<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://website.isecpartners.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>iSEC Partners - </title>
 <link>http://website.isecpartners.com/application_tools</link>
 <description></description>
 <language>en</language>
<item>
 <title>Fuzzbox</title>
 <link>http://website.isecpartners.com/fuzzbox</link>
 <description> &lt;p&gt;Fuzzbox is a multi-codec media fuzzer.&lt;/p&gt;
&lt;p&gt;Prerequisites: Python, py-vorbis 1.4, and mutagen 1.11&lt;br /&gt;
Downloads:&lt;br /&gt;
&lt;a href=&quot;/files/fuzzbox.tar.gz&quot;&gt;fuzzbox.tar.gz&lt;/a&gt;&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <category domain="http://website.isecpartners.com/application_tools">Application Tools</category>
 <pubDate>Tue, 07 Aug 2007 10:04:39 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">275 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Forensic Fuzzing Tools</title>
 <link>http://website.isecpartners.com/forensic_fuzzing_tools</link>
 <description> &lt;p&gt;This is a collection of scripts that can be used to generate fuzzed files, fuzzed file systems, and file systems containing fuzzed files.  These can be used to test the robustness of forensics tools and examination systems.&lt;/p&gt;
&lt;p&gt;Prerequisites:  Linux/Python&lt;br /&gt;
Downloads:&lt;a href=&quot;/files/isec-forensic-tools.tar.bz2&quot;&gt;iSEC Forensics Fuzzing Tools&lt;/a&gt;&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <category domain="http://website.isecpartners.com/application_tools">Application Tools</category>
 <pubDate>Fri, 03 Aug 2007 16:30:07 -0700</pubDate>
 <dc:creator>alex</dc:creator>
 <guid isPermaLink="false">274 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>SAMLPummel</title>
 <link>http://website.isecpartners.com/samlpummel</link>
 <description> &lt;p&gt;SAML Pummel is a BeanShell plug-in for WebScarab.  It automates eight different injection attacks to assist in auditing the implementation of SAML 2.0 single sign-on systems.
&lt;ul&gt;
&lt;li&gt;C14N Entity Expansion
&lt;li&gt;C14N Transforms
&lt;li&gt;Remote DTD
&lt;li&gt;Remote KeyInfo RetrievalMethod
&lt;li&gt;Remote KeyInfo WSSE Security Token Reference
&lt;li&gt;SignedInfo Remote Reference
&lt;li&gt;XSLT Transform URL Retrieval (Xalan)
&lt;li&gt; XSLT Transform Thread Suspension (Xalan)
&lt;/ul&gt;
&lt;p&gt;Prerequisites: Java Runtime Environment 1.5 or greater, WebScarab (modified self-contained jar included)&lt;br /&gt;
Downloads: &lt;a href=&quot;files/SAMLPummel.zip&quot;&gt;SamlPummel&lt;/a&gt;&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <category domain="http://website.isecpartners.com/application_tools">Application Tools</category>
 <pubDate>Tue, 31 Jul 2007 11:08:17 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">252 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Jailbreak</title>
 <link>http://website.isecpartners.com/jailbreak</link>
 <description> &lt;p&gt;Jailbreak is a tool for exporting certificates marked as non-exportable from the Windows certificate store.  This can help when you need to extract certificates for backup or testing. You must have full access to the private key on the filesystem in order for jailbreak to work.&lt;/p&gt;
&lt;p&gt;Prerequisites: Win32&lt;br /&gt;
Downloads:&lt;br /&gt;
&lt;a href=&quot;files/jailbreak-3.1.zip&quot;&gt;jailbreak_3.1.zip&lt;/a&gt;&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <category domain="http://website.isecpartners.com/application_tools">Application Tools</category>
 <enclosure url="http://website.isecpartners.com/files/jailbreak-3.1.zip" length="61946" type="application/zip" />
 <pubDate>Tue, 31 Jul 2007 10:04:26 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">244 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>ProxMon</title>
 <link>http://website.isecpartners.com/proxmon</link>
 <description> &lt;p&gt;ProxMon is an extensible Python based framework that reduces testing effort, improves consistency and reduces errors. Its use requires limited additional effort as it processes the proxy logs that you’re already generating and reports discovered issues. In addition to penetration testing, ProxMon is useful in QA, developer testing and regression testing scenarios. &lt;/p&gt;
&lt;p&gt;Key features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;automatic value tracing of set cookies, sent cookies, query strings and post parameters across sites
&lt;li&gt;proxy agnostic
&lt;li&gt;included library of vulnerability checks
&lt;li&gt;active testing mode
&lt;li&gt;cross platform
&lt;li&gt;open source license
&lt;li&gt;easy to program extensible python framework
&lt;/ul&gt;
&lt;p&gt;Prerequisites: Python&lt;br /&gt;
&lt;a href=&quot;files\proxmon-1.0.18.tar.gz&quot;&gt;proxmon-1.0.18.tar.gz&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;files\proxmon-1.0.18.exe&quot;&gt;proxmon-1.0.18.exe&lt;/a&gt;&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <category domain="http://website.isecpartners.com/application_tools">Application Tools</category>
 <pubDate>Thu, 29 Mar 2007 10:14:01 -0700</pubDate>
 <dc:creator>alex</dc:creator>
 <guid isPermaLink="false">203 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>CyberVillainsCA</title>
 <link>http://website.isecpartners.com/cybervillainsca</link>
 <description> &lt;p&gt;The CyberVillainsCA is a small Java library for on-the-fly generation, duplication and substitution of X.509 certificates.  It is intended for use in building or extending security testing tools, for example, WebScarab (example included).&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Generates a Certification Authority certificate for importation as a Trusted Root
&lt;li&gt;Automatically generates standard SSL server certificates for a given CNAME
&lt;li&gt;Simple API to duplicate and re-sign any certificate, preserving all extensions
&lt;li&gt;Automatically manages persistence and the mapping between original and duplicated certificates
&lt;li&gt;Also can manage substitution of ‘naked’ public keys or a mixture of keys and certificates (as may be seen in WS-Security)
&lt;/ul&gt;
&lt;p&gt;Prerequisites: Java Runtime Environment 1.5 or greater, Legion of the Bouncy Castle Java Cryptography Provider (included)&lt;/p&gt;
&lt;p&gt;Download:&lt;br /&gt;
&lt;a href=&quot;/files/CyberVillainsCA.zip&quot;&gt;CyberVillainsCA.zip&lt;/a&gt;&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <category domain="http://website.isecpartners.com/application_tools">Application Tools</category>
 <pubDate>Wed, 28 Mar 2007 10:26:08 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">201 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>File Fuzzers</title>
 <link>http://website.isecpartners.com/file_fuzzers</link>
 <description> &lt;p&gt;These tools are useful for testing any program which processes binary file inputs such as archivers and image file viewers.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;FileP&lt;/b&gt; is a python-based file fuzzer.  It generates mutated files from a list of source files and feeds them to an external program in batches.&lt;br /&gt;
Prerequisites: Python 2.4&lt;/p&gt;
&lt;p&gt;&lt;b&gt;FileH&lt;/b&gt; is a haskell-based file fuzzer.  It generates mutated files from a list of source files and feeds them to an external program in batches.&lt;br /&gt;
Prerequisites: GHC 6.4.2&lt;/p&gt;
&lt;p&gt;Downloads:&lt;br /&gt;
&lt;a href=&quot;files\filep.zip&quot;&gt;filep.zip&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;files\fileh.zip&quot;&gt;fileh.zip&lt;/a&gt;&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <category domain="http://website.isecpartners.com/application_tools">Application Tools</category>
 <enclosure url="http://website.isecpartners.com/files/filep.zip" length="11060" type="application/x-zip-compressed" />
 <pubDate>Fri, 22 Sep 2006 12:36:41 -0700</pubDate>
 <dc:creator>alex</dc:creator>
 <guid isPermaLink="false">157 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Windows IPC Fuzzing Tools</title>
 <link>http://website.isecpartners.com/windows_ipc_fuzzing_tools</link>
 <description> &lt;p&gt;This is a collection of tools used to attack applications that use Windows Interprocess Communication mechanisms.  This package includes tools to intercept and fuzz named pipes, as well as a shared memory section fuzzer.&lt;/p&gt;
&lt;p&gt;Prerequisites: Windows, Python&lt;br /&gt;
&lt;a href=&quot;files\iSEC_Public_IPC_Fuzzing_Tools.zip&quot;&gt;iSEC_Public_IPC_Fuzzing_Tools.zip&lt;/a&gt;&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <category domain="http://website.isecpartners.com/application_tools">Application Tools</category>
 <pubDate>Tue, 22 Aug 2006 20:25:18 -0700</pubDate>
 <dc:creator>alex</dc:creator>
 <guid isPermaLink="false">155 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>WSMap</title>
 <link>http://website.isecpartners.com/wsmap</link>
 <description> &lt;p&gt;WSMap is a Python-based tool that helps penetration testers find web service endpoints and discovery files. &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Parses WebScarab logs to find testing targets
&lt;li&gt;Tests URLs and implies URLs found in log
&lt;li&gt;Tests for WSDL and DISCO web service discovery formats
&lt;/ul&gt;
&lt;p&gt;Prerequisites: WebScarab, Python 2.4, pyCurl&lt;/p&gt;
&lt;p&gt;Download:&lt;br /&gt;
&lt;a href=&quot;http://website.isecpartners.com/files/WSMap.py.txt&quot; title=&quot;Download: WSMap.py.txt (9.79 KB)&quot;&gt;WSMap.py.txt&lt;/a&gt;&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <category domain="http://website.isecpartners.com/application_tools">Application Tools</category>
 <pubDate>Mon, 31 Jul 2006 17:41:10 -0700</pubDate>
 <dc:creator>chris</dc:creator>
 <guid isPermaLink="false">130 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>WSBang</title>
 <link>http://website.isecpartners.com/wsbang</link>
 <description> &lt;p&gt;WSBang is a Python-based tool used to perform automated security testing of SOAP based web services.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Takes URL of WSDL as input
&lt;li&gt;Fuzzes all methods and parameters in the service
&lt;li&gt;Identifies all methods and parameters, including complex parameters
&lt;li&gt;Fuzzes parameters based on type specified in WSDL
&lt;li&gt;Reports SOAP responses and faults
&lt;/ul&gt;
&lt;p&gt;Prerequisites: Python 2.4, SOAPpy v11.6 , pyXML, fpconst&lt;/p&gt;
&lt;p&gt;Downloads:&lt;br /&gt;
&lt;a href=&quot;http://website.isecpartners.com/files/WSBang.zip&quot; title=&quot;Download: WSBang.zip (22.89 KB)&quot;&gt;WSBang.zip&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://website.isecpartners.com/files/WSBang.tar.gz&quot; title=&quot;Download: WSBang.tar.gz (80 KB)&quot;&gt;WSBang.tar.gz&lt;/a&gt;&lt;/p&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <category domain="http://website.isecpartners.com/application_tools">Application Tools</category>
 <pubDate>Mon, 31 Jul 2006 17:39:12 -0700</pubDate>
 <dc:creator>chris</dc:creator>
 <guid isPermaLink="false">129 at http://website.isecpartners.com</guid>
</item>
</channel>
</rss>
