filename:
file description:
23:
coded in assembly by wow (world of wonder) this trojan came on the scene with some nice features then quickly faded .give this one a try. hope wow. starts the second edition of this soon.
a notification tool with a few different methods of notification.(icq,irc,cgi,mail), also has av and firewall kill. and as a bonus you can add a name of any .exe you wanna kill also
buschtrommel is one of the first trojans to utilize commands over ack segments ... this german trojan quickly faded after the release hopefully more to come soon
converts .exe files into visual basic script.if you know how to script you can have your .exe then do different things.. i.e. outlook spread, etc.
converts .exes into an html file. can be used to silently download exes through an exploit in internet explorer.similar method to godwill and godmessage
a 423 byte trojan that will download and execute a file from an ftp server .. the victim thinks that windows is fixing bad sectors on the hard drive while its downloading.
kick ass tool made by my friend kid arcade. this tool allows you to create an html file containing your trojan encoded in it. also allows you to create an email attachment or make a html page that opens shares and ftp on lans.after veiwing any of these the trojan will stay in the start up folder until comp is restart which then executes the trojan.
very small uploader trojan. very easy to make undetected by adding null bytes to it.use for embedding in html pages etc. cuz of its small size.
net devil is quickly becoming the trojan of choice .. similar interface to sub7 this trojan will work on 9x/me/nt/2k.
coded in c by stan this uploader trojan also features a file manager d upload/download anything. real reliable
this trojan acts as a bouncer proxy .. allows you to relay all your internet activity through someone else to stealth yourself :)
a very good program that allows you to see the desktop of a victim in real time and allows for mouseclicks /file transfers /cmd prompt etc.
small 80kb server .. emails you the ip of the server, has remote gui/file transfers /cmd prompt and a shitload more options :::here::: which allows you to control and find your servers on a network and remotely comes with pdf manual
new version!! works on all windows!!.
by arne vidstrom of ntsecurity. the first one ,tini, is a very small backdoor made in assembler only 3kb which opens a port on 7777 which allows you to send commands to its dos shell it creates, very good if you are fluent in dos commands. the second, ack , is a command line trojan and server which uses ack command segments to send commands .. bypasses some firewall security (firewall tunneling) since most firewalls only block udp and icmp
vnc:
a corporate backdoor .. install allows you to remotely control any computer . not recommended for home computer but more for server that are unattended to allow you to get in and install without and one seeing this on their monitor
"web-server" that allows you to browse victim's computer with any browser on any OS.u have just to open http://victims_ip[:port] in your browser.
opens a port on 21 with r00t access that allows for you to ftp and tranfer files to or from your victim
Open source IRC controlled bot that you can modify to fit you needs ::MOD SITE::
aka 'green lantern' the trojan the fbi supposedly used to hack into suspects.needs a registration key .. a crudley cracked version is ::here:: it was cracked about 6 hours from the time it was released
revision of the infamous netcat with twofish encryption added.
use it to redirect tcp traffic to get around firewalls etc
this program is based off of netcat. this program allows multiple connections while netcat only allows one and is a bit easier to use.
attempts to send garbled fragmented packets to escape intrusion detection programs
tcp redirector it listens on a port and redirects all tcp traffic to another ip and port. optionally, nbounce logs all traffic to disk.
a light weight telnet server. it's small and compact at 36k. given a ort and a password it will listen for inbound telnet connections. it can handle multiple connections at the same time. if you need a remote shell on a windows box this can come in handy.
winrelay is a tcp/udp forwarder/redirector. you can choose the port and ip it will listen on, the source port and ip that it will connect from, and the port and ip that it will connect to.
this proxy redirect program lets you to proxy with any web program that allows you to connect to an ip and port. for example you wish to telnet to a telnet server but not expose your true ip to that server, it will see the ip of the proxy accessing it.
basically a smaller open source vnc.. it allows to remotely view a desktop and other shit ..always undetected
alls this trojan does is allow you to view the victims webcam and nothing more.. needs to add a startup method and some sort of notification to it like illicq :)
one of the fist trojans to feature lan technology using the server to connect to the client that way the outbound connection will be able to be used on a lan
rootkit for Windows NT 4.0, Windows 2000 and Windows XP.
made by phrostic this webdler for win9x is only 826 bytes!! use it to download a larger trojan from a website url
tiny telnet trojan made by janker.. access the trojan through telnet allows you to have multiple connections ,reboot and shutdown,download files also
Windows NT/2000, Extended Telnet Services, support file transfers, support reverse-connect through firewall
 
[back to top]

 

filename:
file description:
keylogger for windows 2000 creates a text file in the directory it was executed in.
made by illwill of illmob.org this tiny asm logger is only 2kb restarts with windows and will logs the files by date in the %sysdir%/logs folder. works on win9x/me/nt/2k looks for newer and better versions to come.
this keylogger will mail you the logs after they reach a certain size
ring0 vxd keylogger
keyspy is an invisible spy software. it is a keyboard logger and a pc remote controller. the spy's engine, which is created from the setup program (480k), is only 64k in size. for win9x/me
keystroke logging tool that runs under several windows 32 versions (it should also run under nt). the best of it's features is it's small size: only 7 kb compiled.
tiny key logger is a very small program that runs hidden in the background, and secretly records every keystroke pressed in all applications. each time a key is pressed in a different window, it logs the window title and application path, along with a timestamp. its author made it for local installation bur for remote install just set it up normally on your own comp and then send the .dll and .exe to the victim and them execute it its only 7.50 kb in size when installed. and works on all version of windows.
sc-keylog logs all keyboard activity to a file. every single typed character and control button can be logged. it can be used to monitor your productivity or to spy on others. sc-keylog can also log the names of the programs used and the date and time of entered characters.
msgate v0.1 aka simple keylogger for ms windows nt/xp by codemorpher.
only 6kb!!! it can capture ALL keyboard strokes by any user, and record them to a log file. KeySpy is written in assembly language, hence it is and .
A simple and effective keyboard logger Written in Assembly Language only 8kb
 
[back to top]

 

filename:
file description:
made by sysinternals this program will show you everything that starts up in your registry, wini.ini files.
made by xeo this program takes autoruns a step further. shows everything that starts up in the registry,wini.ini,system.ini,and even check for the hidden exe command key that sub7 uses to restart itself... gives you that option of deleting keys.. a must have for any trojan tester/user
crypto-lock is a program that will encrypt your files. the password is not stored in the resultant file. the password you entered during encryption is processed with sha-1 and the message digest is encrypted using blowfish(random cbc mode) to produce the key.
made from sysinternals this will monitor your folders for any changes to files
monitors your registry for any changes, for win9x. you can dl the nt version ::here::
pgp:
pretty good privacy. this will encrypt just about anything you do online or on your computer.even outlook mail , icq etc... you can never be too paranoid , believe me.
can kill any running process running even the ones hidden from ctrl-alt-del, for win9x. you can dl the nt version ::here::
shows all inbound and outbound connections to your computer.
will set up your windows 95 or 98 pc so that your internet explorer cache, cookies, url history and typed urls are stored in ram and never written to disk. this enables you to accept cookies for more convenient surfing without leaving traces of your comings and goings on your local machine after re-booting or powering off. you can dl the nt/xp version ::here::
securely deletes files and folder on your hard drive overwritting them to prevent recovery,also can "blank out" the free space on your disk, thus destroying any leftover fragments of files that were previously deleted.
List of some free firewalls
made in delphi this uses the little published win98 secret found on astalavista.com to lock folders
use this utility to see if your firewall has leaks in it...this made me switch from conseal firewall to tiny firewall
shows all active tcp/ip connections on your computer. has a shit load of options including packetmonitoring and other shit.. check it out
commercial program which gets rid of history trail etc.. cracked by fosi
securely delete files ect...
this program will connect to micosoft and make sure all your hotfixes are up to date for nt/2k/xp
encrypts your files
ever wonder why microsoft left out msconfig for win2k? this program is a hacked up modification of the xp version made to work with win2k :)
help protect your privacy by dynamically connecting to non-transparent anonimizing public proxy servers only. you can also test a list of proxy servers and sort them by connection speed and level of anonimity.
eraser is an advanced security tool, which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns. you can drag and drop files and folders to the on-demand eraser, use the convenient explorer shell extension or use the integrated scheduler to program overwriting of unused disk space or, for example, browser cache files to happen regularly, at night, during your lunch break, at weekends or whenever you like.
tcpview is a windows program that will show you detailed listings of all tcp and udp endpoints on your system, including the owning process name, remote address and state of tcp connections. tcpview provides a conveniently presented subset of the netstat program that ships with windows nt/2000/xp.
 
[back to top]

 

filename:
file description:
made by my friend thelooserkiller.. this asm program will decrypt your aim passwords and user names from the registry using aim's own oscore.dll only 7kb... unfortunately aims newer version does not use this dll anymore stay tuned while we work on a new version.
command line utility. change the password of any windows nt/2000 account from anywhere in the world.
burn this .iso as a bootable cd and when you boot from it it will reset the administrator password to a blank password.
make a bootable floppy disk then rawrite the files to the floppy to allow you to boot into a linux type os that will allow you to rewrite the nt password to anything you want
getacct sidesteps "restrictanonymous=1" and acquires account information on windows nt/2000 machines.
famed password cracker
cracks the sam password of winnt/2k can also decrypt password hashes from pwdump3. if you want to own a nt box learn how to use this.get older version l0phtcrack 3.0
this program grabs password hashes from remote windows nt/2000 machines.it prints them to the screen in standard l0phtcrack format, or will optionally write them to a file if desired.
this program will capture the crypted password from ram memory, if successful, passdump will decrypt it and write to a file named "pass.txt", this file was in your windows directory, such as: c:\winnt\pass.txt.
attempts to crack share passwords.
this program with show you the passwords hidden by ***** also can be used for an api spy
shows whats hidden under the *******. by arne vidstrom
spc:
share password checker by security friday checks passwords of remote ip
ares:
html pop3 ftp cracker with proxy support , will not work on https protocol (hotmail) has extra tools that can create word lists with it kill dupe setc
this component of brutus is capable of authenticating against a wide range of character based application protocols. this is used to facilitate dictionary based user/password attacks against various network applications. this release comes with the following built-in network applications :
http - basic authentication
http - cgi application authentication (typically used with html forms)
ftp
pop3
telnet
for nt/2k/xp this program puts up a dummy screen to pretend like the console is locked (like ctrl-alt-del does) then you tell the admin youre locked out and have them think they are unlocking it but in reality your saving the password to a text file :) a little social engineering never hurt nobody
munga bunga's http brute forcer is a utility utilizing the http protocol to brute force into any login mechanism/system that requires a username and password, on a web page (or html form).
great for password retrieval or for enforcing password selection guidelines, the oracle password cracker is a utility which can be used by database administrators to obtain a clear-text password for any user account in an oracle database

samman is a tool for recovering microsoft windows nt/2000 passwords. it reads files generated from pwdump[1-3] and uses dictionary and brute-force based attacks on the cryptographic hashes of the passwords.
a win32 application, developed in assembly, for encrypting and decrypting passwords from ibm net.commerce, websphere and possibly other ibm and lotus applications aswell.

not exactly a password recovery item but this burned to a cd will shut down a running screensaver when inserted into a cd drive
attempts a dictionary attack on password protected zip files.

pwdspy/pwd recovery a simple program to unhide passwords under the ******
this will pop up a fake aim signon screen to trick the user into inputting there user/pw and saves it to a text file

pop3 brute force tool
cgi pop3 ftp smtp auditor

recover forgotten passwords and see windows security weakness with pwltool
 
[back to top]

 

filename:
file description:
very fast and reliable port scanner. everyone uses this one.can output to text file
scan modules include www, sql, ftp, various nt checks, smtp, pop3, dns,finger and more
getacct sidesteps "restrictanonymous=1" and acquires account information on windows nt/2000 machines.
scan for cgi vulnerabilites
port scanner with a sweet interface works on win9x/2k
command line scanner that scans for tcp and udp ports
scan nt boxes running smb port139 for user name lanman hashes
checks nt server for the unicode bug which allows you to gain acces on any nt/2k machine :)
program with many tools like ping traceroute whois and other .. check it out its pretty nice.
this is one of the first progs for windows use that will attempt to get a fingerprintprint of an ip... i.e. what os and services are running on it. sort of like fyodors nmap for unix
get a visual of where in the world an ip is.
toolbox full of tools like whois,ping,finger,traceroute,http header info etc...
very small and very fast port scanner
fast port scanner also gives feedback info from open ports
famous,old, but still useful net tools.
made by my friend burden this ip grabber tool for aol/aim/yahoo or any messenger service where you can cut and paste will send a link to your victim , when they click it ,it will return the ip to you, also has options to scan the ip for open ports.alot of other options too check it out !! http://burden.cc
by mf4, this tool with check a variety of stmps to see if they are open for mail.. saves time of doing it manually in telnet.
tftp:
trivial file tranfer protocol ..comes with win2k this will open a server on your computer to either send or recieve files from nt/2k boxes when using exploits such as the unicode sploit.check out the text achive for ways to exploit unicode :)
traceroute and whois from the guys at foundstone
scan for many web server cgi vulnerabilites
standalone mini ip gui trace tool sort of like neotrace but smaller and no install
tries to enumerate smb server queries to figure out what the box os is running and many other features. the best thing for windows thats next to unix tools
win sniffer is the best tool to intercept and log passwords in your lan. it works as a sniffer, by intercepting all the traffic in your local segment. it works on ethernet, ppp and other lan.
vision, a host based forensic utility is the gui successor to the well-known freeware tool, fport. this innovative new product from foundstone shows all of the open tcp and udp ports on a machine, displays the service that is active on each port, and maps the ports to their respective applications. vision allows users to access a large amount of supplementary information that is useful for determining host status by displaying detailed system information, applications running, as well as processes and ports in use.
the smtp spy finds & tests free useable smtps.
vulnerability assessment software that currently provides more than 18000 security checks. it is effective at reducing the exposure of an web server to potential attacks.
command line scanner has syn fin null xmas scans.
assessment software shows everything on local or remote network ,open port,it enums the port to show whats running get user names domain names computer names.. a whole shitload of stuff.
provides all the tools you need to help diagnose network problems and get information about users, hosts and networks on the internet or on your intranet.ping,trace,whois,lookup,finger,daytime,html headers,services,and scanner are the tools it offers.
gui ethernet packet sniffer for 2k/xp
irs:
the main purpose of irs is to find out ip restrictions set my a particular service on a host. it combines arp poisoning and half scan techniques and tries totally spoofed tcp conections to the selected port of the target.
all around console network toolbox has everything you can imagine
nmap:
prolly one of the best scanners ..made by fyodor this one attempts to have a gui frontend for all the newbies to use
very good packet sniffer
remote packet sniffer by aphex using code he ripped
the retina sql worm scanner is a tool created by eeye that is able to scan up to 254 ip addresses at once and determine if any are vulnerable to the recent sql worm (aka: spida, digispid.b.worm).
the retina apache chunked scanner is a tool created by eeye that is able to scan up to 254 ip addresses at once and determine if any are vulnerable to the recent apache chunked encoding overflow.
 
[back to top]

 

filename:
file description:
made by gobo this program has awesome features like add bytes. pack and scramble and exe2vbs hex editor and much more to help hide from detection.
zyon:
*easy-to-use gui. *drag and drop file capability *add as many files as you list with any extentions.. (.exe, .bmp) and run them. ----options---------- +compression -4 levels of lzh1 algarythms +security -misty1(c) encryption algarythm -password archive feature +notification -send icq pager message *note resolves icq.com's pager address automatically +windows environment -create a message box on execution of the archive
pretty good exe joiner easy gui
command line joiner
by the thinker . drag and drop many files to join together newer version soon to come with better features
commercial exe packer
old trojan joiner gets detected alot.
from the guys at rns.. pretty good
oldy but goodie
command line joiner
fsg:
awesome compressor for very small .exes ... loves asm exes to compress
commercial packer i never use commercial easily detected
gui for upx easier than going to the command prompt.. has drag and drop support. its what i use to compress
aupx:
another upx gui with a windows xp type iface looks pretty
simple design upx gui with compress and decompress
exe joiner from the guys at dbc, allows you to join to files and also choose icon for the resulting file
bind a couple files together
bat2exe exe2com com2exe bmp2txt and other misc. tools
bind many files together and a whole shitload more options very impressed by this one
by stan ... creates a source in c++ code with any files you attach which you then can compile with lcc etc to create a dropper, doesnt use a stub which makes its better because av's wont detect the stub as being the virus first
different kind of binder. this one puts one exe inside anothers null space without use of a stub
i only put this one here because gobo is a good friend otherwise i wouldnt deal with crappystuff from areyoufearless basically a simple binder with icon changing capabilities
 
[back to top]

 

filename:
file description:
features include: - enumeration of account lockout threshold - enumeration of local groups and user accounts - enumeration of global groups and user accounts - enumeration of shares - restrictanonymous bypass routine - password checking
scooplm captures lm/ntlm authentication information (lanmanager and windows nt challenge/response) on the network.
beatlm searches out the password from lm/ntlm authentication information (lanmanager and windows nt challenge/response).
the most frequent examples of information gathered by these applications include: names of users: via netuserenum() names of groups: via netgroupenum() or netlocalgroupenum() members of groups: via netgroupgetusers() or netusergetgroups() shares on a machine: via netshareenum() and netsharegetinfo()
the smb downgrade attacker waits for users to remotely try to map shares, and when they do, it will try to get the usernames and passwords in plaintext.for nt4
fakegina intercepts the communication between winlogon and the normal gina, and while doing this it captures all successful logins (domain, username, password) and writes them to a text file.
**new** lets any user on a nt/2k machine run anything as admin. lets you take over the box or possible the network
allows you to get admin privlidges on a nt box
this is an application to dump the contents of the lsa secrets on a machine. it uses the same technique as pwdump2 to bypass restrictions that microsoft added to lsaretrieveprivatedata(), which cause the original lsadump, by paul ashton, to fail. you need the sedebugprivilege for it to work. by default, only administrators have this right, so this program does not compromise nt security.
lets all the users logon into the nt machine with any password they type. every user that has write access to the \winnt\system32 directory can use this tool.(even guest user)
let you change password of a user in a nt sam file. (not nt4 sp3 syskey) and access any ntfs file
network file system redirecter for dos/windows that is able to recognize and mount ntfs drives for transparent access. it makes ntfs drives appear virtually indistinguishable from standard fat drives, providing the ability to navigate, view and execute programs on them from dos or from windows
allows you delete the guest user on nt/2k box
shows how to hide files form the registry etc.. by calling them _root_
allows any user to be added to the admin group on nt
allows you to point and click what ever you want to do with a unicode-vulnerable nt/2k servers running iis..... directory change,file delete,etc... take over mad iis webservers with this
"winfo" uses null sessions to remotely retrieve a list of user accounts, workstation trust accounts, interdomain trust accounts, server trust accounts, and shares, from windows nt. it also identifies the built-in administrator and guest accounts, even if their names have been changed. of course winfo will show all hidden shares.
get admin account of remote computer and domain.
clearlogs clears the event log (security, system or application) that you specify. you run it from the command prompt, and it can also clear logs on a remote computer. to selectivley delete certain logs use ::winzapper:: but you can only use that locally
two small utilities for windows nt that allow you to query sam and to find out a sid value for a given account name and vice versa.
the flags that userdump checks in the userinfo are: account lockout. account disabled. user cannot change password. password never expires. smartcard required for interactive logon (win2k). account is trusted for delegation (win2k). account is sensitive and connot be delegated (win2k).
this dll allows you to gain system level access to an iis 5.0 system.
the purpose of this app is to illustrate inconsistencies in the ms implementation of the restrictanonymous registry setting.
For Win2k grabs password of the currently logged on user from memory .use on comprimised machines to get the pass quicker than cracking the sam.
use DCOM to execute files on a remote NT machine
 
[back to top]

 

filename:
file description:
coming soon
coming soon when detro gets his shit done
 
[back to top]

 

filename:
file description:
check out what processes are running on your mac basicly anything you want to know about the extentions running on your computer.
deletes temp files in your computer that the system leaves behind taking up hd space if ur mac has slowed down at all this may help.
burn:
just what it says burn files beyond repair re writes the files with 000000000
ceam:
anon mass mailer, spoofer
this is a control strip extention that allows you see all running processes and applications visible and invisible from your contolstrip.
httpver is a port of httpver.c it gets server information by sending requests through the httpd daemon and parsing the incoming headers.
puts your ip in a little window and allows you to copy it to the clipboard.. quicker then going through the control panel
converts any ip into an address and address to ip.
must have for anyone with a mac this shows you all connections incoming and outgoing ,portscanner, ping, trace route the works
gives you a description of what the mac error numbers are. like type 10, 11, 2, 3, and so on.
its a progie thats lets you have multiple settings for your computers system what apps are launched at startup what extentions are running and so on
awesome keylogger for mac
fastest port scanner for mac, made by the guys at team 2600
gives info on running processes
its a proxy bouncer for mac from the guys at team 2600 proxy bouncer allows you to go through a socks 4 server even if the application doesn't have support for it. it also keeps you to be almost hidden by allowing you to connect through multiple socks 4 servers before connecting to the server you want to.
silo:
silo is a remote system analysis tool designed mostly for security and administrative evaluational purposes.
snapperhead is a little app that sends screenshots to people who enter your ip address into a web browser. simply launch snapperhead, then send a friend your ip address (it is shown on the snapperheadª window under "snaps served"). when they type that internet address into the location field of a web browser (you know, where you usually type in "http://www.stimpsoft.com"), they will be sent, as an image in their browser, a picture of your screen. that's all there is to it!
screenshots, snap a pic of anything, .pict .jpg , .gif , and even lets you make small .mov
just what it says programming utility if you dont know what this is just turn your computer off
jack any sound, icon or pic from any macintosh application
yapi:
its a process application that allows you to view bring forward or stop a process from the list and many other options
 
[back to top]

 

filename:
file description:
for win98,lets you change the color behind the desktop icons font to clear like on win2k, can also change the letters and backround any color
from [k] lets you create a vbs script virus .. helps you learn vbs script and how to make your own worms
made in asm this program removes the ads from aim and resizes the gui to remove the dead gray space left behind making your aim look pretty :)
my friend mcbain was bored and made a aim formatter which you turn on when youre idle and will give the appearence of you name moving on others buddy lists
if you dont know what putty is then you are an idiot... putty is the best telnet alternative for windows... i also added a bunch of other putty tools with the zip to you with other apps.. get this shit now
this kick ass standalone program frees up your ram on your computer with one click.. good for getting back lost resources wusing those ram hogging proggies...
this tight little program is a complete resource monitor for your computer it monitors resources in real time including ram hard drive cpus gui etc... has a ram clear to free some resources... all in a kickass little iface
this program will split partions on your hard drive even if you have an os installed without wrecking any data you have. good for when you wanna install dual boot for windows and linux
nice little program lets you choose any folder on your computer and generates an html page with link of the files to download. good for warez servers and other shit.
program show all established and listening connections coming in and out of your computer
really awesome hacking game full version :)
little vb proggie has you hack into accounts and shit pretty kewl
crack for the paltalk service....allows you to see some free titties and shit on paltalk webcams
sterm is a telnet client for windows nt/2k/xp with a unique feature . it enables you to establish am entire bi-directional telnet session to a target host never sending your real ip and mac address in any packet. by using 'arp poisoning' , 'mac spoofing" and 'ip spoofing" techniques it effectivly bypass acls fiewall rules and ip restrictions on servers and network devies. the connection will be done by impersonating a trusted host uses the packet driver contained in the package winpcap v2.3 beta download from the link
this allows you to connect to your yahoo.com account with any pop3 mail program like outlook etc.. better than going to the site all the time to check your mail.
watchcat is a small system tray applet for hiding application windows that clutter up your taskbar. windows hidden by watchcat also will disappear from taskbar and alt+tab chain. it’s extremely convenient if you need to keep applications such as ms outlook open all the time but don’t check them often.
puts system info ram,processor,ip network settings onto a dekstop background picture or ontop of current picture real good for network admins to see what the computer has running.
really good ftp program that i use.
puts system info ram,processor,ip network settings into text that stays ontop of windows showing it in realtime.
made by xeo generates valid credit card numbers for visa/cm/american express/discover.
 
[back to top]