Sinisterly
Building my own pentest distro - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: General (https://sinister.li/Forum-General)
+--- Forum: The Lounge (https://sinister.li/Forum-The-Lounge)
+--- Thread: Building my own pentest distro (/Thread-Building-my-own-pentest-distro)

Pages: 1 2 3 4 5 6


RE: Building my own pentest distro - RogueCoder - 05-31-2013

(05-31-2013, 09:09 PM)noize Wrote:
(05-31-2013, 08:32 PM)shp0ngl3 Wrote:
(05-31-2013, 08:01 PM)noize Wrote: I'd suggest for adding:
- hping;
- Python;
- Perl;
- SciTE.

Nice! Never heard about hping and SciTE. Thanks for the heads up on those Smile Python and Perl is preinstalled in Sabayon SpinBase Smile

Really? Then, how about Burp? I wouldn't preinstall that, but that's on the other side a nice and pretty popular tool. If you choose to take it in, maybe you should take away a couple of tools that Burp Suite can replace, but let me say again that I myself wouldn't add Burp.

Also, I'd take away a couple of scanners, ain't that a bit too much?

For the Firefox addons, consider Fireforce too.

P.S: then how about Lua? And is GIMP already installed?

S.P.S: xmonad is another great windows manager.

Yeah really Smile Burp I've used quite a bit, why wouldn't you add it? What tools would you remove that Burp (free version) can replace?

I'll look into Fireforce. Lua is what awasome wm uses for configuration Smile

(05-31-2013, 09:20 PM)Linuxephus™ Wrote:
(05-31-2013, 06:14 PM)shp0ngl3 Wrote: Yeah. They are good assets when performing penetration tests where a website is a part of the attack surface.. "pentesting plugins" might be more correct? Smile

LOLing...negative, Pentesting Tools is more than adequate mate.:lol:

:lol: ok. I'm still fairly new to all this hacking stuff Smile started in january this year so I try to step a bit carefully still Smile


RE: Building my own pentest distro - RogueCoder - 06-01-2013

@noize I tried hping and for some reason I get 100% packet loss, when I get 0% using regular ping..


RE: Building my own pentest distro - noize - 06-01-2013

(06-01-2013, 08:56 AM)shp0ngl3 Wrote: @noize I tried hping and for some reason I get 100% packet loss, when I get 0% using regular ping..

Well, a filtered port should report 100% packet loss. Might it be the case? I think of hping as a basic DoSer that I would give as default in my own pentesting distro (Backtrack's got hping too).



Quote:Yeah really Smile Burp I've used quite a bit, why wouldn't you add it? What tools would you remove that Burp (free version) can replace?

I'll look into Fireforce. Lua is what awasome wm uses for configuration Smile

Lua is fucking cool. Biggrin

To be honest I'm not sure of what I would remove with the entry of Burp, I should think about that. However, mainly, I don't really like Burp. That's a lot of noize for what it can really do. That's also unpratical and not very useful, but that's just my point of view.

Quote::lol: ok. I'm still fairly new to all this hacking stuff Smile started in january this year so I try to step a bit carefully still Smile

I'm new too. I started programming in January and hacking with ready-made software a few months ago (maybe February, March...), so that's no excuse. Biggrin


RE: Building my own pentest distro - RogueCoder - 06-01-2013

(06-01-2013, 10:49 AM)noize Wrote:
(06-01-2013, 08:56 AM)shp0ngl3 Wrote: @noize I tried hping and for some reason I get 100% packet loss, when I get 0% using regular ping..

Well, a filtered port should report 100% packet loss. Might it be the case? I think of hping as a basic DoSer that I would give as default in my own pentesting distro (Backtrack's got hping too).

I'm gonna tinker a bit more with it Smile Might be just that I'm missing some stuff Smile

Quote:
Quote:Yeah really Smile Burp I've used quite a bit, why wouldn't you add it? What tools would you remove that Burp (free version) can replace?

I'll look into Fireforce. Lua is what awasome wm uses for configuration Smile

Lua is fucking cool. Biggrin

To be honest I'm not sure of what I would remove with the entry of Burp, I should think about that. However, mainly, I don't really like Burp. That's a lot of noize for what it can really do. That's also unpratical and not very useful, but that's just my point of view.

I see Smile I found Burp Suite really handy. I used that more than addons really. Guess it comes down to personal preference really

Quote:
Quote::lol: ok. I'm still fairly new to all this hacking stuff Smile started in january this year so I try to step a bit carefully still Smile

I'm new too. I started programming in January and hacking with ready-made software a few months ago (maybe February, March...), so that's no excuse. Biggrin

It wasn't meant as an excuse for not knowing about hping or SciTE Smile Was a response to Linuxephus™ questioning the "firefox pentest tools" where I asked if "addons" was a more appropriate term to use Wink


RE: Building my own pentest distro - noize - 06-01-2013

(06-01-2013, 03:31 PM)shp0ngl3 Wrote: It wasn't meant as an excuse for not knowing about hping or SciTE Smile Was a response to Linuxephus™ questioning the "firefox pentest tools" where I asked if "addons" was a more appropriate term to use Wink

It wasn't meant as an offense. :angel:

So, you're saying hping gives packet loss while port is not filtered?


RE: Building my own pentest distro - RogueCoder - 06-01-2013

(06-01-2013, 03:56 PM)noize Wrote:
(06-01-2013, 03:31 PM)shp0ngl3 Wrote: It wasn't meant as an excuse for not knowing about hping or SciTE Smile Was a response to Linuxephus™ questioning the "firefox pentest tools" where I asked if "addons" was a more appropriate term to use Wink

It wasn't meant as an offense. :angel:

So, you're saying hping gives packet loss while port is not filtered?

Wasn't taken as an offense Wink

Shoot me if I'm far out on this :whistle: but when I do
Code:
hping -V --scan 80 oleaass.com
I get "Not responding ports: (80 http)"


RE: Building my own pentest distro - noize - 06-01-2013

(06-01-2013, 06:15 PM)shp0ngl3 Wrote: Wasn't taken as an offense Wink

Shoot me if I'm far out on this :whistle: but when I do
Code:
hping -V --scan 80 oleaass.com
I get "Not responding ports: (80 http)"

How about "hping oleaass.com -p 80 -V" ?

P.S: the above should work with hping2, think should work for hping too.


RE: Building my own pentest distro - RogueCoder - 06-01-2013

(06-01-2013, 10:19 PM)noize Wrote:
(06-01-2013, 06:15 PM)shp0ngl3 Wrote: Wasn't taken as an offense Wink

Shoot me if I'm far out on this :whistle: but when I do
Code:
hping -V --scan 80 oleaass.com
I get "Not responding ports: (80 http)"

How about "hping oleaass.com -p 80 -V" ?

P.S: the above should work with hping2, think should work for hping too.

That returned 100% packet loss, and using hping2 returned the same as hping


RE: Building my own pentest distro - noize - 06-01-2013

(06-01-2013, 10:36 PM)shp0ngl3 Wrote:
(06-01-2013, 10:19 PM)noize Wrote:
(06-01-2013, 06:15 PM)shp0ngl3 Wrote: Wasn't taken as an offense Wink

Shoot me if I'm far out on this :whistle: but when I do
Code:
hping -V --scan 80 oleaass.com
I get "Not responding ports: (80 http)"

How about "hping oleaass.com -p 80 -V" ?

P.S: the above should work with hping2, think should work for hping too.

That returned 100% packet loss, and using hping2 returned the same as hping

That's weird to me. Try with a different protocol:

Code:
hping2 www.oleaass.com --udp -p 80



RE: Building my own pentest distro - RogueCoder - 06-01-2013

That returned
Code:
74 packets tramitted, 8 packets received, 90% packet loss
tried without --udp
Code:
149 packets tramitted, 0 packets received, 100% packet loss
Smile