Monday, August 25, 2008

Tools of the Trade - Johari Window Edition

A Johari window is a cognitive psychological tool created by Joseph Luft and Harry Ingham in 1955 in the United States, used to help people better understand their interpersonal communication and relationships. It is used primarily in self-help groups and corporate settings as a heuristic exercise.

---------------------

The Blind Spot quadrant has always interested me....

On to the tools...

On August 25th, CCleaner 2.11.636 was released. CCleaner is a freeware system optimization and privacy tool. It removes unused and temporary files from your system - allowing Windows to run faster, more efficiently and giving you more hard disk space. Check the version history for all the change details.

On August 25th, Carnegie-Mellon's School of Computer Science and College of Engineering released Perspectives, a Mozilla Firefox 3 Extension. Perspectives is a new approach to help clients securely identify Internet servers in order to avoid "man-in-the-middle" attacks. Perspectives is simple and cheap compared to existing approaches because it automatically builds a robust database of network identities using lightweight network probing by "network notaries" located in multiple vantage points across the Internet.

On August 23rd, CDBurnerXP 4.2.1.919 was released. CDBurnerXP is a free application to burn CDs and DVDs, including Blu-Ray and HD-DVDs. This release is primarily bug fixes.

On August 22nd, Microsoft and Mark Russinovich released AutoRuns v9.33. Autoruns shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them. These programs include ones in your startup folder, Run, RunOnce, and other Registry keys. A "show non-Microsoft only" option helps you to zoom in on third-party auto-starting images that have been added to your system.

On August 22nd, Tor 0.2.30 was released. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy.

On August 20th, OWASP DirBuster 0.11.1 was released. DirBuster is a multi threaded java application designed to brute force directories and files names on web/application servers. DirBuster comes a total of 9 different wordlists, this makes DirBuster extremely effective at finding those hidden files and directories.

On August 20th, David Byrne released Grendel v1.0. Grendel-Scan is an open-source web application security testing tool. It has automated testing module for detecting common web application vulnerabilities, and features geared at aiding manual penetration tests. This tool was originally released at Defcon 16 - see accompanying presentation materials. Next the release notes for all the change details.

On August 19th, Pidgin 2.5.0 was released. Pidgin is a multi-protocol Instant Messaging client that allows you to use all of your IM accounts at once. Pidgin is licensed under the GNU General Public License (GPL) version 2. Check out the news section for the change details.

On August 14th, KeePass 1.12 was released. KeePass is a free/open-source password manager or safe which helps you to manage your passwords in a secure way. You can put all your passwords in one database, which is locked with one master key or a key-disk. Check out the release notes for all the change details.

On August 12th, Sandro Gauci released Surf Jack 1.0 during Defcon 16. A tool which allows one to hijack HTTP connections to steal cookies - even ones on HTTPS sites. Works on both Wifi (monitor mode) and Ethernet. The proof of concept tool allows testers to steal session cookies on HTTP and HTTPS sites that do not set the Cookie secure flag.

On August 12th, FileZilla 3.1.11 was released. FileZilla is a powerful FTP-client for Windows NT4, 2000 and XP. It has been designed for ease of use and with support for as many features as possible, while still being fast and reliable.

On August 10th, 757 Labs released PDFResurrect v0.04. PDFResurrect is a tool aimed at analyzing PDF documents. This tool attempts to extract all previous versions while also producing a summary of changes between versions. This tool can also "scrub" or write data over the original instances of PDF objects that have been modified or deleted, in an effort to disguise information from previous versions that might not be intended for anyone else to read. Check out the following whitepaper - Faith in the Format: Unintentional Data Hiding in PDFs.

On July 18th, Solar Designer release John the Ripper 1.7.3.1. John the Ripper is a fast password cracker, currently available for many flavors of Unix, DOS, Win32, and BeOS. Its primary purpose is to detect weak Unix passwords, but a number of other hash types are supported as well. This version corrected the x86 assembly files for building on Mac OS X and merged in some generic changes from JtR Pro.

On July 17th, Irfan Skiljan released IrfanView 4.20. IrfanView is a very fast, small, compact and innovative FREEWARE (for non-commercial use) graphic viewer for Windows 9x/ME/NT/2000/XP/2003/Vista. This is the first updated version he has released in 2008 (v4.10 was released on 10/2007). Check out the changelog for all the details.

On July 13th, WinSCP 4.1.5 was released. WinSCP is an open source free SFTP client and FTP client for Windows. Legacy SCP protocol is also supported. Its main function is safe copying of files between a local and a remote computer. WinSCP has been nominated for 2008 SourceForge.net Community Choice Awards in category Best Tool or Utility for SysAdmins. Check the history file for all the details.

On July 10th, Gmail Drive 1.0.13 was released. GMail Drive is a Shell Namespace Extension that creates a virtual filesystem around your Google Gmail account, allowing you to use Gmail as a storage medium. This new version was released since some users complained that they had problems with login.

No comments:

Post a Comment