PenBox – Um Framework de Teste de Penetração
Um Framework de Teste de Penetração, O Repositório do Hacker. Nossa esperança é que na última versão teremos todos os scripts que um hacker precisa.
#Coleta de Informações :
- nmap
- Setoolkit
- Port Scanning
- Host To IP
- wordpress user enumeration
- CMS scanner
- XSStracer - verifica servidores web remotos para Clickjacking, Cross-Frame Scripting, Cross-Site Tracing e Injeção de Cabeçalho de Host
- Doork - Auditor Passivo de Vulnerabilidades do Google Dorks
- Scan A server's Users
Ataques de Senha :
- Cupp
- Ncrack
- AutoBrowser Screenshot
Testes de Rede Sem Fio :
- reaver
- pixiewps
- Bluetooth Honeypot GUI Framework
Ferramentas de Exploração :
- Venom
- sqlmap
- Shellnoob
- commix
- FTP Auto Bypass
- jboss-autopwn
- Blind SQL Automatic Injection And Exploit
- Bruteforce the Android Passcode given the hash and salt
- Joomla, Mambo, PHP-Nuke, and XOOPS CMS SQL injection Scanner
- cms Few
- BLACKBOx
- Liffy
Sniffing e Spoofing :
- Setoolkit
- SSLtrip
- pyPISHER
- SMTP Mailer
Hacking Web :
- Drupal Hacking
- Inurlbr
- Wordpress & Joomla Scanner
- Gravity Form Scanner
- File Upload Checker
- Wordpress Exploit Scanner
- Wordpress Plugins Scanner
- Shell and Directory Finder
- Joomla! 1.5 - 3.4.5 remote code execution
- Vbulletin 5.X remote code execution
- BruteX - Força bruta automaticamente todos os serviços em execução em um alvo
- Arachni - Framework de Scanner de Segurança para Aplicações Web
- Sub-domain Scanning
- Wordpress Scanning
- Wordpress Username Enumeration
- Wordpress Backup Grabbing
- Sensitive File Detection
- Same-Site Scripting Scanning
- Click Jacking Detection
- Powerful XSS vulnerability scanning
- SQL Injection vulnerability scanning
#Ferramentas Privadas
- Get all websites
- Get joomla websites
- Get wordpress websites
- Find control panel
- Find zip files
- Find upload files
- Get server users
- Scan from SQL injection
- Scan ports (range of ports)
- Scan ports (common ports)
- Get server banner
- Bypass Cloudflare
#Pós-Exploração
- Shell Checker
- POET
- Weeman - Framework de Phishing
- Insecure Web Interface
- Insufficient Authentication/Authorization
- Insecure Network Services
- Lack of Transport Encryption
- Privacy Concerns
- Insecure Cloud Interface
- Insecure Mobile Interface
- Insufficient Security Configurability
- Insecure Software/Firmware
- Poor Physical Security
- Radium-Keylogger - keylogger em Python com múltiplas funcionalidades
#Reconhecimento
#Penetração em Smartphones
- Attach Framework to a Deployed Agent/Create Agent
- Send Commands to an Agent
- View Information Gathered
- Attach Framework to a Mobile Modem
- Run a remote attack
- Run a social engineering or client side attack
- Compile code to run on mobile devices
- Install Stuff
- Use Drozer
- Setup API
- Bruteforce the Android Passcode given the hash and salt
#Outros
- QrlJacking-Framework
- Sniffles - Gerador de Captura de Pacotes para IDS e Avaliação de Expressões Regulares
#Instalação
git clone https://github.com/x3omdax/PenBox.git