Tampilkan postingan dengan label hack tools. Tampilkan semua postingan
Tampilkan postingan dengan label hack tools. Tampilkan semua postingan

Senin, 11 Mei 2009

RockXP V4.0

Synopsis: RockXP lets you retrieve the product key for Windows XP as well as various other Microsoft products. It also lets you recover usernames/passwords in your Windows Protected Storage as well as Remote Access Settings. Finally, it has a password generator for producing random, secure passwords.

Writes settings to: None

How to extract: Download the EXE file to a folder of your choice. Launch the program by double-clicking on RockXP4.exe.

License: Freeware

System Requirements: Win95 / Win98 / WinME / WinNT / Win2K / WinXP

Download RockXP V4.0

L0phtcrack

L0phtCrack is a password auditing and recovery application (now called LC5), originally produced by Mudge from LOpht Heavy Industries. It is used to test password strength and sometimes to recover lost Microsoft Windows passwords, by using dictionary, brute-force, and hybrid attacks. It was one of the crackers tools of choice, although most use old versions because of its price and low availability.

The application was produced by @stake after the LOpht merged with @stake in 2000. @stake was then acquired by Symantec in 2004. Symantec has since stopped selling this tool to new customers citing US Government export regulations, and discontinued support in December 2006. LC5 can still be downloaded from unofficial mirrors.

Download Keygen[disini]

Download LOpHtCrack download

Airsnort

Introduction

AirSnort is a wireless LAN (WLAN) tool which recovers encryption keys. AirSnort operates by passively monitoring transmissions, computing the encryption key when enough packets have been gathered.

802.11b, using the Wired Equivalent Protocol (WEP), is crippled with numerous security flaws. Most damning of these is the weakness described in “ Weaknesses in the Key Scheduling Algorithm of RC4 ” by Scott Fluhrer, Itsik Mantin and Adi Shamir. Adam Stubblefield was the first to implement this attack, but he has not made his software public. AirSnort, along with WEPCrack, which was released about the same time as AirSnort, are the first publicly available implementaions of this attack.

AirSnort requires approximately 5-10 million encrypted packets to be gathered. Once enough packets have been gathered, AirSnort can guess the encryption password in under a second.

AirSnort 0.2.6 Requirements

AirSnort runs under Windows or Linux, and requires that your wireless nic be capable of rf monitor mode, and that it pass monitor mode packets up via the PF_PACKET interface. Cards known to do this are:

  • Cisco Aironet
  • Prism2 based cards using wlan-ng drivers or Host-AP drivers
  • Orinoco cards and clones using patched orinoco_cs drivers
  • Orinoc cards using the latest Orinoco drivers >= 0.15 with built in monitor mode support
  • And many others.
  • Windows: Any(?) card supported by Airopeek.

For Linux users, the best resources for finding out if your card can do monitor mode and what drivers you will need are those maintained at the Kismet site.

To compile AirSnort, do the following:

  • Get your drivers working! To do this you may need one or more of the following
  • Install the LATEST version of libpcap. Please make sure that you have removed any old version of pcap that may be resident on your system. (not required for Windows users.)
  • Make sure you have gtk+-2.2 installed as AirSnort is a gui application. You will also need gtk+-devel
  • Linux users perform the following steps
        # tar -xzf airsnort-0.2.6.tar.gz
    # cd airsnort-0.2.6
    # ./configure
    # make
    # make install (optional)
  • Poof you’re done. The airsnort executable is in the airsnort-0.2.6/src subdirectory, do with it what you will. There are some man pages in airsnort-0.2.6/man
  • Windows users: see the Windows info page.

Orinoco Notes: The latest patches seem to smooth things out for all versions of Orinoco firmware. Please make sure you are using the latest patches. If you do not see a patch for your version of pcmcia-cs, then PLEASE determine what version of the orinoco drivers are included with your version of pcmcia-cs and get the appropriate orinoco-0.XX patches. To do this look in pcmcia-cs-X.Y.Z/wireless/orinoco_cs.c which will list the version number in the first couple of lines.

Download

Anonymous CVS is at the CVSROOT :pserver:anonymous@cvs.airsnort.sourceforge.net:/cvsroot/airsnort . For more information, view our SourceForge page.

Download the tarballs from Sourceforge

RainbowCrack

Introduction


RainbowCrack is a general propose implementation of Philippe Oechslin’s faster time-memory trade-off technique.
In short, the RainbowCrack tool is a hash cracker. A traditional brute force cracker try all possible plaintexts one by one in cracking time. It is time consuming to break complex password in this way. The idea of time-memory trade-off is to do all cracking time computation in advance and store the result in files so called “rainbow table”. It does take a long time to precompute the tables. But once the one time precomputation is finished, a time-memory trade-off cracker can be hundreds of times faster than a brute force cracker, with the help of precomputed tables.

Some ready to work lanmanager and md5 tables are demonstrated in Rainbow Table section. One interesting table set is the lm configuration #6 tables, with which we can break any windows password up to 14 characters in a few minutes.

Download


The latest version of RainbowCrack is 1.2
download platform supported charset supported algorithm
rainbowcrack-1.2-win.zip(547K)
rainbowcrack-1.2-src.zip(44K)
windows binary
source for windows and linux
customizable lm, md5, sha1, customizable
rainbowcrack-1.1-win.zip(403K)
rainbowcrack-1.1-win-src.zip(59K)
windows binary
windows source
customizable lm
rainbowcrack-1.01-win.zip(400K)
rainbowcrack-1.01-win-src.zip(56K)
windows binary
windows source
alpha and alpha-numeric lm
rainbowcrack-1.0-win.zip(400K)
rainbowcrack-1.0-win-src.zip(56K)
not recommended

lm: The LanManager hash algorithm. “lm” table can be used to break windows password.
customizable charset: Charset of rainbow table can be customized as described in documentation.
customizable algorithm: Support of new algorithm can be done with ease, as described in FAQ. A ready to work algorithm patch supporting NTLM, MD2, MD4 and RIPEMD160 is here Algorithm patch for RainbowCrack 1.2(3K).

Documentation


Frequently Asked Questions

RainbowCrack tutorial introduces basic steps to make rainbowcrack tool working.
Large charset configurations for RainbowCrack outlines a lot of tips when generating large rainbow tables, also two new configurations introduced.

Pwdump

Windows 2000/XP/2003 NTLM and LanMan Password Grabber

By fizzgig and the foofus.net Team

UPDATED 07/22/2008
New pwdump6 (version 1.7.2) available! What the heck are you using pwdump for? fgdump does *everything* pwdump does, only more! I highly recommend switching over as soon as possible. :)

We now have a mailing list for all of our foofus.net tools! If you’d like to join, please see the mailman page at http://lists.foofus.net/listinfo.cgi/foofus-tools-foofus.net. This is a great way to get help on using the tools, report bugs, make feature requests and find out about new releases first!

SolarWinds : Network Management Software

Real-time NetFlow Analyzer

Our new free tool unlocks the power of NetFlow on your network: SolarWinds Real-time NetFlow Analyzer! This free desktop tool captures and analyzes NetFlow data in real time to show you exactly what types of traffic are on your network, where that traffic is coming from, and where it is going. With Real-time NetFlow Analyzer, you can take the guesswork out of diagnosing traffic spikes and troubleshooting bandwidth issues.

If you are new to NetFlow, you’re going to love this powerful protocol. If you haven’t already, it is easy to turn on flows on your existing Cisco routers. We even have a free tool – NetFlow Configurator – to help you remotely configure NetFlow v5 via SNMP on supported Cisco® devices. We’ve bundled this tool with the Real-time NetFlow Analyzer download, so that you can get started with monitoring network traffic immediately.

Put an end to complaints about the network being slow! With Real-time NetFlow Analyzer, you’ll have the power to:

  • Investigate, troubleshoot, and quickly remediate network slowdowns
  • Easily identify which users, devices, and applications are consuming the most bandwidth
  • Isolate inbound and outbound traffic by conversation, application, domain, endpoint, and protocol
  • Personalize NetFlow data displays to view traffic by specified time periods and by traffic type
  • Customize refresh rates and display units for NetFlow traffic

* SolarWinds Real-time NetFlow Analyzer supports NetFlow Version 5 and records up to 60 minutes of NetFlow data.

Simply complete the form below to download the FREE Real-time NetFlow Analyzer from SolarWinds! Download Now

Aircrack

Introduction

Aircrack-ng is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured. It implements the standard FMS attack along with some optimizations like KoreK attacks, as well as the all-new PTW attack, thus making the attack much faster compared to other WEP cracking tools. In fact, Aircrack-ng is a set of tools for auditing wireless networks.

What is Aircrack-ng ?

If you are impatient and want to know how to get started, jump to the Getting Started Tutorial.

Aircrack-ng is the next generation of aircrack with lots of new features:

Note: Check trac for planned and requested features

News

15 August 2008 Defcon ath5k frequency patch is avalaible on patches.aircrack-ng.org. The presentation will be available soon.
22 June 2008 ph-neutral pictures are now published (photos.aircrack-ng.org).
9 June 2008 Aircrack-ng 1.0 rc1 is now released.
12 May 2008 A new version of the VMware appliance is released (drivers and aircrack-ng updated and added rt73 driver).
9 April 2008 Sharkfest and San Francisco pictures are published (photos.aircrack-ng.org).
24 february 2008 Shmoocon pictures are published (photos.aircrack-ng.org).
24 february 2008 Aircrack-ng 0.9.3 is now released (mainly fixing endianness bugs).
5 february 2008 Aircrack-ng 0.9.2 is now released. It should be the last release of the 0.X series (it’s a maintenance release).
1 february 2008 Aircrack-ng 1.0 beta2 is now released.
4 january 2008 I will make a talk at Sharkfest ‘08. More details on this forum post.
3 january 2008 We got an award from Security-Database.com for Aircrack-ng. We got “Best” in category “Penetration Tests - Wireless Hacking”. See forum post

more News…

Download

Current version

Latest version: 1.0-rc1

IMPORTANT Information Regarding Windows Version IMPORTANT
The windows version requires you to develop your own DLLs to link aircrack-ng to your wireless card. The required DLLs are not provided in the download nor available anywhere on the Internet. Without these DLLs, the windows version will not function. Do NOT post questions or problems to the forum regarding the windows version. At present, there is no support provided.

Changelog

  • airbase-ng: Multi-purpose tool aimed at attacking clients as opposed to the AP.
  • airbase-ng: Added replay tool for external packet processing feature.
  • aircrack-ng: Fixed: Displaying twice the wep key at the end and “Warning: Previous crack is still running”.
  • aircrack-ng: Fixed detection of WPA handshake (was not working correctly in previous release).
  • aircrack-ng: Fixed PTW attack against QoS and WDS packets.
  • aircrack-ng: Added oneshot option to try PTW only once.
  • airodump-ng: Fixed channel numbers (Fixed “fixed channel” messages).
  • airodump-ng: Added frequency selection (-C).
  • aireplay-ng: Fixed injection on OpenBSD.
  • aireplay-ng: Fixed a rtc bug which freezed aireplay-ng in case /dev/rtc0 is not available.
  • aireplay-ng: Fixed chopchop attack against QoS packets.
  • aireplay-ng: Added Caffe-Latte attack.
  • aireplay-ng: Added CFrag attack: Turns every IP and ARP packet into an ARP request against the client.
  • airtun-ng: Added support for fragmented packets.
  • airdriver-ng: Updated drivers.
  • airserv-ng: Various fixes.
  • airmon-ng: Added nl80211 usage.
  • airmon-ng: Use ‘iw’ when it is found.
  • airmon-ng: Fixed error with madwifi-ng when creating new VAP.
  • wesside-ng: Added option to ignore ACKs.
  • OSdep: Fixed endieanness bugs.
  • OSdep: Orinoco: attempt to bring interface down before switching to monitor mode.
  • All: Added copyright and GPL in missing files.
  • All: Fixed compilation on Mac OSX 10.5.2 (PPC).
  • GUI: Fixed “Choose” button (airdecap-ng).
  • Makefile: Fixed usage of iCC versions other than 9.0.
  • patches: Updated rtl8187 patch.
  • patches: Updated madwifi-ng patch.
  • patches: Updated sqlite patch (cygwin).
  • patches: Added mac80211 frag patch.
  • patches: Added b43 and updated bcm43xx patches.

The complete Changelog

Legacy

Latest version: 0.9.3

Changelog

  • Fix endianness issues in airodump-ng, aireplay-ng.
  • Several small bug fixes.
  • Updated rtl8187 patch.

The complete Changelog

Subversion Repository

The latest svn of the development sources can be found at trac.aircrack-ng.org.

A bug tracker is also available there.

The download and installation instructions can be found on the installation page.

Virtual Machine

A virtual machine is available here. See this page for more information.

A second, very light VMWare (15Mb required on disk) machine is available here. This machine currently only works with RT73. See this thread on the forum for more information.

Driver patches

They can be found here… and this link explains how to install the driver(s) for your adapter(s).

Installation

Aircrack-ng Suite

Drivers

Virtual Machine

Support

Be sure to read the wiki. This wiki contains a vast amount of information to get you going and to resolve problems.

Documentation

Aircrack-ng suite

Tutorials

Other Documentation

Links to Key Resources

URLs

THC Hydra

THC-Hydra

A very fast network logon cracker which support many different services
hydra-5.4-src.tar.gz

Last update 2006-05-05

[0x00] News and Changelog

PLEASE NOTE: I have currently not much time for coding, however some
modules need to be rewritten. If you have time and experience to help
this community project, please contact me at vh (at) thc (dot) org.

CHANGELOG for 5.4:
###########
* Fixes to the http modules as some Apache installations are picky
* The MySQL module also works with mysqld-5.0, updated
* Added AS/400 return code checks to pop3 module
* Fixed memory leaks in the http-form module.
* Implemented a proposal by Jean-Baptiste.BEAUFRETON (at) turbomeca.fr to
check for "530 user unknown" message in the ftp module
* Added a performance patch by alejandro.mendiondo (at) baicom.com. This one
needs stability testing!
* Beautification to remove compiler warnings of modern gcc

Have fun!


[0x01] Introduction

Welcome to the mini website of the THC Hydra project.

Number one of the biggest security holes are passwords, as every password security study shows.
Hydra is a parallized login cracker which supports numerous protocols to attack. New modules
are easy to add, beside that, it is flexible and very fast.

Currently this tool supports:
TELNET, FTP, HTTP, HTTPS, HTTP-PROXY, SMB, SMBNT, MS-SQL, MYSQL, REXEC,
RSH, RLOGIN, CVS, SNMP, SMTP-AUTH, SOCKS5, VNC, POP3, IMAP, NNTP, PCNFS,
ICQ, SAP/R3, LDAP2, LDAP3, Postgres, Teamspeak, Cisco auth, Cisco enable,
LDAP2, Cisco AAA (incorporated in telnet module).

This tool is a proof of concept code, to give researchers and security
consultants the possiblity to show how easy it would be to gain unauthorized
access from remote to a system.

[0x02] Disclaimer

1. This tool is for legal purposes only!
2. If this tool is used as part of a commercial service (e.g. pentest),
name, version and web address of this tool must be mentioned in the report.
3. If this tool is incorporated into a commercial tool (means: it costs
money, has license costs or upgrade fees, etc.) or called by it,
the name, version and web address of this tool must be mentioned in the
report output of the tool. Addtionally, a commercial version, key file,
etc. must be made available to the author free of charge.
4. Beside 1. to 3. above, the GPL 2.0 applies.

[0x03] Documentation

Hydra comes with a rather long README file that describes the
details about the usage and special options.

[0x04] Development & Contributions

Your contributions are more than welcomed!

If you find bugs, coded enhancements or wrote a new attack module for a service,
please send them to vh (at) thc (dot) org

Interesting attack modules would be:
Oracle SQL*Net, PC-Anywhere, SSHv1, BGPv4, HTTP-NTLM, PPTP, ...
(or anything else you might be able to do (and is not there yet))

[0x05] Screenshots


(1) Target selection


(2) Login/Password setup


(3) Hydra start and output

[0x06] The Art of Downloading: Source and Binaries

For your pleasure, Hydra comes as source and binary release.

1. The source code of Hydra: hydra-5.4-src.tar.gz
(compiles on all UNIX based platforms - even MacOS X, Cygwin on Windows, ARM-Linux, etc.)

2. The Win32/Cywin binary release: hydra-5.4-win.zip
(everything you need to run hydra on win32 platforms is in this zip file)

4. The ARM binary release: hydra-5.0-arm.tar.gz (soon updated)
(created by tick (at) thc (dot) org - everything except SAP R/3 is supported,
runs on all Handhelds with ARM processors running Linux, e.g. iPaq, Zaurus, etc.)

3. The Palm binary release: hydra-4.6-palm.zip
(created by snakebyte (at) gmx (dot) de - does not support all attack modules yet)
[NOTE: the Palm release has got a different source tree. Therefore not all]
[ modules are supported, and updates are not very often. ]

Comments and suggestions are welcome.

Yours sincerly,

van Hauser
The Hackers Choice
http://www.thc.org

Jhon The Ripper

John the Ripper is free and Open Source software, distributed primarily in source code form. If you would rather use a commercial product tailored for your specific operating system, please consider John the Ripper Pro, which is distributed primarily in the form of “native” packages for the target operating systems and in general is meant to be easier to install and use while delivering optimal performance.

Proceed to John the Ripper Pro homepage for your OS:

Download one of the latest free “development” versions:

or the latest free “stable” release:

Note: a few Windows “antivirus” and “anti-spyware” products have started to recognize password recovery tools as if they were “trojans”. This is how those products’ vendors inflate their detected “virus” counts. The effect is that end-users are no longer able to check password recovery software for real viruses. If this affects you, please complain to your antivirus vendor.

Please refer to these pages on how to extract John the Ripper source code from the tar.gz and tar.bz2 archives and how to build (compile) it.

The only change between 1.7.0.1 and 1.7.0.2 is irrelevant for 32-bit platforms, hence there are no builds of 1.7.0.2 for Windows and DOS (they would have been exactly the same as those of 1.7.0.1).

In practice, 1.7.2 (a “development” version) has been around for a long time now, and it has been found to be at least as stable as 1.7.0.2, so the use of 1.7.2 is recommended.

Chain & Abel

Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords and analyzing routing protocols. The program does not exploit any software vulnerabilities or bugs that could not be fixed with little effort. It covers some security aspects/weakness present in protocol’s standards, authentication methods and caching mechanisms; its main purpose is the simplified recovery of passwords and credentials from various sources, however it also ships some “non standard” utilities for Microsoft Windows users.

Cain & Abel has been developed in the hope that it will be useful for network administrators, teachers, security consultants/professionals, forensic staff, security software vendors, professional penetration tester and everyone else that plans to use it for ethical reasons. The author will not help or support any illegal activity done with this program. Be warned that there is the possibility that you will cause damages and/or loss of data using this software and that in no events shall the author be liable for such damages or loss of data. Please carefully read the License Agreement included in the program before using it.

The latest version is faster and contains a lot of new features like APR (Arp Poison Routing) which enables sniffing on switched LANs and Man-in-the-Middle attacks. The sniffer in this version can also analyze encrypted protocols such as SSH-1 and HTTPS, and contains filters to capture credentials from a wide range of authentication mechanisms. The new version also ships routing protocols authentication monitors and routes extractors, dictionary and brute-force crackers for all common hashing algorithms and for several specific authentications, password/hash calculators, cryptanalysis attacks, password decoders and some not so common utilities related to network and system security.

Download Cain & Abel v2.0 for Windows 9x (discontinued and not supported anymore)
MD5 - A14185FAFC1A0A433752A75C0B8CE15D
SHA1 - 8F310D3BECC4D18803AF31575E8035B44FE37418

Download Cain & Abel v4.9.22 for Windows NT/2000/XP
MD5 - 6BA2BC1275BE5A75D6C6448FCBF65FA1
SHA1 - 98005421CF59250172B611CCA4226E742A98A9A6

WARNING !!! The password list file format is changed between version 4.9.10 and 4.9.14. Old LST files are not compatible anymore so it is strongly suggested to backup your files before upgrade to this new release.

Cain & Abel User Manual is included in the installation package and also available on-line so you can view all the program’s features without the need to install the program. The on-line version of the manual requires a JavaScript enabled browser.

View Cain & Abel on-line User Manual

Brutus

Introduction

Brutus is one of the fastest, most flexible remote password crackers you can get your hands on - it’s also free. It is available for Windows 9x, NT and 2000, there is no UN*X version available although it is a possibility at some point in the future. Brutus was first made publicly available in October 1998 and since that time there have been at least 70,000 downloads and over 175,000 visitors to this page. Development continues so new releases will be available in the near future. Brutus was written originally to help me check routers etc. for default and common passwords

Features

Brutus version AET2 is the current release and includes the following authentication types :

HTTP (Basic Authentication)
HTTP (HTML Form/CGI)
POP3
FTP
SMB
Telnet
Other types such as IMAP, NNTP, NetBus etc are freely downloadable from this site and simply imported into your copy of Brutus. You can create your own types or use other peoples.