Big List of Tools Flashcards

1
Q

<p>AirSnort </p>

A

crack WEPs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

<p>Maltego </p>

A

Dossier builder

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

<p>nmap</p>

A

port/vuln scanner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

<p>nessus</p>

A

vuln scanner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

<p>ToneLoc</p>

A

Wardialer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

<p>Netcraft </p>

A

suite of tools used to obtain web server version, IP address, subnet data, OS info, subdomain info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

<p>NIKSUN's PhoneSweep</p>

A

Wardialer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

<p>AirSnare </p>

A

alert when unapproved machine connects to ur wireless

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

<p>NetStumbler </p>

A

wireless NW detector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

<p>Kismet</p>

A

linux, wireless NW detector, sniffer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

<p>hping</p>

A

creating custom packets for testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

<p>inSSIDer </p>

A

wireless NW detector, mapper of access points

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

<p>p0f </p>

A

banner grabbing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

<p>whoreadme.com </p>

A

allows you to track emails &amp; provides info on OS, browster type, location, etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

<p>Nexpose</p>

A

vuln scanner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

<p>openVAS</p>

A

vuln scanner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

<p>Link Extractor </p>

A

this tool locates &amp; extracts the internal and external URLs for a given location

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

<p>THC-SCAN</p>

A

Wardialer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

<p>Retina</p>

A

vuln scanner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

<p>Archive.org</p>

A

(aka The Wayback Machine) allows you to find archived copies of websites form which you can extract information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

finger

A

finger username
—returns info about a user on a given system (i.e. user’s home directory, login time, idle times, office location, last time they both received or read mail)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

rpcinfo

A

—enumerates info over RPC (remote procedure call) protocol

Switches used:

  • m //displays list of stats for RPC on given host
  • s //displays list registered RPC apps on given host
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

showmount

A

—lists & identifies shared directories on given system; also displays list of all clients that have remotely mounted a file system

Switches used:

  • a //prints all remote mounts
  • d //lists directories that have been remotely mounted by clients
  • e //prints list of shared file systems
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

nbtstat

A

nbtstat -a
—-This returns the NetBIOS name table & mandatory access control (MAC) address of the address card the computer name specified

nbtstat -A
—-Lists the same info as -a but using IP

  • c (lists contents of the NetBIOS name cache)
  • n (displays names registered locally by NetBIOS)
  • r (displays count of all names resolved by broadcast)
  • s (lists sessions table & converts destination IP addresses to computer NetBIOS names)
  • S (lists the current NetBIOS sesssions & their statuses, along w/ IPs)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
view shares from Windows
net view \\hostnameorIP
26
view null session from Windows
net use \\hostnameorIP\ipc$ " \user:"
27
SNScan
SNMP Scan
28
SMTP VRFY
command to check if specific user ID is present
29
SMTP EXPN
returns all users on a distribution list
30
SMTP RCPT TO
identifies the recipient of an email message (can be used multiple times per message)
31
SuperScan
Windows tool for port & IP scanning + windows enumeration
32
PsTools
Windows admin tools
33
Enum4linux
allows for extraction of info where Samba is in use
34
JXplorer
LDAP enumeration (java based)
35
ntp-monlist
nse script to show last 600 clients to sync clocks over ntp nmap -sU -pU:123 -Pn -n –script=ntp-monlist
36
ntp commands (4)
1) ntpdate 2) ntptrace 3) ntpdc 4) ntpq
37
pwdump7
dumps hashes from windows SAM file
38
winrtgen
generates rainbow tables
39
Rainbow Crack
compares hashes with rainbow table
40
cirt.net
default passwords
41
w3dr.net
default passwords
42
fortypoundhead.com
default passwords
43
pspv.exe
Protected Storage PassView : | windows password grabber (from Outlook, IE, ec.)
44
Ophcrack
cracking hashes
45
L0phtcrack
cracking hashes
46
pwdump
cracking hashes
47
Active@ Password Changer
Windows password recovery
48
Trinity REscue Kit
Windows/Linux password recovery
49
ERD Commander
Windows password recovery
50
Windows Recovery Environment (WinRE)
Windows password recovery
51
PsExec
run remote command (Windows, part of PSTools)
52
auditpol
disable auditing | auditpot \clead
53
Dumpel
can be used to clear log files
54
Elsave
can be used to clear log files
55
WinZapper
can be used to clear log files
56
CCleaner
can be used to clear log files
57
Wipe
can be used to clear log files
58
Tracks Erase Pro
can be used to clear log files
59
Clear My History
can be used to clear log files
60
MRU-Blaster
can be used to clear log files
61
SFIND
Find ADS streamed files (Windows)
62
LNS
Find ADS streamed files (Windows)
63
Tripwire
detects files changes, including ADS streamed files. (Windows)
64
Shark
creates botnet
65
Plugbot
creates botnet
66
Poison Ivy
creates botnet
67
LOIC
Low Orbit Ion Cannon botnet/DDOS
68
DoSHTTP
HTTP Flood
69
UDP Flood
UDP DoS
70
Jolt2
IP packet fragmentation DoS
71
Targa
DoS multitool
72
Trinoo
DDos (UDP Flooding)
73
TFN2K
DDoS (UDP, SYN, UDP Flood)
74
Stacheldraht
DDoS
75
PacketCreator
MITM
76
Ettercap
MITM
77
Dsniff
MITM
78
WebScarab
HTTP Proxy
79
Paros Proxy
HTTP Proxy
80
Burp Suite
HTTP Proxy
81
ProxyFuzz
HTTP Proxy
82
Odysseus Proxy
HTTP Proxy
83
Fiddler (by Microsoft)
HTTP Proxy
84
dnsspoof
spoofs dns