These sorts of laws need to include exceptions for tools that have a non-criminal purpose. Otherwise, a broad reading could include things like NetCat, Curl, and Apache Bench.
Which would render the whole shebang useless. All tools used for breaking into computers have legitimate uses for security professionals, not the least of which is penetration testing.