Web Application Security Memo

ウェブセキュリティに関するメモ書き

Kali Linux とは?

※当サイトにはプロモーションが含まれています。

公開日: 更新日:

Kali Linux

Kali Linux はペネトレーションテストに特化したLinuxディストリビューションです。Offensive Security社によって開発・メンテナンスされています。多くのペネトレーションテストツールが最初からインストールされています。

公式サイト:Kali Linux - Rebirth of BackTrack, the Penetration Testing Distribution.

以前はBackTrackという名前でしたが、UbuntuからDebianにプラットフォームを変更したのを機に、Kali Linuxとなりました(2013年3月)。Kali Linux の誕生については、The Birth of Kali Linux - Kali Linux に記載されています。

Kali Linux

Kali Linuxの画面左上にある[アプリケーション]メニュー -> [Kali Linux]以下に各ツールが登録されており、ここから起動することができます。このメニューはカテゴリ別になっていますが、1つのツールが複数のカテゴリに属していることもあるため、複数回登録されているツールもあります。

以下に、このメニュー内の階層構造をそのままメモしておきます。(つまり、Kali Linuxに収録されているツール一覧です)

  • Top 10 Security Tools
    • aircrack-ng
    • burpsuite
    • hydra
    • john
    • maltego
    • metasploit framework
    • nmap
    • owasp-zap
    • sqlmap
    • wireshark
  • Information Gathering
    • DNS Analysis
      • dnsdict6
      • dnsenum
      • dnsmap
      • dnsrecom
      • dnsrevenum6
      • dnstracer
      • dnswalk
      • fierce
      • maltego
      • nmap
      • urlcrazy
      • zenmap
    • IDS/IPS Identification
      • fragroute
      • fragrouter
      • ftest
      • lbd
      • wafw00f
    • Live Host Identification
      • alive6
      • arping
      • cdpsnarf
      • detect-new-ip6
      • detect_sniffer6
      • dmitry
      • dnmap-client
      • dnmap-server
      • fping
      • hping3
      • inverse_lookupj6
      • miranda
      • ncat
      • netdiscover
      • nmap
      • passive_discovery6
      • thcping6
      • wol-e
      • xprobe2
      • zenmap
    • Network Scanners
      • dmitry
      • dnmap-client
      • dnmap-server
      • netdiscover
      • nmap
      • zenmap
    • OS Fingerprinting
      • dnmap-client
      • dnmap-server
      • miranda
      • nmap
      • zenmap
    • OSINT Analysis
      • casefile
      • creepy
      • dmitry
      • jigsaw
      • maltego
      • metagoofil
      • theharvester
      • twofi
      • urlcrazy
    • Route Analysis
      • Otrace
      • dnmap-client
      • dnmap-server
      • intrace
      • netmask
      • trace6
    • SMB Analysis
      • acccheck
      • nbtscan
      • nmap
      • zenmap
    • SMTP Analysis
      • nmap
      • smtp-user-enum
      • swaks
      • zenmap
    • SNMP Analysis
      • braa
      • cisco-auditing-tool
      • cisco-torch
      • copy-router-config
      • merge-router-config
      • nmap
      • onesixtyone
      • snmpcheck
      • zenmap
    • SSL Analysis
      • sslcaudit
      • ssldump
      • sslh
      • sslscan
      • sslsniff
      • sslsplit
      • sslstrip
      • sslyze
      • stunnel4
      • tlssled
    • Service Fingerprinting
      • dnmap-client
      • dnmap-server
      • implementation6
      • implementation6d
      • ncat
      • nmap
      • sslscan
      • sslyze
      • tlssled
      • zenmap
    • Telephony Analysis
      • ace
    • Traffic Analysis
      • Otrace
      • cdpsnarf
      • ftest
      • intrace
      • irpas-ass
      • irpass-cdp
      • p0f
      • tcpflow
      • wireshark
    • VPN Analysis
      • ike-scan
    • VoIP Analysis
      • ace
      • enumiax
  • Vulnerability Analysis
    • Cisco Tools
      • cisco-auditing-tool
      • cisco-global-exploiter
      • cisco-ocs
      • cisco-torch
      • yersinia
    • Database Assessment
      • bbqsql
      • dbpwaudit
      • hexorbase
      • jsql
      • mdb-export
      • mdb-hexdump
      • mdb-parsecsv
      • mdb-sql
      • mdb-tables
      • oscanner
      • sidguesser
      • sqldict
      • sqlmap
      • sqlninja
      • sqlsus
      • tnscmd10g
    • Fuzzing Tools
      • bed
      • fuzz_ip6
      • ohrwurm
      • powerfuzzer
      • sfuzz
      • siparmyknife
      • spike-generic_chunked
      • spike-generic_listen_tcp
      • spike-generic_send_tcp
      • spike-generic_send_udp
    • Misc Scanners
      • golismero
      • lynis
      • nikto
      • nmap
      • unix-privesc-check
      • zenmap
    • Open Source Assessment
      • casefile
      • maltego
    • OpenVAS
      • openvas check setup
      • openvas feed update
      • openvas initial setup
      • openvas start
      • openvas stop
      • openvas-gsd
  • Web Applications
    • CMS Identification
      • blindelephant
      • plecost
      • wpscan
    • Database Exploitation
      • bbqsql
      • sqlninja
      • sqlsus
    • IDS/IPS Identification
      • ua-tester
    • Web Application Fuzzers
      • burpsuite
      • owasp-zap
      • powerfuzzer
      • webscarab
      • webslayer
      • websploit
      • wfuzz
      • xsser
    • Web Application Proxies
      • burpsuite
      • owasp-zap
      • paros
      • proxystrike
      • vega
      • webscarab
    • Web Crawlers
      • apache-users
      • burpsuite
      • cutycapt
      • dirb
      • dirbuster
      • owasp-zap
      • recon-ng
      • vega
      • webscarab
      • webslayer
    • Web Vulnerability Scanners
      • burpsuite
      • cadaver
      • davtest
      • deblaze
      • fimap
      • golismero
      • grabber
      • joomscan
      • jsql
      • nikto
      • owasp-zap
      • padbuster
      • proxystrike
      • skipfish
      • sqlmap
      • uniscan-gui
      • vega
      • w3af
      • wapiti
      • webscarab
      • webshag-gui
      • websploit
      • whatweb
      • wpscan
      • xsser
  • Password Attacks
    • GPU Tools
      • cudahashcat-plus
      • oclhashcat-lite
      • oclhashcat-plus
      • pyrit
    • Offline Attacks
      • cachedump
      • chntpw
      • cmospwd
      • crunch
      • cudahashcat-plus
      • dictstat
      • fcrackzip
      • hash-identifier
      • hashcat
      • john
      • johnny
      • lsadump
      • maskgen
      • multiforcer
      • oclhashcat-lite
      • oclhashcat-plus
      • ophcrack
      • ophcrack-cli
      • policygen
      • pwdump
      • pyrit
      • rainbowcrack
      • rcracki_mt
      • rsmangler
      • samdump2
      • sipcrack
      • sucrack
      • truecrack
    • Online Attacks
      • acccheck
      • burpsuite
      • cewl
      • cisco-auditing-tool
      • dbpwaudit
      • findmyhash
      • hydra
      • hydra-gtk
      • keimpx
      • medusa
      • ncrack
      • onesixtyone
      • owasp-zap
      • patator
      • phrasendrescher
      • thc-pptp-bruter
      • webscarab
    • Passing the Hash
      • pth-curl
      • pth-net
      • pth-openchangeclient
      • pth-rpcclient
      • pth-smbclient
      • pth-smbget
      • pth-sqsh
      • pth-winexe
      • pth-wmic
      • pth-wmis
  • Wireless Attacks
    • 802.11 Wireless Tools
      • aircrack-ng
      • asleap
      • bully
      • cowpatty
      • eapmd5pass
      • fern-wifi-cracker
      • genkeys
      • genpmk
      • giskismet
      • kismet
      • mdk3
      • wifi-honey
      • wifiarp
      • wifidns
      • wifiping
      • wifitap
      • wifite
    • Bluetooth Tools
      • bluelog
      • bluemaho
      • blueranger
      • bluesnarfer
      • btscanner
      • fang
      • spooftooph
    • Other Wireless Tools
      • zbassocflood
      • zbdsniff
      • zbdump
      • zbfind
      • zbgoodfind
      • zbreplay
      • zbstumbler
    • RFID / NFC Tools
      • NFC Tools
        • mfcuk
        • mfoc
        • mfterm
        • mifare-classic-format
        • nfc-list
        • nfc-mfclassic
      • RFIDiot ACG
        • brute force hitag2
        • bruteforce mifare
        • calculate jcop mifare keys
        • continuous select tag
        • copy iso15693 tag
        • epassport read write clone
        • format mifare 1k value blocks
        • identify hf tag type
        • identify Lf tag type
        • jcop info
        • jcop mifare read write
        • jcop set atr historical bytes
        • read acg reader eeprom
        • read lf tag
        • read mifare
        • read tag
        • read wite clone uniq (em4x02)
        • reset q5 tag
        • select tag
        • set fdx-b id
        • test acg lahf
      • RFIDiot FROSCH
        • read write clone unique (em4x02)
        • reset hitag2 tag
        • set fdx-b id
        • test frosch reader
      • RFIDiot PCSC
        • bruteforce mifare
        • calculate jcop mifare keys
        • chip & pin info
        • continuous select tag
        • epassport read/write/clone
        • identify hf tag type
        • jcop info
        • jcop mifare read/write
        • jcop set atr historical tytes
        • read mifare
        • read tag
        • select tag
    • Software Defined Radio
      • gnuradio-companion
      • gqrx
      • gr-scan
      • modes_gui
      • rtl_adsb
      • rtl_fm
      • rtl_sdr
      • rtl_tcp
      • rtl_test
      • rtlsdr-scanner
  • Exploitation Tools
    • BeEF XSS Framework
      • beef
    • Cisco Attacks
      • cisco-auditing-tool
      • cisco-global-exploiter
      • cisco-ocs
      • cisco-torch
      • yersinia
    • Exploit Database
      • searchsploit
    • Exploit Development Tools
      • NASM shell
      • edb-debugger
      • ollydbg
      • pattern create
      • pattern offset
    • Metasploit
      • metasplit community / pro
      • metasplit diagnostic logs
      • metasplit diagnostic shell
      • metasplit framework
      • update metasploit
    • Network Exploitation
      • armitage
      • exploit6
      • ikat
      • jboss-autopwn-linux
      • jboss-autopwn-win
      • termineter
    • Social Engineering Toolkit
      • setoolkit
  • Sniffing/Spoofing
    • Network Sniffers
      • darkstat
      • dnschef
      • dnsspoof
      • dsniff
      • ettercap-graphical
      • hexinject
      • mailsnarf
      • msgsnarf
      • netsniff-ng
      • passive_discovery6
      • responder
      • sslsniff
      • tcpflow
      • urlsnarf
      • webmitm
      • webspy
      • wireshark
    • Network Spoofing
      • dnschef
      • ettercap-graphical
      • evilgrade
      • fake_advertise6
      • fake_dhcps6
      • fake_dns6d
      • fake_dnsupdate6
      • fake_mipv6
      • fake_mld6
      • fake_mldrouter6
      • fake_router26
      • fake_router6
      • fake_solicitate6
      • fiked
      • macchanger
      • parasite6
      • randicmp6
      • rebind
      • redir6
      • responder
      • sniffjoke
      • sslsplit
      • sslstrip
      • tcpreplay
      • wifi-honey
      • yersinia
    • VoIP Tools
      • iaxflood
      • inviteflood
      • ohrwurm
      • protos-sip
      • rtpbreak
      • rtpfood
      • rtpinsertsound
      • rtpmixsound
      • sctpscan
      • siparmyknife
      • sipp
      • sipsak
      • svcrack
      • svcrash
      • svmap
      • svreport
      • svwar
      • voiphopper
    • Voice and Surveillance
      • msgsnarf
    • Web Sniffers
      • burpsuitednsspoof
      • driftnet
      • ferret
      • hamster
      • mitmproxy
      • owasp-zap
      • urlsnarf
      • webmitm
      • webscarab
      • webspy
  • Maintaining Access
    • OS Backdoors
      • cymothoa
      • dbd
      • intersect
      • powersploit
      • sbd
      • u3-pwn
    • Tunneling Tools
      • cryptcat
      • dbd
      • dns2tcpc
      • iodine
      • miredo
      • ncat
      • proxychains
      • proxytunnel
      • ptunnel
      • pwnat
      • sbd
      • socat
      • sslh
      • stunnel4
      • udptunnel
    • Web Backdoors
      • webacoo
      • weevely
  • Reverse Engineering
    • Debuggers
      • edb-debugger
      • ollydbg
    • Disassembly
      • jad
      • rabin2
      • radiff2
      • rasm2
    • Misc RE Tools
      • apktool
      • clang
      • clang++
      • dex2jar
      • flasm
      • javasnoop
      • radare2
      • rafind2
      • ragg2
      • ragg2-cc
      • rahash2
      • rarun2
      • rax2
  • Stress Testing
    • Network Stress Testing
      • denial6
      • dhcpig
      • dos-new-ip6
      • flood_advertise6
      • flood_dhcpc6
      • flood_mld26
      • flood_mld6
      • flood_mldrouter6
      • flood_router26
      • flood_router6
      • flood_solicitater6
      • fragmentation6
      • inundator
      • kill_router6
      • macof
      • rsmurf6
      • siege
      • smurf6
      • t50
    • VoIP Stress Testing
      • iaxflood
      • inviteflood
    • WLAN Stress Testing
      • mdk3
      • reaver
    • Web Stress Testing
      • thc-ssl-dos
  • Hardware Hacking
    • Android Tools
      • apktool
      • baksmali
      • dex2jar
      • smali
    • Arduino Tools
      • arduino
  • Forensics
    • Anti-Virus Forensics Tools
      • chkrootkit
    • Digital Anti-Forensics
      • chkrootkit
    • Digital Forensics
      • autopsy
      • binwalk
      • bulk_extractor
      • chkrootkit
      • dc3dd
      • dcfldd
      • extundelete
      • foremost
      • fsstat
      • galleta
      • tsk_comparedir
      • tsk_loaddb
    • Forensic Analysis Tools
      • affcompare
      • affcopy
      • affcrypto
      • affdiskprint
      • affinfo
      • affsign
      • affstats
      • affuse
      • affverify
      • affxml
      • autopsy
      • binwalk
      • blkcalc
      • blkcat
      • blkstat
      • bulk_extractor
      • ffind
      • fls
      • foremost
      • galleta
      • hfind
      • icat-sleuthkit
      • ifind
      • ils-sleuthkit
      • istat
      • jcat
      • mactime-sleuthkit
      • missidentify
      • mmcat
      • pdgmail
      • readpst
      • reglookup
      • regripper
      • sigfind
      • sorter
      • srch_strings
      • tsk_recover
      • vinetto
    • Forensic Carving Tools
      • binwalk
      • bulk_extractor
      • foremost
      • jls
      • magicrescue
      • pasco
      • pev
      • recoverjpeg
      • rifiuti
      • rifiuti2
      • safecopy
      • scalpel
      • scrounge-ntfs
    • Forensic Hashing Tools
      • md5deep
      • rahash2
    • Forensic Imaging Tools
      • affcat
      • affconvert
      • blkls
      • dc3dd
      • dcfldd
      • ddrescue
      • ewfacquire
      • ewfacquirestream
      • ewfexport
      • ewfinfo
      • ewfverify
      • fsstat
      • guymager
      • img_cat
      • img_stat
      • mmls
      • mmstat
      • tsk_gettimes
    • Forensic Suites
      • autopsy
      • diff
      • diff gui
    • Network Forensics
      • p0f
    • PDF Forensick Tools
      • pdf-parser
      • peepdf
    • Password Forensics Tools
      • chntpw
    • RAM Forensics Tools
      • volafox
      • volatility
  • Reporting Tools
    • Documentation
      • dradis
      • keepnote
    • Evidence Management
      • casefile
      • magictree
      • maltego
      • metagoofil
      • pipal
      • truecrypt
    • Media Capture
      • cutycapt
      • recordmydesktop
  • System Services
    • BeEF
      • beef start
      • beef stop
    • Dradis
      • dradis start
      • dradis stop
    • HTTP
      • apache2 restart
      • apache2 start
      • apache2 stop
    • Metasploit
      • community / pro start
      • community / pro stop
    • MySQL
      • mysql restart
      • mysql start
      • mysql stop
    • OpenVas
      • openvas check setup
      • openvas feed update
      • openvas initial setup
      • openvas start
      • openvas stop
    • SSH
      • sshd restart
      • sshd start
      • sshd stop

[最終更新日: 2014年2月23日]