AAA Technologies Pvt Ltd, Mumbai

 

Details of the Audit Tools

Freeware :

  1. Nessus
  2. Whisker
  3. HUNT - TCP/IP protocol vulnerability exploiter, packet injector
  4. DOMTOOLS - DNS-interrogation tools
  5. SARA - Vulnerability scanner
  6. RAT
  7. Nikto - This tool scans for web-application vulnerabilities
  8. Snort - IDS
  9. Firewalk - Traceroute-like ACL & network inspection/mapping
  10. Hping – TCP ping utilitiy Dsniff - Passively monitor a network for interesting data (passwords, e-mail, files, etc.). facilitate the interception of network traffic normally unavailable to an attacker
  11. HTTrack - Website Copier
  12. Chkrootkit - Rootkit discovery tool
  13. Tools from FoundStone - Variety of free security-tools
  14. SQL Tools - MS SQL related tools
  15. John the Ripper - Password-cracking utility
  16. ITS4 - Scan C/C++ source-code for vulnerabilities
  17. Paros
  18. NMAP - The famous port-scanner
  19. Ethereal - GUI for packet sniffing. Can analyse tcpdump-compatible logs
  20. Nemesis - Packet injection suite
  21. NetCat - Swiss Army-knife, very useful
  22. RAT – CISecurity’s Router Auditing Tool
  23. DSniff - A collection of different purpose sniffers
  24. Achilles - An SSL-proxy allowing to change data
  25. Whitehats - Snort IDS-signatures & other resources
  26. Hping2 - TCP/IP packet analyzer/assembler, packet forgery, useful for ACL inspection
  27. Brutus – password cracking for web applications, telnet, etc.
  28. WebSleuth - web-app auditing tool
  29. Mieliekoek - SQL Injection tool, use with HTTrack
  30. NT Toolbox - Resources & tools for NT
  31. @Stake Tools - Tools provided by @-Stake
  32. TSCrack - Wordlist-based Terminal Server login-cracker L0phtcrack - NT-password cracking utility
  33. HTTPrint – detect web server and version
  34. Web proxy - web application testing
  35. Web server vulnerability assessment tool

Commercial :

None

Proprietary :

  1. AAA - Used for Finger Printing and identifying open ports, services and misconfiguration