NightLion Logo

Vega – My #1 Web Vulnerability Scanner for Mac OSX and Linux

January 16th, 2012

Vega has quickly become the first tool in my web vulnerability and pen testing arsenal. It’s fast and copiously comes up with more results than any other scanner I’ve come across. It’s also a free (open-source) tool, with a host of great features. It also runs sm on Mac OSX and Linux.

Wireless Security Tool Update: New EAPScan Features Check for WPS

January 13th, 2012

Due to the fact that WPS is an expanded EAP type, SecureState added support to the EAPScan tool of the EAPeak Suite to actively probe an access point to checkif WPS is enabled.

Guide to Installing Metasploit 4 and Armitage on Mac OSX Lion

December 26th, 2011

A quick step by step on installing the Metasploit 4 framework

Duqu exploits zero-day flaw in Windows kernel

November 2nd, 2011

The Duqu trojan infects systems by exploiting a previously unknown Windows kernel vulnerability that is remotely executable, security vendor Symantec said today.

Gather Intelligence from Google using these hand picked Google Dorks

October 15th, 2011

Google dorks can be defined as keywords in a Google search that dig out juicy information like usernames , passwords , documents files , databases etc. from websites (simple and to the point). These google dorks can also be used in Intelligence Gathering.

Prep for the CEH v7 exam: Tune your Web Hacking Skills with these Live Hackable Simulation Environments

October 11th, 2011

I am preparing for for my Certified Ethical Hacker (CEH) certification and have compiled a handful of really helpful ‘Live’ Simulations that you can practice hacking into. Some are webpages, others are virtual environments. I recomend checking these out, even if you’re in the security field and just want to sharpen your skills.

Test your Web Penetration Skills with Damn Vulnerable Web App

October 5th, 2011

Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, help web developers better understand the processes of securing web applications and aid teachers/students to teach/learn web application security in a class room environment.

Spoof your MAC address in OSX Lion and Snow Leopard – Quick 3 Step Guide.

September 15th, 2011

Great tutorial on how to spoof your mac address in Mac OSX. This works in Lion.

Metasploit Framework 4.0 Released!

August 1st, 2011

Metasploit encompasses every aspect of a penetration test. Dozens of auxiliary modules assist with reconnaissance, more than two hundred others help with information gathering and discovery; hundreds of exploits get you a toe-hold on the network; and the newest addition to the module family, post modules, help simplify and automate increasing your access.

XSS-Harvest: Harvesting Cross Site Scripting, Clicks, Keystrokes and Cookies

July 16th, 2011

To summarise, a successfully exploited XSS vulnerability will allow the interception of ALL keystrokes, ALL mouse actions, ALL cookies (unless protected by scope) on ALL pages of the affect domain, regardless of whether or not the vulnerability is “reflected” or “persistent”.XSS-Harvest is multi-threaded pre-forking web server written in Perl, and requires no dependencies other than a couple of common Perl modules; you do not need a web server or database to use this tool.

Social-Engineer Toolkit v1.5 Released – OSX Support Added

June 28th, 2011

The Social Engineering Toolkit (SET) is a python-driven suite of custom tools which solely focuses on attacking the human element of penetration testing. OSX support has now been added.

Cracking WEP Security Video Tutorials – Wireless Password Hacking

June 11th, 2011

A series of great video tutorial on cracking the WEP security protocol on wireless networks. Tutorials include methods using Windows 7 and Linux.

Creepy Tools for Social Engineers and Information Gathering

May 24th, 2011

Track any target’s GeoLocation from their tweets and social media.

The Social Engineering Toolkit (SET) 1.5 released

May 19th, 2011

The Social Engineering Toolkit (SET) is a python-driven suite of custom tools which solely focuses on attacking the human element of penetration testing. It’s main purpose is to augment and simulate social-engineering attacks and allow the tester to effectively test how a targeted attack may succeed.

Pangolin 3.2.3 – Automatic SQL injection penetration testing tool New Release !

April 30th, 2011

Pangolin is an automatic SQL injection penetration testing (Pen-testing) tool for Website manager or IT Security analyst.

Live Hacking DVD v1.3 Beta – Download !

April 29th, 2011

Live Hacking DVD is a new Linux distribution packed with tools and utilities for ethical hacking, penetration testing and countermeasure verification. Based on Ubuntu this ‘Live CD’ runs directly from the DVD and doesn’t require installation on your hard-drive.

The 007 Super Virus That Crippled Iran’s Nuclear Weapons Ambitions

January 3rd, 2011

The mission: Infiltrate the highly advanced, securely guarded enemy headquarters where scientists in the clutches of an evil master are secretly building a weapon that can destroy the world. Then render that weapon harmless and escape undetected.

How To Mass Export All Of Your Facebook Friends’ Private Email Addresses

November 12th, 2010

Simple tutorial to download all of your Facebook friends’ private email addresses.

Mass SQL Injection Attack Hits Sites Running IIS

June 26th, 2010

Mass SQL Injection Attack Hits Sites Running IIS: “Trailrunner7 writes ‘There’s a large-scale attack underway that is targeting Web servers running Microsoft’s IIS software, injecting the sites with a specific malicious script. The attack has compromised tens of thousands of sites already, experts say, and there’s no clear indication of who’s behind the campaign right [...]

Get Adobe Flash playerPlugin by wpburn.com wordpress themes