<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.1" -->
<rss version="0.92">
<channel>
	<title>bLackhammer.org</title>
	<link>http://blackhammer.org</link>
	<description>Ethical Hacking &#124; Penetration Testing &#124; Computer Security</description>
	<lastBuildDate>Fri, 16 May 2008 15:27:41 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Xprobe2 - Active OS Fingerprinting Tool</title>
		<description>Sometimes I wonder to myself have I mentioned a certain tool on the site, usually one of my favourites…often I search the site to find I have never posted about it.

It just goes to show how we often overlook some of the more ‘obvious’ choices, and to many people they ...</description>
		<link>http://blackhammer.org/xprobe2-active-os-fingerprinting-tool/</link>
			</item>
	<item>
		<title>browserrecon - Passive Browser Fingerprinting</title>
		<description>Most of todays tools for fingerprinting are focusing on server-side services. Well-known and widely-accepted implementations of such utilities are available for http web services, smtp mail server, ftp servers and even telnet daemons. Of course, many attack scenarios are focusing on server-side attacks.

Client-based attacks, especially targeting web clients, are becoming ...</description>
		<link>http://blackhammer.org/browserrecon-passive-browser-fingerprinting/</link>
			</item>
	<item>
		<title>Metagoofil v1.4 Released - Metadata and Information Gathering Tool</title>
		<description>Metagoofil is an information gathering tool designed for extracting metadata of public documents (pdf,doc,xls,ppt,odp,ods) available on the target/victim website.

It will generate a html page with the results of the metadata extracted, plus a list of potential usernames very useful for preparing a bruteforce attack on open services like ftp, pop3,web ...</description>
		<link>http://blackhammer.org/metagoofil-v14-released-metadata-and-information-gathering-tool/</link>
			</item>
	<item>
		<title>rtpbreak 1.3a Released - RTP Analysis and Hacking</title>
		<description>With rtpbreak you can detect, reconstruct and analyze any RTP session. It doesn’t require the presence of RTCP packets and works independently form the used signaling protocol (SIP, H.323, SCCP etc). The input is a sequence of packets, the output is a set of files you can use as input ...</description>
		<link>http://blackhammer.org/rtpbreak-13a-released-rtp-analysis-and-hacking/</link>
			</item>
	<item>
		<title>Sandman - Read the Windows Hibernation File</title>
		<description>This is a pretty new tool and a very cool one, Hibernation is a fairly new feature for Windows so it’s good to see a new tool targeting that.

Microsoft provides a feature called Hibernation also know as suspend to disk that aims to save the system state into an undocumented ...</description>
		<link>http://blackhammer.org/sandman-read-the-windows-hibernation-file/</link>
			</item>
	<item>
		<title>CDPSnarf - CDP Packet Sniffer</title>
		<description>CDPSnarf if a network sniffer exclusively written to extract information from CDP packets. It provides all the information a “show cdp neighbors detail” command would return on a Cisco router and even more.

The application is written in C using the popular PCAP library.

Sample Output

Cisco AIR-AP1231G-E-K9 Access Point:
$ sudo ./cdpsnarf eth2
Waiting ...</description>
		<link>http://blackhammer.org/cdpsnarf-cdp-packet-sniffer/</link>
			</item>
	<item>
		<title>Technitium MAC Address Changer v4.8 Released for Download - Free</title>
		<description>Technitium MAC Address Changer allows you to change Media Access Control (MAC) Address of your Network Interface Card (NIC) irrespective to your NIC manufacturer or its driver. It has a very simple user interface and provides ample information regarding each NIC in the machine. Every NIC has a MAC address ...</description>
		<link>http://blackhammer.org/technitium-mac-address-changer-v48-released-for-download-free/</link>
			</item>
	<item>
		<title>Pass-The-Hash Toolkit v1.3</title>
		<description>The Pass-The-Hash Toolkit contains utilities to manipulate the Windows Logon Sessions maintained by the LSA (Local Security Authority) component. These tools allow you to list the current logon sessions with its corresponding NTLM credentials (e.g.: users remotely logged in thru Remote Desktop/Terminal Services), and also change in runtime the current ...</description>
		<link>http://blackhammer.org/pass-the-hash-toolkit-v13/</link>
			</item>
	<item>
		<title>WifiZoo v1.3 Released - Passive Info Gathering for Wifi</title>
		<description>WifiZoo is a tool to gather wifi information passively. It is created to be helpful in wifi pentesting and was inspired by ‘Ferret‘ from Errata Security.

The tool is intended to get all possible info from open wifi networks (and possibly encrypted also in the future, at least with WEP) without ...</description>
		<link>http://blackhammer.org/wifizoo-v13-released-passive-info-gathering-for-wifi/</link>
			</item>
	<item>
		<title>HDIV - Java Web Application Security Framework</title>
		<description>HDIV (HTTP Data Integrity Validator) is a Java Web Application Security Framework. HDIV extends web applications’ behaviour by adding Security functionalities, maintaining the API and the framework specification. This implies that we can use HDIV in applications developed in Struts 1.x, Struts 2.x, Spring MVC and JSTL in a transparent ...</description>
		<link>http://blackhammer.org/hdiv-java-web-application-security-framework/</link>
			</item>
</channel>
</rss>
