About OWASP-ZSC
OWASP ZSC is open source software written in python which lets you generate customized shellcodes and convert scripts to an obfuscated script. This software can be run on Windows/Linux/OSX with Python 2 or 3.
What is shellcode?: Shellcode is a small codes in Assembly language which could be used as the payload in software exploitation. Other usages are in malwares, bypassing antiviruses, obfuscated codes...
You can read more about OWASP-ZSC in these link:
- OWASP ZSC Tool Project - OWASP
- Document: OWASP ZSC · GitBook (Legacy)
- Home page: OWASP ZSC | OWASP ZCR Shellcoder
- Features: OWASP ZSC | OWASP ZCR Shellocder Available Features
- Archive: ZCR-Shellcoder-Archive
- Mailing List: Google Groups
- API: api.z3r0d4y.com
Another good reason for obfuscating files or generating shellcode with OWASP-ZSC is that it can be used during your pen-testing. Malicious hackers use these techniques to bypass anti-virus and load malicious files in systems they have hacked using customized shellcode generators. Anti-virus work with signatures in order to identify harmful files. When using very well known encoders such as
msfvenom
, files generated by this program might be already flagged by Anti-virus programs.Our purpose is not to provide a way to bypass anti-virus with malicious intentions, instead, we want to provide pen-testers a way to challenge the security provided by Anti-virus programs and Intrusion Detection systems during a pen test.In this way, they can verify the security just as a black-hat will do.
According to other shellcode generators same as Metasploit tools and etc, OWASP-ZSC using new encodes and methods which antiviruses won't detect. OWASP-ZSC encoders are able to generate shell codes with random encodes and that allows you to generate thousands of new dynamic shellcodes with the same job in just a second, that means, you will not get the same code if you use random encodes with same commands, And that make OWASP-ZSC one of the best! During the Google Summer of Code we are working on to generate Windows Shellcode and new obfuscation methods. We are working on the next version that will allow you to generate OSX.
OWASP-ZSC Installation:
You must install Metasploit and Python 2 or 3 first:
- For Debian-based distro users:
sudo apt install python2 python3 metasploit-framework
- For Arch Linux based distro users:
sudo pacman -S python2 python3 metasploit
- For Windows users: Download Python and Metasploit here.
sudo
):DISCLAIMER: THIS SOFTWARE WAS CREATED TO CHALLENGE ANTIVIRUS TECHNOLOGY, RESEARCH NEW ENCRYPTION METHODS, AND PROTECT SENSITIVE OPEN SOURCE FILES WHICH INCLUDE IMPORTANT DATA. CONTRIBUTORS AND OWASP FOUNDATION WILL NOT BE RESPONSIBLE FOR ANY ILLEGAL USAGE.
An example of OWASP-ZSC
Related news
- Hack Website Online Tool
- Pentest Tools Free
- Hacker Tools Apk Download
- Hacker Tools Hardware
- Hacker Tools For Ios
- Hacking Tools Github
- Hack Website Online Tool
- Hacker Tools Free Download
- Kik Hack Tools
- How To Make Hacking Tools
- Hacking Tools For Windows
- Hack Tools 2019
- Android Hack Tools Github
- Hacking Tools Github
- Hacker Tools
- Free Pentest Tools For Windows
- How To Install Pentest Tools In Ubuntu
- Hacker Tools Github
- Hacking Tools Windows 10
- Hak5 Tools
- Hack Rom Tools
- Pentest Tools Windows
- Pentest Tools Find Subdomains
- Hacking Tools Online
- Hackers Toolbox
- Pentest Recon Tools
- Pentest Tools Download
- New Hacker Tools
- Pentest Automation Tools
- Ethical Hacker Tools
- Hacking Tools And Software
- Pentest Tools Tcp Port Scanner
- Pentest Tools Find Subdomains
- Hack Tools Mac
- Pentest Tools Website Vulnerability
- Hack Tools For Games
- Hacking Tools Pc
- Hack Tools Download
- Hacker Tools 2020
- Pentest Tools
- Pentest Tools Free
- Nsa Hack Tools
- Hackers Toolbox
- Pentest Tools Github
- Hack Tools Github
- Nsa Hack Tools Download
- Hak5 Tools
- Hacker Tools For Windows
- Pentest Tools Find Subdomains
- Wifi Hacker Tools For Windows
- Hacker Tools Linux
- Hacking Tools Usb
- Hackers Toolbox
- Hack Tools Mac
- Hacking Tools For Windows
- How To Make Hacking Tools
- Pentest Tools Url Fuzzer
Aucun commentaire:
Enregistrer un commentaire