Choose which categories of cookies FortiVox is allowed to use. You can change these settings any time via the "Cookie Settings" link in the footer.
Required for sign-in, security, CSRF protection and core site features. Cannot be disabled because the platform will not work without them.
Let us measure how visitors discover and use FortiVox via Google Analytics. Helps us improve content and performance. Blocked entirely until you accept.
Remember choices such as language and UI preferences so the site behaves the way you expect on your next visit.
Interactive resources for security fundamentals — the Kali Linux commands analysts actually use, secure-versus-insecure code, and answers to the questions every engineer asks about WAF and defence.
nmap -sV -sC target.com
Service version detection with default scripts — map open ports and running services.
nmap -p- --min-rate 1000 target.com
Aggressive full port scan of all 65535 ports at high speed.
curl -I https://target.com
Fetch HTTP response headers only — inspect security headers and server fingerprint.
curl -sS -o /dev/null -w "%{http_code}" https://target.com
Print just the HTTP status code.
dig target.com ANY +noall +answer
Query all DNS records (A, MX, TXT, NS) for a domain.
dig +short target.com
Resolve a hostname to its A/AAAA records quickly.
grep -Rni 'password' /var/www/app
Recursively search files for the word "password" (case-insensitive).
grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' file.txt
Extract every IPv4 address from a file using a regex.
dirb https://target.com /usr/share/wordlists/dirb/common.txt
Brute-force common directories and files on a web server.
gobuster dir -u https://target.com -w common.txt
Fast directory enumeration alternative to dirb.
nikto -h https://target.com
Web server vulnerability scanner — detects outdated software and misconfigurations.
whatweb https://target.com
Fingerprint the web technologies and frameworks powering a site.
sqlmap -u "https://target.com/?id=1" --dbs
Detect and exploit SQL injection (authorised testing only).
hydra -l admin -P wordlist.txt ssh://target.com
Online password brute-force against an SSH service.
whois target.com
Look up domain registration and contact information.
openssl s_client -connect target.com:443 -servername target.com
Inspect the TLS certificate presented by a server.
nc -zv target.com 1-1000
Netcat port-scan a range to see which ports are open.
tcpdump -i eth0 port 443 -nn
Capture HTTPS traffic on an interface (packet analysis).
= "SELECT * FROM users WHERE email = '" . $_GET['email'] . "'";
$r = mysqli_query($conn, $q);
$stmt = $pdo->prepare('SELECT * FROM users WHERE email = ?');
$stmt->execute([$_GET['email']]);
$row = $stmt->fetch();
echo "<div>Hello " . $_GET['name'] . "</div>";
echo '<div>Hello ' . htmlspecialchars($_GET['name'], ENT_QUOTES, 'UTF-8') . '</div>';
import os
os.system('ping ' + host)
import subprocess
subprocess.run(['ping', '-c', '4', host], check=True)
$file = $_GET['file'];
readfile('/var/www/files/' . $file);
$file = basename($_GET['file']);
readfile('/var/www/files/' . $file);
$hash = md5($password); // or sha1()
$hash = password_hash($password, PASSWORD_BCRYPT);
// verify: password_verify($password, $hash)
$obj = unserialize($_COOKIE['session']);
// Use signed tokens (HMAC) or JSON + allow-list of classes.
$data = json_decode($_COOKIE['session'], true, 512, JSON_THROW_ON_ERROR);
The world attack map, live threat feed, top countries, attack types and blocked IPs are all still available — powered by real edge telemetry.
Open the live attack map