Clicky

Pages

Showing posts with label TOOLS. Show all posts
Showing posts with label TOOLS. Show all posts

Sunday, June 27, 2010

Malware Analysis and Forensics tools links


Beginner Malware Analysis and Reverse Engineering
Informational slides about malware 

How-To Forensics and RE links

Malware Analysis and Forensics tools


Scan websites for malware
AV Scanners
ReCon2010 Slides (many many thanks to ARTeam) 

DigitalNinjitsu.com  - A (great) resource for security professionals to perform research.

Malware Analysis -- Links and resources for malware samples

 



Saturday, June 26, 2010

Ru-Eng-Eng Glossary. Russian (human computer slang) -> English (Google machine) -> English (human computer slang)


Many of us use machine Google and other machine translation services to read sites and forums in other languages. As you know, the main problem with any machine translation is that it needs additional human translation afterwords because it cannot recognize many colloquial, misspelled, technical, transliterated, or slang words.

Not everyone knows about Google Translator Toolkit allowing you to upload your documents or to select an URL and save the results for future reference (see Google video below) You can also add your own glossaries to enhance and customize the translation results. I find that they do not work as you would expect (do not get automatically used sort of like your personal dictionaries in MS Office) but they are still semi useful for creating custom vocabulary lists to assist you in translation of "Google machine English" into human English.

I made a quick draft of a custom Ru-GoogleEng-Eng glossary with less than 100 words and you can see a few screenshots below. The English words in bold in the first column are the words offered by Google Translate - these are wrong words and in no way reflect the correct Russian and English versions that you can see in the other two columns. 

There are a couple of ways of using Google Translate kit site - download the csv to your computer and use a plain search for words through the file or to use Google translate toolkit (if you have Gmail, just go to http://translate.google.com/toolkit to see it for searching through the uploaded custom glossary. Other languages can be added too.


 
Download csv Glossary importable to Google translate kit (unicode UTF-8)
Download a HTML page - glossary

screenshot 1  
(1st column shows WRONG translation consistently offered by Google translate , 
2nd column - part of speech and case, 
3rd column - correct English and Russian pairs. 
(Let me know if you have any corrections or comments)


Wednesday, June 9, 2010

A Collection of Web Backdoors & Shells – from DK (http://michaeldaw.org) and ARTeam (http://www.accessroot.com)

"I have collected some WEB backdoors in the past to exploit vulnerable file upload facilities
and others. I think a library like this may be useful in a variety of situations.
Understanding how these backdoors work can help security administrators
implement firewalling and security policies to mitigate obvious attacks."   - DK
cmd-asp-5.1.asp      8baa99666bf3734cbdfdd10088e0cd9f
cmdasp.asp             57b51418a799d2d016be546f399c2e9b
cmdasp.aspx           5e83b6ed422399de04408b80f3e5470e
cmdjsp.jsp               815611cc39f17f05a73444d699341d4
jsp-reverse.jsp         8b0e6779f25a17f0ffb3df14122ba594
php-backdoor.php z0mbie 2b5cb105c4ea9b5ebc64705b4bd86bf7
simple-backdoor.php f091d1b9274c881f8e41b2f96e6b9936
perlcmd.cgi              97ae7222d7f13e908c6d7f563cb1e72b
cfexec.cfm              bd04f47283c53ca0ce6436a79ccd600f

Original Post  http://michaeldaw.org/projects/web-backdoor-compilation

Index of /ARTeam/webshell



Download link 1 http://michaeldaw.org/projects/wbc-v1b.tar.gz
Download link 2 Webshells from ARTeam http://xchg.info/ARTeam/webshell/

Many thanks to Michael and Gunther for sharing.



Sunday, November 8, 2009

COFEE v112

Links updated: Jan 18, 2023



COFEE - Computer forensics tool


Excerpt
What is COFEE?
COFEE has been designed to provide the investigator the ability to collect evidence from a target system
with the minimum of user interaction. After the GUI interface generates a COFEE USB device (copies all
scripts and programs), the investigator can take the device and easily insert it onto a target machine,
and begin the collection process by executing a single program.

Published by NIJ (56)


DOJ Computer forensics tool testing reports