Spectrum Networks Solutions Pvt Ltd
Details of the Information Security Audit Tools
Freeware Tools
- Achilles - A tool designed for testing the security of web applications
- ADMFtp, ADMSnmp - Tools for remote brute-forcing
- Brutus- An Windows GUI brute-force tool for FTP, telnet, POP3, SMB, HTTP, etc
- Crack - A password cracker
- CrypTool - A cryptanalysis utility
- Curl - Curl is a tool for transferring files with URL syntax, supporting FTP, FTPS, HTTP, HTTPS, GOPHER, TELNET, DICT, FILE and LDAP
- Different network mapping tools - ping, traceroute, whois, snmp tools, dig, nslookup, DNS tools etc
- Elza - A family of tools for arbitrary HTTP communication with picky web sites for the purpose of penetration testing and information gathering
- Exploits - publicly available and home made exploit code for the different vulnerabilities around
- FScan - A command-line port scanner. Supports TCP and UDP
- Fragrouter - Utility that allows to fragment packets in funny ways
- HPing - HPing is a command-line oriented TCP/IP packet assembler/analyzer. It supports TCP, UDP, ICMP and RAW-IP protocols, has a traceroute mode, the ability to send files between a covered channel, and many other features.
- ISNprober - Check an IP address for load-balancing.
- ICMPush - ICMPush is a tool that sends ICMP packets fully customized from command line
- John The Ripper - A password cracker
- L0phtcrack - NTLM/Lanman password auditing and recovery application (read: cracker)
- Nessus - A free, powerful, up-to-date and easy to use remote security scanner. This tool could be used when scanning a large range of IP addresses, or to verify the results of manual work.
- Netcat - The swiss army knife of network tools. A simple utility which reads and writes data across network connections, using TCP or UDP protocol
- NMAP - The best known port scanner around.
- p0f - Passive OS Fingerprinting: A tool that listens on the network and tries to identify the OS versions from the information in the packets.
- Pwdump - Tools that grab the hashes out of the SAM database, to use with a brute-forcer like L0phtcrack or John
- SamSpade - Graphical tool that allows to perform different network queries: ping, nslookup, whois, IP block whois, dig, traceroute, finger, SMTP VRFY, web browser keep-alive, DNS zone transfer, SMTP relay check,etc.
- ScanDNS - Script that scans a range of IP addresses to find DNS names
- Scripts - A number of custom developed scripts to test different security issues.
- Sing - Send ICMP Nasty Garbage. A little tool that sends ICMP packets fully customized from command line
- SSLProxy, STunnel - Tools that allow to run non SSL-aware tools/programs over SSL.
- Strobe - A command-line port scanner that also performs banner grabbing
- Telesweep Secure - A commercial wardialer that also does fingerprinting and brute-forcing.
- THC - A freeware wardialer
- TCPdump - A packet sniffer
- TCPtraceroute - Traceroute over TCP
- UCD-Snmp - (aka NET-Snmp): Various tools relating to the Simple Network Management Protocol including snmpget, snmpwalk and snmpset.
- Web Session Editor - Custom made utility that allows to intercept and edit HTTP sessions.
- Webinspect - CGI scanning, web crawling, etc.
- Webreaper, wget - Software that mirrors websites to your hard disk
- Whisker - The most famous CGI scanner. has updated the scanning databases with checks for the latest vulnerabilities.
Commercial Tools
Proprietary Tools