Tony's Tools


All programs require Java Runtime Environment to run.
I take no responsibility for misuse of the software available on this page. It was designed to help webmasters test security of their sites.


Log Sucker 1.3

Have you ever been cursing around because after a scan for open logs you ended up with few hundreds of URLs, then had to download them and exctract combos one by one? If so, you might find this simple tool quite useful. All you need to do is to load a list of URLs, choose output directory, set a proxy server and select 'Parse' option. The program will do all the rest for you.

The log parsing algorythm is exactly the same as in Horny Stripper (below), except it parses on-the-fly while downloading, so you end up with a nice bunch of passfiles. It can recognize 7 different types of logs.


Download Windows version
Download platform independent version
Download source code


Horny Stripper 1.0

It's a simple parsing tool. URL Stripper parses hostnames and login information - useful for building a site scan list or a combo list from leeched URLs. Works like Web Word Leecher in Access Diver, except it doesn't hang on huge files. Log Stripper exctracts username and password data from 7 types of log files. It can process many files at a time. Word Stripper extracts single words from a text file. This is useful for building wordlists for JTR from combo lists, text books, etc.


Download Windows version
Download platform independent version
Download source code


On Cracking Rampage

Thanks to some of you the newest version is not available on this page. I've been asking nicely not to spread it, if you manage to crack the rar protection. And then I've been finding it on public boards. No tool for you.



PassFinder

A tool that searches your wordlists to find combos matching given usernames. For example you can often find list of users on some forums and according to that you can easily build thematic wordlists.


Download platform independent version


Mail Parser

This tiny program cleans your wordlists from email combos and saves them to separate files.


Download platform independent version


EvilNeedle 0.1

This is a simple SQL injection scanner. Provide a list of URLs up to the injectable parameter, provide the values you want to test, set a proxy, set keywords and see what's found.


Download platform independent version