Test your own sites security! - Goolag scanner -

Discussion in 'Security' started by SSANZ, Mar 25, 2008.

  1. #1
    Are you really secure? Test your own sites security :)

    DOWNLOAD HERE - Goolag_Scanner_1.0.0.40_Setup.exe

    verify your own content security ;) Don't get hacked by kids.



    Are you secure?

    DOWNLOAD HERE - Goolag_Scanner_1.0.0.40_Setup.exe



    I see a lot of members on this forum not up to " skill " in security of there own servers, However these easy GUI " scanners " can aid in identifying vulnerable content. :)


    I will be posting more interesting tools, supporting the patching of vulnerable content/servers.

    Regards.
     
    SSANZ, Mar 25, 2008 IP
  2. Ladadadada

    Ladadadada Peon

    Messages:
    382
    Likes Received:
    36
    Best Answers:
    0
    Trophy Points:
    0
    #2
    I'm confused. Why is a site called "FastLinuxDownloads" offering a Windows .exe file ?
     
    Ladadadada, Mar 25, 2008 IP
  3. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Just because the domain has the world linux in it, doesn't mean it must be only linux files.

    :rolleyes:
     
    SSANZ, Mar 25, 2008 IP
  4. Ladadadada

    Ladadadada Peon

    Messages:
    382
    Likes Received:
    36
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Does that mean there's no guarantee of there being "Fast Downloads" on the site either ? :p
     
    Ladadadada, Mar 26, 2008 IP
  5. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #5
    lol...

    lets put the domain into the theory of

    " Fast Linux HOSTED Downloads "

    putting the linux definition into effect :p - Fast, reliable and not WINDOZE.
     
    SSANZ, Mar 26, 2008 IP
  6. Rory M

    Rory M Peon

    Messages:
    1,020
    Likes Received:
    37
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Is there a mac version of this (or something similar)? I could always have crossover try and run it but if there is a native then that would be great
     
    Rory M, Mar 28, 2008 IP
  7. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #7
    check out the vendors site.
     
    SSANZ, Mar 29, 2008 IP
  8. just-4-teens

    just-4-teens Peon

    Messages:
    3,967
    Likes Received:
    168
    Best Answers:
    0
    Trophy Points:
    0
    #8
    just-4-teens, Mar 29, 2008 IP
  9. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #9

    Thats why i put it through anubis.....

    most AV's will detect this as a hack tool scanner, because why? Oh thats right! It is a scanner...
     
    SSANZ, Mar 29, 2008 IP
  10. Ladadadada

    Ladadadada Peon

    Messages:
    382
    Likes Received:
    36
    Best Answers:
    0
    Trophy Points:
    0
    #10
    I think a lot of anti-virus companies put in things like this just to boost the number of malware programs they can claim to detect.

    Technically, if a hacker took control of your computer and then started using a scanning tool on it to scan for new targets to attack then it would be nice to know about it butit doesn't solve the reall problem and it doesn't add very much value.

    While I was investigating some of the hacking attempts on my website, I downloaded one of the PHP scripts the hackers tried to force me to include in my PHP code. (Some examples can be found here but many have been fixed now. A search for "safe.txt or id.txt will usually find fresh ones.) The next day, the virus scan my work runs daily picked up the PHP script I had saved on my desktop as being "malicious" and deleted it.
     
    Ladadadada, Mar 30, 2008 IP
  11. just-4-teens

    just-4-teens Peon

    Messages:
    3,967
    Likes Received:
    168
    Best Answers:
    0
    Trophy Points:
    0
    #11

    my download also said that it was corrupted.
     
    just-4-teens, Mar 30, 2008 IP
  12. the_wanderer

    the_wanderer Peon

    Messages:
    43
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #12
    the_wanderer, Mar 31, 2008 IP
  13. clubmaster3

    clubmaster3 Peon

    Messages:
    103
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #13
    The scanner is nice and i tested it the day it was released. It is a much better scanner than the others that where out there using Google to scan for vulnerabilities. You won´t get banned so fast by google, but if you don´t use proxies you definetely will if you want to check the whole site with all included dorks.
    On the other sites it scans for well known google dorks and this doesn´t mean you are secure.... Your site is secure from people that find vulnerable sites over google.
    This Scanner can´t tell anything about your server secifictions or what you are running on. It´s a good additional option but it isn´t enough in my opinion.
    Acunetix or Shadow security scanner do deliver much detailled scans and not to forget nmap.
    The best is a combination of manual tests and different scanners in my eyes.
     
    clubmaster3, Apr 3, 2008 IP
  14. toby

    toby Notable Member

    Messages:
    6,923
    Likes Received:
    269
    Best Answers:
    0
    Trophy Points:
    285
    #14
    dont you think this could leave a back door for hacker?
    I have been badly hurt by phishing and hacking attempt. Just becareful of keyloggers guys!
     
    toby, Apr 3, 2008 IP
  15. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #15
    if you read above, you wouldn't be scared.

    I have analyzed this via anubis exe analyzer here - http://analysis.seclab.tuwien.ac.at/

    scan it for yourself.

    Its no danger to your pc, md5 checksum it if you have to.
     
    SSANZ, Apr 6, 2008 IP
  16. Louis11

    Louis11 Active Member

    Messages:
    783
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    70
    #16
    Louis11, Apr 8, 2008 IP