Linux.com

Feature: Security

Auditor: The security tool collection

By Mikael Vingaard on September 23, 2005 (8:00:00 AM)

Share    Print    Comments   

The Auditor security collection is a GPL-licensed live CD based on Knoppix, with more than 300 security software tools. Auditor gives you easy access to a broad range of tools in almost no time.

To get started, download the latest image of Auditor and burn it as a bootable image. Remember to use the image option -- just copying the file will not produce a bootable image. After you have successfully written the image to disc, you can start Auditor directly from the CD. It will not install any permanent software on the hard disk unless you request it to, so don't be nervous to use Auditor on a client workstation.

The structure of Auditor

Auditor's menu is divided into several "tool groups" for easy recognition:

  • Footprinting -- Applications to gain initial knowledge about a server, such as Whois and Dig.
  • Analysis -- Tools to analyze a network, such as Ethereal.
  • Scanning -- Tools to scan the network, such as Nmap.
  • Wireless -- Applications to test the wireless network.
  • Brute-forcing -- The brute-force password cracking word list holds more than 64 million word entries, according to the Auditor Web site.
  • Cracking -- Cracking tools to be used with the brute-force word lists.

How can Auditor help you with IT security?

Many security engineers arrive on a client's site and find that the network documentation required for solving the task properly is incorrect or even obsolete. In Auditor's Scanning submenu you'll find the Nmap network scanner. You can choose the traditional shell version or Nmap FE, which provides a graphical front-end for Nmap.

After you have gained a basic overview of the network you can use NBTScan, a NetBIOS name scanner, and Nessus, a vulnerability scanner. If the audit includes Web applications, try the Nikto and Amap application scanners.

Let's say you've been called in to examine a possible compromised server, and until the integrity of the server has been established you are not allowed to install any forensic software or even take the server offline. You can take your Auditor CD and start running the chkrootkit utility to see if any known rootkits are installed on the server. If you find any suspicious activity, you can take a disk image with the dd command and examine it for any possible rootkits or strange processes. You can also use the Autopsy Forensic Browser, a graphical interface that can analyze Windows, Linux, and BSD file systems (NTFS, FAT, Ext2/3) to search for files. If you are analysing a Linux or Unix system, you can use Nibbler to extracts known offsets from binaries to find hidden trojan horses.

Suppose you've been asked to do the security survey on a wireless network for possibly weaknesses. Auditor includes the Kismet and wellenreiter wireless analyzers, which both support automatic hardware identification, helping you avoid wasting time configuring your wireless card. Also on the Auditor CD is Airodump, a kind of wireless TCPdump application which can capture packets to assist in brute force analysis of the data later. Furthermore, there are many crackers, including some against WEP encryption to crack the wireless key. Another interesting application is hotspotter, a program for wireless client hijacking.

In addition to all the security tools Auditor includes several common useful applications, such as the Firefox and Konqueror Web browser and some text editors. You can write full reports directly from the Auditor CD and either burn the result on a CD with the Cdrecord program or place it on a remote server with either SSH or remote desktop tools.

Share    Print    Comments   

Comments

on Auditor: The security tool collection

Note: Comments are owned by the poster. We are not responsible for their content.

knoppix std?

Posted by: Anonymous Coward on September 24, 2005 01:57 AM
if i read it right, its just knoppix std, renamed. why do we need 100 of the same thing with a different name?

#

Re:knoppix std?

Posted by: Anonymous Coward on September 26, 2005 04:21 PM
> if i read it right, its just knoppix std, renamed.
wrong, it's "based on Knoppix, with more than 300 security software tools"

#

Re:knoppix std?

Posted by: Anonymous Coward on September 28, 2005 01:56 AM
Dufus !! Knoppix STD is based on Knoppix with 300 or so security tools. The original poster was stating this. Why do we need yet another Knoppix disk with all the same crap?

People are morons.

#

Re:knoppix std?

Posted by: Anonymous Coward on September 29, 2005 05:23 AM
Because Knoppix STD sucks compared to Auditor. That's why.

#

Re:knoppix std?

Posted by: Anonymous Coward on September 30, 2005 11:26 PM
Fifteen years ago(++/--), someone thought of programming his own Unix system, even when there were other unixes. I don't think Mr. Torvalds is a "moron". Do you?
Do you think all people who makes a new distribution of Linux is a "moron"? There are lots of them, all with "the same crap". And thanks to all those people , even you can download the linux distribution that best fits to your needs. I don't think that your words can sound as "thank you all" to those people.

#

Re:knoppix std?

Posted by: Anonymous Coward on November 02, 2005 04:43 PM
did you even understood the post ?
are you even a security auditor or any kind of auditor so you could use it?
don't you have anything better to do than make a fool out of yourself?

#

relief joint

Posted by: Anonymous Coward on May 28, 2006 05:45 PM
[URL=http://painrelief.fanspace.com/index.htm] Pain relief [/URL]

  [URL=http://lowerbackpain.0pi.com/backpain.htm] Back Pain [/URL]

  [URL=http://painreliefproduct.guildspace.com] Pain relief [/URL]
[URL=http://painreliefmedic.friendpages.com] Pain relief [/URL]
[URL=http://nervepainrelief.jeeran.com/painrelief<nobr>.<wbr></nobr> htm] Nerve pain relief [/URL]

#

Re:Download Link

Posted by: Anonymous Coward on September 05, 2006 07:31 PM
Here you can download the file:
<a href="http://www.remote-exploit.org/index.php/Auditor_mirrors" title="remote-exploit.org">http://www.remote-exploit.org/index.php/Auditor_m<nobr>i<wbr></nobr> rrors</a remote-exploit.org>

#

Re: Help

Posted by: Anonymous Coward on December 20, 2006 07:03 AM
Comon people...did you not read the article?

you need to burn the CD as an image, try using Ashampoo or Nero and burn the<nobr> <wbr></nobr>.ISO (not<nobr> <wbr></nobr>.RAR even though it can be opend and browsed with WinRar) as an image or "disc image" simple as that, my auditor works fine...

and DO NOT extract the files...burn the whole<nobr> <wbr></nobr>.ISO as an image...there I repeated myself...I hope none of you get lost...

#

Re:Download Link

Posted by: Anonymous Coward on February 27, 2007 11:12 PM
link doesn't work

#

how to make the auditor CD

Posted by: Administrator on December 13, 2005 05:23 AM
I need help geting auditor to run. I downloaded the new version of auditor witch is in a<nobr> <wbr></nobr>.rar file I opened that and burned the files to a cd using cd burner xp pro 3. But it will still not boot. Can u walk me though this steep by steep.

I need to know how to get it to Run...



Thank u for your time
joshwilcher05@adelphia.net

#

Re:how to make the auditor CD

Posted by: Administrator on February 13, 2006 11:19 PM
Where do you download the Auditor cd from??

#

Re:how to make the auditor CD

Posted by: Administrator on July 22, 2006 10:47 AM
I am having the same problem. Did you get any help???

#

Auditor: The security tool collection

Posted by: Anonymous [ip: 71.112.98.241] on August 20, 2007 10:50 AM
None of the download links work.

#

Re: Auditor: The security tool collection

Posted by: Anonymous [ip: 139.230.245.21] on August 27, 2007 06:01 AM
Download Back Track 2 from Remote Exploit. Essentially the same security collection just updated. Hope this helps, have fun :D

#

Auditor: The security tool collection

Posted by: Anonymous [ip: 71.172.149.151] on August 29, 2007 12:13 AM
is the Auditor Security Collection and bact trck 2 are same now a days

#

Auditor: The security tool collection

Posted by: Anonymous [ip: 218.214.34.67] on September 23, 2007 12:43 PM
Whax and Auditor Security Collection joined forces and replacing these distribution the BackTrack

http://remote-exploit.org/backtrack.html
http://mirror.switch.ch/ftp/mirror/backtrack/bt2final.iso

#

Re: Auditor: The security tool collection

Posted by: Anonymous [ip: 192.168.0.199] on October 09, 2007 12:47 PM
po

#

Auditor: The security tool collection

Posted by: Anonymous [ip: 68.230.18.23] on September 27, 2007 12:43 AM
The download link is broken!!!!!!

#

Auditor: The security tool collection

Posted by: Anonymous [ip: 70.49.250.61] on September 28, 2007 01:37 AM
You can't burn this using the built in xp burner. It will only put a file on the cd called auditor.iso and will not boot. You need a program that will burn a raw image or burn an iso. Nero, alcohol... final burner is free and works ok.

#

Auditor: The security tool collection

Posted by: Anonymous [ip: 88.228.176.172] on September 28, 2007 11:53 AM
a

#

Auditor: The security tool collection

Posted by: Anonymous [ip: 12.206.60.211] on November 23, 2007 12:01 PM
I can't get Auditor to finish booting. the last lines of text displayed are...
"Starting init process.
INIT: version 2.78-knoppix booting"

then about 5 or 10 minutes later, the screen goes blank, nothing happens. I have an HP Pavilion dv6500 Notebook PC with Intel Core 2 Duo T7500 2.2 GHz 4MB L2 Cache 800 MHz FSB processor and Nvidia GeForce 8400M GS video card and 2 GB of RAM and Windows Vista Home Premium

#

Re: Auditor: The security tool collection

Posted by: Anonymous [ip: 151.54.111.105] on January 11, 2008 12:34 PM
I have same problemo too,and i don't know what to do...somebody can help us?

#

the best

Posted by: Anonymous [ip: 172.206.115.8] on January 09, 2008 06:26 PM
try and get in touch with a specialist from bicester-computers.com
there's one guy called Laurenti or something like that. Send him an email and nicely request some help. the guy is ourely magic!!!
all the best

#

Auditor: The security tool collection

Posted by: Anonymous [ip: 194.30.11.68] on January 17, 2008 01:36 PM
The download link is broken!!!!!!

#

Auditor: The security tool collection

Posted by: Anonymous [ip: 67.60.141.125] on January 20, 2008 01:19 AM
Yall are so slow BackTrack3beta is already out! You are not Pimpin! U needz Windowz skills or general computer skills. Google Foo! It's your friend.

#

Auditor: The security tool collection

Posted by: Anonymous [ip: 82.28.239.47] on January 30, 2008 06:34 PM
how do i download auditor i clicked the link at the top of the page but it i kept getting requested url could not be found in this server please can somebody help me

#

Download Link

Posted by: Anonymous [ip: 78.105.128.255] on February 02, 2008 09:12 AM
Just incase anyone's still unable to access the download, please visit http://remote-exploit.org/backtrack_download.html you will be able to download for a live CD (700mb) or the USB version (946mb @ 600kb/s).

Is it just me or does nobody ever bother to try accessing just the domain anymore.

#

Re: Download Link

Posted by: Anonymous [ip: 83.86.129.224] on February 18, 2008 04:38 PM
thug_bloods15@hotmail.com

#

This story has been archived. Comments can no longer be posted.



 
Tableless layout Validate XHTML 1.0 Strict Validate CSS Powered by Xaraya