tailieunhanh - Google hacking for penetration tester - part 20

Cuối cùng, chúng ta có thể có kịch bản của chúng tôi chấm dứt khi không có tiểu lĩnh vực mới được tìm thấy. Một cách khác để lửa chắc chắn có được tên miền mà không cần phải thực hiện các host / domain kiểm tra là bài quá trình khai thác các địa chỉ e-mail. | Google s Part in an Information Collection Framework Chapter 5 191 allowing for 1 000 fresh results on this sub-domain which might give us deeper subdomains . Finally we can have our script terminate when no new sub-domains are found. Another sure fire way of obtaining domains without having to perform the host domain check is to post process-mined e-mail addresses. As almost all e-mail addresses are already at a domain and not a host the e-mail address can simply be cut after the @ sign and used in a similar fashion. Telephone Numbers Telephone numbers are very hard to parse with an acceptable rate of false positives unless you limit it to a specific country .This is because there is no standard way of writing down a telephone number. Some people add the country code but on regional sites or mailing lists it s seldom done. And even if the country code is added it could be added by using a plus sign . 44 or using the local international dialing method . 0044 . It gets worse. In most cases if the city code starts with a zero it is omitted if the internal dialing code is added . 27 12 555 1234 versus 012 555 1234 . And then some people put the zero in parentheses to show it s not needed when dialing from abroad . 27 0 12 555 1234 .To make matters worse a lot of European nations like to split the last four digits in groups of two . 012 12 555 12 34 . Of course there are those people that remember numbers in certain patterns thereby breaking all formats and making it almost impossible to determine which part is the country code if at all the city and the area within the city . 271 25 551 234 . Then as an added bonus dates can look a lot like telephone numbers. Consider the text From 1823-1825 1520 people couldn t parse telephone numbers. Better still are time frames such as Andrew Williams 1971-04-01 2007-07-07 And while it s not that difficult for a human to spot a false positive when dealing with e-mail addresses you need to be a local to tell the .

TỪ KHÓA LIÊN QUAN