This guide outlines a method to quickly assess the egress traffic filtering of a firewall using the Nmap port scanner. Egress Traffic are connections that are initiated from within an organsiation / system to an external Internet host. Ingress Traffic are connections that are coming into a system, this is typically web servers, mail servers [...]
Webscarab and Ratproxy installation and chaining
In this mini tutorial we are going to use Webscarab and Ratproxy together in a chained fashion. This will enable passive testing of a web application by Ratproxy, with more active intercepting proxy testing to be done by Webscarab. For this reason we will run Ratproxy as the first hop in the proxy chain with [...]
Nessus 5 on Ubuntu 12.04 install and mini review
Having yet to play with Nessus 5, today I grabbed a copy and installed it into my Ubuntu 12.04 64 bit system. Take note I am having a quick look at the product, not using it in a commercial manner as part of the work done by HackerTarget.com. This would require a professional feed license [...]
Install Rapid7′s Nexpose community edition
Today I will look at the installation of the Rapid 7 vulnerability scanner Nexpose. This is a quick overview of the install on Ubuntu 12.04 with a very light review. There are different versions of the NeXpose engine, we will be using the community edition on 64 bit Linux. The company is more famous for [...]
Install OpenVAS 5 in Ubuntu 12.04
OpenVAS 5 installation can be a little confusing for those not familiar with the different OpenVAS components. Making it even more so is a little problem with libgnutls that is causing many people more than a little frustration. This guide will step you through the installation of OpenVAS 5 on Ubuntu 12.04. Here is an [...]
sqlmap POST request injection
In the past using sqlmap to perform POST request based SQL injections has always been hit and miss (more often a miss). However I have recently had to revisit this feature and have found it be to much improved. Both in ease of use and accuracy. This is a quick step by step guide to [...]
Nmap 6.00 added to online port scanning tool
We have completed testing and rolled out the latest Nmap release version 6, to our online port scanner service. At this stage we have enabled Nmap 6 on the immediate port scan page, but are still testing it for scheduled port scanning. This will be upgraded once testing has completed. Congratulations to the Nmap development [...]
OpenVAS 5 released. Now available for download
OpenVAS continues to evolve into an all in one open source vulnerability management solution. We have been following its progress since the early days of following the Nessus fork. Here is a guide we have put together for installing OpenVAS 5 Due to the large amount of functionality and the resources required to keep the [...]
WPScan added to WordPress Security Scan
For all you wordpress lovers we have added wpscan to our existing WordPress Security Scan. WPScan is a handy wordpress focused vulnerability scanner developed by Ryan Dewhurst (ethicalhack3r.co.uk). The scan uses techniques that include brute forcing the plugins directory of a wordpress installation to find installed plugins. This is an accurate way to find plugins [...]
IPv6 added to online port scanner
Our online nmap port scanner is now IPv6 capable. Nmap has had the ability to scan IPv6 ip addresses for some time now and recently Linode also added IPv6 to its VPS offerings. These additions mean we can now provide on-line port scanning of both IPv4 and IPv6 addresses or Host names that have an [...]

