[TOOL] Hping3 (alpha1) - TCL Scripting Support Added To Hping

From: SecuriTeam (support_at_securiteam.com)
Date: 06/22/04

  • Next message: SecuriTeam: "[TOOL] Wasabi - Log Monitoring and Alert Tool"
    To: list@securiteam.com
    Date: 22 Jun 2004 20:06:21 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Hping3 (alpha1) - TCL Scripting Support Added To Hping
    ------------------------------------------------------------------------

    SUMMARY

    DETAILS

     <http://www.hping.org/hping3.html> Hping3 is a network tool able to send
    custom TCP/IP packets and to display target replies like ping does with
    ICMP replies. hping3 can handle fragmentation, and almost arbitrary packet
    size and content, using the command line interface.

    Since version 3, hping implements scripting capabilities. Hping3 fully
    supports the TCL scripting language, and packets can be received and sent
    via a binary or string representation describing the packets. In practice
    this means that a few lines of code can perform things that usually take
    many lines of C code. Examples are automated security tests with pretty
    printed report generation, TCP/IP test suites, many kind of attacks,
    NAT-ting, prototypes of firewalls, implementation of routing protocols,
    and so on.
    Scripts can generate and read packets, but there are also commands to read
    and manipulate interface lists, arp tables, routinging, and firewalls.
    Hping3 is not a packet generation extension for a scripting language, it
    is a scriptable security tool. Of course hping3 scripts can access all the
    features of the Tcl language, so for example your hping3 script performing
    a port scanner can save the result in a MySQL database, draw a graph with
    open ports, and many other things.

    Hping should work without problems on the following unix-like systems:
    ?* Linux, FreeBSD, NetBSD, OpenBSD, Solaris, MacOs X.

    Hping3 requires libpcap, gmake and the TCL development source (tcl-dev).

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:antirez@invece.org>
    Salvatore Sanfilippo.
    Visit the tool's homepage at: <http://www.hping.org/hping3.html>
    http://www.hping.org/hping3.html

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[TOOL] Wasabi - Log Monitoring and Alert Tool"

    Relevant Pages

    • [Full-Disclosure] MS web designers -- "What Security Initiative?"
      ... I commented on the uselessness of the "new, improved" MS Security ... like me whose security sensibilities require surfing with scripting ... the reason for today's swing at MS' web designers -- spam. ... window.parent.location.replace to redirect the page. ...
      (NT-Bugtraq)
    • MS web designers -- "What Security Initiative?"
      ... I commented on the uselessness of the "new, improved" MS Security ... like me whose security sensibilities require surfing with scripting ... the reason for today's swing at MS' web designers -- spam. ... window.parent.location.replace to redirect the page. ...
      (Bugtraq)
    • [Full-Disclosure] MS web designers -- "What Security Initiative?"
      ... I commented on the uselessness of the "new, improved" MS Security ... like me whose security sensibilities require surfing with scripting ... the reason for today's swing at MS' web designers -- spam. ... window.parent.location.replace to redirect the page. ...
      (Full-Disclosure)
    • MS web designers -- "What Security Initiative?"
      ... I commented on the uselessness of the "new, improved" MS Security ... like me whose security sensibilities require surfing with scripting ... the reason for today's swing at MS' web designers -- spam. ... window.parent.location.replace to redirect the page. ...
      (Full-Disclosure)
    • IE scripting Vulnerabilities
      ... The object property of embedded WebBrowser controls is not subject to the Cross Domain security checks that embedded HTML documents ordinarily go through, and as such it is possible to escape any sandboxing and security zone restrictions. ... Any document can extend the properties exposed by the OBJECT element, and any namespace conflicts are handled by querying the object property which is a duplicate reference to the embedded document. ... Disable ActiveX by Setting "Script ActiveX controls marked safe for scripting" to Prompt or Disable. ...
      (NT-Bugtraq)