Mostrando entradas con la etiqueta Software Libre. Mostrar todas las entradas
Mostrando entradas con la etiqueta Software Libre. Mostrar todas las entradas

Software para particionar tu disco duro en Linux

Gparted Logo

En Linux existen diferentes maneras de realizar particiones en tu disco duro, aunque los programas estrella no sean más que interfaces de uno solo: parted.

Para los puristas de KDE hay que decir que existió un particionar específico para KDE, el llamado KParted, pero parece ser que éste cayó en el olvido.

Así que nos queda, que no es poco, qtparted, que como su propio nombre indica utiliza librerías qt. Qtparted es un particionar sencillo, fácil de manejar y que se instala desde repositorio. Tiene un grave problema: hace mucho tiempo que no se actualiza (2005) con lo que le auguro un futuro tan oscuro como Kparted.

QT-parted

La verdadera estrella entre los particionadores de Linux es GParted, que como su inicial indica es propia de Gnome pero que funciona perfectamente en KDE. Su aspecto es prácticamente igual a qtparted pero tiene muchas más funciones, manteniendo siempre la sencillez como bandera.

Gparted

Además, dispone de un LiveCD (y Live USB) utilísimo para poder utilizar Gparted como herramienta antes de instalar un Sistema operativo, como veremos en próximos artículos.

Algunas distribuciones, como Ubuntu, ofrecen GParted como utilidad dentro de su LiveCD con lo que si aprendemos a utilizar dicho programa podemos particionar correctamente nuestros discos para disponer de dos o más sistemas operativos en nuestros PC o a tener la información mejor organizada.

Fuente: http://www.kdeblog.com/software-para-particionar-tu-disco-duro-en-linux.html

Kit de Herramientas para el Análisis Forense

Outport

Programa que permite exportar los datos desde Outlook a otros clientes de correo (p.e. Evolution). Probado por el autor con Outlook 2000 y Evolution 1.0.x y 1.2.x.


AIRT (Advanced incident response tool)
Conjunto de herramientas para el analisis y respuesta ante incidentes, utiles para localizar puertas traseras. Los 5 programas que lo componen son:


  • mod_hunter: busca modulos ocultos
  • process_hunter: busca procesos ocultos
  • sock_hunter: busca puertos ocultos
  • modumper: vuelca el contenido de un modulo oculto en un fichero
  • dismod: permite analizar el volcado anterior


Foremost
Utilidad para linux que permite realizar analisis forenses. Lee de un fichero de imagen o una particion de disco y permite extraer ficheros.


WebJob

Permite descargar un programa mediante HTTP/HTTPS y ejecutarlo en una misma operacion. La salida, en caso de haberla, puede dirigirse a stdout/stderr o a un recurso web. Soporta administracion centralizada, monitoreo de procesos, comprobacion de la integridad de ficheros, etc.


HashDig

Automatiza el proceso de calculo de los hashes MD5 y comprobacion de integridad, distinguiendo entre ficheros conocidos y no conocidos tras compararlos con una base de datos de referencia.


md5deep

Conjunto de programas que permiten calcular resumenes MD5, SHA-1, SHA-256, Tiger Whirlpool de un numero arbitrario de ficheros. Funciona sobre Windows. Linux, Cygwin, *BSD, OS X, Solaris y seguro algunos mas. Similar en funcionalidad al programa md5sum se diferencia en las siguientes caracteristicas:

  • Recursividad.
  • Estimacion del tiempo de duracion del proceso.
  • Modo comparitivo.
  • Permite trabajar sobre un tipo de fichero determinado.


Automated Forensic Analysis

Herramienta para analisis automatizado de volcados vfat o ntfs compuesta por un conjunto de scripts que buscan informacion interesante para un analisis forense.


Gpart

Programa que permite recuperar la tabla de particiones de un disco cuyo sector 0 este dañado, sea incorrecto o haya sido eliminado, pudiendo escribir el resultado obtenido a un fichero o dispositivo.


TestDisk

Programa que permite chequear y recuperar una particion eliminada. Soporta BeFS (BeOS), BSD disklabel (FreeBSD/OpenBSD/NetBSD), CramFS (Sistema de Ficheros Comprimido), DOS/Windows FAT12, FAT16, FAT32, HFS, JFS, Ext2, Ext3, Linux Raid, Linux Swap (versiones 1 y 2), LVM, LVM2, Netware NSS, NTFS (Windows NT/2K/XP/2003), ReiserFS 3.5, ReiserFS 3.6, UFS, XFS y SGI's Journaled File System.


Dump Event Log

Herramienta de linea de comandos que vuelca el log de eventos de un sistema local o remoto en un fichero de texto separado por tabuladores. Tambien puede utilizarse como filtro en la busqueda de determinados tipos de eventos.


fccu-docprop

Utilidad de linea de comandos que muestra las propiedades de ficheros MS OLE como son los DOC o XLS. Utiliza la libreria libgsf para obtener los metadatos y pyede utilizarse en investigaciones forenses.


fccu.evtreader

Herramienta para analisis forense que permite al investigador analizar ficheros de log de eventos de Windows. Se trata de un script de perl que puede funcionar bajo Linux, y que deberia funcionar en otros sistemas.


GrokEVT

Conjunto de scripts en python que permiten analizar ficheros de registros de eventos de Windows NT. Tambien permite extraer cualquier otro tipo de log y convertirlo en un formato legible.


Event Log Parser

Script PHP que, pasandole un fichero de log de Windows, permite extraer su contenido en un fichero de texto ASCII.


srprint

Herramienta que permite volcar el contenido de los ficheros de log de la utilidad de restauracion del sistema de Windows XP. Este tipo de logs permiten averiguar la fecha de creacion y borrado de ficheros que ya no esten presentes en el sistema.


iDetect Toolkit

Utilidad que asiste a un investigador forense en el analisis de la memoria de un sistema comprometido.


Galleta

Una herramienta para el analisis forense de las cookies del Internet Explorer. Parsea la informacion de un fichero de cookie obteniendo como resultado campos separados por tabuladores que pueden importarse facilmente a una hoja de calculo.


Pasco

Permite analizar los ficheros de registro de la actividad del Internet Explorer. Parsea la informacion de un fichero index.dat obteniendo como resultado campos separados por tabuladores que pueden importarse facilmente a una hoja de calculo.


Web Historian

Asiste en la recuperacion de las URLs de los sitios almacenados en los ficheros historicos de los navegadores mas habituales, incluyendo: MS Internet Explorer, Mozilla Firefox, Netscape, Opera y Safari.


Rifiuti

Herramienta para el analisis forense de la informacion almacenada en la Papelera de Reciclaje de un sistema Windows. Parsea la informacion de un fichero INFO2 obteniendo como resultado campos separados por tabuladores que pueden importarse facilmente a una hoja de calculo.


Reg Viewer

GUI en GTK 2.2 para la navegacion de ficheros de registro de Windows. Es independiente de la plataforma en que se ejecute.


RegParse

Script de perl que realiza el parseo de los datos de ficheros de registro de Windows en crudo. Abre el fichero en modo binario y parsea la informacion registro a registro. Escrito originalmente para Windows esta especialmente recomendado para el parseo del fichero NTUSER.DAT, system32\config\SYSTEM y system32\config\SOFTWARE.


Regutils

Herramientas para la manipulacion de ficheros ini y de registro de sistemas Windows 9x desde UNIX.


allimage

Esta herramienta para Windows nos permitira crear imagenes bit a bit de cualquier tipo de dispositivo de almacenamiento de datos (diskettes, cdroms, unidades usb, discos duros, etc). Cabe destacar que incluye un gestor para montaje de particiones de forma que puede resultar muy util para asignar una letra de unidad a un fichero de imagen de un sistema Windows de forma que pueda realizarse un analisis post-mortem.

Como "pega" pues que se trata de un problema comercial. Dispondremos de 14 dias para probar el software, tiempo mas que suficiente para lo que nos traemos entre manos


ProDiscover Basic Edition

Completo entorno grafico para el analisis forense de sistemas bajo entornos Windows. Permite realizar imagenes, preservar, analizar y realizar informes de los elementos contenidos en el dispositivo sujeto del analisis. Esta version, mas limitada que su hermano mayor, es completamente gratuita.

NOTA: He tenido problemas al intentar iniciar la ultima version liberada en un sistema Windows configurado para utilizar el español como idioma predeterminado del sistema, por lo que, en caso de tener problemas, descargar la version anterior.

NOTA: Para conseguir que se inicie la ultima version de la aplicacion (v5) es necesario entrar a la "Configuracion regional y de idioma", a traves del panel de control, y seleccionar "Ingles (Estados Unidos)" dentro de la opcion "Estandares y formatos".


FTK Imager

Herramienta que nos permitira realizar imagenes de un dispositivo comprometido. Entre sus caracteristicas tambien esta la conversion entre diferentes formatos de imagen, p.e. imagen dd a imagen de Encase, etc. Herramienta disponible de forma gratuita. Tambien existe una version lite, cuya funcionalidad es mas reducida.


PyFlag

Avanzada herramienta para el anslisis forense de grandes volumenes o imagenes de log. Desarrollada en python posee una interfaz accesible mediante navegador web. Entre sus caracteristicas posee la de integrar volatility, facilitando de esta forma el analisis de ficheros de imagen de la memoria fisica de un sistema Windows.

En principio esta pensada para ejecutarse bajo sistemas Linux pero en su ultima version tambien estan disponibles los paquetes necesarios para ejecutarla bajo un sistema Windows.


PlainSight

Completo entorno para el analisis forense de sistemas. Se trata de un sistema Linux que podemos ejecutar desde un CD y que contiene muchas utilidades opensource. Todavia se encuentra en sus inicios por lo que puede resultar un proyecto muy interesante al que seguirle la pista.


SmartMount

Herramienta que permite montar diferentes tipos de formatos de imagen, entre otras funcionalidades, y que se encuentra disponible tanto para linux como para Windows. Dado que todavia esta en fase beta es muy presumible que poco a poco vaya incluyendo nuevas funcionalidades.


Volatility Framework

Completo framework desarrollado en Python que nos permitir el analisis de un volcado de la memoria fisica de un sistema Windows. Ademas de ser multiplataforma ofrece las siguientes funcionalidades:

  • Obtener fecha y hora del contenido de la imagen
  • Listado de los procesos en ejecucion
  • Sockets de red abiertos
  • Conexiones de red abiertas
  • DLLs cargadas por cada proceso
  • Ficheros abiertos por cada proceso
  • Claves del registro abiertas por cada proceso
  • Direcciones de memoria asignadas a cada proceso
  • Modulos del kernel
  • Extraccion de ejecutables almacenados en memoria



Mantech Memory DD

Herramienta gratuita que nos permitira obtener un volcado en formato dd del contenido de la memoria fisica de un sistema Windows 2k, 2k3, XP, Vista y 2k8, tanto en sus versiones de 32 como de 64 bits. El fichero resultante es facilmente analizable con Volatility, con toda la potencia que ello implica.


win32dd

Herramienta open source que, al igual que la anterior, nos permitira obtener un volcado en formato dd del contenido de la memoria fisica de un sistema Windows.


Sandman Framework

Libreria desarrollada en C que, entre otras caracteristicas, nos permitira la conversion de un fichero hiberfil.sys a formato dd, de forma que podamos analizarlo con Volatility. Actualmente unicamente soporta los ficheros hiberfil.sys de sistemas Windows XP a 2008 en sus versiones de 32 bits. Tambien incluye un port de la libreria de forma que pueda ser utilizada por scripts generados en python.

Fuente: http://www.wadalbertia.org/phpBB2/viewtopic.php?t=662

Manual SSH: El dios de la administración remota

Y es que no se merece un titular peor. ¿Has estado alguna vez en el trabajo o en casa de y has necesitado o te has acordado de un archivo que no tienes en ese momento pero sí en tu ordenador? Existen los escritorios remotos, de hecho Ubuntu trae uno instalado por defecto, pero puede que no queramos hacer más que mandarnos un archivo o hacer algo en el ordenador remoto. Para esto -y mucho más- existe SSH, con un inmenso potencial.

SSH son las siglas de Secure SHell. Lo que te ofrece es una consola en un ordenador remoto con los privilegios que tenga la cuenta con la que conectes. Es decir, si en tu PC tienes varias cuentas, puedes conectar desde otro ordenador al tuyo con cualquiera de esas cuentas y sus respectivos privilegios, como pudiera ser la cuenta root, la de tu administrador sudo o la de un usuario normal sin poder de administración. Y todo esto con encriptación de datos.

En este tutorial os voy a mostrar algunas facetas de su uso, pero antes debéis saber que tener el servidor de SSH corriendo es de cierto riesgo, ya que si no tocáis la configuración por defecto para aumentar la seguridad a un nivel más que aceptable, puede ser un agujero para que alguien pueda entrar en vuestro sistema. Pero no os preocupéis, si seguís estos pasos es difícil que suceda, nunca imposible, pero sí difícil.

El manual es algo extenso debido a que he intentado hacer que resulte bastante completo y que, como llevo haciendo en el resto de tutoriales, quiero que sepáis lo que estáis haciendo, los porqués y lo que significa cada cambio que hacéis. De esta forma tendréis criterio propio para vuestras modificaciones personales.

Instalar

En vuestros repositorios ya tenéis SSH dispuesto a instalar, así pues:

$ sudo aptitude install ssh

Una vez instalado se autoiniciará el demonio que ejecuta el servidor SSH y gestiona las solicitudes de login remoto.

Configuración: Mayor seguridad

Como decía antes no es muy inteligente usar SSH sin modificar el fichero de configuración del servidor. Vamos a modificar algunas opciones para conseguir una seguridad aceptable.

$ sudo gedit /etc/ssh/sshd_config

(nota) Si algunas de las opciones que aquí comento no aparecen en vuestro sshd_config, simplemente agregadlas. Podéis hacerlo donde queráis, aunque lo suyo es que lo hagáis al principio o al final para que sepáis cuales son las opciones que vosotros habéis agregado.

Vemos un fichero de configuración típico basado en “opción valor”. Vamos a comenzar las modificaciones por el puerto que es lo primero que vemos y una de las cosas más importantes. SSH usa por defecto el puerto 22. Esto significa que si no lo cambiamos estamos entregando a un caco que sabe la dirección de dónde vivimos (nuestra IP) también la llave del portal.

Cambiaremos el puerto para evitarlo. Esto no quita que el caco pueda intentar averiguar “el portal” si sabe cómo hacerlo pero al menos le ponemos impedimentos. También hay scripts que atacan directamente el puerto 22, por lo que el cambio de puerto es algo obligatorio. Poned el que queráis y abridlo también en el router para que podáis acceder a vuestro ordenador desde otro. Usaremos por ejemplo el 4321, podéis poner el que queráis. Así pues en el fichero de configuración:

port 4321

Un poco más abajo buscad la opción “Protocol” debe estar a valor 2, si no es así (valor 1 ó 2,1 ponedla. Hay dos versiones de protocolo SSH. La primera está ya en desuso y tiene varias vulnerabilidades. Así debéis dejarlo en vuestra configuración:

Protocol 2

Buscad la sección “Authentication”. Sus dos primeras opciones son también importantes. La primera es el número de segundos que tendrá el usuario remoto para hacer login en tu máquina. Poned ese valor a pocos segundos, no tardamos mucho en hacer login si sabemos la cuenta y la password. De esta forma evitamos ciertos scripts que se aprovechan de ese tiempo. El valor típico en términos de seguridad es 30, aunque podéis poned incluso menos si estáis más conformes.

LoginGraceTime 30

Justo debajo tenéis otras de las opciones más importantes, PermitRootLogin. Si antes usé la metáfora del caco y el portal, esta opción viene a ser que le digáis también en qué planta del bloque de pisos vivís y qué puerta, faltándole sólo la llave. Con esto lo que insinúo es que si sabe por qué puerto entrar, tan sólo le queda averiguar dos datos: el nombre de una cuenta y su contraseña.

Si tenemos esta opción habilitada (yes) el caco ya tiene la mitad del trabajo hecho, pues el usuario “root” existe en todas las máquinas GNU/Linux, tan sólo le queda averiguar la contraseña. Por eso es más que recomendable deshabilitar esta opción. No os preocupéis los que tenéis en mente usar SSH para hacer un uso administrativo, podéis hacerlo con vuestra cuenta y sudo sin problema alguno. Así pues…

PermitRootLogin no

También podéis señalar con el dedo las cuentas que tienen permitido el uso SSH (AllowUsers). Pongamos un ejemplo, que es como mejor se entienden las cosas: Supongamos que tienes un amigo con el que quieres compartir algo vía SSH y además tiene un hermano que es un enreda y en el que no confías por si te la puede liar. Llamaremos a las cuentas “amigo” y “pesado” respectivamente. Para restringir el uso de SSH a tu amigo y a tu propia cuenta (llamémosla “pepino”) podemos indicárselo mediante configuración. Incluso podemos indicar también que tu amigo sólo se pueda conectar a tu ordenador desde el suyo, sabiendo su IP (supongamos que es 83.45.258.21). Pondríamos en la configuración:

AllowUsers pepino amigo@83.45.258.21

De esta forma tú podrías usar tu cuenta (pepino) para conectar a tu equipo desde cualquier lugar, tu amigo podría hacerlo sólo desde su ordenador (si tiene esa IP) y tu hermano no podría conectar a tu máquina vía SSH, si no tiene tu cuenta.

Otra opción interesante es el número de intentos que tiene el usuario remoto para hacer login (MaxAuthTries). Como comenté antes, quien intente conectar debe acordarse de su login y password, por lo que es tontería darle un número grande de intentos. En principio con dos son más que suficientes. Si al segundo intento no lo ha conseguido se cortará la conexión SSH. Siempre se puede volver a conectar y reintentarlo, pero así nos quitamos de encima ciertos scripts que intentan encontrar el login por fuerza bruta a base de ensayo y error.

MaxAuthTries 2

Por último hay otra opción que define el número máximo de usuarios conectados simultáneamente a tu máquina. Esto ha de adaptarse a tus propias necesidades. Si estamos hablando de un ordenador personal donde sólo vas a conectar tú, pues lo lógico sería que como mucho hubiera una. Si estamos hablando de un ordenador que hará las veces de servidor compartiendo una carpeta a varias máquinas, deberás decidir cuántos son. Cuanto tengas claro el número indícalo en la opción siguiente en lugar de la ‘X’:

MaxStartups X

Ya podéis guardar y cerrar gedit. Con esto tenéis un servidor SSH bastante seguro. Como comenté antes nunca es 100% seguro pero a priori podéis estar bien tranquilos. Sólo resta reiniciar el propio servidor SSH para que tome los cambios que hemos efectuado en su configuración. Escribid en consola:

$ sudo /etc/init.d/ssh restart

Un último consejo. Como habéis visto podemos poner trabas al caco en cuanto a nuestra dirección y puerta, pero ¿podemos ponerle problemas con la llave? La llave se entiende que es la contraseña. Y la respuesta es afirmativa. Podéis hacerlo pero vosotros mismos. Poned claves en condiciones a vuestras cuentas. Usad como poco 5 ó 6 caracteres y a ser posible que se entremezclen mayúsculas, minúsculas y números, por ejemplo: entr3TuXeSyp3p1n0s.

Es un ejemplo exagerado, enrevesado a la hora de escribir e incómodo para meterlo en sudo cada dos por tres, pero intentad que sea del estilo y procurad que no sea algo tan simple como vuestro nombre, el de vuestra mascota, vuestra fecha de nacimiento, grupo favorito, etc.

Uso de SSH en consola
  • Conectar

Ahora que tenemos SSH bien seguro es hora de que veais para qué sirve. Parto de que tenéis dos equipos, el que tenéis delante y al que queréis conectar. Obviamente debéis tener una cuenta en el segundo para poder entrar. La forma de conectar por defecto es la siguiente:

$ ssh tu_cuenta@ip_del_ordenador_remoto

Esto sería si no hubiéramos cambiado el puerto, ya que intentaría conectar por el puerto 22 que es el puerto por defecto del cliente. Podéis cambiarlo si queréis para que conecte por defecto por el puerto que le digáis en lugar del 22 editando el fichero /etc/ssh/ssh_config. Descomentáis (si está comentada) la opción “Port” y en lugar de “22″ ponéis el que queráis.

La otra opción, que es lo más normal, es simplemente indicarle en la línea de conexión qué puerto ha de usar:

$ ssh -p puerto tu_cuenta@ip_del_ordenador_remoto

Para que lo veais más claro os voy a poner un ejemplo. Mi portátil está en la ip 192.168.1.4 y el puerto SSH que tengo para el mismo es el 4884. La cuenta que voy a usar para conectarme es “pepino”, así que para conectar desde mi PC de sobremesa al portatil sería:

$ ssh -p 4884 pepino@192.168.1.4

Tras esto me pedirá la contraseña:

pepino@192.168.1.4's password:

La introducimos y tras un texto de “bienvenida” veremos que nuestro prompt ha cambiado a “nombre_cuenta@nombre_manquina”. Mi portatil se llama salamandra, así pues mi prompt es:

pepino@salamandra:~$

A partir de este instante tu consola está controlando el equipo remoto. Estarás en el home de tu cuenta en la máquina remota. ¿Qué podemos hacer?

  • Copiar ficheros

Seguramente es lo primero que se os ha pasado por la cabeza a algunos. Efectivamente podemos copiar ficheros fácilmente desde el ordenador remoto al que estamos usando en este momento, y es fácil (es una sóla línea):

$ scp ruta/archivo cuenta_en_ordenador_presente@ip_ordenador_presente:ruta/fichero

Complicado a priori, ¿verdad? En el fondo no lo es, una vez sabéis qué es cada cosa. ruta/fichero es el lugar donde está el archivo a copiar en la primera aparición, y el lugar donde se va a copiar en la segunda. cuenta_en_ordenador_presente es la cuenta que estáis usando (u otra) en el ordenador que tenéis delante (no el remoto). La ip_ordenador_presente es precisamente la ip de vuestro ordenador. Pero como siempre mejor con un ejemplo.

Supongamos que quiero copiarme un fichero llamado pepino.jpg que está en el escritorio de la cuenta “pepino” del portátil (el ordenador remoto) y quiero copiármelo en el home de la cuenta “tux” de mi ordenador presente, cuya ip es 192.168.1.6. Ya que estoy quiero aprovechar y cambiarle el nombre. Quiero que se llame pepinaceo.jpg en lugar de pepino.jpg. Escribiremos en el SSH (es una sóla línea):

$ scp /home/pepino/Desktop/pepino.jpg tux@192.168.1.6:/home/tux/pepinaceo.jpg

¿No funciona? ¿Sabes por qué? El puerto, recordad que lo cambiamos y aquí también tenemos que indicárselo. En el ordenador de sobremesa tengo abierto el puerto 8448, así pues (es una sóla línea):

$ scp -P 8448 /home/pepino/Desktop/pepino.jpg tux@192.168.1.6:/home/tux/pepinaceo.jpg

Nos pedirá la contraseña de la cuenta “tux” en el ordenador que tenemos delante y copiará el archivo:

pepino@192.168.1.4's password:
pepinaceo.png 100% 292KB 291.7KB/s 00:00

Y si ya estuvieramos en el escritorio (prompt: pepino@salamandra:~/Desktop$) no habría que poner toda la ruta si no queremos ya que tomaría la ruta relativa a la actual:

$ scp -P 8448 pepino.jpg tux@192.168.1.6:/home/tux/pepinaceo.jpg

(Nota) Ojo con la ‘P’ que en este caso debe ser mayúscula.

Otra gracia del asunto es que no tienes por qué copiarlo a tu equipo actual. Si tienes acceso a otro ordenador más, puedes copiar algo de uno al otro del mismo modo, es decir, teniendo login en ambos y sabiendo su IP. Por otro lado si lo que queremos copiar es una carpeta, basta con añadirle el parámetro ‘-r’ para que copie todo su contenido (r=recursivo).

  • Otros usos

Básicamente cualquiera que se os pase por la cabeza. Daros cuenta que para un sistema GNU/Linux el interfaz no lo es todo, de hecho es prácticamente una aplicación que está corriendo bajo el propio sistema operativo, por lo que podéis administrar perfectamente vuestro equipo desde una consola y con acceso remoto vía SSH. Dentro de una conexión SSH, podéis reiniciarlo:

pepino@salamandra:~$ sudo reboot
Broadcast message from pepino@salamandra
(/dev/pts/1) at 23:45 ...
The system is going down for reboot NOW!

O apagarlo:

pepino@salamandra:~$ sudo halt
Broadcast message from pepino@salamandra
(/dev/pts/1) at 23:51 ...
The system is going down for halt NOW!

O usar cualquier otra aplicación de texto, como podría ser una que os presenté hace poco y que os podría venir muy bien en este caso: links. De esta forma si queréis podeís navegar en la consola y descargaros algo en vuestra máquina estando en otra.

El abanico de posibilidades es realmente inmenso.

SSH en Nautilus

Lo cierto es que si lo que queremos es simplemente copiar archivos o ver el contenido de alguno de ellos que están en otra máquina, podemos usar nautilus que siempre será más amigable para algunos que a través de consola.

No hay mucho cambio al respecto. Alt+F2 y escribid dentro “nautilus”. Se os abrirá el navegador de archivos. Nautilus tiene dos formas de mostrarte dónde estás dentro de la jerarquía de directorios. Una es a través de botones donde cada carpeta es un botón que puedes pulsar para volver atrás:

Y otra que te indica la ruta en modo texto:

Para cambiar de un modo al otro pinchad en el icono que está a la izquierda del todo que es un folio escrito y un lápiz. Nos quedaremos en el segundo modo y en la caja de texto de “Lugar:” escribiremos la orden de conexión:

ssh://tu_cuenta@ip_pc_remoto

Siguiendo con los ejemplos anteriores:

ssh://pepino@192.168.1.4

Esto sería si el puerto es el que está por defecto, como nosotros lo cambiamos tenemos que indicárselo con “:puerto” tras la ip. En nuestro ejemplo:

ssh://pepino@192.168.1.4:4884

Ahora nos pedirá la contraseña de la cuenta.

Tomad la decisión que queráis. Personalmente yo soy de los prefieren tomarse la molestia de introducir la clave en cuestiones tan importantes como es la seguridad de SSH.

Tras esto nos colocará en la raíz de la máquina remota. Si lo que queríamos era que nos dejara en una carpeta determinada se lo podemos indicar en la línea de conexión. Por ejemplo en el escritorio de nuestra cuenta:

ssh://pepino@192.168.1.4:4884/home/pepino/Desktop/

Ahora podéis copiar archivos y carpetas con total comodidad desde vuestro escritorio GNOME.

Ejecutar aplicaciones gráficas remotamente

Otra cosa muy práctica que podemos hacer gracias a SSH es ejecutar una aplicación que no tenemos en el equipo actual pero sí en el remoto y trabajar allí. Es decir, puedes mirarlo como un servidor de trabajo gráfico. Si aún no queda claro os pongo otro ejemplo:

Mientras estábais fuera de casa el pesado de tu hermano se ha hecho con tu ordenador porque tiene que hacer algo y si no “se lo dice a mamá“. Sin embargo tú también tienes cosas que hacer en él. No hay problema. Te pones en el equipo de tu hermano y abres la aplicación que necesites de tu propio ordenador en el PC de tu hermano.

Práctico, ¿verdad? Pues es muy sencillo, basta con añadir un argumento más (-X) y el nombre de la aplicación que queremos usar. Por ejemplo imaginemos que queremos jugar a Doom en DOSBox, y en el ordenador de tu hermano no tenemos ninguna de las dos cosas. Podemos instalar DOSBox, copiar la carpeta de Doom, montarla y jugar. O también podemos ejecutar directamente DOSBox remotamente y montar el juego que ya tenemos en nuestro equipo:

$ ssh -X -p 4884 pepino@192.168.1.4 dosbox

Ahora tan sólo resta montar la carpeta como ya os mostré. Podéis introducir la ruta de vuestro PC pues en el fondo es en vuestro PC donde se está ejecutando todo.

Cambiar el mensaje de bienvenida

Ya saliendo de la parte práctica, he querido hacer esta pequeña sección dentro del manual para los fanáticos de la personalización como yo. Si recordáis cuando os expliqué la conexión por consola, os comenté que tras introducir la clave nos daba una especie de texto de bienvenida. Este texto de bienvenida es modificable y puedes poner lo que quieras. Este es el de mi equipo de sobremesa:

Para hacerlo es simple. Tienes que editar (con privilegios de administrador) el archivo /var/run/motd y escribir dentro lo que quieras que aparezca cuando alguien se conecte. Es decir:

$ sudo gedit /var/run/motd

Lo modificamos a nuestro gusto, guardamos y cerramos gedit.

Fuente: http://tuxpepino.wordpress.com/2007/05/11/ssh-el-dios-de-la-administracion-remota/


Listado de herramientas de Seguridad

Les presentamos el listado denominado " Security Tools List - The security list from security auditors for security auditors " que actualiza la web securitytoolslist.domandhost.com donde se muestra las principales herramientas de seguridad que se utilizan en la actualidad para auditoría informática y cumplimiento de medidas relacionadas con la seguridad de la Información.

Num Tool name License Platform License price
1 BRO-IDS Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Sniffer / network analyzer
Description Bro is an open-source, Unix-based Network Intrusion Detection System
URL http://www.bro-ids.org/
2 Acunetix Non-free (free with restrictions) Windows Free!
Type of tool Analysis of web environments
Description Acunetix is a web vulnerability scanner. Can check XSS, SQL injection, and much more attacks
URL http://www.acunetix.com/
3 IceSword Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool rootkits detectors
Description IceSword has a Windows Explorer-like interface but displays hidden processes and resources that Windows Explorer would never show.
URL http://www.antirootkit.com
4 FTester Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Firewall / perimetral security testing
Description The Firewall Tester (FTester) is a tool designed for testing firewalls filtering policies and Intrusion Detection System (IDS) capabilities
URL http://dev.inversepath.com/trac/ftester
5 GMER Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool rootkits detectors
Description GMER is an application that detects and removes
URL http://www.gmer.net/
6 GFI Languard Non-free (free with restrictions) Windows Free!
Type of tool Exploitation / vulnerability analysis
Description GFI LANguard is the award-winning network and security scanner.
URL http://www.gfi.com/lannetscan
7 FG-Injector Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Exploitation / vulnerability analysis
Description Injection Framework is a security tool designed to detect and research SQL injections.
URL http://sourceforge.net/projects/injection-fwk/
8 netcat Non-free (free with restrictions) Linux Free!
Type of tool Management
Description netcat is a computer networking utility for reading from and writing to network connections using either TCP or UDP. It goes by the tag-line of "The Swiss-army knife for TCP/IP
URL http://netcat.sourceforge.net/
9 rkhunter Free (Unrestricted free. License type GPL, GNU,...) Linux Free!
Type of tool rootkits detectors
Description Rootkit scanner is scanning tool to ensure you for about 99.9%* you're clean of nasty tools. This tool scans for rootkits, backdoors and local exploits.
URL http://www.rootkit.nl/projects/rootkit_hunter.html
10 Secure Auditor Commercial Windows $300-1500
Type of tool Exploitation / vulnerability analysis
Description Secure Auditor is a Unified Risk Management Solution which enables user to perform Enumeration, Scanning, Auditing, Penetration Testing and Forensics on different operational systems
URL http://www.secure-bytes.com/
11 metasploit Non-free (free with restrictions) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Exploitation / vulnerability analysis
Description Metasploit provides useful information to people who perform penetration testing, IDS signature development, and exploit research
URL http://www.metasploit.com/
12 OpenSQLi-NG Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Analysis of web environments
Description OpenSQLi-NG (pronounced Open SQLi N-G) is the next generation open source sql injection tool,
URL http://opensqling.sourceforge.net/?page_id=8
13 OpenVAS Free (Unrestricted free. License type GPL, GNU,...) Linux Free!
Type of tool Exploitation / vulnerability analysis
Description OpenVAS stands for Open Vulnerability Assessment System and is a network security scanner with associated tools like a graphical user front-end. OpenVAS products are Free Software under GNU GPL and a fork of Nessus.
URL http://www.openvas.org/
14 Cain & Abel Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool multiuse
Description Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords and analyzing routing protocols
URL http://www.oxid.it/cain.html
15 tor Free (Unrestricted free. License type GPL, GNU,...) Linux Free!
Type of tool anonymity / security
Description Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet
URL https://www.torproject.org/
16 XPL Non-free (free with restrictions) Linux Free!
Type of tool Exploitation / vulnerability analysis
Description ISO custom for pentest
URL www.ginux.ufla.br/~sandro
17 p0f Free (Unrestricted free. License type GPL, GNU,...) Linux Free!
Type of tool Protocols scanner/ fingerprinting
Description passive OS fingerorinting
URL http://lcamtuf.coredump.cx/p0f.shtml
18 oSpy Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool Exploitation / vulnerability analysis
Description oSpy is a tool which aids in reverse-engineering software running on the Windows platform.
URL http://code.google.com/p/ospy/
19 sqlbrute Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Exploitation / vulnerability analysis
Description Blind SQL injection
URL http://www.justinclarke.com/security/sqlbrute.py
20 Gamja Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Scanner / VPN detector
Description Gamja will find XSS(Cross site scripting) & SQL Injection weak point also URL parameter validation error. Who knows that which parameter is weak parameter? Gamja will be helpful for finding vulnerability[ XSS , Validation Error , SQL Injection].
URL gamja.sf.net
21 AuditPro Enterprise Commercial Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool multiuse
Description AuditPro® is a comprehensive enterprise security assessment solution featuring critical asset identification, policy compliance, risk analysis, real time vulnerability views, enhanced reporting capability, graphical progress analysis and more. Supporting multiple operating systems and databases, AuditPro® brings you the state-of-the-art in information systems security evaluation and risk management.
URL http://www.niiconsulting.com/products/auditpro.html
22 Firesec Commercial Windows Free!
Type of tool Management
Description Firesec is a comprehensive solution for firewall rulebase analysis in medium to large enterprise environments. It addresses the problems inherent with large rule sets and helps purge and update a rule base as per network requirements. Firesec provides multiple functions such as removing redundant rules, grouping similar rules, and searching for vulnerable rule patterns.
URL http://www.niiconsulting.com/products/Firesec.html
23 Technitium MAC Address Changer Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool Management
Description Technitium MAC Address Changer allows you to change Media Access Control (MAC) Address of your Network Interface Card (NIC) irrespective to your NIC manufacturer or its driver. It has a very simple user interface and provides ample information regarding each NIC in the machine. Every NIC has a MAC address hard coded in its circuit by the manufacturer. This hard coded MAC address is used by windows drivers to access Ethernet Network (LAN). This tool can set a new MAC address to your NIC, bypassing the original hard coded MAC address. Technitium MAC Address Changer is a must tool in every security professionals tool box. Technitium MAC Address Changer is coded in Visual Basic 6.0.
URL http://www.technitium.com/tmac/index.html
24 sam spade Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool target information gain
Description Tool that provides various tools for obtaining information on a given objective
URL http://preview.samspade.org/ssw/download.html
25 scanssh Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Scanner / VPN detector
Description The network scanner more versatile and extended
URL http://monkey.org/~provos/scanssh/
26 THC amap Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Scanner / VPN detector
Description network scanner. The perfect complement to nmap
URL http://freeworld.thc.org/thc-amap/
27 superscan Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool Scanner / VPN detector
Description A Foundstone tool. Powerful TCP port scanner, pinger, resolver.
URL http://www.foundstone.com/us/resources/proddesc/superscan.htm
28 nbtscan Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Scanner / VPN detector
Description Netbios scanner
URL http://unixwiz.net/tools/nbtscan.html#download
29 Xprobe2 Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Scanner / VPN detector
Description fingerprinting OS tool
URL http://xprobe.sourceforge.net/
30 Ike-scan Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Scanner / VPN detector
Description IPsec VPN scanning, fingerprinting and testing tool
URL http://www.nta-monitor.com/tools/ike-scan/
31 unicornscan Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Scanner / VPN detector
Description A very fast information gathering and correlation engine.
URL http://www.unicornscan.org/
32 scanrand Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Scanner / VPN detector
Description An unusually fast stateless network service and topology discovery system, part of Paketto Keiretsu suite
URL http://www.doxpara.com/read.php/code/paketto.html
33 upnpscan Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Scanner / VPN detector
Description A tool that scans the LAN or a given address range for UPnP capable devices
URL http://www.cqure.net/wp/upnpscan/
34 netifera Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Security Framework for create custom tools
Description Netifera is a new modular open source platform for creating network security tools
URL http://netifera.com/downloads/
35 usb-watcher Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool cryptography
Description USB-Watcher makes a system-shut-down if hardware-changes were noticed. Some police are using USB-Exploits to access running systems with encrypted filesystems (f.e. by TrueCrypt) and USB-Watcher (not only listening on USB) blocks the intruder.
URL http://keksa.de/?q=usb_watcher
36 proslo Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool Management
Description Proslo (process slowdown) uses an undocumented function in the windows-API to choke a process. It freezes the process and resumes it in a self-defined time period.
URL http://keksa.de/?q=proslo
37 mangleme in PHP Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool Exploitation / vulnerability analysis
Description mangleme (original coded by http://lcamtuf.coredump.cx/) is a HTML-fuzzer. I redesigned it in PHP to make fast code-changes and additions possible.
URL http://keksa.de/?q=mangleme_fuzzing_in_php
38 GreenSQL Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Management
Description GreenSQL is an Open Source database firewall used to protect databases from SQL injection attacks
URL http://www.greensql.net/
39 AutoRuns Non-free (free with restrictions) Windows Free!
Type of tool Forensic
Description Allows the user to view all software that automatically runs when windows starts up.
URL www.sysinternals.com
40 txdns Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool Target information gain
Description TXDNS is a Win32 aggressive multithreaded DNS digger. Capable of placing, on the wire, thousands of DNS queries per minute. TXDNS main goal is to expose a domain namespace trough a number of techniques: Typos, TLD rotation, Dictionary attack, Brute force.
URL http://www.txdns.net/
41 txdns Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool Protocols scanner/ fingerprinting
Description dns brute force
URL www.txdns.net
42 nmap Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Protocols scanner/ fingerprinting
Description A popular tool that is probably already on the list
URL http://nmap.org/
43 Lynis Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Management
Description System and security auditing tool for UNIX based systems.
URL http://www.rootkit.nl/projects/lynis.html
44 Cenzic Hailstorm Non-free (free with restrictions) Windows Starting at $13K
Type of tool Exploitation / vulnerability analysis
Description Cenzic Hailstorm is a Web application scanner. The product integrates with source code scanners and Web application firewalls as well as VMWare for virtualization of production apps
URL http://www.cenzic.com/products/overview/
45 dirb Free (Unrestricted free. License type GPL, GNU,...) Linux Free!
Type of tool Analysis of web environments
Description Website directory discovery via brute force. Supply your own dictionary file. I have a difficult time finding much support, as the name is not easily searchable. If you know how to use it, it's a good tool to add to the arsenal.
URL http://dirb.sourceforge.net/
46 UCSniff Free (Unrestricted free. License type GPL, GNU,...) Linux Free!
Type of tool Sniffer / network analyzer
Description UCSniff is an exciting new VoIP Security Assessment tool that leverages existing open source software into several useful features
URL http://ucsniff.sourceforge.net/
47 voiphopper Free (Unrestricted free. License type GPL, GNU,...) Linux Free!
Type of tool Creation / manipulation packet network
Description VoIP Hopper is a GPLv3 licensed security tool, written in C, that rapidly runs a VLAN Hop into the Voice VLAN on specific Ethernet switches
URL http://voiphopper.sourceforge.net/
48 sipp Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool multiuse
Description SIPp is a free Open Source test tool / traffic generator for the SIP protocol
URL http://sipp.sourceforge.net/
49 Protos Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Creation / manipulation packet network
Description The purpose of this test-suite is to evaluate implementation level security and robustness of numerous protocols: WAP-wsp-request, WAP-wmlc, HTTP-reply, LDAPv3, SNMPv1, SIP, H2250v4, ISAKMP, DNS.
URL http://www.ee.oulu.fi/research/ouspg/protos/
50 firebug Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Firefox pluggins
Description You can edit, debug, and monitor CSS, HTML, and JavaScript live in any web page.
URL http://getfirebug.com/
51 grendal-scan Non-free (free with restrictions) Windows Free!
Type of tool Management
Description Hi test
URL www.grendal.cm
52 Nikto Non-free (free with restrictions) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Scanner / VPN detector
Description Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3500 potentially dangerous files/CGIs, versions on over 900 servers, and version specific problems on over 250 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired).
URL http://www.cirt.net/nikto2
53 wireshark Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Sniffer / network analyzer
Description Wireshark is the world's foremost network protocol analyzer
URL http://www.wireshark.org
54 kismet Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Sniffer / network analyzer
Description Kismet is an 802.11 layer2 wireless network detector, sniffer, and intrusion detection system
URL http://www.kismetwireless.net/
55 tcpdump Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Sniffer / network analyzer
Description tcpdump is a common packet sniffer that runs under the command line. It allows the user to intercept and display TCP/IP and other packets being transmitted or received over a network to which the computer is attached
URL http://www.tcpdump.org/
56 windump Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool Sniffer / network analyzer
Description WinDump is the Windows version of tcpdump, the command line network analyzer for UNIX.
URL http://www.winpcap.org/windump/
57 Ettercap Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Sniffer / network analyzer
Description Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks
URL http://ettercap.sourceforge.net/
58 dsniff Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Sniffer / network analyzer
Description Dsniff is a collection of tools for network auditing and penetration testing: dsniff, filesnarf, mailsnarf, msgsnarf, urlsnarf, webspy, arpspoof, dnsspoof, macof, sshmitm and webmitm.
URL http://monkey.org/~dugsong/dsniff/
59 ngrep Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Sniffer / network analyzer
Description ngrep strives to provide most of GNU grep's common features, applying them to the network layer
URL http://ngrep.sourceforge.net/
60 Ntop Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Sniffer / network analyzer
Description ntop is a network traffic probe that shows the network usage, similar to what the popular top Unix command does
URL http://www.ntop.org/
61 EtherApe Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Sniffer / network analyzer
Description EtherApe is a graphical network monitor for Unix modeled after etherman
URL http://etherape.sourceforge.net/
62 SolarWinds Commercial Windows Starting at $199
Type of tool Sniffer / network analyzer
Description Network Management Software for All
URL http://www.solarwinds.com/
63 firewalk Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Sniffer / network analyzer
Description Firewalk is an active reconnaissance network security tool that attempts to determine what layer 4 protocols a given IP forwarding device.
URL www.packetfactory.net/projects/firewalk/
64 Cheops-ng Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Sniffer / network analyzer
Description Cheops-ng is a Network management tool for mapping and monitoring your network
URL http://cheops-ng.sourceforge.net/
65 fping Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Sniffer / network analyzer
Description fping is a ping(1) like program which uses the Internet Control Message Protocol (ICMP). fping is different from ping in that you can specify any number of hosts on the command line, or specify a file containing the lists of hosts to ping.
URL http://fping.sourceforge.net/
66 tcptraceroute Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Sniffer / network analyzer
Description tcptraceroute is a traceroute implementation using TCP packets
URL http://michael.toren.net/code/tcptraceroute/
67 MBSA Non-free (free with restrictions) Windows Free!
Type of tool Exploitation / vulnerability analysis
Description Microsoft Baseline Security Analyzer (MBSA) is an easy-to-use tool that helps small and medium businesses determine their security state in accordance with Microsoft security recommendations and offers specific remediation guidance.
URL http://technet.microsoft.com/en-us/security/cc184924.aspx
68 w3af Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Analysis of web environments
Description w3af, is a Web Application Attack and Audit Framework. The w3af core and it's plugins are fully written in python. The project has more than 130 plugins, which check for SQL injection, cross site scripting (xss), local and remote file inclusion and much
URL http://sourceforge.net/projects/w3af/
69 MSAT Non-free (free with restrictions) Windows Free!
Type of tool Management of risk / methodologies / ISO
Description The Microsoft Security Assessment Tool (MSAT) is a free tool designed to help organizations like yours assess weaknesses in your current IT security environment, reveal a prioritized list of issues, and help provide specific guidance to minimize those risks
URL http://technet.microsoft.com/en-us/security/cc185712.aspx
70 paros Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Analysis of web environments
Description Through Paros's proxy nature, all HTTP and HTTPS data between server and client, including cookies and form fields, can be intercepted and modified
URL http://www.parosproxy.org/
71 WebScarab Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Analysis of web environments
Description WebScarab is a HTTP and HTTPS proxy. Has several modes of operation and implement numbers plugins:Fragments, Proxy, Manual, Beanshell, Revealhiddenfields, Bandwidthsimulator, Spider, Manualrequest, SessionIDanalysis, Scripted, Parameterfuzzer, Search, Compare, SOAP, Extensions, XSS/CRLF.
URL http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project
72 WebInspect Commercial Windows Free!
Type of tool Analysis of web environments
Description Webinspect is an URLchecker. This is a service that test your website or special pages of your website and warn you when if an important status change is made or if the page is not reachable from the internet
URL http://www.webinspect.net/
73 SPIKE Proxy Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Analysis of web environments
Description SPIKE Proxy is a tool for looking for application-level vulnerabilities in web applications. SPIKE Proxy covers the basics, such as SQL Injection and cross-site-scripting
URL http://www.immunitysec.com/resources-freesoftware.shtml
74 QualysGuard Commercial Windows Starting at $2500
Type of tool Analysis of web environments
Description The QualysGuard Security and Compliance Suite automates the process of vulnerability management and policy compliance across the enterprise, providing network discovery and mapping, asset prioritization, vulnerability assessment reporting and remediation tracking according to business risk.
URL http://www.qualys.com/products/qg_suite/
75 BurpSuite Non-free (free with restrictions) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Analysis of web environments
Description Burp Suite is an integrated platform for attacking web applications. It contains a Suite tools: Proxy, Spider, Scanner, Intruder, Repeater, Sequencer, Decoder, Comparer.
URL http://portswigger.net/suite/
76 Wikto Non-free (free with restrictions) Windows Free!
Type of tool Analysis of web environments
Description Wikto is a Web Server Assessment Tool. It works by trying to find interesting directories and files on the web site, it looks for sample scripts that can be abused or finds known vulnerabilities in the web server implementation itself.
URL http://www.sensepost.com/research/wikto/
77 Watchfire AppScan Commercial Windows Starting at $14,000
Type of tool Analysis of web environments
Description From IBM Rational automate content scanning and analysis to help ensure compliance with privacy, accessibility, and key industry regulations such as Sarbanes-Oxley and HIPAA, as well as internal Web quality standards
URL http://www.watchfire.com
78 N-Stealth Non-free (free with restrictions) Windows Free!
Type of tool Analysis of web environments
Description N-Stalker is a Web Application Security Scanner with 18,000 signatures, web Server security check, Backup check, XSS...
URL http://www.nstalker.com/products
79 SpiDynamics WebInspect Commercial Windows Starting at $2500
Type of tool Exploitation / vulnerability analysis
Description WebInspect complements firewalls and intrusion detection systems by identifying Web application vulnerabilities
URL http://www.whitehatinc.com/products/spi_dynamics/webinspect/
80 NetStumbler Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool Wifi password cracker / sniffer / others wifi tools
Description Tool for Windows that allows you to detect Wireless Local Area Networks (WLANs) using 802.11b, 802.11a and 802.11g
URL http://stumbler.net/
81 Airsnort Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Wifi password cracker / sniffer / others wifi tools
Description AirSnort is a wireless LAN (WLAN) tool which recovers encryption keys. AirSnort operates by passively monitoring transmissions, computing the encryption key when enough packets have been gathered
URL http://airsnort.shmoo.com/
82 Aircrack-ng Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Wifi password cracker / sniffer / others wifi tools
Description Aircrack-ng is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured.
URL http://aircrack-ng.org/
83 KisMAC Free (Unrestricted free. License type GPL, GNU,...) MAC OS Free!
Type of tool Wifi password cracker / sniffer / others wifi tools
Description KisMAC is an open-source and free stumbler/scanner application for Mac OS X. It has an advantage over MacStumbler / iStumbler / NetStumbler in that it uses monitor mode and passive scanning
URL http://trac.kismac-ng.org/
84 Hping2 Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Creation / manipulation packet network
Description Hping is a command-line oriented TCP/IP packet assembler/analyzer. The interface is inspired to the ping unix command, but hping isn't only able to send ICMP echo requests. It supports TCP, UDP, ICMP and RAW-IP protocols, has a traceroute mode, the ability to send files between a covered channel, and many other features.
URL http://www.hping.org/
85 Scapy Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Creation / manipulation packet network
Description Scapy is a powerful interactive, and easy to use, packet manipulation program. It is able to forge or decode packets of a wide number of protocols, send them on the wire, capture them, match requests and replies, and much more. It is writen in python.
URL http://www.secdev.org/projects/scapy/
86 Scaperl Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Creation / manipulation packet network
Description Scaperl is a clon of scapy, but it's writen in perl
URL http://sylv1.tuxfamily.org/projects/scaperl.html
87 nemesis Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Creation / manipulation packet network
Description Nemesis is a command-line network packet crafting and injection utility. Nemesis, is well suited for testing Network Intrusion Detection Systems, firewalls, IP stacks and a variety of other tasks. As a command-line driven utility, Nemesis is perfect for automation and scripting.
URL http://nemesis.sourceforge.net/
88 yersinia Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Creation / manipulation packet network
Description Yersinia is a network tool designed to take advantage of some weakeness in different network protocols. It pretends to be a solid framework for analyzing and testing the deployed networks and systems
URL http://www.yersinia.net/
89 Tcpreplay Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Creation / manipulation packet network
Description Tcpreplay si part of ndisbench suite. Tcpreplay is aimed at testing the performance of a NIDS by replaying real background network traffic in which to hide attacks.
URL http://packetstormsecurity.nl/UNIX/IDS/nidsbench/nidsbench.html
90 fragrouter Free (Unrestricted free. License type GPL, GNU,...) *NIX (Any system derived of UNIX) Free!
Type of tool Creation / manipulation packet network
Description Fragrouter is aimed at testing the correctness of a NIDS, according to the specific TCP/IP attacks listed in the Secure Networks NIDS evasion paper
URL http://packetstormsecurity.nl/UNIX/IDS/nidsbench/nidsbench.html
91 Retina Commercial Windows Starting at $575.00
Type of tool Exploitation / vulnerability analysis
Description Retina Network Security Scanner is a vulnerability assessment, identifies known network and machine security vulnerabilities and assists in prioritizing threats for remediation.
URL http://www.eeye.com/
92 Core Impact Commercial Windows $25000
Type of tool Exploitation / vulnerability analysis
Description Core impact allow you to see your network, endpoint, email-user and web application security as an attacker would.
URL http://www.coresecurity.com/
93 ISS Internet scanner Commercial Windows Free!
Type of tool Exploitation / vulnerability analysis
Description Internet Scanner can identify more than 1,300 types of networked devices on your network, including desktops, servers, routers/switches, firewalls, security devices and application routers
URL http://www-935.ibm.com/services/us/index.wss/offerfamily/iss/a1026710
94 X-scan Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool Exploitation / vulnerability analysis
Description X-Scan is a general scanner for scanning network vulnerabilities for specific IP address scope or stand-alone computer by multi-threading method, plug-ins are supportable
URL http://www.xfocus.org/programs/200507/18.html
95 Sara Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool Exploitation / vulnerability analysis
Description SARA is a third generation network security analysis tool that that has been available and actively updated for over 10 years
URL http://www-arc.com/sara/
96 CANVAS Commercial Independent (Languages like java, python, perl, ruby...) $1450
Type of tool Exploitation / vulnerability analysis
Description CANVAS makes available hundreds of exploits, an automated exploitation system, and a comprehensive, reliable exploit development framework to penetration testers.
URL http://www.immunitysec.com/products-canvas.shtml
97 Saint Commercial Independent (Languages like java, python, perl, ruby...) Starting at $425
Type of tool Exploitation / vulnerability analysis
Description SAINT offers the only integrated vulnerability assessment and penetration testing tools available anywhere
URL http://www.saintcorporation.com/
98 Nessus Non-free (free with restrictions) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool Exploitation / vulnerability analysis
Description Nessus is the world-leader in active scanners, featuring high speed discovery, configuration auditing, asset profiling, sensitive data discovery and vulnerability analysis of your security posture
URL http://www.nessus.org
99 john the ripper Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool password cracker
Description John the Ripper is a fast password cracker
URL http://www.openwall.com/john/
100 THC hydra Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool password cracker
Description A very fast network logon cracker which support many different services
URL http://freeworld.thc.org/thc-hydra/
101 brutus Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool password cracker
Description It works online, trying to break telnet, POP3, FTP, HTTP, RAS or IMAP by simply trying to login as a legitimate users. Brutus imitates a real outside attack (unlike other password cracking applications that simulate an internal attack) and thus serves as a valuable security-auditing tool.
URL http://www.bujarra.com/Brutus.html
102 RainbowCrack Free (Unrestricted free. License type GPL, GNU,...) Multiplatform (Run in different environments: Linux, Windows, MAC OS... Free!
Type of tool password cracker
Description The RainbowCrack software is a hash cracker that use time-memory tradeoff algorithm
URL http://project-rainbowcrack.com/index.htm
103 Ophcrack Commercial Windows Free!
Type of tool password cracker
Description Ophcrack is a free Windows password cracker based on rainbow tables
URL http://ophcrack.sourceforge.net/
104 Angry IP scanner Free (Unrestricted free. License type GPL, GNU,...) Independent (Languages like java, python, perl, ruby...) Free!
Type of tool password cracker
Description Angry IP Scanner (or simply ipscan) is a network scanner designed to be fast and simple to use. It scans IP addresses and ports as well as has many other features.
URL http://www.angryziber.com/
105 pwdump Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool password cracker
Description This handy utility dumps the password database of an NT machine that is held in the NT registry.
URL http://samba.org/samba/ftp/pwdump/
106 pwdump2 Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool password cracker
Description PWDump2 is an application which dumps the password hashes (OWFs) from NT's SAM database, whether or not SYSKEY is enabled on the system
URL http://www.securiteam.com/tools/5ZQ0G000FU.html
107 pwdump3v2 Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool password cracker
Description It works in a similar way of pwdump2, but works over the network.
URL http://limestone.truman.edu/pub/win32/apps/pwdump3/
108 pwdump6 Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool password cracker
Description Improvement of pwdump3e
URL http://www.foofus.net/fizzgig/pwdump/
109 fgdump Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool password cracker
Description .improvement of pwdump6 with addons
URL http://www.foofus.net/fizzgig/fgdump/
110 pwdump7 Free (Unrestricted free. License type GPL, GNU,...) Windows Free!
Type of tool password cracker
Description It works as pwdump6 but uses own filesystem drivers.
URL http://www.tarasco.org/atarasco/2007/06/pwdump7.html


Fuente: http://seguridad-informacion.blogspot.com/2009/05/listado-de-herramientas-de-seguridad.html