Aug 18, 2009

My fishes - Xemo and Memo

Posted in , by \x01 | Edit
Yesterday I bought 2 fish.

White-tailed = Xemo

Orange-tailed = Memo

A few images ;



















English E-Book

Posted in by \x01 | Edit
Courses




Expressions



Applications




Translated




Grammer




Online Courses




language : turkish

download here

Url Dumper v1.8

Posted in , , by \x01 | Edit


Pretty nice tool.

Features:
  • DataBase
  • Url
  • XSS
  • SQL
Ethical hacking tool. Just download and try it.

Download: Here

SQL INJECTION


Sqlmap 0.7 Released ~ Automatic SQL Injection Tool

sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.

Recent Changes

Along all the takeover features introduced in sqlmap 0.7 release candidate 1, some of the new features include:

  • Adapted Metasploit wrapping functions to work with latest 3.3 development version too.
  • Adjusted code to make sqlmap 0.7 to work again on Mac OSX too.
  • Reset takeover OOB features (if any of –os-pwn, –os-smbrelay or –os-bof is selected) when running under Windows because msfconsole and msfcli are not supported on the native Windows Ruby interpreter.
  • This make sqlmap 0.7 to work again on Windows too.
  • Minor improvement so that sqlmap tests also all parameters with no value (eg. par=).
  • HTTPS requests over HTTP proxy now work on either Python 2.4, 2.5 and 2.6+.
Download: Here

~~~~~~~~~~~~~~~~~~~~~~

MultiInjector v0.3

So, if i’ve posted about this tool Here a few months ago. But today we have the latest version of this program.

Features

  • Receives a list of URLs as input
  • Recognizes the parameterized URLs from the list
  • Fuzzes all URL parameters to concatenate the desired payload once an injection is successful
  • Automatic defacement - you decide on the defacement content, be it a hidden script, or just pure old “cyber graffiti” fun
  • OS command execution - remote enabling of XP_CMDSHELL on SQL server, subsequently running any arbitrary operating system command lines entered by the user
  • Configurable parallel connections exponentially speed up the attack process - one payload, multiple targets, simultaneous attacks
  • Optional use of an HTTP proxy to mask the origin of the attacks

CHANGELOG

  • Automatic defacement - Try to concatenate a string to all user-defined text fields in DB
  • Run any OS command as if you’re running a command console on the DB machine
  • Execute SQL commands of your choice
  • Enable OS shell procedure on DB - Revive the good old XP_CMDSHELL where it was turned off
  • Add administrative user to DB server with password: T0pSeKret
  • Enable remote desktop on DB server
  • Fixed nvarchar cast to varchar. Verified against MS-SQL 2000
  • Added numeric / string parameter type detection
  • Improved defacement content handling by escaping quotation marks
  • Improved support for Linux systems
  • Fixed the “invalid number of concurrent connections” failure due to non-parameterized URLs

Download: Here

Read more: Here

~~~~~~~~~~~~~~~~~~~~~~

BSQL - SQL INJECTION Fremework / Tool


BSQL (Blind SQL) Hacker is an automated SQL Injection Framework / Tool designed to exploit SQL injection vulnerabilities virtually in any database.

BSQL Hacker aims for experienced users as well as beginners who want to automate SQL Injections (especially Blind SQL Injections).

It allows metasploit alike exploit repository to share and update exploits.

It ships with Automated Attack modules which allows the dumping of whole databases for the following DBMS:

  • MS-SQL Server
  • ORACLE
  • MySQL (experimental)

Attack Templates for:

  • MS Access
  • MySQL
  • ORACLE
  • PostgreSQL
  • MS-SQL Server
Download: Here

~~~~~~~~~~~~~~~~


WITOOL v.1.0


WITOOL is SQL injection tool by .NET (2.0).

- For SQL Server, Oracle
- Error Base and Union Base

Environment

OS : Windows 2000/XP/2003/VISTA
Requirement : .NET(2.0) library (DOWN)

Download: here

~~~~~~~~~~~~~~~~

m4x sql injection tools download


  • m4x mysql injector more faster than similar programs because it uses different methods
  • It has proxy selection according to user choice.
  • Datas getting one to one like the other database management systems or scripts.
  • You can make your listing process faster because it's include Treeview control
  • It's include data limit.It's mean you can get data with what you decide about that
  • You can get datas from end(desc) or from start(asc)
  • You can see how much time left to end process with progressbar.
  • You can export your datas to Microsoft Excel
  • If you want do your half work later you can do it easyly with saving your database
  • If the m4x mysql injector have database user's permissions, you can execute load_file,
  • into outfile and into dumpfile functions.You can read file which do you want with load file
    and you can write your shell to directory which do you want with into out
  • It doesn't affect with Magic Quotes Gpc.It doesn't matter on or off

m4x mysql injector demonstration (How to use video)
m4x mssql injector demonstration (How to use video)


Download here

Hex Editors

Posted in , , , by \x01 | Edit

FlexHex v2.6 - full-featured hex editor

FlexHEX is a full-featured hex editor designed to edit binary files, OLE compound files, logical devices, and physical drives.
With FlexHEX you can inspect, modify, insert, search, or replace binary, ASCII, or UNICODE data.

In addition to the powerful editing functions, FlexHEX includes an unlimited Undo/Redo feature,
so you are never at risk of losing your data because of a typing error.

Powerful navigation and tracking functions make browsing binary data easy and convenient.
File navigation cannot be simpler - you can always keep track of your position with bookmarks,
area lists, jump history, and other handy tools.

Download: Here

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Portable Hex Workshop 6





The Hex Workshop Hex Editor is a set of hexadecimal development tools for Microsoft Windows, combining advanced binary editing with the ease and flexibility of a word processor. With Hex Workshop you can edit, cut, copy, paste, insert, and delete hex, print customizable hex dumps, and export to RTF or HTML for publishing. Additionally you can goto, find, replace, compare, calculate checksums, add smart bookmarks, color map, and much more. Now Hex Editor 6 has been made portable.

Hex Workshop supports drag and drop abilities and is easily used from your most frequent workspace. Hex Workshop includes a Sector Editor with disk imaging tools, a Base Converter for converting between hex, decimal and binary data types, and a Hex Calculator supporting arithmetic and logical operations. Also included is our Data Inspector that allows you to quickly edit and view data in decimal, floating point or time and date representations.

Portable 'Hex Workshop 6' does not need installation. Just carry it in a flash drive and use on any computer, even without administrator access. No settings on the host computer are changed. The portable app creates a sandbox folder in its current location, where it stores all its settings and temporary files. Make as many copies of the app as you need. No more conflicts with other applications. No more 'hijacking' of file types.

Download: Here



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Hex Workshop v6.0.1.4603

The Hex Workshop Hex Editor is a set of hexadecimal development tools for Microsoft Windows, combining advanced binary editing with the ease and flexibility of a word processor.

With Hex Workshop you can edit, cut, copy, paste, insert, and delete hex, print customizable hex dumps, and export to RTF or HTML for publishing. Additionally, you can find, replace, compare, add smart bookmarks, and generate character distributions within a sector or file. Hex Workshop supports drag-and-drop and is integrated with the Windows operating system so you can quickly and easily hex edit from your most frequently used workspaces. The Data Inspector is perfect for interpreting, viewing, and editing decimal and binary values. An Integrated Structure Viewer allows you to view and edit data in the most intuitive and convenient way.

Download: here



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

WinHex v15.3


WinHex is in its core a universal hexadecimal editor, particularly helpful in the realm of computer forensics, data recovery, low-level data processing, and IT security.

An advanced tool for everyday and emergency use: inspect and edit all kinds of files, recover deleted files or lost data from hard drives with corrupt file systems or from digital camera cards.

Feature include:
  • Disk editor for hard disks, floppy disks, CD-ROM & DVD, ZIP, Smart Media, Compact Flash...
  • Native support for FAT, NTFS, Ext2/3, ReiserFS, Reiser4, UFS, CDFS, UDF
  • Built-in interpretation of RAID systems and dynamic disks
  • Various data recovery techniques
  • RAM editor, providing access to physical RAM and other processes' virtual memory
  • Data interpreter, knowing 20 data types
  • Editing data structures using templates (e.g. to repair partition table/boot sector)
  • Concatenating and splitting files, unifying and dividing odd and even bytes/words
  • Analyzing and comparing files
  • Particularly flexible search and replace functions
  • Disk cloning (under DOS with X-Ways Replica)
  • Drive images & backups (optionally compressed or split into 650 MB archives)
  • Programming interface (API) and scripting
  • 256-bit AES encryption, checksums, CRC32, hashes (MD5, SHA-1, ...)
  • Erase (wipe) confidential files securely, hard drive cleansing to protect your privacy
  • Import all clipboard formats, incl. ASCII hex values
  • Convert between binary, hex ASCII, Intel Hex, and Motorola S
  • Character sets: ANSI ASCII, IBM ASCII, EBCDIC, (Unicode)
  • Instant window switching. Printing. Random-number generator.
  • Supports files >4 GB. Very fast. Easy to use. Extensive online help.
Download: here


Windows 7 Wallpapers






Based off the Windows 7 Home Premium, Professional, and Ultimate box art. Completely re-created in Photoshop CS2, I hope you enjoy them!

Download here

Lolifox 0.3.6

Posted in , , , by \x01 | Edit



lolifox provides a customized version of Mozilla's Firefox made for the Anime-Community. What's the difference? lolifox offers a default collection of the most important bookmarks everyone should know of.


Besides that, it extends the browser with better design for some tasks like FTP-/Gopher-index display (which looks horrible in Firefox) and other custom branding.

Planned for the future are native FTP-support, a aniDB-client and other nice things.

Is it compatible to Firefox?
lolifox is fully compatible to Firefox. So even that it is a total conversion and completly decoupled from Firefox, all plugins, extentions and themes can be used in lolifox. (Compatible version as of lf0.2.5-dev27: Firefox 2.0)

Can I run both browsers side-by-side?
Yes, you can.lolifox installs into it's own directory and has it's own configuration, so that both don't interfere with each other.

Can I import the bookmarks from Firefox to lolifox?
Yes, you can. Export them in Firefox as a bookmarks.html and import that file again in lolifox (Bookmarks Manager).

loli?
The usage of "loli" isn't intended as use of "lolicon". The project is intended for the whole audience, not only lolicons. It's intended as "the cuteness of loli found in anime".