Lynis 1.2.6 – UNIX System & Security Auditing Tool

Lynis is an auditing tool for Unix (specialists). It scans the system and available software, to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes.

This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems. It can be run without prior installation, so inclusion on read only storage is no problem (USB stick, cd/dvd).

Lynis assists auditors in performing Basel II, GLBA, HIPAA, PCI DSS and SOX (Sarbanes-Oxley) compliance audits.

A lot of new checks and controls have been added in this latest release (Full Changelog). Do note Lynix is not a hardening tool, it won’t make any changes – only suggestions.

Intended audience:
Security specialists, penetration testers, system auditors, system/network managers.

Examples of audit tests:

  • Available authentication methods
  • Expired SSL certificates
  • Outdated software
  • User accounts without password
  • Incorrect file permissions
  • Firewall auditing

You can download Lynix 1.2.6 here:

lynis-1.2.6.tar.gz

Or read more here.

winAUTOPWN – Windows Autohacking Tool

winAUTOPWN is a TooL to Autohack your targets with least possible interaction. The aim of creating winAUTOPWN is not to compete with already existing commercial frameworks like Core Impact (Pro), Immunity Canvas, Metasploit Framework (freeware), etc. which offer autohacks, but to create a free, quick, standalone application which is easy to use and doesn’t require a lot of support of other dependencies.

Also not forgetting that winAUTOPWN unlike other frameworks maintains the original exploit writer’s source code intact just as it was and uses it. This way the exploit writer’s credit and originality is maintained. The source is modified only when required to enable a missing feature or to remove hard-coded limitations. Under these circumstances also, the exploit writers credits remain intact.

Newer exploit modules are added as and when they release and older ones are also being daily added.
Binaries of perl, php, python and cygwin DLLs (included) are required to exist either in a common folder or should be properly installed with their paths registered for those exploits which are cannot be compiled into a PE-exe.

Features :

  • Contains already custom-compiled executables of famous and effective exploits alongwith a few original modified exploits.
  • No need to debug, script or compile the source codes.
  • Scans all ports 1 – 65535 after taking the IP address and tries all possible exploits according to the list of discovered open ports (OpenPorts.TXT)
  • PortScan is multi-threaded.
  • Doesn’t require any Database like (PostGres,MySQL,etc.) at the back-end
  • Can be also be used to test effectiveness of IDS/IPS
  • Launched exploits are independent and doesn’t rely on service fingerprinting (to avoid evasion, if any)
  • Requires presence of php, perl and python with registeredpaths in Environment variables.

winAUTOPWN is updated almost daily. A separate DragonflyBSD-server is being set up which will hold the exploit repository and the next version will autosync the exploits from them in the appropriate folder.

You can download winAUTOPWN here:

winAUTOPWN.RAR

Or read more here.