Cатсн²² (in)sесuяitу / ChrisJohnRiley

Because we're damned if we do, and we're damned if we don't!

Tools / Scripts

Here you’ll find a list of tools and scripts that I’ve released. Most I’ve written for my own purposes, so you’re mileage may vary. If you can’t get a script working (after a suitable amount of trying… obviously), feel free to contact me through the comments (I do monitor them on and off).

Metasploit Modules (General)

This page serves as a central location for code I’ve written to work with the Metasploit Framework (version 3.x). Some content here may be outdated, as once it’s integrated to the Metasploit SVN (if accepted into the main tree) all further edits will occur in the SVN directly.

A full list of modules can be viewed/downloaded here.

PRN-2-ME (Printer MITM TOOL)

PRN-2-me is a simple listener that can be configured to run on any port (default is 9100 for jetdirect style connections). The tool will then save all incoming PCL and PostScript print jobs to file and forward them on to the real printer.

More information can be found here.

[PoC] scr.im.tessercap (CAPTCHA OCR)

A short PoC script for decoding scr.im CAPTCHAs using the Python-tesseract library. Based on a script originally written by Andreas Riancho from Bonsai-sec.com. This example is tuned for scr.im CAPTCHA images, but should serve as a basis for other CAPTCHA decoding scripts.

More information can be found here.

[PoC] scr.im-jim

scr.im-jim (a play on the slim-jim tool used to break into cars without keys) is a Proof of Concept Python (2.x / beautifulsoup required) script to demonstrate the ease of which the http://scr.im captcha protection can be bypassed. The issues exploited where first documented in October 2009 here.

More information can be found here.

UA-Tester

UA-Tester is a Python (2.5/2.6) script to compare server header responses given a list of User-Agent strings to test. It will display the results back and show the headers altered, added or removed.

More information can be found here.

TYPo3 Default Encryption Keys (PoC)

These Proof-of-Concept scripts test for and exploit a vulnerability in Typo3 where the default encryption keys are created using a lack of suitable entropy.

More information can be found here.

One response to “Tools / Scripts

  1. Pingback: scr.im revisited | Cатсн²² (in)sесuяitу

Leave a comment