background preloader

Footprinting & Similar

Facebook Twitter

Ist nicht verfügbar. Written by RSnake with input from id, Vacuum and Robert E Lee. A special thanks to IceShaman to porting it to use multi-threading. Fierce domain scan was born out of personal frustration after performing a web application security audit. It is traditionally very difficult to discover large swaths of a corporate network that is non-contiguous. It's terribly easy to run a scanner against an IP range, but if the IP ranges are nowhere near one another you can miss huge chunks of networks. First what Fierce is not. First it queries your DNS for the DNS servers of the target. Next, if it finds anything on any IP address it will scan up and down a set amount (default 5 but you can expand it with -traverse or increase it to the entire subnet with -wide) looking for anything else with the same domain name in it using reverse lookups.

I also added a random call to something that should fail to test for wildcard DNS. Perl fierce.pl -dns widget.com -search widgetcompany,nutsandbolts Not convinced? GHDB « Hackers For Charity. Group - Metagoofil. Goolag.org - Informationen zum Thema goolag. Diese Website steht zum Verkauf! SpiderFoot - The Open Source Footprinting tool. GHDB. Sensepost Research Labs. IGiGLE: Irongeek's WiGLE WiFi Database to Google Earth Client for Wardrive Mapping. IGiGLE: Irongeek's WiGLE WiFi Database to Google Earth Client for Wardrive Mapping About a year back I created a PHP script to convert raw WiGLE data into a KML file that Google Earth could read.

It was a useful script for a wardriver, but it was very convoluted to use since you had to import data from the JiGLE client, paste files together, and have PHP on your box. I decided to re-implement the tool as a standalone AutoIt3 Windows exe, source included (and GPLed). Now you just need this one app (igigle.exe), Google Earth and a WiGLE account to sit on you butt and map out your local wireless networks. For those that don't know, WiGLE is an online database of Wireless Access Points (802.11A/B/G) that is contributed to by folks using Netstumbler,Kismet and other war driving tools. WiGLE has a web interface of its own, as well as Java desktop client called JiGLE. I think the interface is fairly self-explanatory, but here is an explanation anyway :).

Happy mapping. Download IGiGLE. Mapping MAC addresses - samy kamkar. Android map exposes the data that Google has been collecting from virtually all Android devices and street view cars, using them essentially as global wardriving machines. You can use this tool to accurately locate virtually any router in the world, as well as position iPhones and Android phones. When the phone detects any wireless network, encrypted or otherwise, it sends the BSSID (MAC address) of the router along with signal strength, and most importantly, GPS coordinates up to the mothership. This page allows you to ping that database and find exactly where any wi-fi router in the world is located.

Note that iPhones also send this BSSID and Cell Tower Information up to Apple, as well. You can enter any router BSSID/MAC address to locate the exact physical location below, or try the demonstration router by hitting "Probe" below. Follow me on twitter to hear about more of my extremely thrilling projects. Links for Doxing, Personal OSInt, Profiling, Footprinting, Cyberstalking. Links for Doxing, Personal OSInt, Profiling, Footprinting, Cyberstalking Maybe you are doing a pen-test and need information before you carry out a social engineering attack.

Maybe you just want to see if someone who contacted you online is legit, or know what data of yours is out there for others to find. Here are a collection of sites I and others have found useful for finding data about a person or organization. I’m posting them mostly so I don’t lose them, and so I have a place to point others to when they ask.

If you have ideas for additions please contact me. There are tools for automating some of these tasks, but there is something to be said for doing it “by hand”. Finding a user name leads to other profiles with more data, this leads to a full name, then this could lead to a physical address. It’s all about making connections. Please note there a quite a few common problems with these sorts of social network aggregation sites: 1. General Search: Google Duh. Geo Location Tools.