<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DDoSed.com - An IT security information blog &#187; Penetration Testing</title>
	<atom:link href="http://www.ddosed.com/category/penetration-testing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ddosed.com</link>
	<description></description>
	<lastBuildDate>Sat, 04 Oct 2008 07:21:19 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>TXDNS v2.1.5 &#8211; A Multithreaded Digger/Brute Forcer For DNS</title>
		<link>http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns/</link>
		<comments>http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns/#comments</comments>
		<pubDate>Tue, 21 Aug 2007 12:01:27 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-diggerbrute-forcer-for-dns/</guid>
		<description><![CDATA[Arley Silveira has released the 1 year anniversary version of TXDNS. Very soon he will release the version 2.2 of TXDNS.

This release implements DNS queries against multiple DNS servers, a more efficient threading algorithm and some minor bug fixes.

 Quoting from the tool&#8217;s official website:

TXDNS main goal is to expose a domain namespace trough a [...]]]></description>
			<content:encoded><![CDATA[<p>Arley Silveira has released the 1 year anniversary version of <a href="http://www.txdns.net" target="_blank" title="TXDNS official website">TXDNS</a>. Very soon he will release the version 2.2 of TXDNS.</p>
<blockquote>
<p align="justify">This release implements DNS queries against multiple DNS servers, a more efficient threading algorithm and some minor bug fixes.</p>
</blockquote>
<p><span id="more-53"></span> Quoting from the tool&#8217;s official website:</p>
<blockquote>
<p align="justify">TXDNS main goal is to expose a domain namespace trough a number of techniques:</p>
<p>-Typos<br />
-TLD rotation<br />
-Dictionary attack<br />
-Brute force</p>
<p>TXDNS may be used to:</p>
<p align="justify">- Fill the reconnaiscence gap left due to DNS servers hardening, as dns-zone transfers are much like to fail.<br />
- Dig a given domain name for possible phishing variations based on common well-known typo algorithms and return dns queries on both used and not used names.<br />
- Stress-test DNS servers due is configurable aggressive behaviour.</p>
<p>TXDNS provides some cool options, such as:</p>
<p>- Perform queries only for a given Resource Record type:<br />
A, CNAME, HINFO, NS, TXT &amp; SOA<br />
- Perform non-recursive queries.<br />
- Perform queries against a given DNS server.</p></blockquote>
<p><a href="http://www.txdns.net/" target="_blank" title="Read more about the latest version of TXDNS - v2.1.5">Read more</a> about the latest version.</p>
<p><a href="http://www.txdns.net/content/download.htm" target="_blank" title="Download TXDNS v2.1.5">Download TXDNS v2.1.5</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F21%2Ftxdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns%2F';
  addthis_title  = 'TXDNS+v2.1.5+%26%238211%3B+A+Multithreaded+Digger%2FBrute+Forcer+For+DNS';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSHatter v0.2 &#8211; A Password Brute Forcer For SSH</title>
		<link>http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/</link>
		<comments>http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/#comments</comments>
		<pubDate>Tue, 21 Aug 2007 11:33:25 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/</guid>
		<description><![CDATA[Tim Brown from Nth Dimension has coded a cool password brute forcer for SSH called SSHatter.

It is multi threaded and can audit more than one system and account in a given session.

Download SSHatter-0.2

  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F21%2Fsshatter-a-password-brute-forcer-for-ssh%2F';
  addthis_title  = 'SSHatter+v0.2+%26%238211%3B+A+Password+Brute+Forcer+For+SSH';
  addthis_pub    = 'dpan';

]]></description>
			<content:encoded><![CDATA[<p align="justify">Tim Brown from <a href="http://www.nth-dimension.org.uk" title="Nth Dimension">Nth Dimension</a> has coded a cool password brute forcer for SSH called SSHatter.</p>
<blockquote>
<p align="justify">It is multi threaded and can audit more than one system and account in a given session.</p>
</blockquote>
<p><a target="_blank" href="http://www.nth-dimension.org.uk/downloads.php?id=34" title="SSHatter v0.2 download from Nth Dimension">Download SSHatter-0.2</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F21%2Fsshatter-a-password-brute-forcer-for-ssh%2F';
  addthis_title  = 'SSHatter+v0.2+%26%238211%3B+A+Password+Brute+Forcer+For+SSH';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Crackers Deface Websites? Why They Do It?</title>
		<link>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/</link>
		<comments>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/#comments</comments>
		<pubDate>Thu, 09 Aug 2007 01:33:04 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/</guid>
		<description><![CDATA[Through the following post I am not purposing to influence you to start defacing, but to briefly give you a better understanding of how and why it is done.
Almost everyday I visit Zone-H&#8217;s archive of special digital attacks, I find that at least 1 or 2 attacks were done against US governmental web servers. The domain suffix of [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Through the following post I am not purposing to influence you to start defacing, but to briefly give you a better understanding of how and why it is done.</p>
<p align="justify">Almost everyday I visit Zone-H&#8217;s <a target="_blank" href="http://www.zone-h.org/component/option,com_attacks/Itemid,43/" title="Zone-H.org Digital Attacks Archive">archive</a> of special digital attacks, I find that at least 1 or 2 attacks were done against US governmental web servers. The domain suffix of the defaced websites was *.gov. Does this fact means that they are totally secure? I don&#8217;t think so&#8230; Obviously the web servers may host very confidential data. In this case the web server administrators seemed to have allowed threats against governmental assets. Any unwanted consequences that a breach of security can lead to, are mainly caused by the irresponsibility and lazyness of system administrators and web developers.</p>
<p align="justify"><span id="more-50"></span></p>
<p align="justify">The methodology for defacing a website is pretty standard. Here is the standard sequence of tasks that normally the crackers/defacers would follow: <a target="_blank" href="http://en.wikipedia.org/wiki/Footprinting" title="Wikipedia.org - Footprinting">Footprinting</a>, <a href="http://netsecurity.about.com/cs/hackertools/a/aa030404.htm" title="Introduction to Vulnerability Scanning">scanning</a>, enumeration, penetration, attack, covering of tracks and installation of backdoors. As I mentioned before, the motivations for defacing any website are various, whereas when defacing governmental websites, could be a promotion of an ideology, revenge, or just a challenge.</p>
<p align="justify">I don&#8217;t believe that people who are serial website defacers hold good real-life jobs, or any job at all. This is just my personal opinion which is based on the fact that defacing is illegal in most countries &#8211; thus involving a high risk of getting arrested - and requires some basic knowledge, time, and patience. Advanced knowledge of technical and theoretical network security issues is not always required to deface. I think that understanding IT security theories, enhances intelligently your logical application of related practicalities. Achieving a deface could require the application of a complex exploitation methodology. This is enough reason to give up for some defacers without patience and with incomplete knowledge.</p>
<p align="justify">Tools assisting each step mentioned in the last paragraph are widely available for free on the internet. Most of the authors coded them for ethical, legal and educational use. Of course some were specifically coded for easily generating domain lists, exploiting security vulnerabilities, and mass-defacing websites. These are not easy to find on the web, nor are that difficult to code. Instead, individual defacers and groups exchange them in IRC channels, private forums  and servers, and through instant messengers.</p>
<p>One example of such an IRC server is irc.gigachat.net.</p>
<p align="justify">Script kiddies who deface, prefer to use fancy GUIs for tools rather than command line. Command line tools seem to exceed their learning and memory capabilities, or they don&#8217;t have the will and patience to research and analyze effective methodologies used by professionals in netsec pen-testing. They would be more technically skilled and better exercise their brain to remember simple and complex command sequences in multi-OS environments. Plus they would develop their practical skill-set which may be necessary if they choose to follow an IT career at some point &#8211; if they don&#8217;t end up in jail.</p>
<p align="justify">Depending on their ethical and legal attitudes, usually what they want is to quickly accomplish breaking in a network, maybe lookup for confidential data, download them and deface the home pages of hosted sites. Always counting in exceptions, most probably they didn&#8217;t use their own exploits, but what was already public.</p>
<p>Now I&#8217;m going to quote from another of my posts the following:</p>
<p align="justify">&#8220;In the mind and soul of the crackers who deface high-profiled websites, there is a false sense of pride. They think that it reflects their cracking skills and status in the defacers scene. For them defacing is more like a game. The messages shown in their defacements are more like an excuse for taking part in this game. The real motivation and reasoning behind their attacks, in most of the cases is not political, patriotic or other; but is just to show off themselves and their country to the world…</p>
<p align="justify">They attach a nickname to their personalities and cracking abilities, and they try to raise its status in the scene. They like searching for their nicknames in news websites and showing off the link to other crackers in their IRC channel, other channels, or through their websites.&#8221;</p>
<p align="justify">You will be ignored if you request mentioned tools or help to deface a website. Comments are welcome of course. <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p align="justify">&nbsp;</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F09%2Fhow-crackers-deface-websites-why-they-do-it%2F';
  addthis_title  = 'How+Crackers+Deface+Websites%3F+Why+They+Do+It%3F';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Pen-Test Paper: How An Internal Network Becomes External</title>
		<link>http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/</link>
		<comments>http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/#comments</comments>
		<pubDate>Sat, 17 Mar 2007 16:15:16 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/</guid>
		<description><![CDATA[My friend SuRGeoN from Greece wrote a very interesting pen-test paper which explains how easy is to convert an internal network into an external with the port redirection technique. He demonstrates the attack scenarios &#8211; including network architecture diagrams &#8211; and goes into great technical details about them.
 
Furthermore,  here are the steps which [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">My friend SuRGeoN from Greece wrote a very interesting pen-test paper which explains how easy is to convert an internal network into an external with the port redirection technique. He demonstrates the attack scenarios &#8211; including network architecture diagrams &#8211; and goes into great technical details about them.</p>
<p> <span id="more-45"></span></p>
<p>Furthermore,  here are the steps which the attacker would follow:</p>
<blockquote><p>1. Information gathering for the external network<br />
2. Seeking for vulnerabilities &amp; misconfigurations<br />
3. Using flaws to get a shell<br />
4. Information gathering for the internal network<br />
5. Escalating privileges for the internal network<br />
6. Converting internal network to external</p></blockquote>
<p>Download SuRGeoN&#8217;s paper from here: [ <a href="http://www.ddosed.com/uploads/penetration_testing/srgn-pentest-01.pdf" title="SuRGeoN - Paper: How an Internal Network Becomes External">srgn-pentest-01.pdf</a> ]</p>
<p align="justify">This information is provided to you ONLY for educational purposes. The way that the information in this paper will be used, depends on the individual’s legal and ethical attitudes. YOUR choice!&#8230; YOUR risk!&#8230; <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p align="justify">Comments on the paper are of course welcome.  You can also contact SuRGeoN via e-mail: surgeony/\gmail.com (replace /\ with @).</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F03%2F17%2Fpen-test-paper-how-an-internal-network-becomes-external%2F';
  addthis_title  = 'Pen-Test+Paper%3A+How+An+Internal+Network+Becomes+External';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NMapView v0.5 &#8211; Windows GUI Frontend For NMap Security Scanner Released</title>
		<link>http://www.ddosed.com/2007/02/08/nmapview-v05-windows-gui-frontend-for-nmap-security-scanner-released/</link>
		<comments>http://www.ddosed.com/2007/02/08/nmapview-v05-windows-gui-frontend-for-nmap-security-scanner-released/#comments</comments>
		<pubDate>Thu, 08 Feb 2007 20:06:12 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/02/08/nmapview-v05-windows-gui-frontend-for-nmap-security-scanner-released/</guid>
		<description><![CDATA[Vito Antico from CraftySoftwares.com, has recently released NMapView v0.5. NMapview provides the GUI frontend for the free NMap security scanner made by Fyodor. It is compatible with Windows 2000, XP, 2003 and Vista. It works with NMap v4.x, which you can download from Insecure.org.
Note: It requires Microsoft .NET Framework 2.0 and Winpcap.

Furthermore, the features of [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Vito Antico from <a href="http://www.craftysoftwares.com" target="_blank" title="CraftySoftwares.com - Free Tools by Vito Antico">CraftySoftwares.com</a>, has recently released <a href="http://www.craftysoftwares.com/default.aspx?idnavigation=001&amp;idnl=101&amp;id=1&amp;ids=7" target="_blank" title="CraftySoftwares.com - Home of NMapView">NMapView v0.5</a>. NMapview provides the GUI frontend for the free <a href="http://insecure.org/nmap/" target="_blank" title="Home of NMap">NMap</a> security scanner made by <a href="http://www.insecure.org" target="_blank" title="Fyodor's website">Fyodor</a>. It is compatible with Windows 2000, XP, 2003 and Vista. It works with NMap v4.x, which you can download from <a href="http://insecure.org/nmap/download.html" target="_blank" title="Insecure.org - NMap download">Insecure.org</a>.</p>
<p>Note: It requires <a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=0856EACB-4362-4B0D-8EDD-AAB15C5E04F5" title="MS .NET Framework 2.0 download" target="_blank">Microsoft .NET Framework 2.0</a> and <a href="http://www.winpcap.org/install/default.htm" title="Winpcap download" target="_blank">Winpcap</a>.</p>
<p><span id="more-35"></span></p>
<p>Furthermore, the features of NMapView are the following:</p>
<p align="justify">
<blockquote><p>- Automatic composition of the string of command based on selection of checkbox, textbox, ecc.<br />
- Automatic selection of checkbox and textbox, etc. based on tightens of insert comand string.<br />
- In the composition commands, the options of version 4.20 of Nmap are previewed all.<br />
- Supported version NSE (Nmap Scripting Engine)  by Diman Todorov. Found doc in  <a href="http://insecure.org/nmap/nse/" title="NMap Scripting Engine" target="_blank">http://insecure.org/nmap/nse/</a><br />
- Of every option or  parameter one detailed description through ToolTipHelp is supplied.<br />
- The configuration parameters that preview text are history between the varius sessions. (The story memory use Windows user login section).<br />
- The option and the parameters are distributed in logical section (Targhet specification, Host Discover, Scan  Techniques, etc.) based on the documentation of Fiodor.<br />
- Management list of commands throught rows database XML.<br />
- Callback of editor external for  .nse script.<br />
- Colorized: coloration and font combination, of the output of nmap, free and of any complexity through editor of Regex (Regular expressions) filters.<br />
- It se possible to start more commands nmap at the same time. You execute yourself in different task and windows.<br />
- One shot clipbord copy Command, for express past in shell dos.<br />
- The historical archives, of the output commands.<br />
- The Windows of command report, the standard flow output, than the flow of error.<br />
- View  in hierarchical tree  Structure the  raw XML data. (output ad file).<br />
- The output file XML , if present, it is intercepted ad loaded in the Tab &#8220;XML File Vew&#8221; to the end of the command.<br />
- NmapView is freeware software redistribute it and/or modify it under the terms of the GNU LESSER GENERAL PUBBLIC LICENSE.<br />
- Source and info  available in FORUM zone.</p></blockquote>
<p>For more information about NMapView, visit <a href="http://www.craftysoftwares.com/default.aspx?idnavigation=001&amp;idnl=101&amp;id=1&amp;ids=7" title="NMapView - More information about it on its homepage" target="_blank">its homepage</a>.</p>
<p><a href="http://www.craftysoftwares.com/SWdownload/nmapview.zip" title="Download NMapView v0.5" target="_blank">Download NMapView v0.5</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F02%2F08%2Fnmapview-v05-windows-gui-frontend-for-nmap-security-scanner-released%2F';
  addthis_title  = 'NMapView+v0.5+%26%238211%3B+Windows+GUI+Frontend+For+NMap+Security+Scanner+Released';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/02/08/nmapview-v05-windows-gui-frontend-for-nmap-security-scanner-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>googlegath.pl &#8211; Information Gathering Perl Script Using Google Search</title>
		<link>http://www.ddosed.com/2007/02/02/googlegath-information-gathering-perl-script-using-google-search/</link>
		<comments>http://www.ddosed.com/2007/02/02/googlegath-information-gathering-perl-script-using-google-search/#comments</comments>
		<pubDate>Fri, 02 Feb 2007 08:05:03 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/02/02/googlegathpl-information-gathering-perl-script-using-google-search/</guid>
		<description><![CDATA[Matteo Cantoni coded GoogleGath &#8211; a useful script for gathering information through Google searches. As Matteo states on his website, this script &#8220;could be useful for penetration testing, security scanning, script kiddies&#8221;.

To run googlegath.pl, three things are required: the perl interpreter, the Net::Google perl module and Google API. You can use it under Windows with [...]]]></description>
			<content:encoded><![CDATA[<p align="justify"><a href="http://www.nothink.org/" title="Matteo Cantoni's website" target="_blank">Matteo Cantoni</a> coded GoogleGath &#8211; a useful script for gathering information through Google searches. As Matteo states on his website, this script <em>&#8220;could be useful for penetration testing, security scanning, script kiddies&#8221;.<br />
</em></p>
<p align="justify">To run <a href="http://www.nothink.org/perl/googlegath/googlegath.txt" title="googlegath.pl source code" target="_blank">googlegath.pl</a>, three things are required: the <a href="http://www.perl.org" target="_blank" title="Perl.org - Perl Interpreter">perl interpreter</a>, the <a href="http://search.cpan.org/~ascope/Net-Google-1.0/" target="_blank" title="Net::Google perl module">Net::Google perl module</a> and <a href="http://code.google.com/apis/" target="_blank" title="Google APIs">Google API</a>. You can use it under Windows with <a href="http://www.activestate.com/Products/ActivePerl/" target="_blank" title="ActiveState.com - Active Perl download">Active Perl</a> interpreter.</p>
<p><span id="more-29"></span></p>
<p>Example usages:</p>
<blockquote><p>./googlegath.pl -a /backup/ -s gov -f txt -m 10<br />
./googlegath.pl -a /cgi-bin/ -s com -k awstats -m 10 -d<br />
./googlegath.pl -a /cgi-bin/ -s de -f pl -m 10 -d<br />
./googlegath.pl -a /scripts/ -s edu -f cgi -m 10 -l logfile.html<br />
./googlegath.pl -s edu -f cgi -m 20 -d<br />
./googlegath.pl -t &#8220;VNC Desktop&#8221; -i 5800 -m 10 -d -l logfile.html<br />
./googlegath.pl -i &#8220;main.php&#8221; -k &#8220;phpMyAdmin&#8221; -s com -m 10</p></blockquote>
<p>Using googlegath.pl to search for VNC (Virtual Network Computing) desktops running on port 5800:</p>
<blockquote><p>$ ./googlegath.pl -t &#8220;VNC Desktop&#8221; -i 5800 -m 10 -d -l logfile.html</p>
<p>[+] inurl:5800 intitle:&#8221;VNC Desktop&#8221;<br />
http://robot.mc3.edu:5800/ robot.mc3.edu 38.115.60.99<br />
http://129.82.106.115:5800/ 129.82.106.115 129.82.106.115<br />
http://66.97.228.100:5800/ 66.97.228.100 66.97.228.100<br />
http://12.207.102.150:5800/ 12.207.102.150 12.207.102.150<br />
http://12.207.107.126:5800/ 12.207.107.126 12.207.107.126<br />
http://moment.myftp.org:5800/ moment.myftp.org 124.6.20.156<br />
http://69.48.1.32:5800/ 69.48.1.32 69.48.1.32<br />
http://134.241.2.76:5800/ 134.241.2.76 134.241.2.76<br />
http://84.177.42.59:5800/ 84.177.42.59 84.177.42.59<br />
http://203.185.224.34:5800/ 203.185.224.34 203.185.224.34</p>
<p>[+] log file logfile.html created.</p></blockquote>
<p>In the wrong hands, information gathering &#8211; such as the above examples &#8211; can be used for malicious purposes. Therefore, the way that googlegath.pl will be used, depends on the individual&#8217;s legal and ethical attitudes.</p>
<p>googlegath.pl:</p>
<p><a href="http://www.nothink.org/perl/googlegath/googlegath.txt" title="googlegath.pl - source code" target="_blank">http://www.nothink.org/perl/googlegath/googlegath.txt</a><br />
<a href="http://www.ddosed.com/uploads/information_gathering/googlegath.txt" title="googlegath.pl - source code " target="_blank">http://www.ddosed.com/uploads/information_gathering/googlegath.txt </a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F02%2F02%2Fgooglegath-information-gathering-perl-script-using-google-search%2F';
  addthis_title  = 'googlegath.pl+%26%238211%3B+Information+Gathering+Perl+Script+Using+Google+Search';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/02/02/googlegath-information-gathering-perl-script-using-google-search/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
