New Project      Open     Users:  914     Host: Domain      Account: Anonymous      Rank: Newbie     Help      Login     Register
       
  Password:   Your new project information:
   
     
  Repeat password:  
     
     

   
  Start date: Dead line:    

 
       
  New project:  
  Target Host:  
Company:
  Contact name:  
  Contact phone:  
Contact email:
  Website URL:  
       
Work period:      
  Start date: Dead line:    

     
Login to your account
Email:
Password:
Register
Computers Exploits Recent
Skip Navigation Links.
Sessions - Online
Sessions - Offline
Search
Recent

Skip Navigation Links.
Collapse RemoteRemote
[Internet Explorer 8 ASLR]
[Samsung Kies 2.3.2.1]
[Internet Explorer Tracking]
[Aladdin PrivAgent.ocx]
[McAfeeVT 6.3.0.1911]
Client side
Local
Web Apps
DoS/Pocs
Skip Navigation Links.
History
Target Properties Take Control Quick Help Log Report Ban Hammer Download Contribute About us Wall Pentest Online Chat
  Target:   Last Poke:
  Browser type:   Dest IPv4:
  System:   Exploit set:
  Persistent Cookie:   Basic commands:
              
Skip Navigation Links.
Module Real-Time Log
[16:27:37] System running..
Skip Navigation Links.
Executed Modules
Modules loaded status: OK
 
Commands Sent Scheduled Actions
Skip Navigation Links.
Scripted Actions
Command List: Script - State
Sorry, you don't have any active cron

Take control of the remote sessions and execute arbitrary remote code
Send messageRedirect URLPersist PoPUpExecute JSRemote crashProtect SiteExploit thisMonster
Get ride of the basics an start using Exploit Pack - XSS Paradise like a pro!

So, you want to play with remote browsers uh? To do that you have to include in one way or another the agent code in the desired host. To ensure the tunnel works properly we use an AJAX channel, console developer tools like firebug or chrome toolbar came in handy if you want to do something tricky. Any web browser will work whitin the agent but we strongly recommend a fully support of HTML5.

Exploit Pack comes with absolutely no warranty. So inject the agent only on web sites that you have authority and full permissions.
Feel free to contact us or the community if you have any question regarding this easy installation process.

Deployment process: Copy the full URL of the agent code and inject it on the target web site, just before the closing </head> tag and inside a SCRIPT SRC="MyURLAgentCode" /SCRIPT tag. The src attribute specifies the URL of an external script file: I want to know more about script attribute.

Agent path: 

If you want to do a quick test use this demo page it already includes the agent code:

Demo test site:  Open this url on a new tab.


How the agent works?

The agent works by making a JSONP cross domain call through the target site and the control panel. It use websockets to be able to handle hundreds of connections at the same time and a lot of nasty hacks in order to work properly in all the browsers.

The features like persistence, exploits, SQLi and XSS protection are being handled by the control panel and all the sensible data is being dumped to a temporaly database. We do not maintain data information for more than 10 days.

This report log represents a security audit performed by your Exploit Pack - XSS Paradise account
Access to this data by unauthorized people may allow to compromise your network
 
This is a list of the banned IP Address that Exploit Pack - Protect My Site is responsible for manage the black list

In order to re-enable the access for the desire IP you have to first remove the record from the list above.

There are no IP banned to display

If you have any question please read the FAQ or contact to the developer's team.



Desktop version: Launch exploits from a desktop based and intuitive interface, yet another home made tool to do a pentest! And YES you love it! :-)

Penetration testing of desktop applications made easy ( Just like Metasploit, but with an easy to use GUI! and GPLv3 )

This tool is your command and control center to launch exploits to a computer network, by doing this you will be able to test at a low-level the security or insecurity of the installed programs on your network. This tools has the latest available exploits in the market and in order to make the process more agil and ease to use we also add an exploit editor, reports, update manager and many more features.

This software has a no cost and it is completely free

It's free. yet, another home made tool to do pentesting, Yes! and you can't wait to download your own copy directly from here: Download Link

What can be done with Exploit Pack PenteAR

By using this tool you will be able to easily exploit remote systems using the latest exploits available on the wild for penetration testing purposes. Its module are tested before being included on the update manager and also it provides with an instant search to look up for the correct exploit you need, you can search them by service, port, or even type. This tool was made for security professionals, system administrators, exploit developers or security paranoids.

To get a ride on the source code of this app and start contributing with the community please visit our branch on github!

Help is needed in the following things! Please consider taking a moment to help us improve this community project

The following list is needed to improve this proyect, if you have some free time to enjoy a ride with us don't hesitate to contact right away, any help will be received with open arms. We seek for coders, documentation developers, translation support, reporters and people who want to learn more about security!

There are many ways to help depending on your skills. Most of the time you will start by doing testing and bug reporting. After some time you will start to submit patches. Even later, if the community likes what you do, you can receive source code commit rights.

In order of priority, these are the important and more urgent points:

  • Documentation development
  • Videos ( How-to use ) development
  • Translation support
  • Bug fixing and reporting
  • Features enhancement
  • Chat moderators

If you wish to help in any of the sections described here, contact the developers team right away! Thanks a lot and we look forward to it.

Contact directly the developers team by email: support@exploitpack.com to receive a quick answer, thanks!

Exploit Pack is a powerful penetration testing web-based tool for enterprise as well as home use.

Exploit Pack is an extremely useful tool for testing purposes on high performance networks, it is also the only professional solution that is freely available.

Presently Exploit Pack Agent runs on Windows, Linux, Macintosh and supports a large number of Browsers as "guests" operating systems including but not limited to ( Google Chrome, Mozilla Firefox, Internet Explorer, Opera Browser )

Exploit Pack is being actively developed with frequent releases and daily updates and has an ever growning list of features, Exploit Pack is a community effort backed by a dedicated group of people: Everyone is encouraged to contribute while ensures the products always meets professional quality criteria.

 

History of Exploit Pack

We are a young group of security researchers settled in Argentina, Buenos Aires and we love to develop security software. Always thinking in new ideas and trying to be one step ahead. If you want to contribute or participate in any how we have several ways to contact us, email, phone, social networks and instant messengers. Please choose whatever you prefer, any kind of help will be appreciated!

Contact directly the developers team by email: support@exploitpack.com to receive a quick answer, thanks!

There are no data records to display.
Penetration testing services: Exploit Pack offers the most current and up-to-date service for an IT security Audit of your site or company.


Key componets of the pentest:
1) Effective evaluation of your site in order to analyze all applicable exploits/vulnerabilities.
2) Tests for SQLInjection ( SQLi ), Cross Site Scripting ( XSS ), Local/Remote File Inclusion and other exploits/vulnerabilities.
3) Search and testing of Shells, Rootkits and Backdoors on your server.
4) Installation of patches to correct exploits/vulnerabilities.
5) A detailed security REPORT about your site and servers.
6) Advice and recommendations from our specialists regarding the reduction and misuse of security good practices.

Details of the PentTest:
1) Secure and confidencial scanning.
2) Nothing to download or install.
3) No interruption ( DoS ) for your visitors.

Why choose Exploit Pack ?
Our vulnerabity scans are carried manually, the team of Exploit Pack consists are the best minds in the security scene.

What are you waiting for? Order today!
Contact us support@exploitpack.com - Subject: Pentest Order - Fixed cost: 1000usd
Expect the pentest to last anywhere from a day to a week ( depending on the amount of services you have running on your server )
Skip Navigation Links.
Collapse OnlineOnline
[jsacco@exploitpack.com]
[forocochier@gmail.com]
[jsacco@exploitpack.com]
[forocochier@gmail.com]
Collapse OfflineOffline
[support@exploitpack.com]
[telmomiguelxavier@gmail.com]
[rezor192@gmail.com]
[str0k3@gmail.com]
[r4dc0re@hotmail.com]
[ssamuel@ibm.com]
[CrooS302@gmail.com]
[rober1931@gmail.com]
[kingcope1@gmail.com]
[sharronelli@gmail.com]
[yasoob_dear@yahoo.com]
[r_zouat@microsoft.com]
[crash_override@gmail.com]
[nickjoel@microsoft.com]
Quick Information Application Log Debug Log
Exploit Pack - v3.0.1  | For a better pentesting experience get a cold beer and listen to some good music like this: Hermetica                   Quick links: Facebook Group  Mailing list  Donate  Module Status: OK
Exploit Pack - Training Session: Next Friday 6 April 2013 -
How to deploy a web-based full pentest using Exploit Pack tools, SQLi and XSS theory and more! - Type: Basic
Special offer! REGISTER NOW

Register a new account on Exploit Pack

Email:
Verify Email:
Password:
Verify password:
Nickname:
Country:
Leave a comment:


Login to your account
Welcome to Exploit Pack - XSS Paradise
Where to start?
  1. Read the help section
  2. Create your own account
  3. Test the basics and make a tour
  4. Have questions? support@exploitpack.com
  5. Have fun and happy hacking!
 
Exploits Pack is an open source security proyect and it lives thanks to the users support.
So, thank you for keeping alive this tool, go ahead and try the premium access.

Wanna know more? What is Exploit Pack:


This security tool will help you do a pentest via a web-based platform, we are still in development but in a mature state so it is pretty usable. We don't want you to use this tool for hacking purposes, so any kind of action that could affect illegaly other users or websites that you don't have right to access will be banned and your user including your data will be destroyed. So, please don't be a lammer and keep that in mind before start using this tool.

  Quick  access links:

Facebook group
Community forum
Mailing list
Contact the author

BUILD: 20130905-01
Username:      Password:        Tweet
Register a new account
  Reset your password
Wanna Know more? - About Exploit Pack
What is Exploit Pack?

After you found a Web Site is vulnerable to XSS ( Cross Site Scripting ), then what? Then you can inject the Exploit Pack agent, and after that you are able to control all the visits that site gets. By using that established communication channel you can control their browsers and proxy trough them, execute remote commands, and of course bypass all Antivirus Engine protections, WAF filters, FW Controls and any kind of perimetral security, because your vector of attack is the weakest link in the chain, the client side user enviroment.











For technical information or bug reporting please contact us at: support@exploitpack.com
Please wait..