Author Topic: [APP] dSploit *Latest*  (Read 14662 times)

0 Members and 1 Guest are viewing this topic.

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
[APP] dSploit *Latest*
« on: October 16, 2012, 08:52:38 pm »


Requirements: Rooted Device, Busybox

Description:
dSploit is an Android network analysis and penetration suite which aims to offer to IT security experts/geeks the most complete and advanced professional toolkit to perform network security assesments on a mobile device. Once dSploit is started, you will be able to easily map your network, fingerprint alive hosts operating systems and running services, search for known vulnerabilities, crack logon procedures of many tcp protocols, perform man in the middle attacks such as password sniffing ( with common protocols dissection ), real time traffic manipulation, etc, etc . This application is still in beta stage, a stable release will be available as soon as possible, but expect some crash or strange behaviour until then, in any case, feel free to submit an issue on GitHub.

Why?
You might ask why there's the need of another tool like zAnti, NetSpoofer, DroidSheep, FaceNiff, etc. Well, first of all, the only software which is comparable to dSploit in terms of features and support is zAnti ( refer to the following comparison table ), which is a proprietary tool and obviously closed source. Don't get me wrong, i have nothing against proprietary software, i've been in contact with zAnti staff for a while now, i think they're a really great and open minded team, but closed source is closed source, there's no community contribution and most of all, you have to pay for it. Secondly, every tool i've found was very specific, none of them had every feature i needed so most of the times i had to use three or four tools at a time, which is kinda frustrating.
Therefore, dSploit was born, only one ( open source ) tool to rule them all! :D



Github Project Page:
https://github.com/evilsocket/dsploit/

Download:
http://update.dsploit.net/apk

Download Nightly:
http://update.dsploit.net/nightly

Developers Website:
http://www.dsploit.net/
« Last Edit: June 18, 2014, 12:13:32 am by DeepCopy »

Z3R0

  • Guest
Re: dSploit - android network pentest suite
« Reply #1 on: October 16, 2012, 10:11:32 pm »
This looks pretty cool. :)

Offline Dameon

  • Serf
  • *
  • Posts: 48
  • Cookies: 1
    • View Profile
Re: dSploit - android network pentest suite
« Reply #2 on: October 19, 2012, 04:02:51 am »
this is interesting will give this a look

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Re: dSploit - android network pentest suite
« Reply #3 on: November 02, 2012, 10:11:19 am »
I use wifiInspect from the play store. Works pretty well on android 4 rooted. Implements pcap, and analyzer, nmap and some security audits
~Factionwars

Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
Re: dSploit - android network pentest suite
« Reply #4 on: November 03, 2012, 04:21:33 am »
Testing it out, will let you know results

(btw running on CDMA Galaxy Nexus 4.1.1 JR003O stock rooted)



Edit:
"Inspector" worked scanning windows 7 machine
"Vulnerability Scanner" is scanning and displaying vulnerability assessments

ie:
uTorrent utserver web interface
Nothing Found

Microsoft Windows RPC
CVE-2009-2523: The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers (blah blah blah.........)

Other listed as well so I say this works as well ;)


MITM Password Sniffer
Didn't work for facebook.com in IE (not https) so I deem unworking!


I'll be messing around with it more. Some aspects work whilst others do not
« Last Edit: November 03, 2012, 04:32:12 am by skidiot.h »
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline D4rKn355

  • Serf
  • *
  • Posts: 22
  • Cookies: 0
  • This is it... This is where i belong...
    • View Profile
Re: dSploit - android network pentest suite
« Reply #5 on: November 10, 2012, 02:45:37 pm »
Bro this is the greatest android hacking tool that i have ever come across.
My phone is Samsung Galaxy S3 rooted, with original rom, installation fine, running fine. But after some time i notice it's becoming a bit slow. The vulnerability scanner is not good i think, cuz it always display nothing found, when i run it.
The session hijacking function is the greatest thing of the app. I have hijacked several facebook account with that, feels so cool at the first time hijacking.

And btw the simple redirect function has description "reroute traffic through this device, for other sniffers like sharp" Do you guys know what is sharp?
1010100 1101000 1101001 1110011 100000 1101001 1110011 100000 1101111 1110101 1110010 100000 1110111 1101111 1110010 1101100 1100100 100000 1101110 1101111 1110111 101110 101110 101110 100000 1010100 1101000 1100101 100000 1110111 1101111 1110010 1101100 1100100 100000 1101111 1100110 100000 1100101

Offline meepirates

  • NULL
  • Posts: 3
  • Cookies: -3
  • Geek 0-0
    • View Profile
Re: dSploit - android network pentest suite
« Reply #6 on: April 23, 2014, 08:14:27 pm »
How can i use the hijacked session which i did using dsploit ? The file format is in .dhs. 

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: dSploit - android network pentest suite
« Reply #7 on: April 23, 2014, 08:57:59 pm »
How can i use the hijacked session which i did using dsploit ? The file format is in .dhs. 
You swallow it.

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: dSploit - android network pentest suite
« Reply #8 on: April 24, 2014, 12:48:37 am »
Kulver +1
« Last Edit: June 18, 2014, 09:09:34 am by Kulverstukas »

Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
Re: [APP] dSploit *Latest*
« Reply #9 on: June 18, 2014, 12:12:42 am »
Fixed up formatting, added developers webpage and detailed information. Also included direct link APK for the latest stable version as well as a link to the nightly builds
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline haxcore

  • NULL
  • Posts: 4
  • Cookies: 0
    • View Profile
Re: [APP] dSploit *Latest*
« Reply #10 on: November 11, 2014, 11:47:43 am »
anyone still got the last dSploit 1.1.3c nightly build apk? seems that dSploit have been merged onto zAnti 2.0. right now, dSploit 1.1.3c has been re-modified by AntStudio (available on PS and other appstore)  which is crap. I want the original apk or source code  made by evilsocket himself. The source code on github is not available anymore.

Offline Schalla

  • VIP
  • Peasant
  • *
  • Posts: 81
  • Cookies: 29
    • View Profile