Pages

Your IP

Your IP
your IP

Sunday

Zimperium Finally Releases 'Anti' For Android, Allows You To Use Penetration Testing Tools On The Go

The days where penetration testers carry around laptops with them to test the security of networks seem to be numbered, with Zimperium's 'Anti' bringing a lot of those tools over from the PC to Android smartphones.

It's been a long time coming, but Anti is now available to download to your phone for free from the Zimperium website. For some strange reason, you will have to install 'AntiCredit' from the Android Market in order to actually use the application effectively by buying credits, meaning that you will have two apps which, essentially, perform the same function.

After you have downloaded and installed Anti from the web (you will first need to enable the installation of 3rd party applications by going to Settings > Applications > Unknown sources), you are prompted to buy AntiCredits in order to actually use many of the features within the app. Once you have downloaded it separately, you can then choose from three tiered plans.
Buying silver credits will allow you to use man-in-the-middle as well as remote exploits. This pack comes with 20 credits (with one credit being used for each exploit) and will put you back $10. If you to choose to upgrade to gold credits, it will cost you $50, and for that you will be able to access additional server cracking dictionaries and use less crowded servers than members using silver. With gold, you will be able to use 150 credits.

anti android local anti device menu

srgn-InfoGather

One of my old tools which helps for initials steps of Information Gathering. Basic, it works with dig, whois and nmap scan results. Unfortunately, it’s not really user-friendly and not documented. I’ve already coded the basic structure of new information gathering tool, however still needs a looot of work.

WebSurgery v0.6a

WebSurgery is a suite of tools for security testing of web applications. It was designed for security auditors to help them with the web application planning and exploitation. Currently, it uses an efficient, fast and stable Web Crawler, File/Dir Brute forcer, Fuzzer for advanced exploitation of known and unusual vulnerabilities such as SQL Injections, Cross site scripting (XSS), Brute force for login forms, identification of firewall-filtered rules, DOS Attacks and WEB Proxy to analyze, intercept and manipulate the traffic between your browser and the target web application.



DROIDSHEEP

GET IT!

Google removed DroidSheep from the Android Market. So the only way to get it is actually to download it from here.
Changelog for v14:
- Added username resolution for facebook, linkedin, twitter, flickr and yahoo
- Showing IP of the victims device
- Some bugfixes
- New Languages available: polish, bulgarian, croatian, french and german
- Update notification for future versions of DroidSheep
In case you have problems when installing the new version (Android saying “not installed”, please uninstall the old version manually and download the new one!)