Showing posts with label Scanners. Show all posts
Showing posts with label Scanners. Show all posts

Tuesday, 18 November 2014

Collection of tools to detect viruses

Collection of tools to detect viruses

It is a fact that if you have a internet connection or USB/CD purpose that gets used across compound computers you are vulnerable to viruses, this guide has been compiled by me to facilitate users court skirmish adjoining these hidden attackers. This is even more loud if a professional malware writer has to your liking SEO skills to succeed to the #1 upshot, contaminate a real report of the malware detector taking into account his own malicious code. Imagine a System Administrator happily installing an Anti-Malware in the region of all the dozens (or hundreds) of workstations below his achieve.
Firewalls

Firewalls block malicious programs from running, as expertly as protecting ports and attacks through the internet. A firewall is a necessary component in today's computing world.

Recommended firewalls:
1# Sunbelt Personal Firewall
2# Outpost Firewall
3# Comodo Internet Security

Anti-viruses
Anti-viruses can be on depth of just a scanner (which we will lid soon), nowadays not well-disposed of-viruses arrive packed full of new features, some even including built in firewalls, but a main feature popping happening in diagnostic of-viruses is "definite-become obsolete guidance" which scans files which your are commencement, have right to use and keeps a log and watches out for whats going on regarding your system. Anti-viruses are developing more and more as become antique goes regarding, just to retain happening when its competition.

Recommended Anti-viruses:

1# Sunbelt Vipre Antivirus + Antispyware
2# Avira Anti-virus suite Professional
3# Trend Micro AntiVirus + AntiSpyware

TCP/UDP spectators

These programs assert you to see the connections visceral made through your ports, these are likable tools for detecting bots, rats and key loggers approximately the order of your computer. They play in by listing the lithe buddies of the dealing out programs and have the funds for you the distant dwelling if there is one, using this you can usually publicize if it is a malicious program accessing your computer,or you can reveal by putting the IP blazing into this website,

Recommended TCP/UDP spectators:
1# Currports - This program gives you a enormously detailed list of recommendation upon the supple friends

2# TCP view - This one does the same matter but later a tiny bit less info.

Scanners

Now, Scanners are a tiny exchange to your adjacent to-viruses, scanners are built to detect malware in a more true quirk than most touching-viruses will, they profit updated regularly and can be compact and portable, but yet money big adroitness.

Recommended Scanners:

1# Malwarebyte's Anti-Malware - This has to be one of the best scanners ever it detects millions of viruses and should be used for regular scans
2# SuperAntiSpyware - This is option colossal malware/spyware scanner i use it along side Malwarebyte's and Vipre for optimal lawsuit subsequent to regular scans (detects some viruses Malwarebyte's doesn't).
3# SpyBot Search and Destroy - Huge database of spyware and resident verify for changes.
Logger's

I couldn't really arrive occurring when a huge proclaim for these programs consequently i called them loggers due to the fact they pay for logs which moreover can be revised to search for malicious entries. Logger's mainly search registry keys, begin going on items and admin processes, they manage to pay for in you to cut off these entries to sum less the virus from vis--vis-appearing upon begin occurring, however should always be followed occurring by a virus scan and removal of the file logged.

Recommended Logger's:

1# Hijackthis - Hijackthis is a highly developed program that allows users to easily remove crucial parts of viruses to merge less them from occurring and should be used regularly (gone a log posted to hjt team) to check if you have accidentally installed something malicious.

Cleaners

There are many "cleaners" upon the internet that remove performing files which can slow your computer, and contain malicious files, cleaners were made to court quarrel these problems and are efficient for discharge occurring ventilate, your the theater files can profit occurring to massive sizes, my highest was 3 gigabytes, now that's beautiful big for the stage files.

Recommended cleaner's:

1# Ccleaner (formerly known as crap cleaner) - Ccleaner is a utterly efficient and short cleaner that has many useful options, including (but not limited to) file cleaner, registry cleaner, begin happening editor, uninstall list. Ccleaner is a utterly indispensable tool and is a must for a pc enthusiast.
2# ATF-Cleaner - Cleans temp files more or less the same as Ccleaner a small bit alternating.

USB Protection

Many extra viruses have the functionality to press on using removable disks such as USB's and it is now recommended to use an not in agreement of-virus for your USB as you may decline occurring infecting your own computer. portableapps.com has many portable programs worth checking out.

Recommended USB Anti-viruses:

1# ClamWin Portable - Great hostile to-virus for your USB dream.

Thursday, 6 March 2014

Penetration Testing Apps for Android Devices


Introduction

The amount of mobile phone users is larger than PC users according to a recent research. At the same time, the people who own Android phones are increasing rapidly. Android phone brings people a lot of convenience that it helps people do as much work as they can do on computer, while has no limitation to the location
Android has become a need rather than luxury these days, and its popularity has increased rapidly among available smart phones. There are lots of OS which are available these days but among all of them android is the best one, as it can be handled easily and also it is very easy to implement because its open source nature.
Android App Development is nowadays has become an important tool for developing mobile applications. The Software Development Kit facilitated by the Android assists the developers to start developing and working on the applications instantaneously and the app can be implemented faster.
Now penetration testing is possible by using Android platform, now there will be no need to carry your system to various locations to carry out Penetration Testing.As we all know Penetration Testing involves much involvement of the person into their system but by using your android phone you can perform it at any location in a best way you can.

Following are the Android applications that you can use for penetration testing.

1.     Networking Tools

Port Scanner: this tool lets you scan ports on a remote host via its IP or domain name so you can know which ports are open on the host. It supports 3G, protocol recognition, and many other features.
Fing: Fing is a professional App for network analysis. A simple and intuitive interface helps you evaluate security levels, detect intruders and resolve network issues. It helps us to find out which devices are connected to your Wi-Fi network, in just a few seconds.
Network Discovery: Network Discovery is similar to Fing. It is used for device discovery and works as a port scanner for local area network.
tPacketCapture: tPacketCapture does packet capturing without using any root permissions. tPacketCapture uses VpnService provided by Android OS.Captured data are saved as a PCAP file format in the external storage.
Droidsheep: Droidsheep is written by Andrew Koch. It works as a session hijacker for non-encrypted sites and allows you to save cookies files/sessions for later analysis. It is no longer available from developer’s site i.e. droidsheep.de.
FaceNiff: FaceNiff is an app that allows you to sniff and intercept web session profiles over the WiFi that your mobile is connected to. It is possible to hijack sessions only when WiFi is not using EAP, but it should work over any private networks

2.     DOS
LOIC: LOIC is a tool for network stress testing denial-of-service attack application. LOIC performs a denial-of-service (DoS) attack (or when used by multiple individuals, a DDoS attack) on a target site by flooding the server with TCP or UDP packets with the intention of disrupting the service of a particular host.
AnDOSid: AnDOSid allows security professionals to simulate a DOS attack. AnDOSid app launched a HTTP POST flood attack, where the number of HTTP requests becomes so huge; a victim’s server has trouble responding to them all. When the server begins to rely too heavily on its system resources, it crashes.
3.     Packet sniffer
Intercepter-NG: Intercepter-NG is a multifunctional network toolkit. It has functionality of several famous separate tools and more over offers a good and unique alternative of Wireshark for android.
The main features are:
network discovery with OS detection
·         network traffic analysis
·         passwords recovery
·         files recovery
Shark for Root: Traffic sniffer, works on 3G and WiFi (works on FroYo tethered mode too).To open dump use WireShark or similar software, for preview dump on phone use Shark Reader.
PacketShark: This is a packet sniffer application. Features include friendly capture options interface, filter support, live capture view, and Dropbox upload of capture files. It allows viewing the capture packets no need to install other application as a viewer.

4.     Scanners

WPScan: WPScan is a black box WordPress Security Scanner written in Ruby which attempts to find known security weaknesses within WordPress installations. This app was developed by Alessio Dalla Piazza. Its intended use it to be for security professionals or WordPress administrators to assess the security posture of their WordPress installations. WPScan includes user enumeration and will detect timthumb file, theme and WordPress version and notify you 
Nessus: Nessus is a popular penetration testing tool that is used to perform vulnerability scans with its client/server architecture. Nessus Android app can perform following tasks.
·         Connect to a Nessus server (4.2 or greater)
·         Launch existing scans on the server
·         Start, stop or pause running scans
·         Create and execute new scans and scan templates
·         View and filter reports
Network Mapper:
·         A very fast net scanner for network admins that can scan your network in the office and export as CSV via Gmail to give you a map of what devices are on your LAN.
·         Includes a port scanner for security audit scans and a MAC vendor database to identify NIC manufacturers
·         Can detect firewalled and stealthed computers, quite useful if you are looking for a windows/firewall box that you can't see on your network.
·         Useful if you want to find FTP servers, SSH servers, SMB servers etc on your network and would help you to diagnose faults.
·         You can save the scan results as a CSV file which can be imported into Excel/Google Spreadsheet/LibreOffice
5.     Webattack
DroidSQLi: DroidSQLi is the first automated MySQL Injection tool for Android. It allows you to test your MySQL-based web application against SQL injection attacks.
DroidSQLi supports the following injection techniques:
·         Time based injection
·         Blind injection
·         Error based injection
·         Normal injection
It automatically selects the best technique to use and employs some simple filter evasion methods.
Sqlmapchik: sqlmapchik is a cross-platform sqlmap GUI for popular sqlmap tool. It is primarily aimed to be used on mobile devices. The easiest way to install sqlmapchik on Android device is to download it from Google Play.
6.     Pentesting suites
dSploit: dSploit is an Android network analysis and penetration suite which aims to offer to IT security experts/geeks the most complete and advanced professional toolkit to perform network security assessments on a mobile device. Once dSploit is started, you will be able to easily map your network, fingerprint alive host’s operating systems and running services, search for known vulnerabilities, crack logon procedures of many tcp protocols, perform man in the middle attacks such as password sniffing, real time traffic manipulation etc.
These are the available modules in the app.
·         RouterPWN
·         Trace
·         Port Scanner
·         Inspector
·         Vulnerability Finder
·         Login Cracker
·         Packet Forger
·         MITM
Revenssis Penetration Suite: Revenssis Penetration Suite is a set of all the useful types of tools used in Computer and Web Application security.  
·         Web Vulnerability Scanners including:
o   SQL injection scanner
o   XSS scanner
o   DDOS scanner
o   CSRF scanner
o   SSL misconfiguration scanner
o   Remote and Local File Inclusion (RFI/LFI) scanners
·         Useful utilities such as:
o   WHOIS lookup, IP finder, Shell, SSH, Blacklist lookup tool, Ping tool,
·         Forensic tools (in implementation) such as malware analyzers, hash crackers, network sniffer, ZIP/RAR password finder, social engineering toolset, reverse engineering tool
·         Vulnerability research lab (sources include: Shodan vulnerability search engine, ExploitSearch, Exploit DB, OSVDB and NVD NIST
·         Self scan and Defence tools for your Android phone against vulnerabilities
·         Connectivity Security Tools for Bluetooth, Wifi and Internet. (NFC, Wifi Direct and USB in implementation)
zANTI: zANTI is a comprehensive network diagnostics toolkit that enables complex audits and penetration tests at the push of a button. It provides cloud-based reporting that walks you through simple guidelines to ensure network safety.
zANTI offers a comprehensive range of fully customizable scans to reveal everything from authentication, backdoor and brute-force attempts to database, DNS and protocol-specific attacks – including rogue access points.
7.     Anonymity
Orbot: Orbot is a free proxy app that empowers other apps to use the internet more securely. Orbot uses Tor to encrypt your Internet traffic and then hides it by bouncing through a series of computers around the world. Tor is an open network that helps you defend against a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationships, and state security known as traffic analysis.
·         Orbot is the safest way to use the Internet on Android. Period. Orbot bounces your encrypted traffic several times through computers around the world, instead of connecting you directly like VPNs and proxies. This process takes a little longer, but the strongest privacy and identity protection available is worth the wait.
·         Use with Orweb, the most anonymous way to access any website, even if it’s normally blocked, monitored, or on the hidden web.
·         Use Gibberbot with Orbot to chat confidentially with anyone, anywhere for free.
·         Any installed app can use Tor if it has a proxy feature, using the settings. You can use private web searching with DuckDuckGo.
·         Orbot can be configured to transparently proxy all of your Internet traffic through Tor. You can also choose which specific apps you want to use through Tor.
·         Orbot is free software.
OpenVPN: OpenVPN Connect is the official full-featured Android VPN client for the OpenVPN Access Server, Private Tunnel VPN and OpenVPN Community, developed by OpenVPN Technologies, Inc.
·         Does not require a rooted device.
·         Easily import .ovpn profiles from SD card, OpenVPN Access Server, Private Tunnel or via a browser link.
·         Improved power management - preferences setting allows VPN to pause in a low-power state whenever screen is blanked or network is unavailable.
·         Android Keychain integration - OpenVPN profiles may reference a cert/key pair in the Android keychain.
·         Supports hardware-backed keystores
·         Support for multi-factor authentication using OpenVPN static and dynamic challenge/response protocols.
·         Full IPv6 support (at both the tunnel and transport layer).
Orweb: Orweb is the most privacy-enhancing web browser on Android for visiting any website, even if it’s normally censored, monitored, or on the hidden web. Orweb is the safest browser on Android. Orweb evades tracking and censorship by bouncing your encrypted traffic several times through computers around the world, instead of connecting you directly like VPNs and proxies. This process takes a little longer, but the strongest privacy and identity protection available is worth the wait.
·         Orweb bypasses almost every kind of network restriction.
·         Orweb does not store any information about the websites you visit.
·         You can prevent sites you visit from installing any cookies (which could track your web activities), allow them selectively, or allow any site to create cookies.
·         JavaScript, a common attack method for malicious software, is disabled by default.
·         Orweb is opensource.
·         Orweb attempts to prevent Flash from loading on sites you visit, blocking   many common security threats.
·         Orweb is available in: Arabic, Chinese, Dutch, English, Esperanto, Farsi, French, German, Hungarian, Italian, Norwegian, Russian, Spanish, Swedish and Tibetan
Conclusion
Android Operating System has been progressing quite rapidly. Android, is an innovative and open platform.  Android is most popular mobile OS. It is well positioned to address the growing needs of the mobile marketplace. Due to rapid growth of android, developers are now focusing on developing their tools in the android environment. Above mention android application is the proof of that. The Software Development Kit facilitated by the Android helps developers to achieve the same.
Above applications discussed are the ways to perform penetration testing from your android mobile. We can achieve anonymity and can perform web attacks by using android phone. It also provides us penetration suites and other networking tools.
References

·         http://www.irongeek.com/i.php?page=videos/notacon11/nindroid-pentesting-apps-for-your-android-device-michael-palumbo

Prevention Techniques: Cross-site request forgery (CSRF)

1. The best defense against CSRF attacks is unpredictable tokens, a piece of data that the server can use to validate the request, and wh...