follow:

Share This

Think Twice When Choosing Pentesters

Nick Baskett wrote an interesting article in it-observer about best practices when hiring an external penetration testing consultant. I hope that more and more business decision makers will apply his advices :

Share This

How to Turn Firefox Into an Attack Webserver

amazing that this nifty tool supports Server-side JS, GET, POST, uploads, Cookies, SQLite and AJAX.

Share This

How To perform a Social Engineering Attack

OSSTMM guru Pete Herzog released today an interesting guide on social engineering assessments.

Share This

Pantera - A Web Assessment Studio

OWASP is happy to announce the first release of OWASP Pantera - Web
Assessment Studio. Pantera is a mix between a pentest proxy, an application
scanner, and an intelligent analysis framework. Pantera’s goal is to leave
the analysis and automatic (repetitive) stuff to the engine, leaving only
the important decisions to the security expert.
Great tool !
OWASP Pantera Web […]

Share This

OWASP Testing Guide V2

The Open Web Application Security Project (OWASP) is dedicated to finding and fighting the causes of insecure software. Everything here is free and open source.
OWASP has released the Security Testing Guide v2 .At 270 pages, this guide is already a must-have for most developers and penetration/application testers, but we want to take it one step […]

Share This

Automated Scanner vs. The OWASP Top Ten

an interesting article on automated vulnerability scanners and the limitations of these tools in finding real life web application vulnerabilities .

Share This

Penetration Testing Frameworks

A good framework is a great resource for any pentester .
Here are some of the best I found :

The mindmap written by Toggmeister (a.k.a. Kev Orrey) & Lee J Lawson http://www.vulnerabilityassessment.co.uk/Penetration%20Test.html
OSSIG http://www.oissg.org/
OSSTMM http://www.isecom.org/osstmm/
OWASP http://www.owasp.org

Share This
If you enjoyed this post, make sure you subscribe to my RSS feed!

Share This
Pages (2): « 1 [2]
Close
E-mail It