Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] Hellsing |
|---|---|
| Date: | Fri, 28 Dec 2007 04:20:43 -0500 (EST) |
I was looking through my Projects/ folder earlier today and found this discarded piece of work. I vamped it up a little bit and decided to post it in my blog (socialnetworkwhore.com) as well as here. It still has a few things busted (like ssl only works with non self signed certificates), but it gets the job done. Now on to an explanation... Hellsing is a web attack application utility which uses a configuration file to define your attack methods. It supports cookies, ssl, post and get methods. It uses format strings to build useful attack patterns. Example Usage: ./hellsing -c hellsing.conf -t 1 -k 127.0.0.l -v www.localhost -x /index.php -f 't:123;c:/bin/ls' -o This tells hellsing to attack the ip 127.0.0.1 over ssl (-o flag; defaults to port 80; 443 for ssl) and target the virtual host www.localhost. The target app is index.php and the module to be used is 1 (see -l for all modules). Arguments to the module are t and f, each with the respective values of 123 and /bin/ls. I left a few web app vulns in the config file to give you examples to play with. You can do a few more things like encoding (see -e) and selective output buffering (see -s). Oh one other thing, it sends lots of headers. when I wrote it, I wanted it to emulate the headers firefox sent in a generic http get request. Anyhow have a good one. - Ben
hellsing-0.2.tar.gz
Description: application/gzip
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] OpenBiblio 0.5.2-pre4 and prior multiple vulnerabilities, Juan Galiana |
|---|---|
| Next by Date: | [Full-disclosure] Troy Riser, Clifton Bennett |
| Previous by Thread: | [Full-disclosure] OpenBiblio 0.5.2-pre4 and prior multiple vulnerabilities, Juan Galiana |
| Next by Thread: | [Full-disclosure] Troy Riser, Clifton Bennett |
| Indexes: | [Date] [Thread] [Top] [All Lists] |