Tools & Utilities

Get a JAVA capable browser damnit!!!

Unix Sources                    

balu.pl - Mirc 5.5 'DCC Server' pathbug(balu) tool
killport.c - this program will kill a random port on a linux machine
lpstat.x86.c - lpstat sploit for solaris 2.6/2.7
breezecom.txt - BreezeCOM Wireless LAN products have hardcoded backdoor passwords and other TFTP and SNMP issus
calserver.txt - exploit for SCO OpenServer Enterprise System v 5.0.4p calserver, local/remote
xcrack.pl - UNIX password cracker, perl script (used with wordlist.pl.)
wordlist.pl - Wordlist generator, perl script
pron.c - pr0n clicker 1.0 - Given a list of WinGate servers this program will generate click throughs on banner ad networks.
rst_flip.c - Allows you to reset active TCP connections under Linux.
nsreaddir.txt - Netscape Communicator 4.5 can read local files
infofun.txt - AIX infod exploit - Based on RSI.0011.11-09-98.AIX.INFOD.
lrk4.tgz - Linux RootKit IV. Now includes modified versions of pidof/killall, find, crontab, linsniffer, sniffchk, and other updates
iparty.txt - iParty audio/text chat program for Windows DoS.
hunt-1.0.tgz - Linux TCP session hijacking software.
ews11.txt - Security bugs in Excite for Web Servers 1.1
klogd.txt - Linux klogd 1.3-22 buffer overflow.
smad.c - Sendmail DoS for systems running Linux with an accept() bug
freebsdfrag.txt - FreeBSD-SA-98:08.fragment
apcpowernet.txt - APC PowerNet SNMP Denial of Service
shits.c - Kill almost any process in (RedHat 5.1) Linux without root
sshkerb.txt - SSH 1.2.26 contains a buffer overflow in its client kerberos code.
dtap2.txt - Solaris 2.6 /usr/dt/bin/dtappgather still contains a security hole.
jidentd.txt - jidentd and other identd daemons contain several bugs
osicom.txt - Osicom Technologies ROUTERmate products contain several security holes.
ichat3.txt - iChat 3.0 and below allow remote users to read abritrary files.
wwwthreads.txt - wwwthreads Discussion Forum has several security holes.
conseal.txt - ConSeal PC Firewall is vulnerable to a simple DoS attack prior to version 1.2.
wwwboard.txt - wwwboard.pl is vulnerable to a dictionary attack on the admin password and a subtle DoS attack.
mimeflood.txt - Many web servers allow you to consume large amounts of CPU and memory by flooding the server with the mime header.
bashover.txt - Exploit for the buffer overflow in bash's PS1 for Linux x86 systems
hp5.txt - It is possible to crash HP 5M/5N printers with a single SNMP packet.
pinepolicy.txt - Pine 3.95q - 4.02 allow users to bypass site policies and execute arbitrary commands.
hotmail.txt - Complete details about how to exploit the recent Hotmail bug and how to protect yourself.
solarisab2.txt - Solaris answerbook web server contains a bunch of security holes
linuxconf.txt -  Linuxconf contains a /tmp bug Redhat 5.1
asfsm.txt - AfterStep asfsm contains a temp file symlink bug allows users to overwrite files.
icqpw.txt - ICQ users can bypass the password check
rr-1.0.tgz - A program for logging and faking the standard unix udp-based traceroute
eudoraurl.txt - Eudora Pro 4.0 and 4.0.1 will execute Java from a URL which can be damaging
vintra.txt - DOS in Vintra systems Mailserver software
bo121unix.tgz - Back Orafice for *nix
sysmon.pl - This script, run on a regular (daily) basis, keeps tabs on root accounts and set[ug]id root files.
aimpw.zip - This is a simple Visual Basic program that detects AIM users that on the computer have the save password feature clicked
smbls98.tgz - Samba exploit which searches for open file shares remotely, similar to WinHack Gold.
boinfo.txt - ISS Security Advisory: cDc BackOrifice Backdoor
pptp-sniff.tgz - L0pht PPTP (Point to Point Transfer Protocol) Password Sniffer for Solaris 2.4+.
lotusnotes.txt - other users can access Lotus Notes 4.6 databases on your PC.
solfingerd.txt - Sun reintroduced the finger forwarding and finger DoS into Solaris 2.5.1 and 2.6.
faxsurvey.txt - allows an attacker to remotely execute any command s/he wants with the permissions of the HTTP-Server
bo.zip - A remote administration system which allows a user to control a Win95 machine over a network using a simple console or GUI application
Other Sources
aimprotocol.txt - AOL Instant Messenger (AIM) protocol information and password decoder.
ircn.txt - The IRC client mIRC allows remote users to execute arbitrary commands under certain conditions such as the ircn script.
cfingerd.txt - cfingerd 1.3.2 contains a security hole that could lead to a root compromise. (Included in Debain GNU/Linux).
hotmail.txt - Information on how to get into another users Hotmail e-mail account if they forget to click on the logout button.
papasmurf.c - The newly re-written version of smurf by TFreak. This is a combination of smurf and fraggle
papasmurf-linux.c - papasmurf ported to Linux.
mutt.txt - The e-mail reader Mutt 0.93 contains a buffer overflow in the Content-type field.
netscapemail.txt - The Netscape 4.05 mail reader contains a buffer overflow when dealing with attachments.
openbsdreadv.txt - OpenBSD 2.3's readv() allows a normal user to cause a kernel panic.
yp.c - Yahoo Pager Client Emulator allowing you to bump people off, hijack conversations, impersonate people, etc
msword.txt - Some versions of MS Word save random parts of memory into documents
moduleinfect.c - A module infector for Linux 2.0.33 running kerneld
linuxuid.txt - Linux kernel: sys_set*id(uid_t...) confusion
pinebug.txt - Pine 3.96 has a remotely exploitable buffer overflow.
scolp.txt - SCO 5.0.2 Enterprise allows normal users to remove files from /tmp.
hugweb.c - A simple DoS attack against web servers that do not throttle connections.
xcrush-2.0.tgz - A TCL interface to 33 popular exploits all packaged together. Requires TCL/TK 8.0p2 or greater. (Contains binary code not tested by Rootshell staff.)
textcounter - An exploit that allows you to run arbitrary commands from web sites running the textcounter.pl CGI script.
targa.c - Multi-platform DoS attack which integrates bonk, jolt, land, nestea, netear, syndrop, teardrop, and winnuke all into one exploit
mscan.tgz - mscan 1.0 - Scans multiple hosts for many different vulnerabilities. (statd, nfs, cgi, X11, named, pop3, and IRIX defaults)
mailxploit.c - Exploit for a buffer overflow in the mailx present in Solaris 2.5.1, 2.6, Debian GNU/Linux, and Redhat Linux.
fuzz.c - An example UNIX virus similar to "Bliss".
fsbug.txt - A FS bug in FreeBSD and possibly other BSD's allowing a non-root user to cause a kernel panic.
sslpkcs.txt - Describes a vulernability in many SSL implementations that allows a user to decrypt a single session
qpop.c - Qualcomm Popper 2.2 and 2.4 (POP3 Server) buffer overflow.
newxterm.c - Exploit similar to xterm_exp.c, except it defeats the non-executable stack patch.
mailex.c - mailx exploit allowing you to read files that are readable by the group mail.
afhrm-0.6.tgz - Advanced file hide & redirect module for Linux 2.0.xx / i386.
linuxsigio.txt - Linux 2.0.34 kernel bug allowing normal users to kill inetd
sol26log.c - Hacked version of "script" which logs non-echoed keys. Ported to Solaris 2.6 from original unixKeyLogger.c
fix.c - File checksum fixer. Allows you to trick "sum" into thinking a file isn't modified.
metainfo.txt - The MetaInfo products MetaIP and Sendmail contain remotely exploitable security holes.
ioconfig - IRIX 6.4 ioconfig exploit making use of system calls without full paths
aspads.txt - By appending ::$DATA to .asp URLs you are able to download the ASP source code from Microsoft web servers (IIS). Vendor patch.
winhackgold.zip - Winhack Gold is a program for Windows that scans blocks of IPs for open file shares that you can access. This is the same program as featured in Newsbytes. Click here to see if your computer is vulnerable. Windows users may wish to download Legion by Rhino9 which does not require a UNIX machine.
qpopscan.sh - Qualcomm Popper scanner shell script for finding vulnerable servers
netscapetbl.txt - Netscape 3.x and 4.x DoS by using nested tables inside the span tag
qscan.c - Yet another QPOP scanner. This one is written in C.
smurflog-1.0.tgz - Smurf Logger 1.0. Logs smurf attacks and the broadcast address being used
rpk.c - Real Player 5.0 Killer. Allows you to crash users when they are using RP with a UDP stream.
hplj4plus.txt - HP Laserjet 4 Plus denial of service attack.
iis4ftp.txt - Microsoft IIS 4.0 FTP Denial of Service Attack
solaris-sendmail-8.8.4.sh - The old /tmp Sendmail bug ported to Solaris 2.5 and 2.5.1
winproxy.txt - Windows Proxy servers WinGate and StarTech contain buffer overflows.
irixat.txt - IRIX 6.2 at allows you to send yourself files own by root via e-mail
dslip203.txt - Dslip 2.03's allocslip which runs setuid has a buffer overflow
tft.c - TCP Flag Test 'excersizes' a machines TCP/IP stack by passing it all combinations of 64 TCP flags and seeing which flags are usable to determine which ports on the machine are open or not.
linuxfs.txt - Linux users can override quotas and kernel resource limits by storing data inside filenames.
antisentry.c - DoS against servers who use Abacus Sentry
putsyslog - Allows users to hide files within syslog by uuencoding the file and logging it.
icqfile.cpp - ICQ Version 98a beta DLL v1.07 File Transfer Spoofer
slmail3.txt - SLMail 3.0.2421 contains a buffer overflow.
changemac.c - Allows you to change the MAC address of your ethernet card to trick smart / switching hubs. (See Phrack 53)
deceit.c - This program implements enough of the PPTP protocol to steal the password hashes of users that connect to it by asking them to change their password via the MS-CHAP password change protocol version 1. (See Phrack 53)
watcher.c - A network level monitoring tool to detect incoming packets indicative of potential attacks. (See Phrack 53)
scanlogd.c - A simple and reliable example port scan detection tool. (See Phrack 53)
smrex.c - Buffer Overflow for Sunos 4.1 sendmail - execs /usr/etc/rpc.rexd. (See Phrack 53)
drpcscan.tgz - Scans ranges of IPs for known RPC services
lpd-rm.c - Remove a file by exploiting the BSD-style lpd.
perliis.txt - Describes a vulnerability with Microsoft IIS 1/2/3/4 and Perl.
syslog-poison.c - Modded syslog_deluxe.c to allow sending of spoofed syslog messages from either stdin or the command line.
fwbackdoor.txt - A paper on placing backdoors on machines behind firewalls
dilloncrond.c - Dillon's Crond v2.2 exploit (present in Slackware).
ns.tgz - Simple named scanner to find sites remotely exploitable. (Used binfo-udp.c)
wide-dhcp.txt - There is a /tmp bug in the OpenBSD port of wide-dhcp.
lpd-mail.c - Exploits lpd by specifying alternate sendmail alias file to use.
imapd4.txt - New remote root exploit in University of Washington imapd 4. (that came with Pine 4.0)
slackdb.txt - The Berkley DB in some slackware distributions defines snprintf to normal sprintf.
csmproxy.txt - CSM Proxy 4.1 contains a buffer overflow in its FTP service.
eggdrop137.txt - Eggdrop the popular IRC bot contains many buffer overflows.
asmcodes.txt - Assembly drop in replacements for your favorite exploits. (x86 only)
readsmb.c - An implementation of the SMB sniffer that comes with l0phtcrack for UNIX.
nbase.txt - N-Base switch's contain several security holes including backdoor passwords
bsd_procfs.c - In /proc under FreeBSD 2.2.1, you can modify a setuid executable's memory.
webmin.txt - The last version of Webmin has an error which allows users to both guess the valid usernames and attempt brute force password attacks against machines running webmin
ss.pl - Perl script that will scan for an open specified port on a class C IP address block, or all open ports on a single host.
xcrash.tcl - TCL front-end to teardrop, winuke, etc.
lynx28.txt - Lynx 2.8 built in mailer buffer overflow.
netmanage.txt - Netmanage Chameleon tools 4.5 and Unixlink 97 tools all contain many overflows.
xterm_exp.c - Root exploit for the vulnerabilities that exist in the terminal emulator xterm(1), and the Xaw library distributed in various MIT X Consortium; X Consortium, Inc.; and The Open Group X Project Team releases.
3com.txt - Many 3com switches contain an undocumented backdoor telnet password.
dip3.3.7o-exp.c - dip 3.3.7o buffer overflow exploit for Linux.
coke.c - Exploits WindowsNT Servers 3.51/4.0 which are running WINS (Windows Internet Name Service).
msgchk.c - Exploit for the buffer overflow found in the suid msgchk of RedHat 5.0.
pingflood.c - Allows non-root users to 'ping flood' by sending lots of SIGALRM signals to ping
kde.c - KDE klock buffer overflow exploit using environment variables.
count.cgi.l.c - A updated version of the count.cgi exploit.
ADMw0rm-v1.tgz - Remote expoit for the buffer overflow present in some versions of bind.
xosview.txt - Buffer overflow in suid xosview which ships with RedHat 5.1. (Now includes exploit)
ptebug.c - Linux 2.0 PTE DoS exploit.
sendmailhelo.txt - Exploit for a bug in the sendmail HELO code which allows you to hide your true identity in sendmail < 8.9.0.
namedsploit.c - Another named buffer overflow. This one works on many bind version for both FreeBSD and Linux.
smb_mount.c - This overwrites a buffer on Linux systems in smbmount from smbfs-2.0.1.
icqhijaak.c - ICQ Hijaak Version 1C. Allows you to change other users passwords and spoof messages.
ciscopix.txt - Details about the Cisco PIX Private Link Key Processing and Crypto problems.
rsi-uucpd.txt - Buffer overflow in the uucpd daemon when it records wtmp information.
rsi-hpuxrwrite.txt - If a user has an hpterm session logged in to an HP-UX that is running rlpdaemon, it is possible for an attacker to remotely compromise the active account
accelx41.txt - There are bugs in the Accelerated X 4.1 Install and Uninstall allowing non-root users to overwrite arbritrary files.
secureping-1.0.tar.gz - A secure version of ping with admin-definable packet size limits for root and non-root users which logs attempted unauthorized flood/preload and over-size-limit packets, and logs and prevents SIGALRM-bomb floods.
ufsrestore.c - Sparc Solaris 2.4, 2.5, 2.5.1, 2.6 ufsrestore buffer overflow.
netwatch.txt -Netwatch 0.7e has a temp file bug allow you to overwrite files.
binfo-udp.c - Gathers information about BIND which is useful for other named exploits.
bsdseclevel.txt - Allows you to bypass 4.4BSD secure levels.
dreamweaver.txt - Macromedia Dreamweaver uses insecure passwords.
majordomo - Majordomo /tmp exploit (append to files owned by majordomo)
lfloppy - Modified floppies can crash Linux.
croom - ConferenceRoom Exploit (buffer overflow)
eudora4 - Eudora Pro 4 DoS (long filename attack)
wtmpx - wtmpx utility for solaris
appleshare - AppleShare IP Mail Server buffer overflow.
bsdcore - BSD coredumps follow symlinks
bsdiinetd - BSDI inetd crash
syndrop.c - Teardrop mixed with a SYN - syndrop.c
rfc1644.txt - Example of RFC-1644 attack
icqspoof.c - Sends a message to a given ICQ user and it will appear to be from an arbitrary UIN.
portmap.txt - portmap 4.0-8 DoS
impack103.tar.gz - Luke_Skyw'w Imap Pack 1.03 - exploit imapd attack vunerable hosts. (Warning: contains untested binaries)
nickserv.c - Exploits the database memory error bug in DalNet's Nickname Services.
spiffit.c - Spoofed DoS similar to biffit.c for in.comsat
rwhokill.c - DoS for the rwhod daemon
obsd.txt - OpenBSD Boot Hack (boot-modified-kernel-attack)
macoverflow.txt - Eudora Internet Mail Server vs. 1.2, 2.0, 2.01 DoS + Apple's Web Sharing DoS
livradius - Code to crash radiusd from Livingston 1.16 and 2.0.1
mailrc.txt - Mailrc and Pine security holes (via attachments)
nestea.c - This exploits the "off by one ip header" bug in the linux ip frag code. Crashes linux 2.0.* and 2.1.* and some windows boxes.
overdrop.c - Linux 2.0.33 printk abuse (DoS)
inetinfo - Denial of service attack against NT4.0 inetinfo.exe
updatedb - It is possible to overwrite any file with updatedb (Tested under RedHat 4.x)
evil.zip - A new version of the gcc exploit written in C
info2www - Some versions of the info2www CGI allow users to execute arbitrary commands
lc201exe.zip - L0phtCrack Release 2.01 Windows Password Recovery Tool and more!
safeload.c - A wrapper for setuid executables that will stop command line buffer overruns.
xmsg-1.0.0.tgz - Administration tool that displays messages that are received on a UDP port.
bin2c.tar.gz - This is a utility that will take a binary and dump it into C - style arrays.
optsnag.tar.gz - A utility to help administrators find out undocumented command line options in Unix.
gids_patch.tar.gz - Kernel patch that lets 'groups' use ports <1024 so you can replace suid bits w/ sgid bits.
svga_patch.tar.gz - A patch for Linux svgalib that adds extra security to setuid svga programs.
bashncurses - bash 2.01 / ncurses 4.1 console takeover exploit
dumptcplink - Reconstruct original data from tcpdump output (perl script)
rh5dhcp - Red Hat 5 ifdhcpc-done allows for files to be overwritten
spak-0.6b.tar.gz - Spak (Send PAcKet) is a collection of tools that can be used to generate and/or send arbitrary packets.
mdaemon.c - There is a buffer overflow in the MDaemon Windows 95/NT SMTP server.
sol26lp - Solaris 2.6 lp printd race condition exploit
hphack.c - Neat hack that lets you use HP's PJL commands to remotely change the display on networked HP printers.
slmail26 - SLMail 2.6 and IMail 4.03 Buffer Overflow resulting in a DoS and more.
xkeyboard - Exploit for Xfree X servers allowing you to run commands as root.
ws2dos - Windows Winsock 2.0 denial of service attack.
tmpwatch.c - /tmp watcher which logs every single event in /tmp
fraggle.c - This is basically smurf.c with a udp twist.
srlog.c - Incoming source routed connection logger.
gatemail.c - Email bomber program - uses 2 wingates to hide true identity.
osflibroot - Details on how to exploit the old Telnetd Environment Vulnerability under DEC OSF/1 (v2.0 through V3.2c)
snfs-linux.tgz - Linux 2.1.xx port of the snfs.tgz package, source routed NFS.
jizz.sh - Front end shell script for the jizz DNS exploit.
akill2.c - Ascend Kill II - Reboots Ascend routers with a single spoofed UDP packet.
performer_tools - IRIX performer_tools CGI exploit - run any command under the webserver uid.
lynxhole - Lynx 2.7.1 bug allowing remote execution of code.
akill2.pl - Perl version of Ascend Kill II - doesn't spoof the source IP.
aixttdbserver - AIX 4.1.5 DoS attack (aka "Port 1025 problem") with ttdbserver
ncftp - Remote exploit for ncftp 2.4.2
WinGate Search - Search netblocks for open WinGate proxy servers.
biffit.c - NetBSD in.comsat DoS attack
ld-so - An old ld-linux.so hole for Linux
pma2.tar.gz - Version 2 of Poor Man's Access - a daemon that issues remote shell commands.
yapp_exploit.c - An overflow exploit for the Yapp Conferencing System, v2.2 via envion vars.
ssyslog.tar.gz - A secure replacement for syslog that implements cryptographical logging.
defeat_solar.txt - Text and source about defeating Solar Designer's non-executable stack patch.
secure-linux.tar.gz - Solar Designer's patch for Linux that stops many forms of buffer overruns.
www-sql.txt - Using the cgi www-sql, files in protected webserver realms can be read.
nt_hash.txt - NT passwords can be picked out of the registry or sniffed over the net.
sun4_tmpfs.txt - Show how an ordinary user can cause the SunOS 4.1.4 kernel to panic.
nt_bind.txt - On NT, a user can bind to any port, thus redirecting or blocking services.
ld_problems.txt - The ld linker exploit for Linux as well as discussion about LD_PRELOAD.
redhat_floppy.txt - Redhat lets users obtain dumps of floppy disk contents and lock serial ports.
imapd_core.txt - When imapd coredumps, the core will have encrypted shadowed passwords.
k_desktop.txt - When the K Desktop screen savers start, ~/.kss.pid can be overwrite files.
cron_files.txt - It is possible for users to hide files in their crontab and escape disk quotas.
war_ftpd.txt - There is buffer overflow in the Windows warftpd than cause it to crash.
openbsd_crash.txt - Script to crash OpenBSD systems if user process limits are high enough.
XFree86_exploit.c - This will overwrite a buffer in the XFree86 Server, giving a rootshell.
Passwd-starve - Resource starvation against passwd(1) on Red Hat 5
quake2-313 - Quake 2 Linux 3.13 - ref_root.so root exploit
dtappgather - Sun Solaris dtappgather root exploit (not fixed by patch 104498-02)
x11amp - Root exploit for setuid x11 audio mpeg player (x11amp) version 0.65
quake.c - remote exploit that sends a couple of spoofed udp packets causing the system to crash.
gcc-exploit-2 - Simple GCC exploit (tested under 2.7.2.3.f.1)
dgux_fingerd.txt - The fingerd that ships w/ dgux allows remote execution of arbitrary commands.
exchange5.txt - Microsoft Exchange Server v5 buffer overflow
dally.zip - boink clone that runs under Windows NT as a new protocol. (UNTESTED)
sharepw.c - Windows 95 Share Password recovery tool (source code)
sharepw.exe - Windows 95 Share Password recovery tool (windows binary)
newtear.c - Another variant of teardrop.c which is slightly different than bonk.c
newpep.c - Solaris version of the random UDP flooder pepsi.c
boink.c - An improved version of bonk.c that allows UDP port ranges.
ld.so.c - Overwrites a buffer via LD_PRELOAD env. variable, giving root on Linux.
riptrace.c - BSD 4.4 based routed trace file exploit
Strobe (V1.03) - Scans TCP ports on a target host and reveals which daemons are running.
wuftpd-sploit.tar.gz - wu-ftpd 2.4 signal exploit
statd-scan.c - A program which scans hosts for the RPC service statd.
xdmpasswd - Overwrite files with xdmpasswd.
sliplogin.c - Buffer overflow in BSDI's sliplogin allowing root access.
solaris-ping.c - Sparc Solaris 2.5 and 2.5.1 root exploit for ping (buffer overflow).
NTsunkill.c - A port of sunkill.c for Windows NT machines (also compiles under unix).
cisco76x.txt - On Cisco 76x routers, a long string for the password causes a reboot.
icq_sniff.c - Source that Sniff plaintext ICQ passwords that are sent once per session.
ipwatcher.txt - A Linux network tool that lets you view, hijack, or disconnect connections. (removed due to copyright violation)
mozilla_killer.c - This CGI code will crash all Windows Netscape browsers v2.0-3.0.
sun4_tmpfs.txt - Show how an ordinary user can cause the SunOS 4.1.4 kernel to panic.
sunkill.c - An effective denial of service attack against sun boxes running Solaris. A port of sunkill.c for Windows NT machines (also compiles under unix).
xdm_problem.txt - Anyone can connect to xdm/cde via XDMCP and get a login screen.
xotpcalc-1.0.tar.gz - An OTP calculator that works w/ S/Key and conforms to RFC 1938.
aix_mount.txt - Shows how a normal user on AIX 4.x boxes can mount any filesystem
beck.tar.gz - Exploits that will increase the load averages using Apache httpd v1.2.x.
bliss.tar.gz - An example of a virus that will execute on unix systems such as Linux
ccdconfig.txt - On Free/NetBSD, ccfconfig w/ -f option can be used to read arbitrary files.
linux_stack.tar.gz - Solaris Designer's non-executable user stack area and symlink fix patch.
phant0m.c - Makes an XTACACS server believe that you are disconnected from it.
trace_shell.c - This will overwrite a buffer on Redhat 5.0 in traceroute, thus giving root.
userv.tar.gz - Allows one program to invoke another with limited trust between them.
digital_dbx.txt - Shows how to get root on Digital Unix 4.0*, by using dbx on a suid program.
solaris_land.c - A version of the land.c attack with Solaris 2.5 as the attacking platform.
seyon_exploit.sh - Exploit for seyon, giving you the euid or egid of whatever seyon is suid to.
linux_httpd.c - Overwrites a buffer in NSCA httpd v1.3 on linux systems, giving a remote shell.
xtacacs.c - exploit to trick XTACACS servers to believe that you've disconnected.
vsyslog.txt - Linux exploit for libc 5.4.38's vsyslog().
innd_exploit.c - Overwrites a buffer in innd on Linux x86 systems thus giving a remote shell.
ntpptp.c - NT 4.0 SP3 PPTP denial of service attack exploit
ntpwgrabber.txt - A false FPNWCLNT.DLL can be stored in the %systemroot%\system32 directory under Windows NT 3, 3.51, 4 which collects passwords in plain text.
latierra.c - An enhanced version of land.c which works better against NT SP3 among other things.
rip.c - RIP (Routing Information Protocol) Version 1 Spoofer
lownoise.txt - Exploit for Digital Unix v4.0 that let's you create a writeable /.rhosts file.
sgi_cgihandler.txt - On IRIX systems, /cgi-bin/handler can be used to issue arbitrary commands.
medax_linux.tgz - A TCP sequence number predictor that also lets you execute commands.
wm_exploit.c - Overwrites a buffer in 'wm' from Ideafix package for Linux, giving root.
udpscan.c - Identifys open UDP ports by sending a bogus UDP packet and wait for a response
lizards.txt - Explains how to get root on Slakware 3.4 from the suid lizards game
ciscocrack.c - This contains script and source for decrypting cisco encrypted passwords.
imaps.tar.gz - Serveral different versions of the remote imapd buffer overflow exploit.
evil-term.c - This is the remote buffer overflow termcap exploit for BSDI BSD/OS 2.1.
portd.c - A daemon that listens on a port and provides passworded shell access.
pingexploit.c - This lets you send oversized ICMP packets from a unix box just like Win95.
checksyslog.tgz - Analyze your system logs for security problems while ignoring normal behavior
dosemu.txt - On Debian v1.1, /usr/sbin/dos can be used to read any file on the system
yaping.0.1.tgz - Yet another ping for Linux. Packets of size > 65535 octets are supported
messages.sh - Parses through /var/adm/messages to see if user typed password at login prompt.
FreeBSDmail.txt - This exploit will overwrite a buffer on sendmail 8.6.12 running on FreeBSD 2.1.0.
securelib.tar.Z - Shared library for SunOS 4.1 and later that will help protect your RPC daemons
ypsnarf.c - This handy little program will get you yp domain names, yp maps, and yp maplists.
YPX - YPX guesses NIS domain names.YPX will extract the maps directly from domains.
ftp-scan.c - This program exploits the ftp protocol to let you scan services on firewalls.
rdist-ex.c - This will write past a buffer, straight onto the stack, giving a root shell on FreeBSD.
ttywatcher-1.1b.tgz - ttywatcher lets a user monitor and interact with every tty on the system.
splitvt.c - An older exploit for Linux that overwrites a buffer in /usr/bin/splitvt, giving root.
mount-ex.c - All Linux versions are vulnerable to this buffer overflow attack on suid mount.
perl-ex.sh - perl-ex.sh is a simple little sperl script that gives you a root shell via suidperl.
sndmail8.8.4.txt - This will explain how to exploit sendmail version 8.8.4 to get root access
irix-xhost.txt - In default setup for irix, xhost is set to global acess when someone logs into console
mod_ldt.c - Gives access to all of Linux's linear memory to user processes at will, and thus root.
dipExploit.c - Linux dip Exploit. Overwrite a buffer in do_chatkey(), thus giving you a root shell.
rexecscan.txt - The rexecd can be used easily to scan the client host from the server host.
rpcs.01b.tar.gz - This is program that is designed to scan subnets for rpc services.
rxvtExploit.txt - Exploits a popen() call issued by rxvt on Linux machines, thus giving a root shell.
nfsbug.c - Demonstates a security problem in unfsd guessing the file handle of the root FS.
abuse.txt - A Linux exploit for Red Hat 2.1. This gives a root shell by exploitng abuse.console.
xtermOverflo.c - A program that overwrites a buffer in libXt.so while xterm is suid to root.
resolv+.exp - Quick and Simple way to read the /etc/shadow file as well as many other things
resizeExp.txt - Another Red Hat 2.1 exploit for resizecons due to lack of absolute pathnames.
aixdtaction.c - Overwrites a buffer in /usr/dt/bin/dtaction via HOME env. variable, giving root.
gpm-exploit.txt - This will get root on Linux systems using /usr/games/doom/killmouse
sneakin.tgz - A way to 'reverse telnet' from a box behind a firewall that allows ICMP packets.
telnetd exploit - This will create a shared library that gives a root shell remotely or locally.
pop3d exploit - Read the contents of the mail spool of a user when they connect to in.popd.
xpusher.c - This is a neat way to send keyboard events to another user's X window.
vif.tar.gz - This code lets you have multiple IP addresses for a single interface.
amod.tar.gz - Amodload is a tool which allows the loading of arbitrary code into SunOS kernels.
getethers1.6.tgz - getthers scans all address on an ethernet and producing a hostname/ethernet list.
rootkitSunOS.tgz - Here is another root kit designed for SunOS operating systems. Lots of cool stuff.
demonKit-1.0.tar.gz - A suite of trojan programs opening back doors to root on a Linux system.
eviltelnetd - telnet-hacked.tgz is a hacked telnet daemon that gives a root shell w/o password.
cfexec.sh - This let's you issue arbitrary commands as root on GNU cfingerd 1.0.1.
NFS Problems - Shows some potential problems with Linux in.nfsd concerning read-only exports.
cdromvuln.txt - If Linux CD is mounted w/ suid flag, older suid exploits will work on live filesystem
vixie.c - On Redhat Linux systems this will overwrite a buffer in crontab, thus giving root.
rshd_problem.txt - You can figure out valid usernames on hosts by examining the response from in.rshd.
Sol2.4Core.txt - Solaris 2.4 exploit that allows you to overwrite files when a suid prog. core dumps.
SolAdmtool.txt - On Solaris 2.5, the Admintool can be used to create a writeable /.rhosts file.
irix-netprint.txt - On IRIX, /usr/lib/print/netprint calls 'disable' without specifying absolute path.
SYNpacket.tgz - Floods a port with TCP packets with the SYN bit turned on causing inetd to segment
login_trojan.c - A login trojan program to be run at the console to get other user's passwords.
Sendmail.c - Sendmail exploit.
telnet_core.txt - On Linux systems, it is possible to get part of the shadow file w/ cores
SYNWatch.tar.gz - This program watches for TCP packets with the SYN bit turned on.
pinglogger.tar.gz - Logs all ICMP packets to a log file so you can see who is ping flooding you.
screen.txt - On BSDi systems, you can use /usr/contrbi/bin/screen to read /etc/master.passwd.
ftpBounceAttack - Implementation of the ftp Bounce Attack allowing you to anonymously do things.
Traceroute - Traceroute is an indispensable tool for troubleshooting and mapping your network.
pcnfsd.c - Exploit that allows local users to chmod arbitrary directories on hosts running pcnfsd.
netcraft.tgz - Contains various (and older) web security issues and exploits from Netcraft.
superforker.c - This is a supercharged version of the classic fork() denial of service attack
tripwire-1.2.tgz - Creates a signature of binary files, and then checks to see if these file were modified.
tcpr-1.3.tar.gz - A set of perl scripts that enable you to run ftp and telnet commands across a firewall
syslogFogger.c - This allows you to write to system logging facilites via UDP packets to port 514.
ypbreak.c - Lets you change your username, password, gecos, or shell via yppasswd daemon.
hdtraq.c - This runs as a daemon and purportedly creates bad sectors on a hard drive.
bind_nuke.txt - Bind8.1.(1) can't update the same RR more than once in the same DNS packet.
logdaemon.tar.gz - Version 5.6 of a suite of tcp/ip programs that enhance network system logging.
suTrojan.c - This is a replacement program for su that mails you when an attempt to su is made.
Tcpmon.c - TCP Monitor v1.0
sushiPing.c - On Sun 4 platforms, this trojan ping gives you a root shell when you make a triggerfile.
webgais.txt - This will explain how to issue shell commands remotely using /cgi-bin/webgais.
socket_demon13.zip - Daemon that sits on a specified IP port and provides passworded shell access.
pcs.tgz - A libpcap based sniffer that supports multiple interfaces and PPP (with no filtering).
sfingerd-1.8.tgz - A replacement for the standard unix finger daemon designed for security.
gnmp.tar.gz - Generic Network Message Passing is a simple client server messaging system
irixmail.sh - Exploit shell script that gives a root shell on IRIX systems.
lpr Exploit - This small program exploit the suid root lpr program giving root.
Xfree86 Exploit - There is a problem with XFree86 3.1.2 that lets you overwrite files.
wipehd.asm - Assembly Language program that will remove the first 10 sectors of a hardrive
minicom.c - This is an exploit for minicom on Linux systems that will overwrite a buffer.
sam.txt - On HP-UX, the System Administration Manager (sam) can be used to truncate files.
wuftpd_umask.txt - The umask for wuftpd 2.4.2-b13 is 002 making files group writeable by anyone
xspy.tar.gz - xspy is a program that makes logins appear on your display.
scan.sh - This is a perl script that scans subnets and reports if rexd or ypserv is running.
xscan.tar.gz - scans subnets for unsecured X clients and automatically logs results
BSDcron-ex.c - BSD cron exploit. This program overruns a buffer, giving root access.
OSF1_dxchpwd - On OSF1, /usr/tcb/bin/dxchpwd can be used to overwrite any file on the system.
bindExploit.txt - Setting SO_REUSEADDR options and calling bind allows user to steal udp packets.
cloak.c - This program wipes all traces of a user from a UNIX system.
convfontExploit.sh - Script that exploits /usr/bin/convfont on Linux systems to get root access.
marry.c - This program is a log editor with lots of interesting features.
portscan.c - A Linux port scanner program that reports the services running on another host.
dumpExploit.txt - On Linux systems /sbin/dump can be used to read arbitrary files.
fingerd.c - This program is another finger daemon trojan program.
solaris_ping.txt - On Solaris 2.x systems, any user can crash or reboot the system using ping.
generic_buffer.tgz - Generic buffer overrun program for Linux, SunOS, and Solaris.
linux_lpr.c - This program overwrites a buffer in the suid program lpr, thus giving a root shell.
SunOS_user.txt - On SunOS, chsh and chfn use getenv("USER") to validate the userid of the caller.
secure_shell.txt - Using SSH, a non-root user can open privleged ports and redirect them.
grabBag.tgz - Tons of old and miscellaneous exploits from different versions of unix.
wu-ftpd.sh - This shell script lets you create a file anywhere on the system.
sol_mailx.txt - An old security hole in /usr/bin/mailx still exists in the mailx on Solaris 2.5
glimpse_http.txt - Glimpse HTTP (Interface to Glimpse Search Tool) can issue remote commands.
hp_stuff.tgz - Lots of exploits for HP/UX from the Scriptors of Doom.
hpjetadmin.txt - hpjetadmin can be tricked giving away root by a writeable .rhosts file.
irix-buffer.txt - IRIX buffer overruns for df, eject, /sbin/pset, /usr/bsd/ordist, and xlock.
irix-xterm.c - This will overwrite a buffer in xterm on IRIX systems, giving a root shell.
irix-iwsh.c - This will overwrite a buffer in /usr/sbin/iwsh on IRIX 5.3, giving root access.
irix-printers.c - This will overwrite a buffer in /usr/sbin/printers on IRIX systems giving root.
modstat.c - This program will overrun a buffer in /usr/bin/modstat on FreeBSD systems.
pine_exploit.sh - This script is an exploit for pine. It can be used to create .rhosts files
view_source.txt - On some httpd distributions, you can use cgi-bin/view-source to read arbitray files.
sendmail-ex.sh - This is an exploit script for sendmail 8.7-8.8.2 for FreeBSD and Linux. Gives root.
smh.c - smh.c is an exploit for sendmail 8.6.9. It gives a bin owned setuid shell.
rlogin_exploit.c - This overwrites a buffer in gethostbyame() on Solaris 2.5.1, giving a root shell.
expect_bug.txt - Expect does not make handles to pseudo tty's inaccessable to other processes.
html.txt - Shows interesting links to put in your HTML pages causing denial of service.
autoreply.txt - autoreply(1) can be used to create root owned files with a mode of 666.
bdexp.c - On older versions of Linux, this will overwrite a buffer in suid bdash, giving root.
irix-csetup.txt - Get root on IRIX via /usr/Cadmin/bin/csetup in conjunction with /usr/sbin/sgihelp
solsocket.txt - On Solaris-x86 2.5, any normal user can connect to unix domain sockets.
lemon25.c - Exploit for Solaris 2.5.(1) that overwrites a buffer in passwd, giving root access
reflscan.c - Another TCP port scanner that escapes logging by using half open connections.
yp.txt - On YP systems, when a password expires, the old password is not required.
bsd_core.txt - On BSDi 3.x, users arbitrarly write files with binary data, but not overwrite them.
ffbconfig-ex.c - This program overwrites a buffer in /usr/sbin/ffbconfig on Solaris 2.5.1 giving root.
FreeBSD-ppp.c - This will overwrite a buffer in pppd on FreeBSD systems, giving a root shell.
sol-license.txt - On Solaris 2.4, if the license manager is running, root can be obtained.
lin-pkgtool.txt - This file explains how to get root on Linux system with the pkgtool program.
startmidi.txt - On IRIX systems, startmidi can be exploited to obtain root privileges.
linux_rcp.txt - On Linux, if you have access to uid 65535 (nobody), then root can be obtained.
doomsnd.txt - This will get root on Linux systems by exploiting the doom sndserver.
solaris_ps.txt - This will exploit /usr/bin/ps and /usr/ucb/ps on Solaris systems, giving root access.
dec_osf1.sh - This script exploits /usr/sbin/dop on DEC unix 4.0, 4.0A, and 4.0B, giving a root shell.
tcp_wrapper.tgz - Version 7.5 (the latest) of the tcp/ip wrapper for inetd. (Does logging and monitoring)
rpcbind_1.1.tgz - This is an rpcbind replacement that includes tcp wrapper style access control.
breaksk.txt - Netscape's server key format is susceptible to dictionary attacks.
irix-dataman.txt - This file show how to exploit dataman on irix system to obtain root access.
irix-fsdump.txt - This is an exploit for /var/rfindd/fsdump that gives root on irix systems.
qmail.tar.gz - This is a replacement sendmail-binmail system providing security and efficiency.
h_rpcinfo.tar.gz - Allows you to sneak past port filters on port 111 and get dumps of RPC services.
synlog-0.1.tar.gz - Synlog monitors half open TCP connections such as synfloods or synscans.
wrapper-v2.tgz - This is a generic wrapper to prevent the exploitation of suid/sgid programs.
solaris_ifreq.c - On Solaris, users can do control requests on a root created socket descriptor.
longpath.sh - Shell script that implements a long path attack causing various problems on Linux.
logarp.tar.gz - Useful for seeing if users on your subnet are "stealing" IP addresses.
aix_dtterm.c - This will overwrite a buffer in /usr/dt/bin/dtterm on AIX 4.2 PPC, giving root.
irix-wrapper.c - Wraps programs on IRIX to prevent command line argument buffer overruns.
irix-df.c - This will overwrite a buffer in /bin/df on IRIX systems, thus giving a root shell.
irix-dp.c - This overwrites a buffer in /usr/lib/desktop/permissions, giving egid of sys on IRIX.
irix-login.c - This will overwrite a buffer in /bin/login on IRIX systems, giving root.
irix-xlock.c - This will give root by overwriting a buffer in /usr/bin/X11/xlock on IRIX.
synsniff.tar.gz - Script in perl which watches for inbound connections (SYN's) and logs them.
SunOS_crash.txt - Reading /dev/tcx0 on a SunOS 4.1.4 Sparc 20 causes a system panic.
imapd_exploit.c - Get remote root access on Redhat Linux systems by overwriting a buffer in impad.
xlock.c - On Linux systems, this will overwrite a buffer in setuid xlock, giving root access.
elm_exploit.c - Overwrites a buffer in Elm and Elm-ME+ on Linux via TERM environ. variable.
daynotify.sh - This script will exploit a bug in SGI's Registration Software under IRIX 6.2.
tcpdump.tar.Z - A tool for network monitoring and data acquisition. (needs library packet capture.)
sperl.tgz - Overwrites a buffer in the sperl5.001 and sperl5.003, thus giving root access.
dip-prob.txt - Dip will allow an ordinary user to gain control of arbitrary devices in /dev.
nlspath.txt - Exploits for ping, minicom, su and others on Linux via NLSPATH env. variable.
solaris_lp.sh - Script for Solaris that breaks lp, then use lp priv to break root (or bin, etc...).
AIX_mount.c - Overwrites a buffer in /usr/sbin/mount on AIX 4.x systems via LC_MESSAGES.
fdformat-ex.c - This will overwrite a buffer in /usr/bin/fdformat on Solaris 2.x systems giving root.
sunos-ovf.tar.gz - This program is designed to test buffer overflows on SunOS 4.1.x boxes.
slammer.tar.gz - Slammer lets you issue arbitray commands on hosts by exploting yp daemons.
color_xterm.c - This will overwrite a buffer in /usr/X11/bin/color_xterm, giving root on Linux.
tlnthide.c - Allocates a port and sets up a telnet gateway making it difficult to trace telnets.
LPRng.tgz - A light weight printing system especially designed with security in mind.
utclean.c - This will remove your presence from wtmp, wtmpx, utmp, utmpx, and lastlog.
eject.c - Overwrites a buffer on Solaris 2.x systems in /usr/bin/eject, giving a root shell.
bind-8.1.1.tgz - Version 8.1.1 of bind with many improvements - (includes documentation)
webs099.tgz - A minimalist web server designed primarily for security and handles redirects.
talkd.txt - This explains how to get root remotely by overwriting a buffer in in.talkd.
udpstorm.tgz - This is an implenmentation of the udpstorm attack. Works with Linux.
jakal.c - A portscanner that avoids tcp-logging by not completing the 3-way TCP handshake.
lin_probe.c - This overwrites a buffer in /usr/X11/bin/SuperProbe on Linux, thus giving root.
AIX_host.c - Overwrites a buffer in gethostbyname() on AIX 4.2 Power PC, giving a root shell.
connect.c - Lets a normal user crash AIX 4.1.4, AIX 4.1.5, HP-UX 10.01, and HP-UX 9.05
sol2.5_nis.txt - This show how to exploit /usr/lib/nis/nispopulate on Solaris 2.5 systems.
xdm_bugs.txt - It is possible to deny service from xdm and xdm does not close file handles correctly.
lilo-exploit.txt - Get root on the lastest versions of Linux (at the console) using LD_PRELOAD.
rsucker.pl - Perl script that acts as a fake r* daemon and logs the usernames sent from clients.
portmap_5b.tar.gz - A portmapper that supports access control in the style of the tcp wrapper package.
irix-login.txt - On Irix systems /var/adm/badlogin contains failed logins and passwords in clear text.
iebugs.tar.gz - Microsoft Internet Explorer bugs one through six in text and html format.
arnudp.c - Demonstrates how to send single UDP packets from an arbitray souce/destination.
cgiwrap-3.22.tgz - This is a gateway that allows a more secure user access to CGI programs.
pma.tar.gz - Poor Man's Access - A daemon that lets you issue shell commands remotely.
makedir.txt - Programs to create thousands of directories and to delete these directories.
tcpprobe.c - This is a tcp portscanner that shows accepted connections on a remote host.
locktcp.c - This program will freeze a Solaris/x86 2.5.1 systems, causing denial of service.
irix-wrap.txt - This shows how to get a listing of directories (755) from cgi-bin/wrap on Irix 6.2.
block.c - Prevents users from logging in by monitoring utmp and closing down user's tty ports
tin_problem.txt - rtin/tin will create /tmp/.tin_log with mode of 0666 in /tmp and follows symbolic links.
sun_patch.sh - If you have a sun SPARC, this script will stop all forms of buffer overrun attacks.
riputils.tgz - This is a set of routing internet protocol utilities designed for Linux systems.
test-cgi.txt - Using the CGI program test-cgi, you can inventory files on remote systems.
fakerwall.c -This program lets you send an rwall message from an arbitrary host of your choice.
bind.txt - This describes a potenital denial of service problem with BIND-4.9.5-P1.
remove.c - A universal utmp, wtmp, and lastlog editor that also compiles under AIX & SCO.
hide.c - Exploits a world-writeable /etc/utmp and allow the user to modify it interactively.
hsh002.c - This is a neat little shell for experimentation with lots of interesting features.
nfswatch4.1.tar.Z - This lets you monitor NFS requests to any given machine or the entire network.
nfstrace.tgz - The rpcspy/nfstrace package lets you to perform NFS tracing by network monitoring.
wuftpd-owrite.sh - Exploits a bug in wu-ftpd to create or overwrite a file anywhere on the filesystem
wuftpd-sdump.sh - Exploit a bug in wu-ftpd to assemble and view the shadow password file.
shadowyank.c - This will reconstruct shadow entries from the core file from ftp daemon segmenting.
ident-scan.c - TCP scanner that gets the username of the daemon running on the specified port
ascend.txt - Program for Linux designed to attack Ascend routers with zero length tcp offsets.
gzip.txt - While a file is being compressed with gzip it is world readable.
libc.so.5 - This is a hacked libc.so.5 for Linux that spawns a shell when a call is made to crypt().
sdtcm_convert.txt - This explains to how exploit sdtcm_convert on Solaris machines to get root access.
mnt.tar.gz - Exploits a hole in HP-UX 9 rpc.mountd program and lets you steal NFS file handles.
kmemthief.c - If /dev/kmem is writeable by normal users, then this program will get you root.
nfsshell.c - This should be very useful if you have located an insecure NFS server.
psrace.c - This code exploits a race condition in Solaris, thus allowing you to make a root shell.
rpc_chk.sh - Shell Script to get a list of running hosts from a DNS nameserver for a given domain.
seq_number.c - This is a program that exploits the TCP Sequence Number Generator bug.
asppp.txt - On Solaris 2.5x86, /tmp/.asppp.fifo can be used to make a world writeable .rhosts file
kcms.txt - Explains how to get root on solaris 2.5 by exploiting /usr/openwin/bin/kcms_calibrate.
Spoofing
any-erect.c - Another DNS spoofing type program much like jizz.c. Compiles on Linux.
smurf.c - Spoofs IMCP packets resulting in multiple replies to a host from a single packet.
Jizz.c - A DNS spoofer that exploits the cache vulnerability in most BIND daemons
ipspoof.c - The classic IP spoofer.
sirc4.gz - IRC spoofer
Sniffers
web_sniff.c - A Linux sniffer that is designed to retrieve web usernames and passwords.
Linsniff.c - This is a simple Linux Sniffer that shows you incoming TCP packets on most ports.
Esniff.c- Source for a basic ethernet sniffer
Linux_sniffer.c - Monitors ip packets for Linux.
Solsniff.c - This is sunsniffer.c modified to run on dlpi systems
Sunsniff.c - A sniffer for SUN machines.
Secsniff.c - Another sniffer.
sniffit.0.3.5.tar.gz - A very flexible network sniffer that has many interesting features (like curses)
tcpview.c - Another sniffer type program designed for Sun OS 4.1 architectures using /dev/nit.
IPInvestigator.tgz - IPIvestigator is another sniffer that lets you watch traffic between machines.
snifftest.c - snifftest.c will try to tell you if a sniffer is running on Sun machines.
solsniffer.c - This is a version of ESniff.c that has been modified for Solaris 2.X.
Nuking
sping.tar.gz - Linux binary and source of 'sping' which causes Win95 machines to crash.
Winnuke.c - This sends Out of Band Data to Win95/NT computers causing panics and reboots.
Jolt.c - Sends oversized fragmented packets to Win95 boxes causing them to lock up.
jping.tar.gz - This is another simple IMCP flooding program that compiles under Linux.
puke.c - Spoofs an ICMP unreachable error to a target, causing connection drops.
Synk4.c - An improved and updated Syn Flooder that also supports a random IP spoofing mode
fping.tar.gz - Like UNIX ping(1), but allows efficient pinging of a large list of hosts.
simping.c - Simulates the "ping -l 65510 victim.host" from Windows95 - also compiles on Linux.
pong.c - Attacks an arbitrary host by sending a flood of spoofed ICMP packets.
land.c - Crash WFW311, Win95, and WinNT by sending a spoofed packet with the SYN flag from a host on an open port setting as source the same host and port.
teardrop.c - Exploits the overlapping IP fragment bug present in all Linux kernels and NT 4.0 / Windows 95 (others?)
pentium_bug.c - Denial of service attack for the Intel Pentium CPU for any operating system.

Hacking Utilities                    

Tiger (V2.2.3) - Tiger attemps to exploit known bugs, holes, and misconfigurations to attain root
Netcat (V1.10) - Like Unix cat(1) but this one talks network packets (TCP or UDP). Excellent tool.
Auto-Hack v1.0- First, its general overview of AutoHack. It contains two basic programs inone. A Scanner, which will scan through a set range of numbers and check for carriers, and a Hacker, which will "hack" through codes on a given Long Distance service, such as MCI, Sprint, Metrophone, or Allnet
Allnet Hacker v4.0- Good for Telenet, PooPnet, or any other computer that you want to hack on.
Modem Jammer- supposedly makes your modem untracable
COPS (Computer Oracle and Password System) checks for many common Unix system misconfigurations. I find this tool very valuable, as it is non-trivial to break a system which has passed a COPS check. I run it on all the systems I admin. It's getting a bit old, but it's still an excellent way to systematically check for file permission mistakes.
ICMPinfo V1.10 - ICMPinfo is a tool for looking at ICMP messages received on the running host.
ISS (V1.3) - The Internet Security Scanner is used to automatically scan subnets and gather information about the hosts it finds, including the guessing of YP/NIS domainnames and the extraction of passwd maps via ypx. It also does things like check for verisons of sendmail which have known security holes.
Phobia.tgz - This utility does a scan of an internet host looking for various vulnerabilities.
Keyloggings
Playback - version 1.9c
Keytrap - Keyboard Key Logger TRS
Keycopy v1.01 - keystroke recorder great for recording macros
Phantom- A keystroke recorder and playback for MS-DOS
Windows Key Login - A keystroke recorder and playback for Windows
Denial of Service (Mail Bombers)
Anonymous Mailer- Just a plain anonymous mailer. Sends one at a time and is very easy to use.
Fuckin' Sendmail
Unabomber v.1.0 - forget everything else get this one is easy to use and very configurable to your own liking.
Kaboom - A great mailbomber written in ObjectPascal.
Mailbomb - Just a plain mailbomber.
Up Yours v3.0 - Great Progam. Has a standard bomber, with a pre-done list of mail servers to use. Also has a Flamer option, that puts your victem on as many mailing lists as you would like.

 

Get a JAVA capable browser damnit!!!

| Main Page | Documents | Tools | Crackers,Etc. | Survey |

All rights reserved. Copyright © 1999 FiRe StOrM.
For problems or questions regarding this website contact
[[email protected]].
Last updated: June 17, 1999.