Downloads
Downloads
Downloads Home » Blackpapers
DocumentsDate added
-
Using traceroute as an ACL determinatehot!
- 07.10.1999
- This was a document I put together after a "reputable" security firm argued that we missed a UDP hole in the firewall which they picked up after running the "tracert" program. I did this writeup as soon as I verified their spelling of "tracert". ;)
- Hits: 11618
-
Phrack 52: Steganography Thumprintinghot!
- 26.01.1998
- A decent article, although it's old. This was my first real article/paper. I met Mike (Shiffman) / Daemon9 / Route through a friend of mine, Topher, and we got to chatting. We came up with the idea of this paper, and here it is. Seems like a lifetime ago.
- Hits: 12321
-
DNS Prediction With Googlehot!
- 25.03.2005
- It's possible to use Google to help find hosts that Google doesn't even KNOW about! This paper outlines a technique we'll call DNS name prediction with Google. This technique can help a security auditor locate hosts, targets, and subdomains that exist on a target network via Google queries, name expansion with Google sets, and DNS lookups. A neat topic, outlined with working examples.
- Hits: 12552
-
The URL and the URIhot!
- 04.03.2002
- A history and overview of these two items. c'mon... you know URI's.. http:// or aim:// or ftp://.. those things you put before your address in your browser. I wrote this beacuse of eeye's cool post entitled "Windows Shell Overflow" at http://www.eeye.com/html/Research/Advisories/AD20020308.html
- Hits: 15009
-
The Google Hacker's Guidehot!
- 19.03.2004
- The Google search engine found at www.google.com offers many different features including language and document translation, web, image, newsgroups, catalog and news searches and more. These features offer obvious benefits to even the most uninitiated web surfer, but these same features allow for far more nefarious possibilities to the most malicious Internet users including hackers, computer criminals, identity thieves and even terrorists. This paper outlines the more nefarious applications of the Google search engine, techniques that have collectively been termed "Google hacking". The intent of this paper is to educate web administrators and the security community in the hopes of eventually securing this form of information leakage. This was the early predecessor to Google Hacking For Penetration Testers.
- Hits: 109048