FakeNet – Beta – Windows Network Simulation tool for Malware Analysis.

FakeNet is Windows network simulation tool designed for malware analysis. It redirects all traffic leaving a machine to the localhost (including hard-coded IP traffic and DNS traffic) and implements several protocols to ensure that malicious code continues to execute and can be observed by a malware analyst.

The tool supports DNS, HTTP, and SSL protocols and provides a python extension interface for implementing new or custom protocols. It also the capability to listen for traffic to any port as well as create packet capture on the localhost.

Right now the tool only support WinXP Service Pack 3. The tool runs fine on Windows Vista/7 although certain features will be automatically disabled.

Features

  • Supports DNS, HTTP, and SSL
  • HTTP server always serves a file and tries to serve a meaningful file; if the malware request a .jpg then a properly formatted .jpg is served, etc. The files being served are user configurable.
  • Ability to redirect all traffic to the localhost, including traffic destined for a hard-coded IP address.
  • Python extensions, including a sample extension that implements SMTP and SMTP over SSL.
  • Built in ability to create a capture file (.pcap) for packets on localhost.
  • Dummy listener that will listen and display traffic destined for any port.

Platform : Windows

Download Latest Version : FakeNet0.9.exe (8.3 MB)

Find Other Version |

Read more in here : http://practicalmalwareanalysis.com/

websploit – Is a open source tool for scan and analysis cms’s

WebSploit :

  • Scan All Sql Injection Vulnerability In Plugin’s Of WordPress , DataLife , Joomla , Drupal
  • Scan All Local File Inclusion Vulnerability In Plugin’s Of WordPress , DataLife , Joomla , Drupal
  • Scan All Remote File Include & Remote Code Execution Vulnerability In All Themes And Plugin’s Of WordPress , DataLife , Joomla , Drupal

Download Latest version : websploit-v.1.2.zip (1.1 MB)

Find Other Version | Read more in here : http://code.google.com/

SuStorID – Alpha

SuStorID is an advanced Intrusion Detection System (IDS) for web services, based on machine learning. Its name comes from the term “Su Stori”, which in Sardinian language means “The Falcon”. It’s version is experimental, but demonstrates a number of interesting features, that can be readily exploited to detect and act against web attacks. SuStorID can be coupled with modsecurity, the well known web application firewall, to gather training data and provide for real-time counteractions. So, SuStorID is a host-based Intrusion Detection System, and by means of modsecurity can access internal web server’s data (i.e. http request/response fields) exactly as Apache does.

How to Installation :

Download Latest Version :

– SuStorID_alpha.zip (1.1 MB)

– modsecurity-apache_2.6.2_for_sustorid.zip

find other version |

read more in here : http://comsec.diee.unica.it/sustorid/

iSkim – Skim mobile devices on the go

open source project for using forensic tools to help analyze devices for potential privacy and security vulnerabilities

The iSkim tool is a small script to help forensic peeps to quickly dump all “sqlit”,”log” and “db” files.
The tool is a BETA at this moment and covers only non-jailbroken devices.

Requirements
————
– ubuntu 11.10
– libimobiledevice and all supporting libs.

Running it
———-
run ‘python iSkim.py’

Download latest Version : iSkim_test.py (4.5 kB)

Find Other Version | Read more in here : iSkim