![]() - Palm Security Tools - last updated: Thu, August 18, 2005 |
| Overview | The PalmOS is the perfect platform for hacking tools and hacking in general. I believe the security, networking, hacking, & programming potential of handhelds are far under-rated. This is not even taking into account the huge open-source factor.
Fyodor (the writer and maintainer of the nmap security scanner) was quoted saying... "Nothing beats doing penetration tests from the beach using a Palm and Ricochet packet modem (or other wireless device)". Also keep in mind that Palm devices have many other advantages: small, economical, easy to conceal, and can be taken anywhere. Here are some of the tools available... |
| Defense | Ping Requests: My palm can be pinged from an a remote host when connected to a network. This means that detection is possible. With a Time-To-Live (TTL) of 255 it responds to ICMP requests. Port Scans: Q: How do you block basic ICMP packets? |
| Sniffers | WifFi is a simple sniffer for finding 802.11 compatible access points with a WiFi enabled Palm OS device. NetChaser is similar to above but has "tap-to-connect" and this is shareware. BtSerial Pro allows you to connect to any Bluetooth device that supports the Serial Port profile. This gives you an easy way to connect to cell phones, sensors and more. BtSerial Pro is a member of a family of communication programs that includes BtSerial and BtServer. Unlock and start-up cars with key remotes. Packet sniffer - Coming Soon! |
| Scanners | Mergic Ping is a Palm OS implementation of the UNIX PING (ICMP Echo) program. It can be used with Mergic VPN to verify your connectivity to the private network. It's also useful to test for the availability of specific private network computers. http://www.mergic.com/vpnDoPingDownload.php PalmPing given a host name or an IP address, the program will cycle through several services (e.g. echo), detecting the presence of that service at the given host. Network statistics are also shown, using the PalmOS statistics queries. PortScanner is the first version of a Port Scanner for tcp/ip network. It allows you to check if some ports are open on a specified computer given by its ip adresses. This is usefull with wifi-enabled devices to find which services are avaible on a hotspot by example. cgicheck99 is one of the worlds most cross platform cgi scanners, running on 37 operating systems! Even Palmos soon! Will check for 119 of common cgi and other remote issues. Plus it will report you the Bugtraq ID of some vulnerabilities. Get the rebol interpreter at http://www.rebol.com. |
| File Access & Transfer | LFtp is a FTP client for my palm http://lthaler.free.fr/guppy/articles.php?lng=en&pg=19 VSFTP – FTP Client Palm SMB Client is a PalmOS client for the SMB protocol (access Windows shares from your Palm device!) http://sourceforge.net/projects/palm-smbclient/ SMBMate is the GUI SMB Client for PalmOS. The newest version of this app goes by the name WiFile ($). http://www.cbulock.com/2004/03/smbmate_freeware.html FilePoint ($), a great file management tool that allows you to map remote Windows shares. http://www.bachmannsoftware.com LGet is said to be the best HTTP downloader for the PalmOS. It changes pages to Palm DOC format on the spot. http://www.freewarepalm.com/communication/lget.shtml Downloader, this application enables you to download files from the internet to your Palm's memory card. http://www.freewarepalm.com/communication/ downloader.shtml Filez... |
| Remote Access Tools | Win-Hand Anywhere goes through Almost Any Firewall, Any Network. Access Any Windows Remote computer. Simple 3 questions installation and it is ready to be used! PalmVNC 2.0 is the latest evolution of PalmVNC, the widely acclaimed remote control software for the Palm OS® platform. PdaReach ($) display and manipulate your Palm device from Windows at realtime. What you see is what you get. |
| Phreaking | DigiDialer is a dual tone multiple frequency (DTMF) telephone dialer for use several Palm-based handhelds. SMS spoof sends spoofed SMS messages from your Palm. |
| Coding | OnBoard C is a C compiler that runs on and creates executables for the Palm OS. OnBoard C creates stand-alone, fully-fledged PRCs -- there's no need for run time libraries or any other software to run an executable created by OnBoard C. SmallBASIC (SB) is a simple computer language, featuring a clean interface, strong mathematics and graphics. We feel it is an ideal tool for experimenting with simple algorithms, for having fun. PilotDis is a disasssembler for palm binaries. |
fake mail - coming soon |
|
| Password Cracking | PalmCrack tries to crack a single encrypted UNIX, Cisco, or Windows NT password. If a wordlist database is found, it tries to crack the password against the entries in this wordlist. The better the wordlist, the better the ability for the program to crack a password. A brute force crack is attempted next (if requested by the user) if the password wasn't found using the wordlist. Hydra is a parallized login cracker which supports numerous protocols to attack. New modules are easy to add, beside that, it is flexible and very fast. Currently this tool supports: TELNET, FTP, HTTP, HTTPS, HTTP-PROXY, SMB, SMBNT, MS-SQL, MYSQL, REXEC, CVS, SNMP, SMTP-AUTH, SOCKS5, VNC, POP3, IMAP, NNTP, PCNFS, ICQ, SAP/R3, LDAP2, LDAP3, Teamspeak, Cisco auth, Cisco enable, LDAP2, Cisco AAA (incorporated in telnet module) |
| Denial of Service | mailbox flooder - Coming Soon! ping flood - Coming Soon! |
| Terminal | ptelnet is a powerful communication software for the Palm Computing platform. By using the built-in TCP/IP stack (telnet mode), it acts as a Telnet Client. TuSSH is an SSH client for Palm OS devices. It should now work with any device with Palm OS 4 or greater. I has been reproted to work with OS3.5 and greyscale devices. Devices With a hires screen can get a full 80x25 colour terminal . pssh is a free, open-source SSH 2 client for Palm OS 5. |
| Servers | httpd for PalmOS is a small web server (http) that runs on your palm. |
| Chat | VeriChat is a instant message client that can be used for MSN, Yahoo!, AIM, and ICQ chatting. |
| Other | Netstat display network statistics, as given by PalmOS NetLib http://page-appart.nerim.net/palm/netstat/page10.shtml Crash helps manage an unfortunate (& rare) crash of a PalmOS device. Resets the device in a clean way. http://www.freewarepalm.com/utilities/crash.shtml vWhois, a whois client for Palm OS http://tinyurl.com/cw6xx Traceroute test network routes with this small utility change mac address http://www.versiontracker.com/dyn/moreinfo/palm/1012 iServices is a Internet Service database browser http://www.tamalo.com/downloads/ PowerNet, this utility prevent auto-off while you connected to network. http://www.freewarepalm.com/utilities/powernet.shtml NS Lookup - Coming Soon! |
|