Showing posts with label Pentesting. Show all posts
Showing posts with label Pentesting. Show all posts

Tuesday, November 1, 2011

Online Sqli scanners

All these sites perform SQLI scan and give output in same window. Which then needs to be read and identify the vulnerability in output. To use these sites we need to have some knowledge about Sql Injection and techniques.
  1. http://www.be007.gigfa.com/scanner/scanner.php
  2. http://scanner.drie88.tk/
  3. http://localvn.biz/Tools/tools/Hack-Shop/SQLI-Scan
  4. http://wolfscps.com/gscanner.php

Monday, October 31, 2011

windows NTLM password cracking using john the ripper

The following vedio shows the grabbing NTLM files from Memory Dump and cracking them with John the ripper


Sunday, April 24, 2011

what is the pentesting ???


Penetration testing, often called “pentesting”,“pen testing”, or “security testing”, is the practice of attacking your own or your clients’ IT systems in the same way a hacker would to identify security holes. Of course, you do this without actually harming the network. The person carrying out a penetration test is called a penetration tester or pentester.
Let’s make one thing crystal clear: Penetration testing requires that you get permission from the person who owns the system. Otherwise, you would be hacking the system, which is illegal in most countries – 
In other words: The difference between penetration testing and hacking is whether you have the system owner’s permission. If you want to do a penetration test on someone else’s system, we highly recommend that you get written permission. In this case, asking first is definitely better than apologizing later!
You can become a penetration tester at home by testing your own server and later make a career out of it.

Twitter Delicious Facebook Digg Stumbleupon Favorites More

 
Design by Vamshi krishnam raju | Bloggerized by Vamshi krishnam raju - Vamshi krishnam raju | Vamshi krishnam raju