Featherduster |
|
For breaking crypto; It tries to make the process of identifying and exploiting weak cryptosystems as easy as possible |
|
Hashcat |
|
World’s fastest and most advanced password recovery tool. CPU/GPU brute forcing |
|
John |
|
Enhanced, "jumbo" version of John the Ripper supports hundreds of hash and cipher types |
|
Ophcrack |
|
Free Windows password cracker based on rainbow tables |
|
Aircrack-ng |
|
Complete suite to assess WiFi network security (replay attacks, deauth, fakeap and packet injection etc) Cracking: WEP and WPA PSK (WPA 1 and 2) |
|
Masscan |
|
Internet-scale port scanner. It can scan the entire Internet in under 5 minutes, transmitting 10 million packets per second, from a single machine |
|
Stegbreak |
|
Launches brute-force dictionary attacks on JPG image |
|
Stegseek |
|
Lightning fast steghide cracker that can be used to extract hidden data from files |
|
Quipqiup |
|
An online tool for breaking substitution ciphers or vigenere ciphers (without key) |
|
Hydra |
|
Parallelized login cracker which supports numerous protocols to attack |
|
Wordpress brute #1 |
|
hydra -V -l <wordlist> -p 123 <ip_host> http-post-form '/wp-login.php:log=^USER^&pwd=^PASS^&wp-submit=Log+In:F=Invalid Username' |
|
Dirstalk |
|
Dirstalk is a multi threaded application designed to brute force paths on web servers |
|
Dirb |
|
DIRB is a Web Content Scanner. It looks for existing (and/or hidden) Web Objects |
|
Thor |
|
SSH login brute force cracker |
|
Dirbuster |
|
DirBuster is a multi threaded java application designed to brute force directories and files names on web/application servers |
|
Wfuzz |
|
Wfuzz has been created to facilitate the task in web applications assessments and it is based on a simple concept: it replaces any reference to the FUZZ keyword by the value of a given payload |
|
Gobuster |
|
tool used to brute-force URIs, DNS, Virtual Host, Open Amazon S3 buckets |
|
Gobuster dir+session |
|
gobuster dir -u http://<ip_host> -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php -c PHPSESSID=<session_value> |
|
Vigenere |
|
online tool breaks Vigenere ciphers without knowing the key |
|
Unshadow |
|
Tool combines the passwd and shadow files so John can use them |
|
Fcrackzip |
|
A braindead program for cracking encrypted ZIP archives |
|
CiLocks |
|
Crack Interface lockscreen, Metasploit and More Android/IOS Hacking |
|
Truecrack |
|
TrueCrack is a brute-force password cracker for TrueCrypt (Copyrigth) volumes (GPU support) |
|
Hackingtool |
|
ALL IN ONE Hacking Tool For Hackers (It's okay and works but i would use it just a yey an option for a tool) |
|
Ciphey |
|
Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes |
|
Cryptii |
|
Web app offering modular conversion, encoding and encryption online. Translations are done in the browser without any server interaction. Very handy CTF tool! |
|
Mfoc |
|
Mifare Classic Offline Cracker |
|
Ffuf |
|
Fast web fuzzer written in Go |
|
Dirsearch |
|
Web path scanner |
|