Sockets, Shellcode, Porting & Coding: Reverse Engineering Exploits and Tool Coding for Security Professionals

Appendix B: Security Tool Compendium

Source Code Auditing

  • Application Defense

    www.applicationdefense.com

  • Prexis

    www.ouncelabs.com

  • Fortify Software

    www.fortifysoftware.com

  • CodeAssure

    www.securesoftware.com

  • FlawFinder

    www.dwheeler.com/flawfinder/

  • ITS4

    www.cigital.com/its4/

  • RATS

    www.securesw.com/rats/

  • Splint

    www.splint.org/

Shellcode Tools

  • Metasploit

    www.metasploit.com/

  • MOSDEF

    www.immunitysec.com/MOSDEF/

  • Hellkit

    http://teso.scene.at/releases/hellkit-1.2.tar.gz

  • ShellForge

    www.cartel-securite.fr/pbiondi/shellforge.html

  • HOON

    http://felinemenace.org/~nd/HOON.tar.bz2

  • InlineEgg

    http://community.corest.com/~gera/ProgrammingPearls/InlineEgg.html

  • ADMmutate

    www.ktwo.ca/security.html

Debuggers

  • GDB

    http://sources.redhat.com/gdb/

  • GVD

    http://libre.act-europe.fr/gvd/

  • OllyDebug

    http://home.t-online.de/home/Ollydbg/

  • Turbo Debug for Borland C 5.5

    www.borland.com/bcppbuilder/turbodebugger/

  • Microsoft Debuggers

    www.microsoft.com/whdc/ddk/debugging/default.mspx

  • Compuware Driver Studio (SoftICE)

    www.compuware.com/_products/driverstudio/782_ENG_HTML.htm

  • IDA Pro

    www.datarescue.com/

Compilers

  • Microsoft Visual Studio

    www.microsoft.com

  • GCC

    www.gnu.org/software/gcc/gcc.html

  • DJGPP

    www.delorie.com/djgpp

  • CygWin

    http://cygwin.com

  • MinGW32

    http://mingw.sourceforge.net/

  • Borland C 5.5

    www.borland.com/bcppbuilder/freecompiler/

  • Watcom C

    www.openwatcom.org

  • nasm

    http://nasm.sourceforge.net/

  • MASM

    www.easystreet.com/~jkirwan/pctools.html

  • MASM32

    www.movsd.com/masm.htm

  • Assembly Studio

    www.negatory.com/asmstudio/

  • ASMDev

    http://asmdev.tripod.com/

Hardware Simulators

  • VMware

    www.vmware.com

  • Bochs

    http://bochs.sourceforge.net/

  • PearPC

    http://pearpc.sourceforge.net/

  • Virtual PC

    www.microsoft.com/windows/virtualpc/default.mspx

Security Libraries

  • Libpcap

    www.tcpdump.org/

  • LibWhisker

    www.wiretrip.net/rfp/lw.asp

  • Libnet

    www.packetfactory.net/projects/libnet/

  • Libnids

    www.packetfactory.net/projects/libnids/

  • Libexploit

    www.packetfactory.net/projects/libexploit/

  • Libdnet

    http://libdnet.sourceforge.net/

  • Lcrzo

    www.laurentconstantin.com/en/lcrzo/

  • Privman

    http://opensource.nailabs.com/privman/

  • Dyninst

    www.dyninst.org/

  • LibVoodoo

    www.u-n-f.com/releases/Libvoodoo/

  • Winpcap

    http://winpcap.polito.it/

Vulnerability Analysis

  • SPIKE

    www.immunitysec.com/spike.html

  • FuzzerServer

    www.atstake.com/research/tools/vulnerability_scanning/

  • l0phtwatch

    www.atstake.com/research/tools/vulnerability_scanning/l0pht-watch.tar.gz

  • Sharefuzz

    www.atstake.com/research/tools/vulnerability_scanning/sharefuzz1.0.tar.gz

  • COMBust

    www.atstake.com/research/tools/vulnerability_scanning/COMbust.zip

  • Bruteforce Exploit Detector

    http://snake-basket.de/bed.html

  • screamingCobra

    http://cobra.lucidx.com/

  • screamingCSS

    www.devitry.com/screamingCSS.html

  • envFuzz

    www.nologin.org/main.pl?action=codeView&codeId=15&

Network Traffic Analysis

  • Ethereal

    www.ethereal.org

  • Tcpdump

    www.tcpdump.org

  • WinDump

    http://windump.polito.it/

  • Snort

    www.snort.org

  • Ettercap

    http://ettercap.sourceforge.net/

  • TCPreplay

    http://sourceforge.net/projects/tcpreplay/

  • TCPslice

    www.tcpdump.org/other/tcpslice.tar.Z

  • TCPtrace

    www.tcptrace.org/

  • TCPflow

    www.circlemud.org/~jelson/software/tcpflow/

  • EtherApe

    http://etherape.sourceforge.net/

  • NetDude

    http://netdude.sourceforge.net/

  • Ngrep

    http://ngrep.sourceforge.net/

Packet Generation

  • Hping2

    www.hping.org/

  • ISIC

    www.packetfactory.net/Projects/ISIC/

  • dnet

    http://libdnet.sourceforge.net/

  • IRPAS

    www.phenoelit.de/irpas/docu.html

  • Paketto Keiretsu

    www.doxpara.com/paketto

  • fragroute

    www.monkey.org/%7Edugsong/fragroute/

  • naptha

    http://razor.bindview.com/publish/advisories/adv_NAPTHA.html

Scanners

  • Foundstone

    www.foundstone.com

  • Application Defense

    www.applicationdefense.com

  • Retina

    www.eeye.com

  • Internet Scanner

    www.iss.net

  • NMAP

    www.insecure.org/nmap/

  • Scanline

    www.foundstone.com

  • AMAP

    www.thc.org

  • Nessus

    www.nessus.org

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Microprocessor and IC Programmers, Compilers, and Debuggers
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.