<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4663920677497378824</id><updated>2012-02-16T16:16:45.336+01:00</updated><category term='scanner'/><category term='jdbc'/><category term='mysql'/><category term='syn'/><category term='sinfp'/><category term='security'/><category term='perl'/><category term='debian'/><category term='hash'/><category term='john'/><category term='hacking'/><category term='ubuntu'/><category term='scan'/><category term='mssql'/><category term='database'/><category term='oracle'/><title type='text'>H4cking P@lace</title><subtitle type='html'>The place to find the best security Tools for your Evil work !</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://h4ckingpalace.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4663920677497378824/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://h4ckingpalace.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Thr3atSeek3r</name><uri>http://www.blogger.com/profile/15575590367184591309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4663920677497378824.post-5700290162351086821</id><published>2010-04-30T12:44:00.014+02:00</published><updated>2010-05-03T15:14:56.114+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='scanner'/><category scheme='http://www.blogger.com/atom/ns#' term='scan'/><category scheme='http://www.blogger.com/atom/ns#' term='mysql'/><category scheme='http://www.blogger.com/atom/ns#' term='hash'/><category scheme='http://www.blogger.com/atom/ns#' term='john'/><category scheme='http://www.blogger.com/atom/ns#' term='mssql'/><category scheme='http://www.blogger.com/atom/ns#' term='perl'/><category scheme='http://www.blogger.com/atom/ns#' term='database'/><category scheme='http://www.blogger.com/atom/ns#' term='jdbc'/><category scheme='http://www.blogger.com/atom/ns#' term='oracle'/><title type='text'>DB-BRUTATOR the Multi Database scanner/auditing tool !!</title><content type='html'>&lt;div&gt;Hi there ,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I finally managed to take some time to release one of my tools:  &lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;db-brutator&lt;/span&gt; is&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;a  new database auditing tool written in Perl using JDBC drivers. It is very similar to oscanner for oracle databases but it does  much more than just scanning for default accounts, it is designed to be flexible and easily customizable.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_SKhtWqdaYqM/S9rijcYyK_I/AAAAAAAAABM/BzVnN_I61nA/s1600/screen.png"&gt;&lt;br /&gt;&lt;/a&gt;Why using it ? :&lt;br /&gt;&lt;br /&gt;Because you want to audit all database servers with the same efficiency:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Because  you want to check for specific configuration for let's say with 100 different accounts&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Because you want to brute-force some of the accounts.&lt;/li&gt;&lt;li&gt;Because  you like to retrieve all database user hashes.&lt;/li&gt;&lt;li&gt;Because you want to search for credentials in a huge database&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;Features:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Simple  &amp;amp; efficient design&lt;/li&gt;&lt;li&gt;JDBC drivers =&gt; it means it can support every possible database system on the market&lt;br /&gt;&lt;/li&gt;&lt;li&gt;100 % command line interface to be able to automate&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Custom SQL query&lt;/li&gt;&lt;li&gt;Easy database Hash extraction to &lt;a href="http://www.openwall.com/john/"&gt;john&lt;/a&gt; format&lt;/li&gt;&lt;li&gt;Specifics Word lists included&lt;br /&gt;&lt;/li&gt;&lt;li&gt;multi-threaded&lt;/li&gt;&lt;li&gt;Unique of his kind (to my knowledge there is no equivalent on the net)&lt;/li&gt;&lt;li&gt;Multi OS (OSX,Linux,Win32)&lt;/li&gt;&lt;li&gt;Oracle SID bruteforce&lt;/li&gt;&lt;li&gt;Can extract Database structure (DBS,tables,columns)&lt;/li&gt;&lt;li&gt;Can extract X first rows of data of each tables&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Designed by a pentester for pentesters :-P&lt;/li&gt;&lt;li&gt;Already been tested in "real life" conditions&lt;/li&gt;&lt;li&gt;License: Hmm let's say it's GPL but the JDBC drivers are not  &lt;/li&gt;&lt;/ul&gt;Performances:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;It depends on the database, here are the results for each type of database:&lt;/li&gt;&lt;/ul&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;i&gt;Starting JDBC driver proxy on port: 63145 with driver: net.sourceforge.jtds.jdbc.Driver&lt;br /&gt;Done !&lt;br /&gt;Bruteforcing Password length: 1 for user: test&lt;br /&gt;Bruteforcing Password length: 2 for user: test&lt;br /&gt;Bruteforcing Password length: 3 for user: test&lt;br /&gt;Stopping JDBC driver proxy on port: 63145&lt;br /&gt;Done !&lt;br /&gt;DB-brutator Scan Finished at 10/08/2009 16:21:45 duration: 2 minutes 23 seconds on host: NA on port: 1433&lt;br /&gt;DB-brutator Scan Speed: &lt;b&gt;335&lt;/b&gt; auth/sec&lt;br /&gt;Starting JDBC driver proxy on port: 60007 with driver: com.mysql.jdbc.Driver&lt;br /&gt;Done !&lt;br /&gt;Bruteforcing Password length: 1 for user: test&lt;br /&gt;Bruteforcing Password length: 2 for user: test&lt;br /&gt;Bruteforcing Password length: 3 for user: test&lt;br /&gt;Stopping JDBC driver proxy on port: 60007&lt;br /&gt;Done !&lt;br /&gt;DB-brutator Scan Finished at 10/08/2009 16:25:21 duration: 2 minutes 46 seconds on host: NA on port: 3306&lt;br /&gt;DB-brutator Scan Speed: &lt;b&gt;288&lt;/b&gt; auth/sec&lt;br /&gt;&lt;br /&gt;Starting JDBC driver proxy on port: 64297 with driver: oracle.jdbc.driver.OracleDriver&lt;br /&gt;Done !&lt;br /&gt;Bruteforcing Password length: 1 for user: sys as sysdba&lt;br /&gt;Bruteforcing Password length: 2 for user: sys as sysdba&lt;br /&gt;Bruteforcing Password length: 3 for user: sys as sysdba&lt;br /&gt;DB-brutator Scan Finished at 10/08/2009 16:47:58 duration: 18 minutes 28 seconds on host: NA on port: 1521&lt;br /&gt;DB-brutator Scan Speed: &lt;b&gt;43&lt;/b&gt; auth/sec&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Example:&lt;br /&gt;&lt;br /&gt;Here is a typical use to extract the most information from a database if an account &lt;span style="font-style: italic;"&gt;(with priv ;-P)&lt;/span&gt; is discovered, db-brutator will list all database user, grab their hashes if possible dump all tables and columns and finally extract the 5 first rows of data of each tables:&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;user@host: ~$ db-brutator -ho 192.168.142.160 -port 3306 -sgbd mysql -logins /usr/local/db-brutator/dict/common_user.dic -dblist -hash -table -col -data 5 -th 1 | spc -c &lt;/span&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;/usr/local/db-brutator/&lt;/span&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;conf/spcrc&lt;/span&gt;&lt;br /&gt;Result:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_SKhtWqdaYqM/S9rijcYyK_I/AAAAAAAAABM/BzVnN_I61nA/s1600/screen.png"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_SKhtWqdaYqM/S9riyqZNNwI/AAAAAAAAABU/7N5Ff318HgA/s1600/screen.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 197px;" src="http://4.bp.blogspot.com/_SKhtWqdaYqM/S9riyqZNNwI/AAAAAAAAABU/7N5Ff318HgA/s400/screen.png" alt="" id="BLOGGER_PHOTO_ID_5465930457768867586" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;using supercat (spc) to colorize the log&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Online  Help:&lt;br /&gt;&lt;br /&gt;Here is the help message when your launch the db-brutator  without any parameter&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;Usage: &lt;/span&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;bin/db-brutator.pl &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;&lt;/span&gt; &lt;span style="color: rgb(51, 255, 51);"&gt;[-logins loginsfilename or login/passwordfilename] &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;&lt;/span&gt; &lt;span style="color: rgb(51, 255, 51);"&gt;[-host hostname/ip]&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;[-port port]&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;[-sgbd mysql|oracle|mssql|sybase]&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-passwords filename)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-domain Windows Domain for NTLM auth)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-dbname sid)&lt;/span&gt;  =&gt; database name (only useful for oracle because a SID is required to connect), if this param is empty and the database type is oracle then a bruteforce will be performed on the SID. &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-thread x)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-m maxqueuesize)&lt;/span&gt; =&gt; maximum size of queue to store in memory, it is very useful to prevent a memory leak when using huge word lists.&lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-v verbose)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-deb debug)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-delay delay between authentication)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-o outputfilename)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-u list user account)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-dba list dba user account)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-dblist list databases)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-hash list user hashes)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-sql execute custom SQL query)&lt;br /&gt;(-cmd execute custom system command via xp_cmdshell MSSQL/SYBASE only)&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-table list database tables)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-column list databases)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-data N list the N first rows of data)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-b bruteforce)&lt;/span&gt;  =&gt; brute force mode using the default charset file&lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-len max passwd length for bruteforce)&lt;/span&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-char bruteforce charset file)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Important  Note:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Take care of the account lockout policy on Oracle Databases (this does not affect SYS account ...)&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Known Bugs or limitations:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;In bruteforce mode some JDBC drivers (JTDS) do not close properly the connection, it means that after some time you will reach the limit of the max open connection on your system.&lt;/li&gt;&lt;/ul&gt;TODO:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Implement a threadsafe print Queue&lt;/li&gt;&lt;li&gt;Add a regexp to extract credit card number (PCI compliance check)&lt;/li&gt;&lt;li&gt;write a nmap script to launch db-brutator once a known database service is found &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;Download:&lt;br /&gt;&lt;a href="https://launchpad.net/%7Ethr3atseek3r/+archive/ppa/+files/db-brutator_0.5.6.5.tar.gz"&gt;source&lt;/a&gt;&lt;br /&gt;&lt;a href="https://launchpad.net/%7Ethr3atseek3r/+archive/ppa/+files/db-brutator_0.5.6.5_i386.deb"&gt;debian  package&lt;/a&gt;&lt;br /&gt;&lt;a href="apt://db-brutator"&gt;package using repository&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Please leave comments/bugs and share if you write any improvement on it.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Enjoy Database scanning !!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4663920677497378824-5700290162351086821?l=h4ckingpalace.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://h4ckingpalace.blogspot.com/feeds/5700290162351086821/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://h4ckingpalace.blogspot.com/2010/04/db-brutator-multi-database-auditing.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4663920677497378824/posts/default/5700290162351086821'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4663920677497378824/posts/default/5700290162351086821'/><link rel='alternate' type='text/html' href='http://h4ckingpalace.blogspot.com/2010/04/db-brutator-multi-database-auditing.html' title='DB-BRUTATOR the Multi Database scanner/auditing tool !!'/><author><name>Thr3atSeek3r</name><uri>http://www.blogger.com/profile/15575590367184591309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_SKhtWqdaYqM/S9riyqZNNwI/AAAAAAAAABU/7N5Ff318HgA/s72-c/screen.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4663920677497378824.post-3842538845377702855</id><published>2009-01-02T18:22:00.015+01:00</published><updated>2009-10-02T16:04:58.082+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='syn'/><category scheme='http://www.blogger.com/atom/ns#' term='scan'/><category scheme='http://www.blogger.com/atom/ns#' term='sinfp'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='perl'/><title type='text'>Syn 'N Destroy ! (Update new version)</title><content type='html'>It's time to introduce &lt;span style="font-weight: bold;"&gt;Synator &lt;/span&gt;a new Ultra Fast TCP Port Scanner based on the Syn Scan technique &lt;span style="font-style: italic;"&gt;(You have already guessed that by the name right ?)&lt;/span&gt;. It is very similar to Synscan (&lt;a href="http://www.bindshell.net/tools/synscan"&gt;http://www.bindshell.net/tools/synscan&lt;/a&gt;) but a lot easier to use and require no compilation, it uses the libraries from SinFP (&lt;a href="http://www.gomor.org/bin/view/Sinfp"&gt;http://www.gomor.org/bin/view/Sinfp&lt;/a&gt;) to handle all the low level network interaction.&lt;br /&gt;&lt;br /&gt;Why using it ? :&lt;br /&gt;&lt;br /&gt;Now why would you use this tool instead of the widely used &lt;span style="font-weight: bold;"&gt;nmap&lt;/span&gt; port scanner ?&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Because you don't like to wait &lt;/li&gt;&lt;li&gt;Because when nmap receives his acknowledgments a bit slowly (slow network or slow server) it reduces the scan speed (it takes sometime 10 minutes or more).&lt;/li&gt;&lt;li&gt;Because you have a huge IP range to scan and you want to be able to scan 65535 ports on all IP in a reasonable delay.&lt;/li&gt;&lt;/ol&gt;Features:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Simple &amp;amp; efficient design&lt;/li&gt;&lt;li&gt;Service identification using amap&lt;/li&gt;&lt;li&gt;Source Port option&lt;/li&gt;&lt;li&gt;Fast scan based on Nmap Top port&lt;/li&gt;&lt;li&gt;Fexible Slow scan to avoid scan detection (-d and -m option)&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Performances:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;On a good LAN network it takes approximately 2m30 sec to scan all open ports of a host.&lt;/li&gt;&lt;li&gt;On Internet it is quite variable but tends to  settle around 2 minutes (from 1m20 sec to 2m40) when using a high speed connection against a Fast server (ideal conditions ...).&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Online Help:&lt;br /&gt;&lt;br /&gt;Here is the help message when your launch the synator without any parameter&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);font-family:courier new;" &gt;&lt;/span&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;Usage: bin/Synator2v1.pl&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;[-h IP]&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;[-s tcp|udp]&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;[-f OutputFilename] &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-p Destination PortNumber)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-S Source PortNumber)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-b Service Banner Grabbing)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-c ShowClosedPort)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-d DelayInSeconds)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;(-m maxSynPacketBeforeDelay)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;Options -p support multiple value separated by ',' and '-' ie 21,80 or 1-100.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Important Note:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Using a hostname instead of an IP address is not supported yet (is it really useful ?)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Avoid scanning with a wifi card&lt;/li&gt;&lt;li&gt;Avoid using synator inside a Virtual Machine, there is a high performance drop !&lt;/li&gt;&lt;/ul&gt;Known Bugs or limitations:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Synator does not work with some wifi card like the WPN311, this is bug due to libdnet that is unable to get the network configuration from the card "addr_net: undef input".&lt;/li&gt;&lt;/ul&gt;TODO:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Perform DNS resolution when a hostname is given as IP&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Screenshots:&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_SKhtWqdaYqM/SWKQ92E38-I/AAAAAAAAAA0/3i3yxnTC3uE/s1600-h/screen.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 38px;" src="http://3.bp.blogspot.com/_SKhtWqdaYqM/SWKQ92E38-I/AAAAAAAAAA0/3i3yxnTC3uE/s320/screen.png" alt="" id="BLOGGER_PHOTO_ID_5287948304648762338" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;using supercat to colorize the log&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;Download:&lt;br /&gt;&lt;a href="https://launchpad.net/%7Ethr3atseek3r/+archive/ppa/+files/synator_0.5.tar.gz"&gt;source&lt;/a&gt;&lt;br /&gt;&lt;a href="https://launchpad.net/%7Ethr3atseek3r/+archive/ppa/+files/synator_0.5_i386.deb"&gt;debian package&lt;/a&gt;&lt;br /&gt;&lt;a href="apt://synator"&gt;package using repository&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4663920677497378824-3842538845377702855?l=h4ckingpalace.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://h4ckingpalace.blogspot.com/feeds/3842538845377702855/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://h4ckingpalace.blogspot.com/2009/01/syn-n-destroy.html#comment-form' title='2 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4663920677497378824/posts/default/3842538845377702855'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4663920677497378824/posts/default/3842538845377702855'/><link rel='alternate' type='text/html' href='http://h4ckingpalace.blogspot.com/2009/01/syn-n-destroy.html' title='Syn &apos;N Destroy ! (Update new version)'/><author><name>Thr3atSeek3r</name><uri>http://www.blogger.com/profile/15575590367184591309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_SKhtWqdaYqM/SWKQ92E38-I/AAAAAAAAAA0/3i3yxnTC3uE/s72-c/screen.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4663920677497378824.post-8529701951970571578</id><published>2009-01-02T17:46:00.003+01:00</published><updated>2009-01-02T17:59:06.172+01:00</updated><title type='text'>Introducing the Debian Repository</title><content type='html'>To use the Debian package from the repository just add theses 2 lines to your &lt;span style="font-weight: bold;"&gt;/etc/apt/sources.list&lt;/span&gt;&lt;br /&gt;&lt;pre style="border: 1px solid gray; padding: 0.3em;" id="sources-list-entries"&gt;deb &lt;a href="http://ppa.launchpad.net/thr3atseek3r/ubuntu"&gt;http://ppa.launchpad.net/thr3atseek3r/ubuntu&lt;/a&gt; &lt;span id="series-deb"&gt;hardy&lt;/span&gt; main&lt;br /&gt;deb-src &lt;a href="http://ppa.launchpad.net/thr3atseek3r/ubuntu"&gt;http://ppa.launchpad.net/thr3atseek3r/ubuntu&lt;/a&gt; &lt;span id="series-deb-src"&gt;hardy&lt;/span&gt; main&lt;/pre&gt;For those using a non Debian based system I recommend retrieving the source directly&lt;span style="font-style: italic;"&gt; &lt;/span&gt;using any HTTP client &lt;span style="font-style: italic;"&gt;(who's said &lt;span style="font-weight: bold;"&gt;wget&lt;/span&gt; ?). &lt;/span&gt;Once extracted the tools should be usable right away !&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;PS: Don't worry if you don't have Ubuntu hardy it will work anyway as long as your distro use &lt;span style="font-weight: bold;"&gt;debian packages&lt;/span&gt;. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4663920677497378824-8529701951970571578?l=h4ckingpalace.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://h4ckingpalace.blogspot.com/feeds/8529701951970571578/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://h4ckingpalace.blogspot.com/2009/01/introducing-debian-repository.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4663920677497378824/posts/default/8529701951970571578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4663920677497378824/posts/default/8529701951970571578'/><link rel='alternate' type='text/html' href='http://h4ckingpalace.blogspot.com/2009/01/introducing-debian-repository.html' title='Introducing the Debian Repository'/><author><name>Thr3atSeek3r</name><uri>http://www.blogger.com/profile/15575590367184591309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4663920677497378824.post-7977810701439114823</id><published>2009-01-02T17:09:00.007+01:00</published><updated>2009-01-02T17:44:53.125+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='debian'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='perl'/><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Searching for Threats ?</title><content type='html'>It's the first post on my new security blog, this blog focuses on the security tools I've been using during pentest or on those that I've written specifically for certain tasks.&lt;br /&gt;&lt;br /&gt;For all the tools I've made the &lt;span style="font-style: italic;"&gt;common features&lt;/span&gt; are:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;written in perl&lt;/li&gt;&lt;li&gt;few dependencies as possible&lt;/li&gt;&lt;li&gt;portability when possible&lt;br /&gt;&lt;/li&gt;&lt;li&gt;flexibility&lt;/li&gt;&lt;li&gt;preferred OS is Ubuntu Linux hardy but they should work on other Debian based distro as well (I'll make win32 version of some if there is a huge demand for this)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;a debian package and a repository are provided&lt;/li&gt;&lt;/ul&gt;If some of you wants to give an hand to improve the tools or to contribute to this site feel free to contact me.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4663920677497378824-7977810701439114823?l=h4ckingpalace.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://h4ckingpalace.blogspot.com/feeds/7977810701439114823/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://h4ckingpalace.blogspot.com/2009/01/seeking-for-threats.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4663920677497378824/posts/default/7977810701439114823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4663920677497378824/posts/default/7977810701439114823'/><link rel='alternate' type='text/html' href='http://h4ckingpalace.blogspot.com/2009/01/seeking-for-threats.html' title='Searching for Threats ?'/><author><name>Thr3atSeek3r</name><uri>http://www.blogger.com/profile/15575590367184591309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
