The excellent open source vulnerability scanner OpenVas has been released; the latest release is version 3.0. The GPL-licensed Open Vulnerability Assessment System (OpenVAS) has become the Open Source Network Vulnerability Scanner. It is complemented with the largest open collection of vulnerability tests, the daily updated OpenVAS NVT Feed with over 15,500 Network Vulnerability Tests (NVTs). [...]
Nikto 2.1.0 released
Nikto, the most excellent web scanner has just been released in version 2.1.0. Numerous improvements have been made to both reliability, vulnerability scope and scan optimisation. Go here for a full run down on the new features. Or here for some comprehensive documentation. We are currently testing the new release before adding it to the [...]
Samurai and BackTrack – LiveCD’s to Test your Security
Linux has brought a wonderful concept to the world of computers and that is easy to use live cd’s that allow you to boot up a fully operational operating system that does not require installation to the hard drive. Ubuntu, SuSe, Mandriva and Fedora all have boot-able Live CD options that allow you to test [...]
Maltego – Open Source Intelligence Gathering
A powerful new tool is about to go into a new release. Maltego makes the collection of open source intelligence about a target organisation a simple matter. DNS queries, document collection, email addresses, whois, search engine interrogation and a wide range of other collection methods allows a Penetration Tester or vulnerability assessment to quickly gather [...]
DirBuster – Brute force a web server for interesting things
You would be surprised at what people leave unprotected on a web server. In our Full Vulnerability Assessment toolkit is a tool that does a simple job and does it very well. DirBuster is a java application that will brute force web directories and filenames on a web server / virtual host. This can often [...]
OSSEC Introduction and Installation Guide
OSSEC is a Host Based Intrusion Detection and Prevention system. Best practice security management calls for a layered approach to security, security vulnerability scanning, a firewall, strong passwords, patch management and intrusion detection are all important layers. Using a HIDS is a great way to understand what security events are taking place on a server. [...]


