pwndbg
masscan
Our great sponsors
pwndbg | masscan | |
---|---|---|
9 | 64 | |
6,563 | 22,472 | |
3.2% | - | |
9.5 | 7.8 | |
4 days ago | 13 days ago | |
Python | C | |
MIT License | GNU Affero General Public License v3.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
pwndbg
- Need help installing pwndbg on Kali Linux
-
Hacked GDB Dashboard Puts It All on Display
There are a lot of these types of tools already in the reverse engineering community (in order of lowest chance of breaking when you throw really weird stuff at it):
GEF: https://gef.readthedocs.io/en/master/
PWNDBG: https://github.com/pwndbg/pwndbg
PEDA: https://github.com/longld/peda
They also come with a slew of different features to aid in RE/exploit dev, but many of them are also useful for debugging really weird issues.
-
Debugging with GDB
GDB is great. I definitely recommend checking out watchpoints as well, a very useful tool for monitoring how a variable changes over time.
GDB also has many good plugins - pwndbg has tons of features and UI improvements over stock GDB.
-
Awesome CTF : Top Learning Resource Labs
Pwndbg - A GDB plugin that provides a suite of utilities to hack around GDB easily.
masscan
- Why so many bots?
-
Has anyone ever had their homelab or network hacked? What happened?
Nope, this doesn't work any more. Shodan checks all ports (so any attackers using data from Shodan already know which ports you have open), and tools like masscan (https://github.com/robertdavidgraham/masscan) let you portscan the entire IPv4 address space in less than 10 minutes.
-
Private server intruded
https://github.com/LogoiLab/mcsl https://github.com/robertdavidgraham/masscan
The discord user at the time used the tool "Masscan" to scan every 25565 port on the internet, he claims he was able to get the entire internet scanned in just a few minutes with a 512MB buyvm slice.
- PSA: Masscan has changed his IP. Please block the new one on your firewall! Its likely our vps reporting worked.
-
Is this something i should worry about? Its whitelist, online mode, and the ip/user has been banned. Its been happening for a week now
Masscan is a tool for scanning large segments of the internet for open ports. I've used it previously and it's not an inherently malicious tool.
-
Recommended high speed port scanner?
https://github.com/robertdavidgraham/masscan can scan the entire Internet in under 5 minutes
-
Large scale Internet SSH brute force attacks seem to have stopped here
"Not hard", to say the least, yeah:
- Shodan
What are some alternatives?
gef - GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux
RustScan - 🤖 The Modern Port Scanner 🤖
peda - PEDA - Python Exploit Development Assistance for GDB
zmap - ZMap is a fast single packet network scanner designed for Internet-wide network surveys.
amass - In-depth attack surface mapping and asset discovery
nuclei - Fast and customizable vulnerability scanner based on simple YAML based DSL.
zgrab2-configurations - A repository for possible zgrab2 configurations
pwntools - CTF framework and exploit development library
gdb-dashboard - Modular visual interface for GDB in Python
one_gadget - The best tool for finding one gadget RCE in libc.so.6
SQLMap - Automatic SQL injection and database takeover tool
Metasploit - Metasploit Framework