Author Topic: Ethical Hacking Tool [XSS,SQLi,RFI/LFI...]  (Read 1654 times)

0 Members and 1 Guest are viewing this topic.

Offline jhN

  • NULL
  • Posts: 2
  • Cookies: 1
    • View Profile
Ethical Hacking Tool [XSS,SQLi,RFI/LFI...]
« on: February 20, 2015, 04:53:24 pm »
Hello, I'm currently studying network and systems programming. I was proposed for a project, because it is the last year on the school.

I decided to develop a security tool because I have some knowledge in pentesting, and it was a challenge for me to do something related with programming and security. Both software source codes are available on my GitHub (http://github.com/joaovarelas/vuln-scanner)
 
 The main app, the scanner, was coded in C++ with the help of Qt IDE. It allows to scan vulnerable services in a target machine, test cross-site scripting (XSS) in web applications, SQL injection, local and remote file inclusion, and many others.
 
 The second app, the vuln database, was coded in PHP and MySQL. It will save all the scans done with the main application for further analysis and exploitation.
 
 I'm sharing with you guys, because I would like to know what you think about the idea. Until now, I'm still having a nice feedback from it.

Screenshots:






Small video:

https://docs.google.com/file/d/0BwPFOxkRfkGgb1d3b2ZDLTc0OXc/edit


Download: source-code + binaries -> https://github.com/joaovarelas/vuln-scanner

Thanks in advance.
« Last Edit: February 20, 2015, 05:41:22 pm by Kulverstukas »

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: Ethical Hacking Tool [XSS,SQLi,RFI/LFI...]
« Reply #1 on: February 20, 2015, 05:40:54 pm »
It would be more useful if it was in proper English... and since you provide the source, this is moved.

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
Re: Ethical Hacking Tool [XSS,SQLi,RFI/LFI...]
« Reply #2 on: February 20, 2015, 05:57:15 pm »
Has someone tested how much noise it makes. Not in the moods for it and i wouldn't know which commands to use when it is in a language alien to me.
Ok, since it is for a school project but GUI isn't much in most of our tests. I think i should look at the code when i get time but i am not mush for QT
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]

Offline jhN

  • NULL
  • Posts: 2
  • Cookies: 1
    • View Profile
Re: Ethical Hacking Tool [XSS,SQLi,RFI/LFI...]
« Reply #3 on: February 20, 2015, 08:35:06 pm »
Sorry, this is for the school. It is written in portuguese. I'm planning to allow the user to choose both languages in the future because I don't have many time now.

Thanks and regards

Offline hppd

  • Knight
  • **
  • Posts: 163
  • Cookies: 7
    • View Profile
Re: Ethical Hacking Tool [XSS,SQLi,RFI/LFI...]
« Reply #4 on: February 21, 2015, 02:01:02 am »
Haha nice first post man good job and welcome to ez. How was your score?

ps I'm going to portugal in 2 weeks :P