• Register

Privilege escalation is the act of exploiting a bug, design flaw or configuration oversight in an operating system or software application to gain elevated access to resources that are normally protected from an application or user. The result is that an application with more privileges than intended by the application developer or system administrator can perform unauthorized actions.

Privilege escalation means a user receives privileges they are not entitled to. These privileges can be used to delete files, view private information, or install unwanted programs such as viruses. It usually occurs when a system has a bug that allows security to be bypassed or, alternatively, has flawed design assumptions about how it will be used. Privilege escalation occurs in two forms:

  • Vertical privilege escalation, also known as privilege elevation, where a lower privilege user or application accesses functions or content reserved for higher privilege users or applications (e.g. Internet Banking users can access site administrative functions or the password for a smartphone can be bypassed.)
  • Horizontal privilege escalation, where a normal user accesses functions or content reserved for other normal users (e.g. Internet Banking User A accesses the Internet bank account of User B)

 

PRIVILEGE ESCALATION- SOFTWARE'S / TOOLS / UTILITIES

  1. Password Attacks - Online and Offline
  2. Sniffing
  3. Spoofing
  4. Network Authentication
  5. Log Cleaner



PASSWORD ATTACKS - ONLINE AND OFFLINE

  • Bkhive
  • Crunch
  • CUPP
  • John The Ripper
  • Pw-Inspector
  • Rainbowcrack
  • Rarcrack
  • Samdump2
  • Saltymd5
  • Wyd
  • Cain And Abel
  • RAR Password Cracker
  • fcrackzip
  • chntpw
  • enumiax
  • FSCrack
  • Bruter
  • BruteSSH
  • Hydra
  • Lodowep
  • Medusa
  • SSHatter
  • TFTP-Bruteforce



SNIFFING

  • Arpalert
  • Driftnet
  • DSniff
  • Etherape
  • Ettercap
  • Ferret
  • Fimap
  • GToolBarSnoop
  • Hamster
  • MIMEDefang
  • Ntop
  • SMBRelay
  • SSLDump
  • SSLStrip
  • TcPick
  • Wireshark
  • Xspy
  • Tcpdump
  • Driftnet
  • Hexinject
  • sslsniff
  • sniffjoke
  • sessionlist
  • CSniffer



SPOOFING

  • ADM-Dns-Tools
  • Etherape
  • Ettercap
  • ICMP Redirect
  • IGRP Route Injection
  • IRDP Responder
  • Nemesis
  • Netenum
  • NetSed
  • PackETH
  • Packit
  • Scapy
  • SendEmail
  • Sing
  • SSLDump
  • SSLStrip
  • Tcpreplay
  • Yersinia
  • pwntcha


   
NETWORK AUTHENTICATION

  • KrbGuess
  • Ncrack
  • MACAddresschanger
  • kippo



LOG CLEANER

  • Eraseme

CORE Impact Professional

Logo Core ImpactCORE Impact Professional is the most comprehensive software solution for assessing and testing security vulnerabilities throughout your organization.

 
 

Read More...

IBM Security AppScan

Logo IBM Rational AppScanIBM Rational AppScan Enterprise is a scalable solution to help resolve application security vulnerabilities, offering recommendations to simplify remediation.

 

Read More...

HP WebInspect

Logo - HP WebInspectHP WebInspect gives security professionals and security novices alike the power and knowledge to quickly identify and validate critical, high-risk security vulnerabilities.

 

Read More...

Acunetix WVS

logo acunetix web application securityAcunetix Web Vulnerability Scanner (WVS) is an automated web application security testing tool that audits web applications by checking for hacking vulnerabilities. 

 

Read More...

w4rri0r - Hacking Is Not A Crime - It's an art of Awareness

\/ w4rri0r - Hacking Is Not A Crime - It's an art of Awareness \/ -  w4rri0r work in the dark, w4rri0r do what w4rri0r can, w4rri0r give what w4rri0r have, w4rri0r doubt is w4rri0r passion and w4rri0r passion is w4rri0r task. The rest is the madness of art \/ w4rri0r \/ 

\/ w4rri0r.com \/ are the great resource for information security professionals and researcher. \/ w4rri0r \/ offers a extensive variation of information security services that include SECURITY EXPLOITS (Bug or Vulnerability), SECURITY ADVISORIES (Security Alerts), SECURITY RESEARCHER TOOLBOX (Freeware, Shareware & Open-Source), SHELLCODE (Attacker Controller - Chunk of Data), SECURITY TRAINING (Educational Purpose), SECURITY NEWS (Security Recent or Important Events) and with this group you can be assured that you’re in the right hands. \/ w4rri0r gr0up \/  efforts being endorsed and appreciated by administrators, security researchers and members of various underground hacking groups and communities worldwide.

\/ w4rri0r mission \/ are to make the information systems more secure, more aware, more reliable and protect against possible security breaches.