lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <COL103-W22686817A458DB74ABAB53A06D0@phx.gbl>
Date: Fri, 1 May 2009 10:05:41 +0000
From: Benjilenoob <benjilenoob@...mail.com>
To: "pen-test@...urityfocus.com" <pen-test@...urityfocus.com>,
	<full-disclosure@...ts.grok.org.uk>, <webappsec@...urityfocus.com>,
	<bugtraq@...urityfocus.com>
Subject: Durzosploit v0.1 alpha


Hi all readers,

Just releasing a very small tool I wrote called Durzosploit.

Durzosploit is a javascript exploits generator framework that works through the console. This goal of that project is to quickly and
easily generate working exploits for cross-site scripting vulnerabilities in popular web applications or web sites.

Please note that Durzosploit does not find browser vulnerabilities, it only is an framework containing exploits you can use.

More info can be found here: http://engineeringforfun.com/wiki/index.php/Durzosploit_Introduction
You can get it through the SVN: http://engineeringforfun.com/wiki/index.php/Durzosploit_SVN

At present there isn't many exploits:
(dz)> search exploits
twitter.com/update_status               -       Updates a target's status
twitter.com/update_settings             -       Updates your target's settings
facebook.com/what_is_on_your_mind       -       Write your message in your target's mind
drupal/edit_user_profile                -       Drupal 6.x - edit the profile of the user
drupal/logout                           -       Drupal 6.x - makes target logout
(dz)>

My focus has been on the framework itself; allowing people to quickly write their exploits and adding some automated obfuscators (Deanedwards is in there).

I'll also use that email as a chance to give a quick update on Browser Rider. I am currently working on its API, a ruby client and a small firefox extension. I think Durzosploit will be a good addition to all of that.

Please email to benjilenoob(_at_)gmail.com if you have any questions, issues, bugs, ideas, contributions. I'll be happy to answer you ASAP.

have fun!

Benjilenoob

_________________________________________________________________
Téléphonez gratuitement à tous vos proches avec Windows Live Messenger  !  Téléchargez-le maintenant !
http://www.windowslive.fr/messenger/1.asp

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ