System hardening tools

Viruses, hackers and crackers
Post Reply
Frozenfireside
Registered User
Posts: 2618
Joined: 26 Apr 2007, 02:00
Location: Westcliff, Johannesburg
Contact:

System hardening tools

Post by Frozenfireside »

Hi
I am a networker by studies and I've been looking around for some nifty tools to use for network testing, hacking my teachers PC (I have permission and we are actually learning to hack) and generally messing about with my own network.

So I'll post a few of my favourites (everyone should know a few of them) but the one I just found that has really impressed me is SPIKE Proxy.

Able to
o SQL Injection
o Directory scanning
o File Scanning
o Crawling
o Overflows and format strings
Now this runs in windows for easier use by noobs.

It's really easy to use and really effective.

here's a link to the website

I'll just post an easy guide here

-Extract to C:\SPIKEProxy ( this is just easier then having to change the dir)
-Internet explorer>tools->Internet Options->Connections->LAN Settings change to proxy of 127.0.0.1 (your loopback IP)
-Run the runme.bat file in the spike dir (keep open)
-Then in IE run http://spike/
-select the test you want and watch as the programme test your website/machine/etc in the command screen.

Now this is useful for website admin who want to do some stress testing on their web machines.

Other useful tools include
Cain and Able
The top password recovery tool for Windows
UNIX users often smugly assert that the best free security tools support their platform first, and Windows ports are often an afterthought. They are usually right, but Cain & Abel is a glaring exception. This Windows-only password recovery tool handles an enormous variety of tasks. It can recover passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols.
Oxid.it forums[/url

[url=http://nmap.org/download.html]Nmap

Nmap is a great app that all networkers should learn to use.

Brutus AET 2-Password cracker
HTTP (Basic Authentication)
HTTP (HTML Form/CGI)
POP3
FTP
SMB
Telnet
Other types such as IMAP, NNTP, NetBus
useful but some apps (like Brutus) will get a virus warning as they have been listed on Antivirus security risk list.
Basically they don't want you to have the power of them.

I've also found some great tools that will try to inject malicious codes into a system, analyse the results and give you an report with the issue, it's meaning and how to fix it.

I'm sure you guys know Nessus (register for the free edition)

X-Scan
Xscan is very user friendly and a personal fav.

Both of these are really simple to use and incredibly powerful.

For hidden passwords get Asterisk Key

Cain and able, Xscan, EtherChange, AirSnare, AirCrack-NG video guides here

Have fun and don't do anything stupid!
If you want to add any, please do. I'm looking for a powerful SMTP app.

If I can find anything more, I'll edit the main body of the thread.
regards
Frozen
(if any of my links are not working properly then please excuse this and copy and paste into your web browser.
Soon Google will know everything...including how to divide by zero :(
Image
Frozenfireside
Registered User
Posts: 2618
Joined: 26 Apr 2007, 02:00
Location: Westcliff, Johannesburg
Contact:

Re: System hardening tools

Post by Frozenfireside »

An example of Nessus 3 scan reports
Image
Soon Google will know everything...including how to divide by zero :(
Image
Frozenfireside
Registered User
Posts: 2618
Joined: 26 Apr 2007, 02:00
Location: Westcliff, Johannesburg
Contact:

Re: System hardening tools

Post by Frozenfireside »

Firewalls:
So far I've used a few firewalls including Norton 360, Zonealarm free and paid for versions, COMODO free and some others. Windows firewall is meh. it offers not outgoing protection so if you get a bug you can spread it very easily.

My favourite is Zonealarm paid for but the free version is not bad. Authorise an app and it doesn't bother you much after that.

Zonealarm home
Zonealarm free

COMODO free products
This just annoys the living **** out of me. Instead of asking per .exe it asks per .exe and every app, .dll, file and so on so you get 30 approval questions when installing even the smallest of apps.
SoftPerfect Personal Firewall
Very tiny firewall but I haven't used it.

Norton 360 wasn't a bad firewall but I didn't like the rest of the product and uninstalled it with something like 60 days left on the account.

I want to get AVG firewall pro but I'm low on funds.

If you want to monitor every app and every port open (communicating and non communicating), use port explorer. Not free and a bit pricey but is a nice application.
here is a pic (1182X864 so not 56k friendly)
http://i122.photobucket.com/albums/o269 ... erdemo.jpg
Soon Google will know everything...including how to divide by zero :(
Image
User avatar
rustypup
Registered User
Posts: 8872
Joined: 13 Dec 2004, 02:00
Location: nullus pixius demonica
Contact:

Re: System hardening tools

Post by rustypup »

Frozenfireside wrote:My favourite is Zonealarm paid for but the free version is not bad.
zone alarm is not a good choice... i would invite you to try outpost... while it may not be newbie friendly, it knocks ZA into a cocked hat...

even comodo beats ZA in the f/wall stakes.....
Most people would sooner die than think; in fact, they do so - Bertrand Russel
Frozenfireside
Registered User
Posts: 2618
Joined: 26 Apr 2007, 02:00
Location: Westcliff, Johannesburg
Contact:

Re: System hardening tools

Post by Frozenfireside »

Ok I'll try that but COMODO just annoyed me. 30 questions was alot for one app.
I have found some holes with ZA though. Thanks for the heads up.
Soon Google will know everything...including how to divide by zero :(
Image
DeathStrike
Registered User
Posts: 2663
Joined: 29 Jul 2004, 02:00
Location: hidden deep in the depths of the underworld is my home.
Contact:

Re: System hardening tools

Post by DeathStrike »

comodo only asks 1ce for the network access the rest is for system access. u can disable that part if you like. Defence+ > disable. :)
Spoiler: (show)
Image
SIG by HMAN 8)
Member of The Pride Of Darkness
DeathStrike on Twitter
About me
Spoiler: (show)
Asus P5KPL-CM motherboard, 4 GIG RAM, Q6600 @ 2.88GHz (Thanks Anthro), GeForce 8600GT, Samsung 2333 23" + CRT 17" Monitors. 500GB + 1.5TB HDD, Compro TV tuner, 350 WATT PSU
Frozenfireside
Registered User
Posts: 2618
Joined: 26 Apr 2007, 02:00
Location: Westcliff, Johannesburg
Contact:

Re: System hardening tools

Post by Frozenfireside »

Soon Google will know everything...including how to divide by zero :(
Image
Frozenfireside
Registered User
Posts: 2618
Joined: 26 Apr 2007, 02:00
Location: Westcliff, Johannesburg
Contact:

Re: System hardening tools

Post by Frozenfireside »

*Hangs head and shuffles feet*
I might have got into the college switches and rebooted them with Telnet.
It's their own bloody fault for not protecting them in the first place! :| :lol:
It didn't do much but my account has been suspended :mrgreen:
Told my lecturer. He just laughed.
Soon Google will know everything...including how to divide by zero :(
Image
Mori
Registered User
Posts: 6471
Joined: 07 Mar 2006, 02:00
Location: Northern Cape river surfer.

Re: System hardening tools

Post by Mori »

Frozenfireside wrote:*Hangs head and shuffles feet*
I might have got into the college switches and rebooted them with Telnet.
It's their own bloody fault for not protecting them in the first place! :| :lol:
It didn't do much but my account has been suspended :mrgreen:
Told my lecturer. He just laughed.
LOL ?
Frozenfireside
Registered User
Posts: 2618
Joined: 26 Apr 2007, 02:00
Location: Westcliff, Johannesburg
Contact:

Re: System hardening tools

Post by Frozenfireside »

I am laughing about it.
I don't really care. If they give me **** I'll just take the slap on the wrist and wait till dec 12th when I get out of there.
Soon Google will know everything...including how to divide by zero :(
Image
Post Reply