Friday, January 9, 2009

Tools of the Trade - 4002 Edition

Hey everyone, Technocrat here. Things have been super crazy around my parts, so I didn't even notice that this is post number 4002. I totally missed the 4000 milestone...o'well. Also, I never did get a chance to wish everyone happy holidays....so happy holidays!

It may be a new year, but the security threats facing all of us are still as real as they were 10 days ago. It is important we move into this new year with a renewed sense of vigilance, purpose and resolve.

I would like to personally thank all my readers and visitors for all your continue support. This blog might be managed by me, but I do it for you guys. I would like to wish everyone a happy near year and may peace be with you in the coming year.

With that being said....on the tools

---------------------------

As always, Jeremy Brown is releasing fuzzers like a mad man over @ his blog. He has released VNC fuzzers, JPEG fuzzers, SSH fuzzers, CVS fuzzers, RSH fuzzers...the list goes on and on. Keep it up Jeremy.

On Jan 9th, Samir Vaidya released OpenStego 0.5.1. OpenStego is a tool implemented in Java for generic steganography, with support for password-based encryption of the data. It supports plugins for various steganographic algorithms (currently, only Least Significant Bit algorithm is supported for images).

On Jan 7th, Filezilla 3.2.0 was released. FileZilla is a fast and reliable FTP client and server with lots of useful features and an intuitive interface.

On Jan 5th, Adam Laurie released RFIDIOt 0.1v. RFIDIOt is a python library for exploring RFID devices. It currently drives a couple of RFID readers made by ACG, called the HF Dual ISO and the LFX. Includes sample programs to read/write tags and the beginnings of library routines to handle the data structures of specific tags like MIFARE(r).

On Jan 5th, Cain & Abel v4.9.26 was released. Cain & Abel is a 'password recovery tool' which can provide easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords and analyzing routing protocols. This new version adds support for Licensing Mode Terminal Server connections in APR-RDP sniffer filter.

On Jan 3rd, 7-Zip 4.64 was released. 7-Zip is an open source file archiver predominantly for the Microsoft Windows operating system. Check out the history file for all the change details.

On Jan 1st, Foxit Reader 3.0.1301 was released. Foxit Reader is a free PDF document viewer and printer, with incredible small size (only a few M download size), breezing-fast launch speed and rich feature set. Foxit Reader supports Windows Me/2000/XP/2003/Vista. Its core function is compatible with PDF Standard 1.7. Check the bug fix report for all the change details.

On Dec 31st, Márton Anka released SSL Blacklist v4.0.30. The SSL Blacklist is a Firefox extension which was originally created to flag weak SSL certificates which were generated using vulnerable version of Debain OpenSSL. But now, the tool has been updated to also detect certificate chains that use the MD5 algorithm for RSA signatures. An attack has been demonstrated yesterday that highlights the practicality of the well-publicized weaknesses of the MD5 algorithm. Essentially, any certificate signed with the MD5 algorithm may be counterfeit.

On Dec 30th, Irfan Skiljan released IrfanView v4.23. IrfanView is a very fast, small, compact and innovative Freeware (for non-commercial use) graphic viewer for Windows. I have been personally using this viewer for years...very small, very fast. Check out the changelog for all the change details.

On Dec 30th, Acri Emanuele (aka crossbower) released a collection of tools called Complemento v0.5. Complemento is a collection of tools that Acri originally grokked up for solving some problems or just for fun. LetDown is a TCP flooder written after reading the Fyodor article "TCP Resource Exhaustion and Botched Disclosure". Reverse raider is a domain scanner that uses brute force wordlist scanning for finding a target's subdomains or reverse resolution for a range of IPs. Httsquash is an HTTP server scanner, banner grabber, and data retriever. It can be used for scanning large ranges of IPs for finding devices or HTTP servers.

On Dec 22nd, CCleaner 2.15.815 was released. CCleaner is a freeware system optimization, privacy and cleaning tool. It removes unused files from your system - allowing Windows to run faster and freeing up valuable hard disk space. This version includes minor browser fixes and minor architecture improvements.

On Dec 22nd, Pidgin 2.5.3 was released. Pidgin is a GPL licensed multi-protocol Instant Messaging client that allows you to use all of your IM accounts at once.

On Dec 16th, Virtual Box 2.1.0 was released. VirtualBox is a family of powerful x86 virtualization products for enterprise as well as home use. Not only is VirtualBox an extremely feature rich, high performance product for enterprise customers, it is also the only professional solution that is freely available as Open Source Software under the terms of the GNU General Public License (GPL). Check the changelog for all the details.

On Dec 10th, Wireshark 1.05 was released.
Wireshark is the world's foremost network protocol analyzer, and is the de facto (and often de jure) standard across many industries and educational institutions. This version addresses some security-related bugs in the SMTP and WLCCP dissectors. See the advisory for details. Check out the release notes for all the change details.

No comments:

Post a Comment