![]() |
|
Building my own pentest distro - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: General (https://sinister.li/Forum-General) +--- Forum: The Lounge (https://sinister.li/Forum-The-Lounge) +--- Thread: Building my own pentest distro (/Thread-Building-my-own-pentest-distro) |
RE: Building my own pentest distro - RogueCoder - 05-31-2013 -- Update -- Ok, so I made my decision on the window manager, and landed on AwesomeWM Why? Well.. It's awesome ![]() Now I'm working on the tools I should install on it, and I've come up with this list so far - Leafpap - Truecrypt - Tor & Tor Browser - Firefox (with pentest tools) - apache - php - mysql - postgresql - sqlmap - metasploit - wpcan - joomscan - ripe - nmap - hydra - xhydra - aircrack-ng - recon-ng - dirbuster - wireshark - spiderfoot - fern wifi cracker - set (social engineering toolkit) - maltego - netcat - hashcat - john - owasp zed attack proxy (zap) - subterfuge I've got the tools I've used most so far. Any suggestions on missing tools?
RE: Building my own pentest distro - Linuxephus™ - 05-31-2013 (05-31-2013, 08:28 AM)LukeMST Wrote: You can try openbox too I believe that was one of quite a few already made mention of in several links I provided.:lol: (05-31-2013, 12:18 PM)shp0ngl3 Wrote: -- Update -- Looking good so far brother. And I didn't know Firefox had pentesting tools worth mentioning. RE: Building my own pentest distro - RogueCoder - 05-31-2013 (05-31-2013, 05:49 PM)Linuxephus™ Wrote: Looking good so far brother. They have some very handy plugins for different tasks like Tamper Data, XSS me, SQLi me, and many more ![]() Here's a good collection of tools to choose from ![]() https://addons.mozilla.org/en-US/firefox/collections/adammuntner/webappsec/ --- Edit --- What I'm doing atm I think is the hardest part of this project actually Coming up with a name for the project I hate naming stuff. I always get stuck on completely retarded stuff.. At one point I was actually thinking about naming it Hack Community OS iSec, Forensec, HackIt and Ethack are also some I've been considering.. Guess I'll just go and play some Black Ops 2 for a while, see if something decent appears
RE: Building my own pentest distro - Linuxephus™ - 05-31-2013 Those are what you're listing as "pentesting tools". Understood. I'm already quite familiar with those plugins. My apologies accordingly. Meanwhile, I must be off elsewhere for Moderating tasks and then the continuation of a good conversation with two of our other fellow Members. Shalom. RE: Building my own pentest distro - RogueCoder - 05-31-2013 (05-31-2013, 06:10 PM)Linuxephus™ Wrote: Those are what you're listing as "pentesting tools". Yeah. They are good assets when performing penetration tests where a website is a part of the attack surface.. "pentesting plugins" might be more correct?
RE: Building my own pentest distro - noize - 05-31-2013 I'd suggest for adding: - hping; - Python; - Perl; - SciTE. RE: Building my own pentest distro - noize - 05-31-2013 I'd suggest for adding: - hping; - Python; - Perl; - SciTE. RE: Building my own pentest distro - RogueCoder - 05-31-2013 (05-31-2013, 08:01 PM)noize Wrote: I'd suggest for adding: Nice! Never heard about hping and SciTE. Thanks for the heads up on those Python and Perl is preinstalled in Sabayon SpinBase
RE: Building my own pentest distro - noize - 05-31-2013 (05-31-2013, 08:32 PM)shp0ngl3 Wrote:(05-31-2013, 08:01 PM)noize Wrote: I'd suggest for adding: Really? Then, how about Burp? I wouldn't preinstall that, but that's on the other side a nice and pretty popular tool. If you choose to take it in, maybe you should take away a couple of tools that Burp Suite can replace, but let me say again that I myself wouldn't add Burp. Also, I'd take away a couple of scanners, ain't that a bit too much? For the Firefox addons, consider Fireforce too. P.S: then how about Lua? And is GIMP already installed? S.P.S: xmonad is another great windows manager. RE: Building my own pentest distro - Linuxephus™ - 05-31-2013 (05-31-2013, 06:14 PM)shp0ngl3 Wrote: Yeah. They are good assets when performing penetration tests where a website is a part of the attack surface.. "pentesting plugins" might be more correct? LOLing...negative, Pentesting Tools is more than adequate mate.:lol: |