{"id":72,"date":"2008-10-14T12:15:24","date_gmt":"2008-10-14T18:15:24","guid":{"rendered":"http:\/\/www.jedge.com\/wordpress\/?page_id=72"},"modified":"2016-07-01T10:59:30","modified_gmt":"2016-07-01T16:59:30","slug":"security-tools","status":"publish","type":"page","link":"https:\/\/www.jedge.com\/wordpress\/security-tools\/","title":{"rendered":"Security Tools"},"content":{"rendered":"<p>2015 &#8211; This page is so damn old.  Back in 2008 I thought I can post some tools that an IS Auditor should know about and could learn to use on an audit.  If you are an IS auditor, a penetration tester, or anybody who happened to stumble I apologize.<\/p>\n<p>These are all tools I\u2019ve used to conduct an audit of an agency or university.\u00a0 I have working knowledge of all of these tools and would be able to offer advice or assistance in their use.\u00a0 I would also suggest getting familiar with all of the tools listed in the Security List Top 100 Tools (http:\/\/sectools.org\/)<\/p>\n<p><strong><span style=\"font-size: medium;\">Footprinting<\/span><\/strong><\/p>\n<p><strong>BiDiBlah <\/strong>(<a href=\"http:\/\/www.sensepost.com\">http:\/\/www.sensepost.com<\/a>)<br \/>\n<strong>SiteDigger <\/strong>(<a href=\"http:\/\/www.foundstone.com\">http:\/\/www.foundstone.com<\/a>)<\/p>\n<p><strong><span style=\"font-size: medium;\">Network\/Port Scanning<\/span><\/strong><\/p>\n<p><strong>Nmap <\/strong>(<a href=\"http:\/\/www.nmap.org\/\">http:\/\/www.nmap.org<\/a>)<br \/>\n<strong>Scapy <\/strong>(<a href=\"http:\/\/www.secdev.org\/\">http:\/\/www.secdev.org<\/a>)<br \/>\n<strong>Scanline<\/strong> (<a href=\"http:\/\/www.foundstone.com\">http:\/\/www.foundstone.com<\/a>) [Stand-Alone]<\/p>\n<p><strong><span style=\"font-size: medium;\">Windows Enumeration<\/span><\/strong><\/p>\n<p><strong>net view<\/strong> (Windows Default)<br \/>\n<strong>nbtstat <\/strong>(Windows Default)<br \/>\n<strong>Browstat <\/strong>(<a href=\"http:\/\/www.dynawell.com\/download\/reskit\/microsoft\/win2000\/browstat.zip\">exe<\/a>) [Stand-Alone]<br \/>\n&#8211; (<a href=\"http:\/\/www.microsoft.com\/downloads\/details.aspx?FamilyId=49AE8576-9BB9-4126-9761-BA8011FABF38&amp;displaylang=en\">Windows XP Support Tools<\/a>)<br \/>\n&#8211; (<a href=\"http:\/\/www.petri.co.il\/download_free_reskit_tools.htm\">Windows 2000 Resource Kit<\/a>)<br \/>\n&#8211; Command <a href=\"http:\/\/ss64.com\/nt\/browstat.html\">Help<\/a><br \/>\n<strong>Nbtscan <\/strong>(<a href=\"http:\/\/www.unixwiz.net\">http:\/\/www.unixwiz.net<\/a>) [Stand-Alone]<br \/>\n<strong>Enum <\/strong>(<a href=\"http:\/\/www.darkridge.com\">http:\/\/www.darkridge.com<\/a>) [Stand-Alone]<br \/>\n<strong>Dumpsec <\/strong>(<a href=\"http:\/\/www.somarsoft.com\">http:\/\/www.somarsoft.com<\/a>) [Stand-Alone]<br \/>\n&#8211; (needs to be installed by then you can just copy the DumpSec exe file)<br \/>\n<strong>Solarwinds <\/strong>Tools (<a href=\"http:\/\/www.solarwinds.com\">http:\/\/www.solarwinds.com<\/a>)<\/p>\n<p><strong><span style=\"font-size: medium;\">Sniffing<\/span><\/strong><\/p>\n<p><strong>Ettercap <\/strong>(<a href=\"http:\/\/ettercap.sourceforge.net\">http:\/\/ettercap.sourceforge.net<\/a>)<br \/>\n<strong>Cain &amp; Abel<\/strong> (<a href=\"http:\/\/www.oxid.it\">http:\/\/www.oxid.it<\/a>)<br \/>\n<strong>Tcpdump <\/strong>(<a href=\"http:\/\/www.tcpdump.org\">http:\/\/www.tcpdump.org<\/a>)<br \/>\n<strong>Wireshark <\/strong>(<a href=\"http:\/\/www.wireshark.org\">http:\/\/www.wireshark.org<\/a>)<\/p>\n<p><strong><span style=\"font-size: medium;\">Password Tools<\/span><\/strong><\/p>\n<p><strong>Cain &amp; Abel<\/strong> (<a href=\"http:\/\/www.oxid.it\">http:\/\/www.oxid.it<\/a>)<br \/>\n<strong>John the Ripper<\/strong> (<a href=\"http:\/\/www.openwall.com\">http:\/\/www.openwall.com<\/a>)<br \/>\n<strong>Cifspwscan <\/strong>(<a href=\"http:\/\/www.cqure.net\">http:\/\/www.cqure.net<\/a>) [Stand-Alone (Needs Java)]<br \/>\n<strong>THC-Hydra<\/strong> (<a title=\"THC-Hydra\" href=\"http:\/\/freeworld.thc.org\/thc-hydra\/\">http:\/\/freeworld.thc.org\/thc-hydra\/<\/a>)<br \/>\n<strong>PwdumpX <\/strong>(<a href=\"http:\/\/www.packetstormsecurity.org\/\">http:\/\/www.packetstormsecurity.org<\/a><a href=\"http:\/\/reedarvin.thearvins.com\"><\/a>)[Stand-Alone]<br \/>\n<strong>Pwdump2 <\/strong>(<a href=\"http:\/\/www.packetstormsecurity.org\">http:\/\/www.packetstormsecurity.org<\/a>)[Stand-Alone]<br \/>\n<strong>Cachedump <\/strong>(<a href=\"http:\/\/www.packetstormsecurity.org\">http:\/\/www.packetstormsecurity.org<\/a>)[Stand-Alone]<br \/>\n<strong>SamInside <\/strong>(<a href=\"http:\/\/www.insidepro.com\/eng\/saminside.shtml\">http:\/\/www.insidepro.com<\/a>)[Stand-Alone]<br \/>\n<strong>creddump <\/strong>(<a href=\"http:\/\/code.google.com\/p\/creddump\/\">http:\/\/code.google.com\/p\/creddump\/<\/a>) [Needs Python]<\/p>\n<p><strong><span style=\"font-size: medium;\">Vulnerability Scanners<\/span><\/strong><\/p>\n<p><strong>Tenable Nessus<\/strong> (<a href=\"http:\/\/www.nessus.org\">http:\/\/www.nessus.org<\/a>)<br \/>\n<strong>eEye Retina<\/strong> (<a href=\"http:\/\/www.eeye.com\">http:\/\/www.eeye.com<\/a>)<br \/>\n<strong>HP WebInspect<\/strong> (<a href=\"http:\/\/www.hp.com\">http:\/\/www.hp.com<\/a>)<br \/>\n<strong>Application Security AppDetective<\/strong> (<a href=\"http:\/\/www.appsecinc.com\">http:\/\/www.appsecinc.com<\/a>)<br \/>\n<strong>Nikto <\/strong>(<a href=\"http:\/\/www.cirt.net\">http:\/\/www.cirt.net<\/a>)<\/p>\n<p><strong><span style=\"font-size: medium;\">Wireless<\/span><\/strong><\/p>\n<p><strong>Kismet <\/strong>(<a href=\"http:\/\/www.kismetwireless.net\">http:\/\/www.kismetwireless.net<\/a>)<br \/>\n<strong>Aircrack-ng<\/strong> (<a href=\"http:\/\/www.aircrack-ng.org\">http:\/\/www.aircrack-ng.org<\/a>)<br \/>\n<strong>Karmasploit <\/strong>(<a title=\"Karmasploit\" href=\"http:\/\/trac.metasploit.com\/wiki\/Karmetasploit\">http:\/\/trac.metasploit.com\/wiki\/Karmetasploit<\/a>)<\/p>\n<p><strong><span style=\"font-size: medium;\">Database Tools<\/span><\/strong><\/p>\n<p><strong>Navicat <\/strong>(<a href=\"http:\/\/www.navicat.com\">http:\/\/www.navicat.com<\/a>)<br \/>\n<strong>SQL Ninja<\/strong> (<a href=\"http:\/\/sqlninja.sourceforge.net\">http:\/\/sqlninja.sourceforge.net<\/a>)<br \/>\n<strong>SQLat <\/strong>(<a href=\"http:\/\/www.cqure.com\">http:\/\/www.cqure.com<\/a>)[Stand-Alone]<br \/>\n<strong>Automagic <\/strong>(<a title=\"Automagic\" href=\"http:\/\/packetstormsecurity.org\/UNIX\/scanners\/automagic.zip\">http:\/\/packetstormsecurity.org\/UNIX\/scanners\/automagic.zip<\/a>)<br \/>\n<strong>Oracle Audit Tools (OAT)<\/strong> (<a href=\"http:\/\/www.cqure.com\">http:\/\/www.cqure.com<\/a>)[Stand-Alone (Needs Java)]<br \/>\n<strong>Oracle Assessment Kit (OAK)<\/strong> (<a href=\"http:\/\/www.databasesecurity.com\/\">http:\/\/www.databasesecurity.com<\/a>) [Stand-Alone]<\/p>\n<p><strong><span style=\"font-size: medium;\">Exploitation<\/span><\/strong><\/p>\n<p><strong>Metasploit <\/strong>(<a href=\"http:\/\/www.metasploit.com\">http:\/\/www.metasploit.com<\/a>)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>2015 &#8211; This page is so damn old. Back in 2008 I thought I can post some tools that an IS Auditor should know about and could learn to use on an audit. If you are an IS auditor, a penetration tester, or anybody who happened to stumble I apologize. These are all tools I\u2019ve [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"class_list":["post-72","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/pages\/72","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/comments?post=72"}],"version-history":[{"count":12,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/pages\/72\/revisions"}],"predecessor-version":[{"id":1000,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/pages\/72\/revisions\/1000"}],"wp:attachment":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/media?parent=72"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}