Section: .. / distributed /
|
Denial of Service tools are for use when testing your own machines only. Use of these tools on a test network is the only way to build a stable network enabled product that will not crash under the load of a distributed packet flood.
|
| /// File Name: |
cisco-newsflash.htm |
Description:
|
Cisco Newsflash - Distributed Denial of Service. Contains information to help you understand how DDoS attacks are orchestrated, recognise programs used to launch DDoS attacks, and apply measures to prevent the attacks (including anti-spoofing commands, egress filtering, RPF and CEF, ACL's, rate limiting for SYN packets). Also contains information on gathering forensic information if you suspect an attack, and learning more about host security.
| | File Size: | 12786 | | Last Modified: | Feb 11 01:14:05 2000 |
| MD5 Checksum: | 7c18c020e8436f0a308e7e315655f43c |
|
| /// File Name: |
flitz-0.1.tgz |
Description:
|
Flitz is a DDOS tool which features spoofed ip/tcp/udp flood, flooding in parallel, distributed smurf attack and status report of the slave. With one stop command, you can stop all the slaves at once.
| | Author: | Xphere | | Homepage: | http://home.wanadoo.nl/gin | | File Size: | 12659 | | Last Modified: | Jan 9 00:42:01 2001 |
| MD5 Checksum: | 4fc98181098322eecfb91ab4b2860d61 |
|
| /// File Name: |
Freak88.zip |
Description:
|
Freak88's Distributed Attack Suite is a windows trojan similar to wintrin00. It can connect up to 3 infected machines and start 65000 byte ICMP floods. Auto starts from the registry and copies itself to c:\windows\system.
| | Author: | Freak88[at]dalnet | | Homepage: | http://www.freak88.net | | File Size: | 12434 | | Last Modified: | May 14 23:30:14 2000 |
| MD5 Checksum: | 7dbf5b3a7be12d4ee861d5b33bfe1f2d |
|
| /// File Name: |
TFN2k_Analysis-1.3.txt |
Description:
|
This document is a technical analysis of the Tribe Flood Network 2000 (TFN2K) distributed denial-of-service (DDoS) attack tool, the successor to the original TFN Trojan by Mixter. Additionally, countermeasures for this attack are also covered.
| | Author: | Jason Barlow | | Homepage: | http://www2.axent.com/swat/ | | Changes: | This revision includes several new discoveries, corrections, and clarifications. Many thanks to those who responded with feedback and comments to the original posting of this paper. | | File Size: | 12384 | | Last Modified: | Mar 9 21:03:42 2000 |
| MD5 Checksum: | b5d3d9e9a39745decbd6d2d701451e77 |
|
| /// File Name: |
zmbscap-0.1.tar.gz |
Description:
|
The zombie scapper is an automated perl tool for detecting and stopping distributed denial of service programs. The tool automatically searches and scans the desired target for programs by looking for the ports that are used by the zombie masters. It stops the zombie masters by sending a kill/stop trigger.
| | Homepage: | http://www.metaeye.org/projects/zmbscap/ | | File Size: | 11675 | | Last Modified: | Feb 20 02:15:49 2007 |
| MD5 Checksum: | cc93207baf3dcbcf2b16c9293accbba7 |
|
| /// File Name: |
ramenfind.v0.4.gz |
Description:
|
Ramenfind v0.4 is a local Ramen worm detection and removal tool. Final release unless problems are found.
| | Homepage: | http://www.sans.org/y2k/ramen.htm | | Changes: | Ramenfind now handles a new ramen variant, which creates /usr/sbin/update. | | File Size: | 11542 | | Last Modified: | Feb 16 02:29:41 2001 |
| MD5 Checksum: | 47ec41edc981a66df35e1dcaec2fa47c |
|
| /// File Name: |
dscan-0.4.tar.gz |
Description:
|
A simple distributed port scanner that uses many computers to conduct a port scan which should make it harder to trace the source. This release of dscan has many improvements of the last release, for a full list see the HISTORY file in the archive. Dscan started off as proof of concept code and has now turned into a project for testing new techniques such as linked lists. This release does not come with UDP port scanning support but a patch file should be available in a few days time to add UDP support.
| | Author: | Andrew Kay | | File Size: | 11145 | | Last Modified: | Jan 7 22:43:44 2000 |
| MD5 Checksum: | 3c2bb813c280c1a902e2f385e8c0a543 |
|
| /// File Name: |
mio-star.tgz |
Description:
|
The mio-star distributed multihosted unix password cracker v0.1 runs on all platforms where perl is installed. Comments and documentation is in German.
| | Author: | Drunken Monkey Style | | File Size: | 9961 | | Last Modified: | Apr 25 19:08:42 2000 |
| MD5 Checksum: | 38125314bcf691a20a4acf5974f43e02 |
|
| /// File Name: |
ramenfind.v0.3.gz |
Description:
|
Ramenfind v0.3 is a local Ramen worm detection and removal tool. Final release unless problems are found.
| | Homepage: | http://www.sans.org/y2k/ramen.htm | | File Size: | 9678 | | Last Modified: | Feb 11 01:13:23 2001 |
| MD5 Checksum: | 6e86aeec1678f9955176db9aa9d73f7d |
|
| /// File Name: |
ddosping.zip |
Description:
|
DDoSPing v2.0 is a Win 9x/NT GUI scanner for the DDoS agents Wintrinoo, Trinoo, Stacheldraht and TFN.
| | Author: | Robin Keir | | Homepage: | http://www.foundstone.com | | File Size: | 9655 | | Last Modified: | Dec 13 07:28:23 2000 |
| MD5 Checksum: | 92dbe2bfc9673ec480aea091b042093b |
|
| /// File Name: |
icmpenum-1.1.tgz |
Description:
|
This is a proof-of-concept tool to demonstrate possible distributed attacking concepts, such as sending packets from one workstation and sniffing the reply packets on another.
| | Author: | Simple Nomad | | Homepage: | http://razor.bindview.com | | File Size: | 8613 | | Last Modified: | Feb 17 00:37:04 2000 |
| MD5 Checksum: | 887a4b39a441342a46a392bddced1aaa |
|
| /// File Name: |
slurpie.tgz |
Description:
|
Slurpie v2.0b - Slurpie is a passwd file cracker similar to CrackerJack and John the Ripper except that it runs in a distributed environment. It supports file based and generated dictionary comparison.
| | Author: | Adam Klosowicz. | | File Size: | 8117 | | Last Modified: | Aug 17 02:07:14 1999 |
| MD5 Checksum: | 820b4bf746e0a1297516ddd4a83958db |
|
| /// File Name: |
tfn.tgz |
Description:
|
Distributed flood network client/server that can be installed on a large number of hosts and used to hit a target with high bandwidth simultaneously. communicates over icmp and supports udp, syn, icmp/8, smurf flood and more. Courtesy of Mixter.
| | File Size: | 8093 | | Last Modified: | Sep 23 21:47:52 1999 |
| MD5 Checksum: | 4286277c823ee297b84142ebb50be118 |
|
| /// File Name: |
blitznet.tgz |
Description:
|
Blitznet launches a distributed syn flood attack with spoofed source IP, without logging.
| | Author: | Phreeon | | File Size: | 8055 | | Last Modified: | Dec 9 21:33:31 1999 |
| MD5 Checksum: | c58067ac29321e40ba72d357c136f798 |
|
| /// File Name: |
tfn2kpass.c |
Description:
|
Tfn2k password recovery tool - Tfn2k asks for a password during the build, which is used to prevent someone from recovering the password from the td or tfn binaries. Usefor for forensics, or to command a whole flood network to send you mail letting you know all the machines infected, or to command an attack to stop if you can recover a binary.
| | Author: | Simple Nomad | | Homepage: | http://razor.bindview.com | | File Size: | 7716 | | Last Modified: | Feb 25 04:13:08 2000 |
| MD5 Checksum: | 85a08d1006bc2666af3ae36a80775b53 |
|
| /// File Name: |
icmpenum-1.1.1.tgz |
Description:
|
This is a proof-of-concept tool to demonstrate possible distributed attacking concepts, such as sending packets from one workstation and sniffing the reply packets on another.
| | Author: | Simple Nomad | | Homepage: | http://razor.bindview.com | | File Size: | 7610 | | Last Modified: | Oct 21 05:14:03 2003 |
| MD5 Checksum: | 007b9032c081f6fef832762eec96be5e |
|
| /// File Name: |
firstaid.txt |
Description:
|
Mixters guide to defending against DDOS - 10 Proposed 'first-aid' security measures which should be implemented by anyone at risk.
| | Author: | Mixter | | Homepage: | http://mixter.void.ru | | File Size: | 7465 | | Last Modified: | Feb 11 20:16:50 2000 |
| MD5 Checksum: | fc483ecea83567cb0345cc2edf2227c6 |
|
| /// File Name: |
icmpdoor.tar.gz |
Description:
|
Small ICMP based backdoor and DDoS slave + master. In German and English.
| | Author: | l0om | | File Size: | 7147 | | Last Modified: | Oct 21 04:21:56 2003 |
| MD5 Checksum: | 3cae6d2651972b788eb60a662a67ea5d |
|
| /// File Name: |
ddos.txt |
Description:
|
DDoS IRC bots are becoming popular Distributed Denial Of Service attack method. They do not require unix clients to operate and are easy to use. Hypnosis
| | File Size: | 6735 | | Last Modified: | Aug 2 04:15:16 2001 |
| MD5 Checksum: | 980ed56098d63fbde886f77e2e9c335c |
|
| /// File Name: |
ddnsf.tar.gz |
Description:
|
Distributed DNS Flooder v0.1b - A powerful attack against DNS servers.
| | Author: | Extirpater | | File Size: | 6233 | | Last Modified: | Mar 27 02:43:53 2001 |
| MD5 Checksum: | 3672dfbec5c48d4a4a8aef930a29c8fa |
|
| /// File Name: |
UDPer.asm |
Description:
|
UDPer is a logic bomb written in ASM for Windows which floods a victim with packets at a certain date.
| | Author: | Frost_Byte | | File Size: | 6155 | | Last Modified: | Jul 24 19:11:22 2000 |
| MD5 Checksum: | 09825a75cecb5dea72f26eddaa024528 |
|
| /// File Name: |
ddos-thought.txt |
Description:
|
Some thoughts on the solutions to Distributed Attack Technology - Distribited ownership tools [DOT] exist that scan numerous hosts for vunerabilities that allow agents to be installed automatically. Potential solutions include more host based security, fixing ipv4, legislation, and fighting fire with fire.
| | Author: | The Cat | | File Size: | 5999 | | Last Modified: | Mar 10 09:14:38 2000 |
| MD5 Checksum: | 366c7309dbce3df4ecb3b6cb219300a5 |
|
| /// File Name: |
yahoo.txt |
Description:
|
Technical details of the attack on Yahoo! last week. Includes information on what kind of packets were sent, how they were affected, and how they fixed it.
| | File Size: | 5766 | | Last Modified: | Feb 17 19:20:52 2000 |
| MD5 Checksum: | 4da5382bb2001defe0ab0207cdf348dd |
|
| /// File Name: |
rivat.tgz |
Description:
|
Rivat is a distributed CGI scanner written in perl which scans for over 405 vulnerabilities.
| | Author: | Xtremist | | Homepage: | http://www.r00tabega.com | | File Size: | 5730 | | Last Modified: | Jul 31 23:22:46 2000 |
| MD5 Checksum: | 3e13dff1d33f06227f8e2e98d96d6a46 |
|
|
|
|
|