я ещё ни один knoppix не юзал ))
Knoppix STD 0.1b
security tools distribution
Tools are grouped as follows:
Authentication
/usr/bin/auth/
freeradius 0.8.1 : GPL RADIUS server
PAM config
Cracker
/usr/bin/cracker/
john 1.6 : John the Ripper password cracker. Includes the CERIAS dictionary: allwords2 (27 MB!) and NTLM patch
Encryption
/usr/bin/crypto/
gpg 1.2.1: GNU Privacy Guard
openssl 0.9.7a
cryptcat : netcat + encryption
sslwrap : SSL wrapper
stunnel : SSL wrapper
Forensics
/usr/bin/forensics/
sleuthkit 1.61 : atstake/sleuthkit.org's extensions to The Coroner's Toolkit forensic toolbox.
autopsy 1.71 : Web front-end to TASK. Evidence Locker defaults to /mnt/evidence
mac-robber 1.0 : TCT's graverobber written in C rather than perl
fenris .07: code debugging, tracing, decompiling, reverse engineering tool
wipe : wipe a partition securely. good for prep'ing a partition for dd
secure_delete : securely delete files, swap, memory....
and other typical system tools used for forensics (dd, lsof, strings, grep, etc.)
Firewall
/usr/bin/fw/
iptables 1.2.7a
gtk-iptables : GUI front-end
shorewall 1.4 : iptables based package
Honeypots
/usr/bin/honeypot/
honeyd 0.5-2
labrea 2.3-2 : tarpit (slow to a crawl) worms and port scanners
IDS
/usr/bin/ids/
snort 1.8.7-4: but of course
aide 0.9 : host baseline tool, tripwire-esque
swatch 3.0.1 : monitor any file, oh like say syslog
sha1sum
md5sum
syslogd
Network Utilities
/usr/bin/net-utils/
LinNeighboorhood : Linux network neighborhood
cheops 0.61-4 : snmp, network discovery and monitor tool
etherape 0.8.2-3 : network monitor and visualization tool
ntop 2.1.0 : network top, protocol analyzer
iptraf : network monitor
arptool : monitor and manage arp
arping : ping hosts by MAC
arpwatch : another arp tool
macchanger : change your MAC addr. works with wireless too.
mtr : traceroute
samba 2.2.3a
Penetration Tools
/usr/bin/pen-test/
Way too many to list. All the usual suspects. dsniff toolkit, much THC, ADM, Gobbles, RFP, nmrc, teso, irpas routing tools, brute force tools, buffer overflows, dns spoofing, man in the middle, tcp/ip hijacking, denial of service... Includes exploits for cve-2002-0392, cve-2001-0241, can-2002-1337, can-2002-0656, can-2003-0109. There is some overlap into Vuln-test tools. These tools are meant to test IDS systems and to learn how exploits in the wild are used and written. Be very careful. You are entirely responsible for your own actions. When source code was available you'll find it under /usr/bin/pen-test/src/.
Servers
/usr/bin/servers
apache 1.3.27
smail 3.2
sshd
vnc
bind9
net-snmp
iacd
tftpd
xinetd
netcat
httptunnel
Packet Sniffers and Assemblers
/usr/bin/sniff/
ethereal 0.9.5 : simply amazing.
ettercap 0.6.a : sniff on a switched network and more.
ngrep : network grep, a sniffer with grep filter capabilities
netsed : network sed, change the contents of packets traveling through your gateway on the fly
tcpdump 3.6 : the core of it all (libpcap 0.6)
ip-sorcerer : magic and ipmagic packet assemblers
nemesis 1.4 beta 1 : Packet injector or "a portable IP stack"
paketto 1.10 : fun with TCP/IP, scanning, tracerouting, NAT
tcpreplay 1.4.0 : replay tcpdump or snoop captures
dsniff 2.4 : sniffs only for username

assword pairs passed on the wire in clear text protocols (telnet, ftp, http .....)
Vulnerability Assessment
/usr/bin/vuln-test/
nessus 2.0.4 : what else?
nasl : command line nessus to trigger nasl scripts directly
nmap 3.10 : a necessity (also w/ a front-end for gui freaks)
amap 2.5 : application mapper (can find apps running on strange ports. like http on 2993.)
chkrootkit 0.40: look for rootkits
rpcinfo : hmmmm.... info from RPC?
snot : replay snort rules back onto the wire. test your ids/incidence response/etc.
whisker 2.1 : cgi web vulnerability scanner (Thanks for everything RFP!)
winscan tools: SMB enumeration
hping2 : port scanner, host enumerator, packet assembler, traceroute on any port, much underrated, essential tool!
Wireless tools
/usr/bin/wireless/
airsnort : sniff, find, crack 802.11b
wardrive : ditto
kismet 2.6.2 : ummm ... yeah, ditto
macchanger : change your MAC address
patched orinoco drivers