经过BlackHat组委会近两个月的收集,近日Blackhat2012放出了本届大会接收到的“安全工具”列表。
新工具(将在Blackhat上首发)46%
漏洞评估工具 22%
Web应用工具 12%
逆向工具 5%
白帽子工具 20%
Fuzzing工具 5%
恶意软件研究 7%
监控软件(IDS,IPS,网络,主机,进程)2%
信息收集 5%
以下所列是大会上会涉及到的兵器谱:
..cantor.dust.. Armitage ARPwner AWS Scout backfuzz Burp Extensibility Suite Bypassing Every CAPTCHA provider with clipcaptcha CrowdRE FakeNet GDFuzz Generic Metasploit NTLM Relayer Gsploit HTExploit bypassing htaccess restrictions ice-hole 0.3 (beta) Incident Response Analysis Visualization and Threat Clustering through Genomic Analysis iSniff GPS Kautilya and Nishang LiME Forensics 1.1 MAP MIRV ModSecurity Open Source WAF OWASP Broken Web Applications Project Oyedata for OData Assessments peepdf phpmap Redline Registry Decoder SAP Proxy Semi-Automated iOS Rapid Assessment Smartphone Pentesting Framework Tenacious Diggity - New Google Hacking Diggity Suite Tools ThreadFix Vega WATOBO - Web Application Toolbox XMPPloit zCore IPS
感兴趣可以看看原文对每个工具的简介:
https://www.blackhat.com/html/bh-us-12/bh-us-12-arsenal.html