PenBox – 침투 테스트 프레임워크
침투 테스트 프레임워크, 해커의 저장소. 마지막 버전에서는 해커가 필요로 하는 모든 스크립트를 갖추길 바랍니다.
#정보 수집 :
- nmap
- Setoolkit
- Port Scanning
- Host To IP
- wordpress user enumeration
- CMS scanner
- XSStracer - 원격 웹 서버에서 Clickjacking, Cross-Frame Scripting, Cross-Site Tracing 및 Host Header Injection을 검사합니다
- Doork - Google Dorks 수동 취약점 감사 도구
- Scan A server's Users
#비밀번호 공격 :
- Cupp
- Ncrack
- AutoBrowser Screenshot
#무선 테스트 :
- reaver
- pixiewps
- Bluetooth Honeypot GUI Framework
#익스플로잇 도구 :
- Venom
- sqlmap
- Shellnoob
- commix
- FTP Auto Bypass
- jboss-autopwn
- Blind SQL Automatic Injection And Exploit
- Bruteforce the Android Passcode given the hash and salt
- Joomla, Mambo, PHP-Nuke, and XOOPS CMS SQL injection Scanner
- cms Few
- BLACKBOx
- Liffy
#스니핑 및 스푸핑 :
- Setoolkit
- SSLtrip
- pyPISHER
- SMTP Mailer
#웹 해킹 :
- Drupal Hacking
- Inurlbr
- Wordpress & Joomla Scanner
- Gravity Form Scanner
- File Upload Checker
- Wordpress Exploit Scanner
- Wordpress Plugins Scanner
- Shell and Directory Finder
- Joomla! 1.5 - 3.4.5 remote code execution
- Vbulletin 5.X remote code execution
- BruteX - 대상에서 실행 중인 모든 서비스를 자동으로 무차별 대입합니다
- Arachni - 웹 애플리케이션 보안 스캐너 프레임워크
- Sub-domain Scanning
- Wordpress Scanning
- Wordpress Username Enumeration
- Wordpress Backup Grabbing
- Sensitive File Detection
- Same-Site Scripting Scanning
- Click Jacking Detection
- Powerful XSS vulnerability scanning
- SQL Injection vulnerability scanning
#Private Tools
- Get all websites
- Get joomla websites
- Get wordpress websites
- Find control panel
- Find zip files
- Find upload files
- Get server users
- Scan from SQL injection
- Scan ports (range of ports)
- Scan ports (common ports)
- Get server banner
- Bypass Cloudflare
#Post Exploitation
- Shell Checker
- POET
- Weeman - 피싱 프레임워크
- Insecure Web Interface
- Insufficient Authentication/Authorization
- Insecure Network Services
- Lack of Transport Encryption
- Privacy Concerns
- Insecure Cloud Interface
- Insecure Mobile Interface
- Insufficient Security Configurability
- Insecure Software/Firmware
- Poor Physical Security
- Radium-Keylogger - 여러 기능을 갖춘 Python 키로거
#Recon
#스마트폰 침투
- 배포된 에이전트에 프레임워크 연결 / 에이전트 생성
- 에이전트에 명령 전송
- 수집된 정보 보기
- 모바일 모뎀에 프레임워크 연결
- 원격 공격 실행
- 사회 공학 또는 클라이언트 측 공격 실행
- 모바일 장치에서 실행할 코드 컴파일
- Stuff 설치
- Drozer 사용
- API 설정
- 해시와 솔트가 주어진 Android 비밀번호 무차별 대입
#기타
- QrlJacking-Framework
- Sniffles - IDS 및 정규 표현식 평가를 위한 패킷 캡처 생성기
#설치
git clone https://github.com/x3omdax/PenBox.git