SSA is based upon the Open Vulnerability and Assessment Language (OVALâ„¢) is an international, information security, community standard to promote open and publicly available security content, and to standardize the transfer of this information across the entire spectrum of security tools and services. OVAL includes a language used to encode system details, and an assortment of content repositories held throughout the community.
(*) Changelog
1.5 Final Release : NOW SSA Security System (...)
Home > Security Tools
Security Tools
-
SSA Security System Analyzer version 1.5 Final is out
5 February 2007, by Tools Tracker Team -
SandCat Web Scanner 3.0.4 released
2 February 2007, by Tools Tracker TeamSandcat allows web administrators to perform aggressive and comprehensive scans of an organization’s web server to isolate vulnerabilities and identify security holes. The Sandcat scanner requires basic inputs such as host names, start URLs and port numbers to scan a complete web site and test all the web applications for security vulnerabilities.
Provides more than 30,000 security checks for all leading web server platforms a target server can be local or remote Scans for SANS Top Twenty (...) -
iWar Dialer with VoIP enabled capabilities
1 February 2007, by Tools Tracker TeamiWar is a "war dialer" written completely in C for Unix types of operating systems (Linux, FreeBSD, OpenBSD, etc). It is intended for legal phone security equipment auditing. Full and Normal logging: Full logging records all possible events during dialing (busy signals, no answers, carriers, etc). By default it only records things that we might find interesting (carriers, possible telco equipment). ASCII flat file and MySQL logging: You can log to a traditional ASCII flat file, and record (...)
-
OWASP Live CD Beta 0.10 RC1 available
1 February 2007, by Tools Tracker TeamThe OWASP Live CD (LabRat) is a bootable CD akin to knoppix but dedicated to Application Security. It shall serve as a vehicle and distrubition medium for OWASP tools and guides.
The RC1 version of the CD is now available for testing. The download can be found here: http://www.packetfocus.com/hackos/AOC_Labrat-ALPHA-0010.iso The latest version is v0.10 and is just around 800mb. This version has quite a few OWASP tools and documentation included. Have a look and email your ideas to (...) -
Sussen release 0.34 is available
29 January 2007, by Tools Tracker TeamSussen is a tool that checks for vulnerabilities and configuration issues on computer systems. It is based on the Open Vulnerability and Assessment Language.
ChangeLog
0.34 agent: Fixed crash when loading app.config in Mono 1.1.13.x applet: Save results to desktop if explict path not specified applet: Run as tray icon by default oval: Fixed incorrect behavior in variable handling oval: Increased debug information available oval: Make sure all tested objects are recorded in system (...) -
Saint Scanner 6.3.6 released
27 January 2007, by Tools Tracker TeamWith SAINT® vulnerability assessment tool, you can: Detect and fix possible weaknesses in your network’s security before they can be exploited by intruders. Anticipate and prevent common system vulnerabilities. Demonstrate compliance with current government regulations such as FISMA, Sarbanes Oxley, GLBA, HIPAA, and COPPA.
The SAINT® scanning engine is the ideal cornerstone for your vulnerability assessment program. SAINT features a graphical user interface that is intuitive and easy to use. (...) -
IKE Scan version 1.9 is out
25 January 2007, by Tools Tracker Teamike-scan is a command-line tool that uses the IKE protocol to discover, fingerprint and test IPsec VPN servers. It is available for Linux, Unix, MacOS and Windows under the GPL license
IKE Scan added to SD Security Tools Watch Process -
Snort version 2.6.1.2 released
23 January 2007, by Tools Tracker TeamSnort is a lightweight network intrusion detection system, capable of performing real-time traffic analysis and packet logging on IP networks. It can perform protocol analysis, content searching/matching and can be used to detect a variety of attacks and probes
such as buffer overflows, stealth port scans, CGI attacks, SMB probes, OS fingerprinting attempts, and much more. Snort uses a flexible rules language to describe traffic that it should collect or pass, as well as a detection engine (...) -
[Update] OWASP LiveCD LabRat Version 0.8 available
23 January 2007, by Tools Tracker TeamThe OWASP Live CD (LabRat) is a bootable CD akin to knoppix but dedicated to Application Security. It shall serve as a vehicle and distrubition medium for OWASP tools and guides.
OWASP LiveCD is ready to download. This distro is Beta Version 0.8 named "LabRat" and is part of the OWASP Autumn of Code sponsorship. The distro is focused on providing all of OWASP tools and documents on a bootable CD. The goal is to have a portable distro that can be used by professional penetration (...) -
Paros Proxy v.3.2.13 added to SD Security Tools Watch Process
23 January 2007, by Tools Tracker TeamParos Proxy is a Java application that can not only monitor and capture all HTTP and HTTPS data passing between servers and clients, it can also track cookies and form fields and allows you to modify and resend individual requests. It also supports proxy-chaining, filtering and performs intelligent vulnerability scanning
Paros is for application auditing what is netcat for network. A good swissarmy knife. You can almost do anything (almost..) with this piece of software.
Some functions : (...)