Exam4 is essentially a word-processor for law school exams. But don't try to update to the most recent versions of Mac OS X or Windows 8:
Lawyer ⚖️, Historian, Navy vet ✈️, Philly and Penn State sports fanatic 🏈⚾🏀, Dad and Husband. Blogging at the intersection of state power and civil liberties.
Showing posts with label computers. Show all posts
Showing posts with label computers. Show all posts
09 October 2013
29 August 2013
04 March 2013
Prenda lawyer facing sanctions in BitTorrent copyright infringement case
A lawyer with the notorious Prenda Law (wefightpiracy.com, how cute!) firm is facing sanctions in federal court in a case involving allegations of copyright infringement via BitTorrent. Brett Gibbs must answer to the court by March 11 why he should not be sanctioned for making unsupported allegations on behalf of Ingenuity 13 LLC, an adult film company.
In his complaint on behalf of Ingenuity (see below), Gibbs alleged that a John Doe (later identified as Benjamin Wagar) downloaded a copyrighted video via BitTorrent. In the original complaint, Gibbs identified the John Doe only by an IP address, the BitTorrent client, and the time of the download.
David McAuley, writing for Bloomberg's BNA Law Reports (14 CTLR 136 (Issue No. 05, 03/01/13)), described how Gibbs identified Wagar:
The court's order to show cause with respect to the possible sanctions for Rule 11 and Local Rule 83-3 violations is shown in full below.
In his complaint on behalf of Ingenuity (see below), Gibbs alleged that a John Doe (later identified as Benjamin Wagar) downloaded a copyrighted video via BitTorrent. In the original complaint, Gibbs identified the John Doe only by an IP address, the BitTorrent client, and the time of the download.
David McAuley, writing for Bloomberg's BNA Law Reports (14 CTLR 136 (Issue No. 05, 03/01/13)), described how Gibbs identified Wagar:
Worse, it continued, was the plaintiff's methodology to identify the defendant. In a status report to the court, counsel indicated that he identified one defendant, Benjamin Wagar, by virtue of the household where the implicated IP address was located, along with eliminating females or subscribers who were 75 years old. The court rejected this approach out of hand.
The Court interprets this to mean: if the subscriber is 75 years old or female, then Plaintiff looks to see if there is a pubescent male in the house; and if so, he is named as the defendant. Plaintiff's “factual analysis” cannot be characterized as anything more than a hunch.
There was nothing to show that Wagar was the infringer, the court remarked. While it was plausible that he was the infringer, the plaintiff's deduction fell short of the reasonableness standard that Rule 11 required.
There were reasonable steps the plaintiff could have taken to factually bolster its claim, the court noted, from an old-fashioned stakeout to an assessment nearby the house to determine if the defendant had Wi-Fi, and if it was password-protected. These steps might not be perfect, but they beat, “blindly picking a male resident from a subscriber's home,” the court said.There are a few interesting takeaways from this case. First, plaintiffs alleging as much must do more investigation than just associating an IP address with whomever might be living at the residence in question. An IP address does not equal a person. Second, the judge recognized that someone could have leeched Wagar's wireless internet. Gibbs didn't do any of this. Third, Prenda Law is getting smacked down again. They have a record as copyright trollers and this adds to their notorious reputation.
The court's order to show cause with respect to the possible sanctions for Rule 11 and Local Rule 83-3 violations is shown in full below.
30 December 2012
Foursquare's new privacy policy
Here's the email that Foursquare sent to its users regarding its new privacy policy. Remember, they can only show your full name if you actually give them your full name. They're making it pretty clear that you can change this if you don't want your actual full name displayed.
Hello Foursquare community!
2012 has been a pretty huge year. We’ve released over fifty new features, welcomed nearly 15,000,000 new people to Foursquare, and had our 3,000,000,000th check-in. It’s a bit clichéd to say this, but your support really is what keeps us going day after day.
As our product evolves, one of the things we do is update our policies to match it. And a big aspect of that is privacy (something we think about a lot). This email lays out a couple changes that we’ll be making to our privacy policy in the coming month, and explains how they affect you and what you can do about it.
We know that privacy policies can be dense, so we put together a high-level document that we think of as our “Privacy 101.” It describes, in an easy-to-read way, how we build privacy into our product. While it doesn't replace the legal need for the complete description of our privacy practices (which you can read here), we hope it helps you better understand how we think about privacy. We’ve also added new explanations of how privacy works throughout the app in our FAQs, including our default privacy settings and how they can be adjusted.
In addition to creating and refining those documents, we want to point out two specific changes to our policy, both of which will go into effect on January 28, 2013.
1. We will now display your full name. Currently, Foursquare sometimes shows your full name and sometimes shows your first name and last initial (“John Smith” vs. “John S.”). For instance, if you search for a friend in Foursquare, we show their full name in the results, but when you click through to their profile page you don’t see their last name. In the original versions of Foursquare, these distinctions made sense. But we get emails every day saying that it's now confusing. So, with this change, full names are going to be public. As always, you can alter your ‘full name’ on Foursquare at https://foursquare.com/settings.
2. A business on Foursquare will be able to see more of their recent customers. Currently, a business using Foursquare (like your corner coffee shop) can see the customers who have checked in in the last three hours (in addition to the most recent and their most loyal visitors). This is great for helping store owners identify their customers and give them more personal service or offers. But a lot of businesses only have time to log in at the end of the day to look at it. So, with this change, we're going to be showing them more of those recent check-ins, instead of just three hours worth. As always, if you'd prefer not to permit businesses to see when you check into their locations going forward, you can uncheck the box under ‘Location Information’ at https://foursquare.com/settings/privacy.
The Foursquare of today is so different than the first version that launched in 2009, and we appreciate that you let us continue to evolve and build our vision. This occasionally means altering our privacy policy. When we do, we make it a priority to come up with clear ways to help you understand your privacy choices, and to communicate them clearly. If you have any questions or want more details, head over to our updated privacy policy or support.foursquare.com.
Have a lovely holiday, and thanks for being part of the nearly 30,000,000-strong Foursquare community. We have a lot planned for 2013!
- Team Foursquare
22 December 2012
Bugs in the boardroom? They're already there
Despite an ongoing joke otherwise, I did not create SHODAN. On the other hand, I have blogged and presented about SHODAN in the past, and I was one of the first people to recognize the impact of SHODAN to vulnerability identification analysis.
During a recent engagement for one of my clients, I came across an unsecured instance of a Polycom web interface; in other words this web interface required zero authentication to access all of its options (including, quite obviously, its administrative options).
I developed two searches to locate these devices. The first search finds results for telnet sessions associated with these Polycom devices. To be sure, this is more of an information search to show you how many of these sorts of devices are out there (and exposed to the Internet).
The second search is more useful: it relies on a unique HTTP response and returns exposed web interfaces for these Polycom devices. Many of these instances require additional administrative authentication, but some do not. Even though some of these devices require additional authentication, it seems at least mildly surprising that some of them are exposed to the Internet, among them: "Fargo Cass Co District Court Rm 5," and "British Embassy - Brasilia."
Here are the most common options on the front page:
The difference should be immediately available: by clicking on "Admin Settings" on the top bar, you will either be prompted for a password or not. Here (when no password is required), we are taken the Admin Settings page and every option is available to us, include remote administration and monitoring.
Low-hanging fruit to be sure, but it will literally gives you eyes and ears into the conference room.
18 March 2012
MS12-020, exploits, and words mean things
On Friday, Core Security announced that they had released an exploit for CVE-2012-0002 (patched by Microsoft as MS12-020):
I thought this was great news. I am currently working on a client engagement with a lot of RDP on their network and we use Core as one of our tools. Time to pwn, right?
Not quite.
As subsequent tweets made more clear, the Core exploit was a denial of service module, not code execution. This got me thinking--what does it mean when you call something an exploit? I am a moderately-experienced penetration tester, and I think there's probably a misunderstanding about what this means. To me, an exploit is something that results in arbitrary code execution. Maybe a denial of service that results in a BSoD is an exploit, technically, but that's not what I expect the word to mean.
I hadn't thought about it much this weekend until HD Moore of Rapid 7/Metasploit summed up my feelings earlier today:
So, what do you think?
Is a denial of service module an exploit? Does it really matter, or are we splitting hairs?
EDITED TO ADD: And to add to HD's tweet: what exactly does commercial grade mean in reference to a DoS module? Does it give you an extra special BSoD? It seems the words in Core's original tweet are specifically designed as marketing pull, and as a result, imply that the module is a code execution exploit when it is not. The tweet clarifications made it obvious to me that others were as confused as I was.
Lastly, "Enjoy!" seems to suggest that we will like the result. I don't know about other penetration testers, but I can't think of any clients who have ever asked me to run DoS modules against their systems, and even if they asked me to do it, I'd probably advise them against it. What about you?
I thought this was great news. I am currently working on a client engagement with a lot of RDP on their network and we use Core as one of our tools. Time to pwn, right?
Not quite.
As subsequent tweets made more clear, the Core exploit was a denial of service module, not code execution. This got me thinking--what does it mean when you call something an exploit? I am a moderately-experienced penetration tester, and I think there's probably a misunderstanding about what this means. To me, an exploit is something that results in arbitrary code execution. Maybe a denial of service that results in a BSoD is an exploit, technically, but that's not what I expect the word to mean.
I hadn't thought about it much this weekend until HD Moore of Rapid 7/Metasploit summed up my feelings earlier today:
So, what do you think?
Is a denial of service module an exploit? Does it really matter, or are we splitting hairs?
EDITED TO ADD: And to add to HD's tweet: what exactly does commercial grade mean in reference to a DoS module? Does it give you an extra special BSoD? It seems the words in Core's original tweet are specifically designed as marketing pull, and as a result, imply that the module is a code execution exploit when it is not. The tweet clarifications made it obvious to me that others were as confused as I was.
Lastly, "Enjoy!" seems to suggest that we will like the result. I don't know about other penetration testers, but I can't think of any clients who have ever asked me to run DoS modules against their systems, and even if they asked me to do it, I'd probably advise them against it. What about you?
08 March 2012
BackTrack tool review: snmpcheck
Note: This is part of a series on BackTrack 5 tool reviews. It is not meant to be an exhaustive analysis of any tool, just a demonstration of the tool using real-world targets.
This tool presumes that you know of a host running the snmp service. Alternatively, you can try finding one with a tool like SHODAN or scan with Nmap for port 161 (UDP) open.
Pretty simple--enter an IP address. Everything else is optional. If you know the snmp service is running on a different port, you can add that with the -p option. Additionally, if you happen to know the community string, add it with -c. Otherwise, snmpcheck will use the default public.
root@bt:/pentest/enumeration/snmp/snmpcheck# ./snmpcheck-1.8.pl
I found a random host with UDP port 161 open and the snmp service running. Point snmpcheck at it, and you're off:
root@bt:/pentest/enumeration/snmp/snmpcheck# ./snmpcheck-1.8.pl -t 134.48.81.17
snmpcheck.pl v1.8 - SNMP enumerator
Copyright (c) 2005-2011 by Matteo Cantoni (www.nothink.org)
[*] Try to connect to 134.48.81.17
[*] Connected to 134.48.81.17
[*] Starting enumeration at 2012-03-08 20:28:07
[*] System information
-----------------------------------------------------------------------------------------------
Hostname : MARYN12105
Description : Hardware: x86 Family 6 Model 8 Stepping 6 AT/AT COMPATIBLE - Software: Windows 2000 Version 5.0 (Build 2195 Uniprocessor Free)
Uptime system : 6 hours, 47:16.37
Uptime SNMP daemon : 16 hours, 35:50.71
Motd : -
Domain (NT) : MARQNET
[*] User accounts
-----------------------------------------------------------------------------------------------
Administrator
Guest
arianace
chapr
ficengar
mmana
wilyrt
[*] Network information
-----------------------------------------------------------------------------------------------
IP forwarding enabled : no
Default TTL : 128
TCP segments received : 74692479
TCP segments sent : 57614412
TCP segments retrans. : 150854
Input datagrams : 2412799
Delivered datagrams : 2255627
Output datagrams : 1114372
[*] Network interfaces
-----------------------------------------------------------------------------------------------
Use of uninitialized value within @intspeed in pattern match (m//) at ./snmpcheck-1.8.pl line 676.
Use of uninitialized value within @intspeed in division (/) at ./snmpcheck-1.8.pl line 678.
Interface : [ up ] 3Com EtherLink PCI
Hardware Address : 00:a0:c9:c9:1a:7d
IP Address : 134.48.81.17
Netmask : 255.255.255.0
MTU : 1500
Bytes In : 1280835700 (1.2G)
Bytes Out : 802255200 (766M)
[*] Routing information
-----------------------------------------------------------------------------------------------
Destination Next Hop Mask Metric
0.0.0.0 134.48.81.17 0.0.0.0 -
[*] Listening TCP ports and connections
-----------------------------------------------------------------------------------------------
Local Address Port Remote Address Port State
0.0.0.0 139 0.0.0.0 139 Listening
0.0.0.0 23 0.0.0.0 23 Listening
[*] Listening UDP ports
-----------------------------------------------------------------------------------------------
Local Address Port
0.0.0.0 1101
0.0.0.0 137
0.0.0.0 138
[*] Non-administrative shares
-----------------------------------------------------------------------------------------------
Share Name : Inbox
Path : D:\Inbox
Comments :
Share Name : Outbox
Path : D:\Outbox
Comments :
[*] Wait...don't stop snmpcheck.pl...
Total non anonymous users : -
[*] Enumerated 134.48.81.17 in 46.98 seconds
Windows 2000, hostname and domain, user accounts, open ports (both TCP and UDP), shares...Pretty nice bit of information gathering for one open port, don't you think?
This tool presumes that you know of a host running the snmp service. Alternatively, you can try finding one with a tool like SHODAN or scan with Nmap for port 161 (UDP) open.
Pretty simple--enter an IP address. Everything else is optional. If you know the snmp service is running on a different port, you can add that with the -p option. Additionally, if you happen to know the community string, add it with -c. Otherwise, snmpcheck will use the default public.
root@bt:/pentest/enumeration/snmp/snmpcheck# ./snmpcheck-1.8.pl
snmpcheck.pl v1.8 - SNMP enumerator
Copyright (c) 2005-2011 by Matteo Cantoni (www.nothink.org)
Usage ./snmpcheck.pl -t
-t : target host;
-p : SNMP port; default port is 161;
-c : SNMP community; default is public;
-v : SNMP version (1,2); default is 1;
-r : request retries; default is 0;
-w : detect write access (separate action by enumeration);
-d : disable 'TCP connections' enumeration!
-T : force timeout in seconds; default is 20. Max is 60;
-D : enable debug;
-h : show help menu;
root@bt:/pentest/enumeration/snmp/snmpcheck# ./snmpcheck-1.8.pl -t 134.48.81.17
snmpcheck.pl v1.8 - SNMP enumerator
Copyright (c) 2005-2011 by Matteo Cantoni (www.nothink.org)
[*] Try to connect to 134.48.81.17
[*] Connected to 134.48.81.17
[*] Starting enumeration at 2012-03-08 20:28:07
[*] System information
-----------------------------------------------------------------------------------------------
Hostname : MARYN12105
Description : Hardware: x86 Family 6 Model 8 Stepping 6 AT/AT COMPATIBLE - Software: Windows 2000 Version 5.0 (Build 2195 Uniprocessor Free)
Uptime system : 6 hours, 47:16.37
Uptime SNMP daemon : 16 hours, 35:50.71
Motd : -
Domain (NT) : MARQNET
[*] User accounts
-----------------------------------------------------------------------------------------------
Administrator
Guest
arianace
chapr
ficengar
mmana
wilyrt
[*] Network information
-----------------------------------------------------------------------------------------------
IP forwarding enabled : no
Default TTL : 128
TCP segments received : 74692479
TCP segments sent : 57614412
TCP segments retrans. : 150854
Input datagrams : 2412799
Delivered datagrams : 2255627
Output datagrams : 1114372
[*] Network interfaces
-----------------------------------------------------------------------------------------------
Use of uninitialized value within @intspeed in pattern match (m//) at ./snmpcheck-1.8.pl line 676.
Use of uninitialized value within @intspeed in division (/) at ./snmpcheck-1.8.pl line 678.
Interface : [ up ] 3Com EtherLink PCI
Hardware Address : 00:a0:c9:c9:1a:7d
IP Address : 134.48.81.17
Netmask : 255.255.255.0
MTU : 1500
Bytes In : 1280835700 (1.2G)
Bytes Out : 802255200 (766M)
[*] Routing information
-----------------------------------------------------------------------------------------------
Destination Next Hop Mask Metric
0.0.0.0 134.48.81.17 0.0.0.0 -
[*] Listening TCP ports and connections
-----------------------------------------------------------------------------------------------
Local Address Port Remote Address Port State
0.0.0.0 139 0.0.0.0 139 Listening
0.0.0.0 23 0.0.0.0 23 Listening
[*] Listening UDP ports
-----------------------------------------------------------------------------------------------
Local Address Port
0.0.0.0 1101
0.0.0.0 137
0.0.0.0 138
[*] Non-administrative shares
-----------------------------------------------------------------------------------------------
Share Name : Inbox
Path : D:\Inbox
Comments :
Share Name : Outbox
Path : D:\Outbox
Comments :
[*] Wait...don't stop snmpcheck.pl...
Total non anonymous users : -
[*] Enumerated 134.48.81.17 in 46.98 seconds
Windows 2000, hostname and domain, user accounts, open ports (both TCP and UDP), shares...Pretty nice bit of information gathering for one open port, don't you think?
BackTrack tool review: goofile
Note: This is part of a series on BackTrack 5 tool reviews. It is not meant to be an exhaustive analysis of any tool, just a demonstration of the tool using real-world targets.
Goofile is a simple script that searches Google for specific file types from specific domains. This is useful if you're looking for specific types of files because it parses the results for you.
root@bt:/pentest/enumeration/google/goofile# ./goofile.py
-------------------------------------
|Goofile v1.5 |
|Coded by Thomas (G13) Richards |
|www.g13net.com |
|code.google.com/p/goofile |
-------------------------------------
Goofile 1.5
usage: goofile options
-d: domain to search
-f: filetype (ex. pdf)
example:./goofile.py -d test.com -f txt
Using un.org (one of our common examples), we can quickly put together a list of PDF files from the domain:
root@bt:/pentest/enumeration/google/goofile# ./goofile.py -d un.org -f pdf
-------------------------------------
|Goofile v1.5 |
|Coded by Thomas (G13) Richards |
|www.g13net.com |
|code.google.com/p/goofile |
-------------------------------------
Searching in un.org for pdf
========================================
Files found:
====================
www.un.org/sport2005/a_year/questions.pdf
www.un.org/un60/60ways_short.pdf
www.un.org/millenniumgoals/MDG2011_Asia_EN.pdf
www.un.org/millenniumgoals/MDG2011_na_EN.pdf
www.un.org/largerfreedom/executivesummary.pdf
www.un.org/summit2005/events_schedule.pdf
www.un.org/secureworld/report3.pdf
www.un.org/millenniumgoals/MDG2011_PRa_EN.pdf
www.un.org/WCAR/durban.pdf
www.un.org/summit2005/calendar.pdf
www.un.org/secureworld/report.pdf
www.un.org/secureworld/report2.pdf
www.un.org/millenniumgoals/MDG2011_SSA_EN.pdf
www.un.org/WCAR/aconf189_12.pdf
www.un.org/peace/bnote010101.pdf
www.un.org/events/res_1325e.pdf
www.un.org/secureworld/brochure.pdf
www.un.org/millenniumgoals/MDG2012_MediaContact_EN.pdf
www.un.org/peace/ppbm.pdf
www.un.org/millenniumgoals/MDG2011_cca_EN.pdf
www.un.org/millenniumgoals/MDG2011_wa_EN.pdf
www.un.org/smallislands2005/parallel.pdf
www.un.org/esa/population/publications/adoption2010/child_adoption.pdf
www.un.org/en/hq/dm/pdfs/RFS_Accountability.pdf
www.un.org/esa/population/publications/reprobehavior/partrepro.pdf
www.un.org/depts/los/general_assembly/study/study_files/unep_basel_convention.pdf
www.un.org/depts/los/general_assembly/.../unep_basel_convention.pdf
www.un.org/depts/los/general_assembly/study/study_files/germany_e.pdf
www.un.org/depts/los/general_assembly/study/study.../germany_e.pdf
www.un.org/events/smallarms2005/bms_faq_e.pdf
www.un.org/democracyfund/Docs/UU13.pdf
www.un.org/partnerships/Docs/Newsletter.pdf
www.un.org/millenniumgoals/pdf/mg1_hunger_badiane.pdf
www.un.org/russian/summit2005/outcome.pdf
www.un.org/democracyfund/Docs/UNDEF_brochure.pdf
www.un.org/millenniumgoals/pdf/rockefeller_march_25_prep.pdf
www.un.org/disabilities/documents/user_survivor_initiatives.pdf
www.un.org/millenniumgoals/pdf/PR_Africa_MDG09_EN.pdf
www.un.org/partnerships/Docs/Fellows_2010_bios.pdf
www.un.org/partnerships/Docs/GSCP_Guide.pdf
www.un.org/millenniumgoals/pdf/josette_sheeran_8mar2010.pdf
www.un.org/durbanreview2009/pdf/summary_report.pdf
www.un.org/millenniumgoals/pdf/MDG_FS_7_EN.pdf
www.un.org/millenniumgoals/pdf/sha_zukang_8mar2010.pdf
www.un.org/millenniumgoals/pdf/mdg_snapshot_16mar.pdf
www.un.org/webcast/pdfs/21century59.pdf
www.un.org/esa/peacebuilding/mapping.pdf
www.un.org/partnerships/Docs/MSD_Partnerships.pdf
www.un.org/chinese/millenniumgoals/MDGProgressChart2006.pdf
www.un.org/partnerships/Docs/Organisation_UNOP.pdf
www.un.org/millenniumgoals/pdf/MDG2010_PR_EN.pdf
www.un.org/sg/ethicalstandards/PublicDisclosure.pdf
www.un.org/durbanreview2009/pdf/E_Bulletin_Issue1_10_2008.pdf
www.un.org/millenniumgoals/pdf/Press_release_MDG_Gap_2009.pdf
www.un.org/democracyfund/Docs/UU09.pdf
www.un.org/sg/files/staff_fd_form.pdf
www.un.org/WCAR/journal/j31aug.pdf
www.un.org/law/books/IntlLawAsLanguageForIntlRelations.pdf
www.un.org/democracyfund/Docs/Worth_Reading_Laos_Newsletter_Vol1.pdf
www.un.org/democracyfund/.../Worth_Reading_Laos_Newsletter_Vol1.pdf
www.un.org/partnerships/Docs/Philanthropy_UK_profile_Ted_Turner.pdf
www.un.org/millenniumgoals/pdf/EPG_Report_031511_B_ENGLISH_w.pdf
www.un.org/millenniumgoals/.../EPG_Report_031511_B_ENGLISH_w.pdf
www.un.org/millenniumgoals/sgreport2004.pdf
www.un.org/webcast/pdfs/21century60Azerbaijan.pdf
www.un.org/millenniumgoals/pdf/MDG_H_LatinAm.pdf
www.un.org/law/technical/FinalReport.pdf
www.un.org/millennium/declaration/ares552e.pdf
www.un.org/regionalcommissions/CSW2010/escwa.pdf
panel.pdf
www.un.org/waterforlifedecade/pdf/05_2010_reader_financing_eng.pdf
www.un.org/millenniumgoals/pdf/WaterAid_sanitation_and_water.pdf
www.un.org/disabilities/documents/review_of_disability_and_the_mdgs.pdf
endviolence.un.org/pdf/unite_framework_en.pdf
www.un.org/millenniumgoals/pdf/MDG_PR_EN.pdf
www.un.org/law/trustfund/eterms.pdf
www.un.org/regionalcommissions/CSW2010/eclac.pdf
www.un.org/disabilities/documents/csw56_ortoleva.pdf
www.un.org/millenniumgoals/pdf/mdg_pressrel_sept2010.pdf
www.un.org/millenniumgoals/pdf/MDG_FS_8_EN.pdf
www.un.org/waterforlifedecade/pdf/05_2011_human_right_to_water_reader_eng.pdf
www.un.org/.../pdf/05_2011_human_right_to_water_reader_eng.pdf
www.un.org/webcast/pdfs/21century62.pdf
www.un.org/millenniumgoals/sgreport2002.pdf
www.un.org/democracyfund/Docs/UU_11.pdf
www.un.org/webcast/pdfs/21century45.pdf
www.un.org/waterforlifedecade/pdf/hrw_glossary_eng.pdf
www.un.org/law/books/CollectionOfEssaysByLegalAdvisers.pdf
www.un.org/millenniumgoals/pdf/PR_NorthAfrica_MDG09_EN.pdf
www.un.org/millenniumgoals/SG_MDGREport2011_ecosoc-7july2011.pdf
www.un.org/durbanreview2009/pdf/InfoNote_10_Indigenous_Peoples_En.pdf
www.un.org/ga/civilsocietyhearings/infonote.pdf
www.un.org/democracyfund/Docs/AfricanCharterDemocracy.pdf
www.un.org/democracyfund/Docs/Third_Round.pdf
www.un.org/media/main/roadmap122002.pdf
www.un.org/millenniumgoals/pdf/MDG_G_CIS.pdf
www.un.org/docs/sc/Forecast.pdf
www.un.org/WCAR/journal/journalE.pdf
www.un.org/millenniumgoals/2011_Gap_Report/2011MDGGAP_PR_EN.pdf
www.un.org/millenniumgoals/2011_Gap.../2011MDGGAP_PR_EN.pdf
www.un.org/millenniumgoals/pdf/MDG_FS_2_EN.pdf
www.un.org/durbanreview2009/pdf/InfoNote_09_Peoples_of_African_Descent_En.pdf
www.un.org/.../pdf/InfoNote_09_Peoples_of_African_Descent_En.pdf
www.un.org/millenniumgoals/pdf/MDG_FS_4_EN.pdf
www.un.org/partnerships/Docs/BJ_Speech.pdf
www.un.org/waterforlifedecade/pdf/water_for_life_award_eng.pdf
www.un.org/millenniumgoals/pdf/MDG_C_Asia.pdf
www.un.org/webcast/pdfs/unia1326.pdf
====================
Goofile is a simple script that searches Google for specific file types from specific domains. This is useful if you're looking for specific types of files because it parses the results for you.
root@bt:/pentest/enumeration/google/goofile# ./goofile.py
-------------------------------------
|Goofile v1.5 |
|Coded by Thomas (G13) Richards |
|www.g13net.com |
|code.google.com/p/goofile |
-------------------------------------
Goofile 1.5
usage: goofile options
-d: domain to search
-f: filetype (ex. pdf)
example:./goofile.py -d test.com -f txt
Using un.org (one of our common examples), we can quickly put together a list of PDF files from the domain:
root@bt:/pentest/enumeration/google/goofile# ./goofile.py -d un.org -f pdf
-------------------------------------
|Goofile v1.5 |
|Coded by Thomas (G13) Richards |
|www.g13net.com |
|code.google.com/p/goofile |
-------------------------------------
Searching in un.org for pdf
========================================
Files found:
====================
www.un.org/sport2005/a_year/questions.pdf
www.un.org/un60/60ways_short.pdf
www.un.org/millenniumgoals/MDG2011_Asia_EN.pdf
www.un.org/millenniumgoals/MDG2011_na_EN.pdf
www.un.org/largerfreedom/executivesummary.pdf
www.un.org/summit2005/events_schedule.pdf
www.un.org/secureworld/report3.pdf
www.un.org/millenniumgoals/MDG2011_PRa_EN.pdf
www.un.org/WCAR/durban.pdf
www.un.org/summit2005/calendar.pdf
www.un.org/secureworld/report.pdf
www.un.org/secureworld/report2.pdf
www.un.org/millenniumgoals/MDG2011_SSA_EN.pdf
www.un.org/WCAR/aconf189_12.pdf
www.un.org/peace/bnote010101.pdf
www.un.org/events/res_1325e.pdf
www.un.org/secureworld/brochure.pdf
www.un.org/millenniumgoals/MDG2012_MediaContact_EN.pdf
www.un.org/peace/ppbm.pdf
www.un.org/millenniumgoals/MDG2011_cca_EN.pdf
www.un.org/millenniumgoals/MDG2011_wa_EN.pdf
www.un.org/smallislands2005/parallel.pdf
www.un.org/esa/population/publications/adoption2010/child_adoption.pdf
www.un.org/en/hq/dm/pdfs/RFS_Accountability.pdf
www.un.org/esa/population/publications/reprobehavior/partrepro.pdf
www.un.org/depts/los/general_assembly/study/study_files/unep_basel_convention.pdf
www.un.org/depts/los/general_assembly/.../unep_basel_convention.pdf
www.un.org/depts/los/general_assembly/study/study_files/germany_e.pdf
www.un.org/depts/los/general_assembly/study/study.../germany_e.pdf
www.un.org/events/smallarms2005/bms_faq_e.pdf
www.un.org/democracyfund/Docs/UU13.pdf
www.un.org/partnerships/Docs/Newsletter.pdf
www.un.org/millenniumgoals/pdf/mg1_hunger_badiane.pdf
www.un.org/russian/summit2005/outcome.pdf
www.un.org/democracyfund/Docs/UNDEF_brochure.pdf
www.un.org/millenniumgoals/pdf/rockefeller_march_25_prep.pdf
www.un.org/disabilities/documents/user_survivor_initiatives.pdf
www.un.org/millenniumgoals/pdf/PR_Africa_MDG09_EN.pdf
www.un.org/partnerships/Docs/Fellows_2010_bios.pdf
www.un.org/partnerships/Docs/GSCP_Guide.pdf
www.un.org/millenniumgoals/pdf/josette_sheeran_8mar2010.pdf
www.un.org/durbanreview2009/pdf/summary_report.pdf
www.un.org/millenniumgoals/pdf/MDG_FS_7_EN.pdf
www.un.org/millenniumgoals/pdf/sha_zukang_8mar2010.pdf
www.un.org/millenniumgoals/pdf/mdg_snapshot_16mar.pdf
www.un.org/webcast/pdfs/21century59.pdf
www.un.org/esa/peacebuilding/mapping.pdf
www.un.org/partnerships/Docs/MSD_Partnerships.pdf
www.un.org/chinese/millenniumgoals/MDGProgressChart2006.pdf
www.un.org/partnerships/Docs/Organisation_UNOP.pdf
www.un.org/millenniumgoals/pdf/MDG2010_PR_EN.pdf
www.un.org/sg/ethicalstandards/PublicDisclosure.pdf
www.un.org/durbanreview2009/pdf/E_Bulletin_Issue1_10_2008.pdf
www.un.org/millenniumgoals/pdf/Press_release_MDG_Gap_2009.pdf
www.un.org/democracyfund/Docs/UU09.pdf
www.un.org/sg/files/staff_fd_form.pdf
www.un.org/WCAR/journal/j31aug.pdf
www.un.org/law/books/IntlLawAsLanguageForIntlRelations.pdf
www.un.org/democracyfund/Docs/Worth_Reading_Laos_Newsletter_Vol1.pdf
www.un.org/democracyfund/.../Worth_Reading_Laos_Newsletter_Vol1.pdf
www.un.org/partnerships/Docs/Philanthropy_UK_profile_Ted_Turner.pdf
www.un.org/millenniumgoals/pdf/EPG_Report_031511_B_ENGLISH_w.pdf
www.un.org/millenniumgoals/.../EPG_Report_031511_B_ENGLISH_w.pdf
www.un.org/millenniumgoals/sgreport2004.pdf
www.un.org/webcast/pdfs/21century60Azerbaijan.pdf
www.un.org/millenniumgoals/pdf/MDG_H_LatinAm.pdf
www.un.org/law/technical/FinalReport.pdf
www.un.org/millennium/declaration/ares552e.pdf
www.un.org/regionalcommissions/CSW2010/escwa.pdf
panel.pdf
www.un.org/waterforlifedecade/pdf/05_2010_reader_financing_eng.pdf
www.un.org/millenniumgoals/pdf/WaterAid_sanitation_and_water.pdf
www.un.org/disabilities/documents/review_of_disability_and_the_mdgs.pdf
endviolence.un.org/pdf/unite_framework_en.pdf
www.un.org/millenniumgoals/pdf/MDG_PR_EN.pdf
www.un.org/law/trustfund/eterms.pdf
www.un.org/regionalcommissions/CSW2010/eclac.pdf
www.un.org/disabilities/documents/csw56_ortoleva.pdf
www.un.org/millenniumgoals/pdf/mdg_pressrel_sept2010.pdf
www.un.org/millenniumgoals/pdf/MDG_FS_8_EN.pdf
www.un.org/waterforlifedecade/pdf/05_2011_human_right_to_water_reader_eng.pdf
www.un.org/.../pdf/05_2011_human_right_to_water_reader_eng.pdf
www.un.org/webcast/pdfs/21century62.pdf
www.un.org/millenniumgoals/sgreport2002.pdf
www.un.org/democracyfund/Docs/UU_11.pdf
www.un.org/webcast/pdfs/21century45.pdf
www.un.org/waterforlifedecade/pdf/hrw_glossary_eng.pdf
www.un.org/law/books/CollectionOfEssaysByLegalAdvisers.pdf
www.un.org/millenniumgoals/pdf/PR_NorthAfrica_MDG09_EN.pdf
www.un.org/millenniumgoals/SG_MDGREport2011_ecosoc-7july2011.pdf
www.un.org/durbanreview2009/pdf/InfoNote_10_Indigenous_Peoples_En.pdf
www.un.org/ga/civilsocietyhearings/infonote.pdf
www.un.org/democracyfund/Docs/AfricanCharterDemocracy.pdf
www.un.org/democracyfund/Docs/Third_Round.pdf
www.un.org/media/main/roadmap122002.pdf
www.un.org/millenniumgoals/pdf/MDG_G_CIS.pdf
www.un.org/docs/sc/Forecast.pdf
www.un.org/WCAR/journal/journalE.pdf
www.un.org/millenniumgoals/2011_Gap_Report/2011MDGGAP_PR_EN.pdf
www.un.org/millenniumgoals/2011_Gap.../2011MDGGAP_PR_EN.pdf
www.un.org/millenniumgoals/pdf/MDG_FS_2_EN.pdf
www.un.org/durbanreview2009/pdf/InfoNote_09_Peoples_of_African_Descent_En.pdf
www.un.org/.../pdf/InfoNote_09_Peoples_of_African_Descent_En.pdf
www.un.org/millenniumgoals/pdf/MDG_FS_4_EN.pdf
www.un.org/partnerships/Docs/BJ_Speech.pdf
www.un.org/waterforlifedecade/pdf/water_for_life_award_eng.pdf
www.un.org/millenniumgoals/pdf/MDG_C_Asia.pdf
www.un.org/webcast/pdfs/unia1326.pdf
====================
07 March 2012
BackTrack tool review: Nmap (UDP scanning)
Note: This is part of a series on BackTrack 5 tool reviews. It is not meant to be an exhaustive analysis of any tool, just a demonstration of the tool using real-world targets.
No, I'm not going to review "Nmap" in a single blog post; you could write an entire book about Nmap (Fyodor did, you should buy it).
This post is based upon a recent client experience: you run a UDP scan and you get the dreaded open|filtered. In the scan below, some UDP ports appear to be open (111, 177, 2049), but all others are open|filtered, which means Nmap doesn't know:
nmap -sU ###.###.###.### -p 1-65535
--- snip ---
PORT STATE SERVICE
67/udp open|filtered dhcps
69/udp open|filtered tftp
111/udp open rpcbind
123/udp open|filtered ntp
177/udp open xdmcp
514/udp open|filtered syslog
657/udp open|filtered rmc
832/udp open|filtered unknown
2049/udp open nfs
2279/udp open|filtered xmquery
3161/udp open|filtered unknown
32820/udp open|filtered unknown
32825/udp open|filtered unknown
32827/udp open|filtered unknown
32870/udp open|filtered unknown
32871/udp open|filtered unknown
32872/udp open|filtered unknown
32897/udp open|filtered unknown
-- snip --
Obviously, this isn't very useful. The goal here is to disambiguate open ports from filtered reports. One way to do that is to add service detection (-sV):
nmap -sU -sV ###.###.###.### -p 1-65535
-- snip --
PORT STATE SERVICE VERSION
67/udp open|filtered dhcps
69/udp open|filtered tftp
111/udp open rpcbind 2-4 (rpc #100000)
123/udp open|filtered ntp
177/udp open xdmcp XDMCP (willing; status: 6 users load: 14., 14., 12.)
514/udp open|filtered syslog
657/udp open|filtered rmc
832/udp open pcnfsd 1-2 (rpc #150001)
2049/udp open nfs 2-3 (rpc #100003)
2279/udp open|filtered xmquery
3161/udp open snmp Lexmark SNMP service
32820/udp open rpcbind 2-4 (rpc #100000)
32825/udp open pcnfsd 1-2 (rpc #150001)
32827/udp open cmsd 2-5 (rpc #100068)
32870/udp open mountd 1-3 (rpc #100005)
32871/udp open mountd 1-3 (rpc #100005)
32872/udp open status 1 (rpc #100024)
32897/udp open nlockmgr 1-4 (rpc #100021)
-- snip --
You can see here that a number of additional services are running which we could not detect with the simple UDP scan. One additional thing you can do is add the --reason switch, which describes which discovery test the port responded to:
nmap -sU -sV ###.###.###.### -p 1-65535 --reason
-- snip --
PORT STATE SERVICE REASON VERSION
67/udp open|filtered dhcps no-response
69/udp open|filtered tftp no-response
111/udp open rpcbind udp-response 2-4 (rpc #100000)
123/udp open|filtered ntp no-response
177/udp open xdmcp udp-response XDMCP (willing; status: 6 users load: 14., 14., 12.)
514/udp open|filtered syslog no-response
657/udp open|filtered rmc no-response
832/udp open pcnfsd udp-response 1-2 (rpc #150001)
2049/udp open nfs udp-response 2-3 (rpc #100003)
2279/udp open|filtered xmquery no-response
3161/udp open snmp udp-response Lexmark SNMP service
32820/udp open rpcbind udp-response 2-4 (rpc #100000)
32825/udp open pcnfsd udp-response 1-2 (rpc #150001)
32827/udp open cmsd udp-response 2-5 (rpc #100068)
32870/udp open mountd udp-response 1-3 (rpc #100005)
32871/udp open mountd udp-response 1-3 (rpc #100005)
32872/udp open status udp-response 1 (rpc #100024)
32897/udp open nlockmgr udp-response 1-4 (rpc #100021)
-- snip --
Lastly, a somewhat unrelated tip: I didn't include it here for reasons of space, but I always use the -v (verbose) option. Always nice to have more information, especially when documenting your penetration test.
No, I'm not going to review "Nmap" in a single blog post; you could write an entire book about Nmap (Fyodor did, you should buy it).
This post is based upon a recent client experience: you run a UDP scan and you get the dreaded open|filtered. In the scan below, some UDP ports appear to be open (111, 177, 2049), but all others are open|filtered, which means Nmap doesn't know:
nmap -sU ###.###.###.### -p 1-65535
--- snip ---
PORT STATE SERVICE
67/udp open|filtered dhcps
69/udp open|filtered tftp
111/udp open rpcbind
123/udp open|filtered ntp
177/udp open xdmcp
514/udp open|filtered syslog
657/udp open|filtered rmc
832/udp open|filtered unknown
2049/udp open nfs
2279/udp open|filtered xmquery
3161/udp open|filtered unknown
32820/udp open|filtered unknown
32825/udp open|filtered unknown
32827/udp open|filtered unknown
32870/udp open|filtered unknown
32871/udp open|filtered unknown
32872/udp open|filtered unknown
32897/udp open|filtered unknown
-- snip --
Obviously, this isn't very useful. The goal here is to disambiguate open ports from filtered reports. One way to do that is to add service detection (-sV):
nmap -sU -sV ###.###.###.### -p 1-65535
-- snip --
PORT STATE SERVICE VERSION
67/udp open|filtered dhcps
69/udp open|filtered tftp
111/udp open rpcbind 2-4 (rpc #100000)
123/udp open|filtered ntp
177/udp open xdmcp XDMCP (willing; status: 6 users load: 14., 14., 12.)
514/udp open|filtered syslog
657/udp open|filtered rmc
832/udp open pcnfsd 1-2 (rpc #150001)
2049/udp open nfs 2-3 (rpc #100003)
2279/udp open|filtered xmquery
3161/udp open snmp Lexmark SNMP service
32820/udp open rpcbind 2-4 (rpc #100000)
32825/udp open pcnfsd 1-2 (rpc #150001)
32827/udp open cmsd 2-5 (rpc #100068)
32870/udp open mountd 1-3 (rpc #100005)
32871/udp open mountd 1-3 (rpc #100005)
32872/udp open status 1 (rpc #100024)
32897/udp open nlockmgr 1-4 (rpc #100021)
-- snip --
You can see here that a number of additional services are running which we could not detect with the simple UDP scan. One additional thing you can do is add the --reason switch, which describes which discovery test the port responded to:
nmap -sU -sV ###.###.###.### -p 1-65535 --reason
-- snip --
PORT STATE SERVICE REASON VERSION
67/udp open|filtered dhcps no-response
69/udp open|filtered tftp no-response
111/udp open rpcbind udp-response 2-4 (rpc #100000)
123/udp open|filtered ntp no-response
177/udp open xdmcp udp-response XDMCP (willing; status: 6 users load: 14., 14., 12.)
514/udp open|filtered syslog no-response
657/udp open|filtered rmc no-response
832/udp open pcnfsd udp-response 1-2 (rpc #150001)
2049/udp open nfs udp-response 2-3 (rpc #100003)
2279/udp open|filtered xmquery no-response
3161/udp open snmp udp-response Lexmark SNMP service
32820/udp open rpcbind udp-response 2-4 (rpc #100000)
32825/udp open pcnfsd udp-response 1-2 (rpc #150001)
32827/udp open cmsd udp-response 2-5 (rpc #100068)
32870/udp open mountd udp-response 1-3 (rpc #100005)
32871/udp open mountd udp-response 1-3 (rpc #100005)
32872/udp open status udp-response 1 (rpc #100024)
32897/udp open nlockmgr udp-response 1-4 (rpc #100021)
-- snip --
Lastly, a somewhat unrelated tip: I didn't include it here for reasons of space, but I always use the -v (verbose) option. Always nice to have more information, especially when documenting your penetration test.
BackTrack tool review: theHarvester
Note: This is part of a series on BackTrack 5 tool reviews. It is not meant to be an exhaustive analysis of any tool, just a demonstration of the tool using real-world targets.
root@bt:/pentest/enumeration/theharvester# ./theHarvester.py
*************************************
*TheHarvester Ver. 2.1 (reborn) *
*Coded by Christian Martorella *
*Edge-Security Research *
*cmartorella@edge-security.com *
*************************************
Usage: theharvester options
-d: Domain to search or company name
-b: Data source (google,bing,bingapi,pgp,linkedin,google-profiles,exalead,all)
-s: Start in result number X (default 0)
-v: Verify host name via dns resolution and search for virtual hosts
-f: Save the results into an HTML and XML file
-n: Perform a DNS reverse query on all ranges discovered
-c: Perform a DNS brute force for the domain name
-t: Perform a DNS TLD expansion discovery
-e: Use this DNS server
-l: Limit the number of results to work with(bing goes from 50 to 50 results,
-h: use SHODAN database to query discovered hosts
google 100 to 100, and pgp doesn't use this option)
Examples:./theharvester.py -d microsoft.com -l 500 -b google
./theharvester.py -d microsoft.com -b pgp
./theharvester.py -d microsoft -l 200 -b linkedin
root@bt:/pentest/enumeration/theharvester# ./theHarvester.py -d un.org -b google -l 500 -h -n -c -t
*************************************
*TheHarvester Ver. 2.1 (reborn) *
*Coded by Christian Martorella *
*Edge-Security Research *
*cmartorella@edge-security.com *
*************************************
[-] Searching in Google:
Searching 0 results...
Searching 100 results...
Searching 200 results...
Searching 300 results...
Searching 400 results...
Searching 500 results...
[+] Emails found:
------------------
treaty@un.org
cocok@un.org
outreach@un.org
navarroperez@un.org
vandenwildenberg@un.org
ecu@un.org
news8@secint00.un.org
abukubi@un.org
@un.org
[+] Hosts found in search engines:
------------------------------------
157.150.185.49:www.un.org
157.150.195.212:careers.un.org
157.150.195.69:jobs.un.org
157.150.195.18:untreaty.un.org
157.150.195.187:comtrade.un.org
157.150.195.187:Comtrade.un.org
157.150.195.186:data.un.org
157.150.195.186:Data.un.org
157.150.185.49:cyberschoolbus.un.org
157.150.195.185:millenniumindicators.un.org
157.150.34.48:daccess-dds-ny.un.org
157.150.34.48:Daccess-dds-ny.un.org
157.150.195.94:mdgs.un.org
157.150.34.66:unasav4.un.org
157.150.185.202:Lists.un.org
157.150.185.201:unasav1.un.org
157.150.185.202:lists.un.org
157.150.185.28:ns1.un.org
157.150.195.76:unic.un.org
157.150.195.76:Unic.un.org
157.150.34.24:webmail02.un.org
193.188.135.35:escwa.un.org
157.150.195.153:unstats.un.org
157.150.195.153:Unstats.un.org
157.150.195.178:odslogin.un.org
157.150.196.65:myun.un.org
157.150.195.130:esa.un.org
157.150.195.105:doc.un.org
98.129.229.168:blogs.un.org
157.150.195.130:webapps01.un.org
157.150.195.193:icsc.un.org
157.150.185.49:Cyberschoolbus.un.org
157.150.195.93:dss.un.org
157.150.185.49:visit.un.org
157.150.185.49:Visit.un.org
157.150.195.94:Mdgs.un.org
157.150.195.30:unpan1.un.org
157.150.34.32:radio.un.org
157.150.34.32:Radio.un.org
157.150.34.48:daccess-ods.un.org
157.150.195.69:Jobs.un.org
157.150.195.39:secint00.un.org
157.150.34.32:endviolence.un.org
157.150.195.75:ochaonline.un.org
157.150.195.75:Ochaonline.un.org
157.150.195.130:Webapps01.un.org
157.150.195.30:Unpan1.un.org
[+] Proposed SET
---------------
[]
[+] Starting active queries:
[-]Performing reverse lookup in :157.150.185.0/24
157.150.185.255[-]Performing reverse lookup in :157.150.195.0/24
157.150.195.255[-]Performing reverse lookup in :157.150.34.0/24
157.150.34.255[-]Performing reverse lookup in :193.188.135.0/24
193.188.135.255[-]Performing reverse lookup in :157.150.196.0/24
157.150.196.255[-]Performing reverse lookup in :98.129.229.0/24
98.129.229.255Hosts found after reverse lookup:
---------------------------------
157.150.185.21:ny-mail-p-av-001.un.org
157.150.185.22:ny-mail-p-av-002.un.org
157.150.185.26:ny-mail-p-cl-001.un.org
157.150.185.27:ny-mail-p-cl-002.un.org
157.150.185.28:ns1.un.org
157.150.185.43:euq1.un.org
157.150.185.55:webmail.un.org
157.150.185.73:sftp.un.org
157.150.185.85:ws.dss.un.org
157.150.185.86:tfs.dss.un.org
157.150.185.87:ldap03.un.org
157.150.185.201:unasav1.un.org
157.150.185.202:unasav2.un.org
157.150.185.203:qa.dss.un.org
157.150.195.1:sms4.un.org
157.150.195.2:itsraudio.un.org
157.150.195.3:secap1515.un.org
157.150.195.5:www1.un.org
157.150.195.6:jsserver.un.org
157.150.195.7:secap262.un.org
157.150.195.8:cgi.un.org
157.150.195.9:www2.un.org
157.150.195.10:secint24.un.org
157.150.195.12:www4.un.org
157.150.195.14:secint05.un.org
157.150.195.16:secdhl01.un.org
157.150.195.18:untreaty.un.org
157.150.195.19:secln079.un.org
157.150.195.22:secint01.un.org
157.150.195.23:srch2.un.org
157.150.195.24:secrs02-195.un.org
157.150.195.25:secfil01.un.org
157.150.195.26:secap514.un.org
157.150.195.27:dcfs17.un.org
157.150.195.28:www0.un.org
157.150.195.29:secap591.un.org
157.150.195.30:secap061.un.org
157.150.195.31:secap254.un.org
157.150.195.33:secint02.un.org
157.150.195.34:secint03.un.org
157.150.195.36:secap068.un.org
157.150.195.37:secext1a.un.org
157.150.195.38:secext1b.un.org
157.150.195.39:secint00.un.org
157.150.195.40:secap093.un.org
157.150.195.41:secint26.un.org
157.150.195.42:secap097.un.org
157.150.195.43:websrch1.un.org
157.150.195.45:secap263.un.org
157.150.195.46:secint10.un.org
157.150.195.47:secint11.un.org
157.150.195.48:secint12.un.org
157.150.195.51:dcfs19.un.org
157.150.195.52:secap622.un.org
157.150.195.53:secap623.un.org
157.150.195.54:secap770.un.org
157.150.195.56:secap248.un.org
157.150.195.57:secap222.un.org
157.150.195.58:secap282.un.org
157.150.195.59:secap624.un.org
157.150.195.60:secap426.un.org
157.150.195.61:secap427.un.org
157.150.195.62:secap428.un.org
157.150.195.63:secap429.un.org
157.150.195.65:secap625.un.org
157.150.195.66:secap640.un.org
157.150.195.67:secap771.un.org
157.150.195.68:secap772.un.org
157.150.195.69:secap838.un.org
157.150.195.70:secap887.un.org
157.150.195.71:secap888.un.org
157.150.195.72:secap961.un.org
157.150.195.75:secap922.un.org
157.150.195.76:secint56.un.org
157.150.195.79:secap150-c3.un.org
157.150.195.81:secap014-c1.un.org
157.150.195.82:secap026.un.org
157.150.195.83:secap027.un.org
157.150.195.86:secap408.un.org
157.150.195.87:secap409.un.org
157.150.195.88:secap410.un.org
157.150.195.90:secap414.un.org
157.150.195.91:training.epas.un.org
157.150.195.92:netscaler-unpa.un.org
157.150.195.93:secap510.un.org
157.150.195.94:secap509.un.org
157.150.195.96:ictsurvey.un.org
157.150.195.97:secap056-c5.un.org
157.150.195.101:secint33.un.org
157.150.195.102:secint34.un.org
157.150.195.103:secint35.un.org
157.150.195.104:secint36.un.org
157.150.195.105:secint38.un.org
157.150.195.106:secint50.un.org
157.150.195.110:escwadr.un.org
157.150.195.111:ns2e.un.org
157.150.195.116:secnet020.un.org
157.150.195.132:secap836.un.org
157.150.195.135:secap308.un.org
157.150.195.136:secap034.un.org
157.150.195.139:secap685-c1.un.org
157.150.195.157:secnet045.un.org
157.150.195.160:secnet050.un.org
157.150.195.163:secap1032.un.org
157.150.195.168:secnet069.un.org
157.150.195.185:secnet086.un.org
157.150.195.186:secnet087.un.org
157.150.195.187:secnet088.un.org
157.150.195.188:secnet089.un.org
157.150.195.190:mobileoffice.un.org
157.150.195.193:secnet105.un.org
157.150.195.194:secnet106.un.org
157.150.195.203:dfs-vbpproxy-03.un.org
157.150.195.204:secap1315.un.org
157.150.195.206:secnet128.un.org
157.150.195.207:unsmin.un.org
157.150.195.208:secnet153.un.org
157.150.195.209:secnet154.un.org
157.150.195.210:secnet156.un.org
157.150.195.211:secnet157.un.org
157.150.195.212:secnet158.un.org
157.150.195.213:secap1439.un.org
157.150.195.214:secent161.un.org
157.150.195.215:secnetdss-tmp.un.org
157.150.195.216:secnet162.un.org
157.150.195.217:secnet163.un.org
157.150.195.218:secnet164.un.org
157.150.195.219:dfs-vbpproxy-01.un.org
157.150.195.220:dfs-vppproxy-02.un.org
157.150.195.221:secnet173.un.org
157.150.195.222:mobileofficebeta.un.org
157.150.195.238:seclg01-195.un.org
157.150.195.239:seclgnd3-195.un.org
157.150.34.20:ny-mail-r-av-001.un.org
157.150.34.21:ny-mail-r-av-002.un.org
157.150.34.31:sftp.un.org
157.150.34.37:ny-mail-r-cl-001.un.org
157.150.34.38:ny-mail-r-cl-002.un.org
157.150.34.40:ldap02.un.org
157.150.34.43:webmaildr.un.org
157.150.34.49:euq2.un.org
157.150.34.57:ns2.un.org
157.150.34.65:unasav3.un.org
157.150.34.66:unasav4.un.org
157.150.34.68:ldap04.un.org
157.150.196.1:intranet.un.org
157.150.196.3:esdstest.un.org
157.150.196.11:secln017.un.org
157.150.196.20:secap092.un.org
157.150.196.22:wwwppbd.un.org
157.150.196.29:intranet3.un.org
157.150.196.34:secap149.un.org
157.150.196.36:galaxy.un.org
157.150.196.38:secap137.un.org
157.150.196.41:galaxy-training.un.org
157.150.196.52:secap179.un.org
157.150.196.53:secap180.un.org
157.150.196.62:eassets.un.org
157.150.196.63:secap220.un.org
157.150.196.65:secap235.un.org
157.150.196.86:iseek.un.org
157.150.196.196:telecommutingapps.un.org
157.150.196.200:unhq-appsuat-c1.un.org
[-] Starting DNS brute force:
zlog.un.org[+] Hosts found after DNS brute force:
[-] Starting DNS TLD expansion:
Searching for: un.aero
[+] Hosts found after DNS TLD expansion:
==========================================
157.150.34.32:un.org
[+] Shodan Database search:
Searching for: 157.150.185.49:www.un.org
Searching for: 157.150.195.212:careers.un.org
Searching for: 157.150.195.69:jobs.un.org
Searching for: 157.150.195.18:untreaty.un.org
Searching for: 157.150.195.187:comtrade.un.org
Searching for: 157.150.195.187:Comtrade.un.org
Searching for: 157.150.195.186:data.un.org
Searching for: 157.150.195.186:Data.un.org
Searching for: 157.150.185.49:cyberschoolbus.un.org
Searching for: 157.150.195.185:millenniumindicators.un.org
Searching for: 157.150.34.48:daccess-dds-ny.un.org
Searching for: 157.150.34.48:Daccess-dds-ny.un.org
Searching for: 157.150.195.94:mdgs.un.org
Searching for: 157.150.34.66:unasav4.un.org
Searching for: 157.150.185.202:Lists.un.org
Searching for: 157.150.185.201:unasav1.un.org
Searching for: 157.150.185.202:lists.un.org
Searching for: 157.150.185.28:ns1.un.org
Searching for: 157.150.195.76:unic.un.org
Searching for: 157.150.195.76:Unic.un.org
Searching for: 157.150.34.24:webmail02.un.org
Searching for: 193.188.135.35:escwa.un.org
Searching for: 157.150.195.153:unstats.un.org
Searching for: 157.150.195.153:Unstats.un.org
Searching for: 157.150.195.178:odslogin.un.org
Searching for: 157.150.196.65:myun.un.org
Searching for: 157.150.195.130:esa.un.org
Searching for: 157.150.195.105:doc.un.org
Searching for: 98.129.229.168:blogs.un.org
Searching for: 157.150.195.130:webapps01.un.org
Searching for: 157.150.195.193:icsc.un.org
Searching for: 157.150.185.49:Cyberschoolbus.un.org
Searching for: 157.150.195.93:dss.un.org
Searching for: 157.150.185.49:visit.un.org
Searching for: 157.150.185.49:Visit.un.org
Searching for: 157.150.195.94:Mdgs.un.org
Searching for: 157.150.195.30:unpan1.un.org
Searching for: 157.150.34.32:radio.un.org
Searching for: 157.150.34.32:Radio.un.org
Searching for: 157.150.34.48:daccess-ods.un.org
Searching for: 157.150.195.69:Jobs.un.org
Searching for: 157.150.195.39:secint00.un.org
Searching for: 157.150.34.32:endviolence.un.org
Searching for: 157.150.195.75:ochaonline.un.org
Searching for: 157.150.195.75:Ochaonline.un.org
Searching for: 157.150.195.130:Webapps01.un.org
Searching for: 157.150.195.30:Unpan1.un.org
Searching for: 157.150.185.21:ny-mail-p-av-001.un.org
Searching for: 157.150.185.22:ny-mail-p-av-002.un.org
Searching for: 157.150.185.26:ny-mail-p-cl-001.un.org
Searching for: 157.150.185.27:ny-mail-p-cl-002.un.org
Searching for: 157.150.185.43:euq1.un.org
Searching for: 157.150.185.55:webmail.un.org
Searching for: 157.150.185.73:sftp.un.org
Searching for: 157.150.185.85:ws.dss.un.org
Searching for: 157.150.185.86:tfs.dss.un.org
Searching for: 157.150.185.87:ldap03.un.org
Searching for: 157.150.185.202:unasav2.un.org
Searching for: 157.150.185.203:qa.dss.un.org
Searching for: 157.150.195.1:sms4.un.org
Searching for: 157.150.195.2:itsraudio.un.org
Searching for: 157.150.195.3:secap1515.un.org
Searching for: 157.150.195.5:www1.un.org
Searching for: 157.150.195.6:jsserver.un.org
Searching for: 157.150.195.7:secap262.un.org
Searching for: 157.150.195.8:cgi.un.org
Searching for: 157.150.195.9:www2.un.org
Searching for: 157.150.195.10:secint24.un.org
Searching for: 157.150.195.12:www4.un.org
Searching for: 157.150.195.14:secint05.un.org
Searching for: 157.150.195.16:secdhl01.un.org
Searching for: 157.150.195.19:secln079.un.org
Searching for: 157.150.195.22:secint01.un.org
Searching for: 157.150.195.23:srch2.un.org
Searching for: 157.150.195.24:secrs02-195.un.org
Searching for: 157.150.195.25:secfil01.un.org
Searching for: 157.150.195.26:secap514.un.org
Searching for: 157.150.195.27:dcfs17.un.org
Searching for: 157.150.195.28:www0.un.org
Searching for: 157.150.195.29:secap591.un.org
Searching for: 157.150.195.30:secap061.un.org
Searching for: 157.150.195.31:secap254.un.org
Searching for: 157.150.195.33:secint02.un.org
Searching for: 157.150.195.34:secint03.un.org
Searching for: 157.150.195.36:secap068.un.org
Searching for: 157.150.195.37:secext1a.un.org
Searching for: 157.150.195.38:secext1b.un.org
Searching for: 157.150.195.40:secap093.un.org
Searching for: 157.150.195.41:secint26.un.org
Searching for: 157.150.195.42:secap097.un.org
Searching for: 157.150.195.43:websrch1.un.org
Searching for: 157.150.195.45:secap263.un.org
Searching for: 157.150.195.46:secint10.un.org
Searching for: 157.150.195.47:secint11.un.org
Searching for: 157.150.195.48:secint12.un.org
Searching for: 157.150.195.51:dcfs19.un.org
Searching for: 157.150.195.52:secap622.un.org
Searching for: 157.150.195.53:secap623.un.org
Searching for: 157.150.195.54:secap770.un.org
Searching for: 157.150.195.56:secap248.un.org
Searching for: 157.150.195.57:secap222.un.org
Searching for: 157.150.195.58:secap282.un.org
Searching for: 157.150.195.59:secap624.un.org
Searching for: 157.150.195.60:secap426.un.org
Searching for: 157.150.195.61:secap427.un.org
Searching for: 157.150.195.62:secap428.un.org
Searching for: 157.150.195.63:secap429.un.org
Searching for: 157.150.195.65:secap625.un.org
Searching for: 157.150.195.66:secap640.un.org
Searching for: 157.150.195.67:secap771.un.org
Searching for: 157.150.195.68:secap772.un.org
Searching for: 157.150.195.69:secap838.un.org
Searching for: 157.150.195.70:secap887.un.org
Searching for: 157.150.195.71:secap888.un.org
Searching for: 157.150.195.72:secap961.un.org
Searching for: 157.150.195.75:secap922.un.org
Searching for: 157.150.195.76:secint56.un.org
Searching for: 157.150.195.79:secap150-c3.un.org
Searching for: 157.150.195.81:secap014-c1.un.org
Searching for: 157.150.195.82:secap026.un.org
Searching for: 157.150.195.83:secap027.un.org
Searching for: 157.150.195.86:secap408.un.org
Searching for: 157.150.195.87:secap409.un.org
Searching for: 157.150.195.88:secap410.un.org
Searching for: 157.150.195.90:secap414.un.org
Searching for: 157.150.195.91:training.epas.un.org
Searching for: 157.150.195.92:netscaler-unpa.un.org
Searching for: 157.150.195.93:secap510.un.org
Searching for: 157.150.195.94:secap509.un.org
Searching for: 157.150.195.96:ictsurvey.un.org
Searching for: 157.150.195.97:secap056-c5.un.org
Searching for: 157.150.195.101:secint33.un.org
Searching for: 157.150.195.102:secint34.un.org
Searching for: 157.150.195.103:secint35.un.org
Searching for: 157.150.195.104:secint36.un.org
Searching for: 157.150.195.105:secint38.un.org
Searching for: 157.150.195.106:secint50.un.org
Searching for: 157.150.195.110:escwadr.un.org
Searching for: 157.150.195.111:ns2e.un.org
Searching for: 157.150.195.116:secnet020.un.org
Searching for: 157.150.195.132:secap836.un.org
Searching for: 157.150.195.135:secap308.un.org
Searching for: 157.150.195.136:secap034.un.org
Searching for: 157.150.195.139:secap685-c1.un.org
Searching for: 157.150.195.157:secnet045.un.org
Searching for: 157.150.195.160:secnet050.un.org
Searching for: 157.150.195.163:secap1032.un.org
Searching for: 157.150.195.168:secnet069.un.org
Searching for: 157.150.195.185:secnet086.un.org
Searching for: 157.150.195.186:secnet087.un.org
Searching for: 157.150.195.187:secnet088.un.org
Searching for: 157.150.195.188:secnet089.un.org
Searching for: 157.150.195.190:mobileoffice.un.org
Searching for: 157.150.195.193:secnet105.un.org
Searching for: 157.150.195.194:secnet106.un.org
Searching for: 157.150.195.203:dfs-vbpproxy-03.un.org
Searching for: 157.150.195.204:secap1315.un.org
Searching for: 157.150.195.206:secnet128.un.org
Searching for: 157.150.195.207:unsmin.un.org
Searching for: 157.150.195.208:secnet153.un.org
Searching for: 157.150.195.209:secnet154.un.org
Searching for: 157.150.195.210:secnet156.un.org
Searching for: 157.150.195.211:secnet157.un.org
Searching for: 157.150.195.212:secnet158.un.org
Searching for: 157.150.195.213:secap1439.un.org
Searching for: 157.150.195.214:secent161.un.org
Searching for: 157.150.195.215:secnetdss-tmp.un.org
Searching for: 157.150.195.216:secnet162.un.org
Searching for: 157.150.195.217:secnet163.un.org
Searching for: 157.150.195.218:secnet164.un.org
Searching for: 157.150.195.219:dfs-vbpproxy-01.un.org
Searching for: 157.150.195.220:dfs-vppproxy-02.un.org
Searching for: 157.150.195.221:secnet173.un.org
Searching for: 157.150.195.222:mobileofficebeta.un.org
Searching for: 157.150.195.238:seclg01-195.un.org
Searching for: 157.150.195.239:seclgnd3-195.un.org
Searching for: 157.150.34.20:ny-mail-r-av-001.un.org
Searching for: 157.150.34.21:ny-mail-r-av-002.un.org
Searching for: 157.150.34.31:sftp.un.org
Searching for: 157.150.34.37:ny-mail-r-cl-001.un.org
Searching for: 157.150.34.38:ny-mail-r-cl-002.un.org
Searching for: 157.150.34.40:ldap02.un.org
Searching for: 157.150.34.43:webmaildr.un.org
Searching for: 157.150.34.49:euq2.un.org
Searching for: 157.150.34.57:ns2.un.org
Searching for: 157.150.34.65:unasav3.un.org
Searching for: 157.150.34.68:ldap04.un.org
Searching for: 157.150.196.1:intranet.un.org
Searching for: 157.150.196.3:esdstest.un.org
Searching for: 157.150.196.11:secln017.un.org
Searching for: 157.150.196.20:secap092.un.org
Searching for: 157.150.196.22:wwwppbd.un.org
Searching for: 157.150.196.29:intranet3.un.org
Searching for: 157.150.196.34:secap149.un.org
Searching for: 157.150.196.36:galaxy.un.org
Searching for: 157.150.196.38:secap137.un.org
Searching for: 157.150.196.41:galaxy-training.un.org
Searching for: 157.150.196.52:secap179.un.org
Searching for: 157.150.196.53:secap180.un.org
Searching for: 157.150.196.62:eassets.un.org
Searching for: 157.150.196.63:secap220.un.org
Searching for: 157.150.196.65:secap235.un.org
Searching for: 157.150.196.86:iseek.un.org
Searching for: 157.150.196.196:telecommutingapps.un.org
Searching for: 157.150.196.200:unhq-appsuat-c1.un.org
Searching for: 157.150.34.32:un.org
[+] Shodan results:
===================
Subscribe to:
Posts (Atom)





