bettercap
The Swiss Army knife for 802.11, BLE, IPv4 and IPv6 networks reconnaissance and MITM attacks. (by bettercap)
nuclei
Fast and customizable vulnerability scanner based on simple YAML based DSL. (by projectdiscovery)
Our great sponsors
bettercap | nuclei | |
---|---|---|
28 | 17 | |
15,655 | 17,148 | |
1.5% | 3.2% | |
1.0 | 9.8 | |
18 days ago | 7 days ago | |
Go | Go | |
GNU General Public License v3.0 or later | MIT License |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
bettercap
Posts with mentions or reviews of bettercap.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2023-10-03.
-
bettercap VS petep - a user suggested alternative
2 projects | 3 Oct 2023
-
Malware installed in this bluetooth remote?
you can do this with Bettercap
- bettercap hell
-
quicklisp security (or total lack of it)
I've been learning some common lisp, reading through Practical Common Lisp, and it's really neat. People say the good ideas of lisp got adapted in other languages and sure that's true of garbage collection, lambda's and some others, but I'm seeing plenty incredible stuff I haven't seen elsewhere, the condition system that among other things lets you fix and resume your program on exception, real interactive development, flexible object system, macros way more understandable than in other languages with AST macros as in lisp the AST is simple, an expressive dynamic language at high level of ruby and python while being an order of magnitude faster performance. Quicklisp also is really neat, how many other package managers can load new dependencies without restarting your application? And I was learning it with idea that it's not just of historical or hobby interest but legitimately a good choice I can use for new programming projects today for many tasks, but I just learned something that makes it impossible for me to consider, which is complete lack of security of quicklisp. You go to the website and see sha256 hash and PGP signature for quicklisp download, awesome it seems at the security standard you expect for a package manager. But then the actual quicklisp client does all downloads over http with no verification. What this means in practical terms is basically if you use quicklisp, anyone on your local network can easily hack your computer, by MITM (man-in-the-middle) the traffic and serving you backdoored software when you install packages from quicklisp. mitm6 will MITM windows machines on normal networks, bettercap can MITM linux and os x on most networks. Aside from attackers on your local network there's plenty other scenarios, you can go near office of CL using company and set up a open WIFI access point with same name as company wifi and hack their developers, using quicklisp over something like Tor is extremely dangerous at present as it would let the exit node backdoor the packages you download, and then in less likely but still should be protected against scenarios is just if quicklisp.org or any router between you and it is compromised, you can be hacked.
- Grannar från helvetet
- Bettercap – Swiss Army Knife for 802.11, BLE, IPv4 and IPv6 Networks
-
Hacker News top posts: Dec 3, 2022
Bettercap – Swiss Army Knife for 802.11, BLE, IPv4 and IPv6 Networks\ (5 comments)
nuclei
Posts with mentions or reviews of nuclei.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2023-05-22.
-
The 36 tools that SaaS can use to keep their product and data safe from criminal hackers (manual research)
Nuclei
- Show HN: Oneleet – Penetration Testing for SoC 2 and beyond
-
Looking for short-term, resource intensive tasks to throw at a cloud server
If you own any web properties, you can use https://github.com/projectdiscovery/nuclei running in a beefy VM to scan them for vulnerabilities. It will scale to use all available resources if you give it a big box.
-
Pentesting Tools I Use Everyday
Learn more about nuclei here: https://nuclei.projectdiscovery.io/
-
How I found 130+ Sub-domain Takeover vulnerabilities using Nuclei
Read about how I was able to find 136 Sub-domain Takeover vulnerabilities on a Single Target using the Nuclei tool 👉👉👉Click Here - How I found 130+ Sub-domain Takeover vulnerabilities using Nuclei
-
How to develope a Network Vuln Scanner
I’d look at flan and nmap and nuclei for inspiration.
-
Thoughts on Vuln scanning public facing websites/hosts during an incident?
Had an idea to leverage the community vuln scanner Nuclei (https://nuclei.projectdiscovery.io/) to just run a quick scan against the public facing hostname/IP. The job isn't supposed to be "hey you're vulnerable to xyz, but to aid in the discovering initial access. I believe this would be considered "good faith" and you're not technically be doing anything nefarious, but wanted to get the communities thoughts on this.
- Nuclei – Community Powered Vulnerability Scanner
-
Log4J Network Scanning/Detection on a 100k+ Node Network
Check out Nuclei (https://github.com/projectdiscovery/nuclei)
What are some alternatives?
When comparing bettercap and nuclei you can also consider the following projects:
aircrack-ng - WiFi security auditing tools suite
jaeles - The Swiss Army knife for automated Web Application Testing
MITMf - Framework for Man-In-The-Middle attacks
ZAP - The ZAP core project
mitmproxy - An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
SQLMap - Automatic SQL injection and database takeover tool
wifipumpkin3 - Powerful framework for rogue access point attack.
ffuf - Fast web fuzzer written in Go
pwnagotchi-display-password-plugin - Pwnagotchi plugin to display the most recently cracked password on the Pwnagotchi face
RustScan - 🤖 The Modern Port Scanner 🤖
Metasploit - Metasploit Framework
osmedeus - A Workflow Engine for Offensive Security