SHMOO
(lê-se “chimu grulpi”)
Em inglês
Who we are
The Shmoo Group is a non-profit think-tank comprised of security professionals from around the world who donate their free time and energy to information security research and development.
What we do
In addition to all of our internal projects, (ShmooCon, AirSnort, Rainbow Tables to name a few), our work extends into some of the most widely used infosec software (and books!) around. From Lord of the Rings, to Mixmaster, to Apache, to PGP, to Snort, to OpenSSL, to StackGuard/FormatGuard ... the list goes on and on. Oh, and sometimes you can catch us teaching, preaching, and expounding various topics we find interesting at conferences around the planet.
Projects:
ShmooCon
An annual East coast hacker convention hell-bent on offering an interesting and new atmosphere for demonstrating technology exploitation, inventive software & hardware solutions, as well as open discussion of critical information security issues.
Summer Of Code
TSG is taking part in Google's Summer of Code mentor program, working with students to advance the state of art of information security.
airsnort
A wireless lan encryption key recovery tool. AirSnort operates by passively monitoring transmissions, computing the encryption key when enough packets have been gathered.
bluesniff
A PoC bluetooth war-driving utility. Bluesniff provides a GUI for finding discoverable and hidden bluetooth devices. See the DefCon 11 presentation on Bluetooth wardriving for more info. You can download the latest bluesniff release here.
airsnarf
Airsnarf is a simple rogue wireless access point setup utility designed to demonstrate how a rogue AP can steal usernames and passwords from public wireless hotspots. Airsnarf was developed and released to demonstrate an inherent vulnerability of public 802.11b hotspots. snarfing usernames and passwords by confusing users with DNS and HTTP redirects from a