sexta-feira, 19 de janeiro de 2024

Gotanda - Browser Web Extension For OSINT


Gotanda is OSINT(Open Source Intelligence) Web Extension for Firefox/Chrome.

This Web Extension could search OSINT information from some IOC in web page.(IP,Domain,URL,SNS...etc)

This Repository partly the studying and JavaScript practice.

Download link below.


Usage

Right click highlighted IOC strings, It will show contextmenus.(Or right clicking any link. )

When You want to search using some engine, You choose one of list.


Search Engine List
Name URL Category
Domain Tools https://whois.domaintools.com/ whois Lookup
Security Trails https://securitytrails.com/ whois lookup
whoisds https://whoisds.com/ whois lookup
ThreatCrowd https://www.threatcrowd.org/ Domain, IPv4
AbuseIPDB https://www.abuseipdb.com/ IPv4
HackerTarget https://hackertarget.com/ IPv4
Censys https://censys.io/ IP, Domain
Shodan https://shodan.io/ IP, Domain
FOFA https://fofa.so/ IP, Domain
VirusTotal https://virustotal.com/ IP, Domain, URL,Hash
GreyNoise https://viz.greynoise.io/ IPv4
IPAlyzer https://ipalyzer.com/ IPv4
Tor Relay Search https://metrics.torproject.org/ IP,Domain
Domain Watch https://domainwat.ch/ Domain, Email,whois lookup
crt.sh https://crt.sh/ SSL-certificate
SecurityHeaders https://securityheaders.com/ URL, Domain
DNSlytics https://dnslytics.com/ IPv4,IPv6,ASN
URLscan https://urlscan.io/ URL
Ultratools https://www.ultratools.com/ IPv6
Wayback Machine https://web.archive.org URL
aguse https://www.aguse.jp/ URL
check-host https://check-host.net/ URL
CIRCL https://cve.circl.lu/ CVE
FortiGuard https://fortiguard.com/ CVE
Sploitus https://sploitus.com/ CVE
Vulmon https://vulmon.com/ CVE
CXSecurity https://cxsecurity.com/ CVE
Vulncode-DB https://www.vulncode-db.com/ CVE
Malshare https://malshare.com/ MD5 Hash
ThreatCrowd https://www.threatcrowd.org/ IP,Domain
Hybrid Analysis https://www.hybrid-analysis.com/ hash
Twitter https://twitter.com/ SNS, w/TimeLine
Qiita https://qiita.com SNS
GitHub https://github.com SNS
Facebook https://www.facebook.com/ SNS, w/TimeLine
Instagram https://www.instagram.com/ SNS
LinkedIn https://linkedin.com/ SNS
Pinterest https://www.pinterest.jp SNS
reddit https://www.reddit.com/ SNS

About Twitter and FaceBook could search timeline with any words.


Misc

This extension is optimized for the Japanese environment.




Related word

Hacking All The Cars - Part 2


Connecting Hardware to Your Real Car: 

 I realized the other day I posted Part 2 of this series to my youtube awhile ago but not blogger so this one will be quick and mostly via video walkthrough. I often post random followup videos which may never arrive on this blog. So if you're waiting on something specific I mentioned or the next part to a series its always a good idea to subscribe to the YouTube. This is almost always true if there is video associated with the post.  

In the last blog we went over using virtual CAN devices to interact with a virtual car simulators of a CAN network This was awesome because it allowed us to learn how to interact with he underlying CAN network without fear of hacking around on an expensive automobile. But now it's time to put on your big boy pants and create a real CAN interface with hardware and plug your hardware device into your ODB2 port. 

The video I created below will show you where to plug your device in, how to configure it and how to take the information you learned while hacking around on the virtual car from part1 and apply it directly to a real car.   

Video Walk Through Using Hardware on a Real Car




As a reference here are the two device options I used in the video and the needed cable: 

Hardware Used: 

Get OBD2 Cable:
https://amzn.to/2QSmtyL

Get CANtact:
https://amzn.to/2xCqhMt

Get USB2CAN:
https://shop.8devices.com/usb2can


Creating Network Interfaces: 

As a reference here are the commands from the video for creating a CAN network interface: 

USB2Can Setup: 
The following command will bring up your can interface and you should see the device light color change: 
sudo ip link set can0 up type can bitrate 125000

Contact Setup: 
Set your jumpers on 3,5 and 7 as seen in the picture in the video
Sudo slcand -o -s6 /dev/ttyACM can0 <— whatever device you see in your DMESG output
Ifconfig can0 up

Summary: 

That should get you started connecting to physical cars and hacking around. I was also doing a bit of python coding over these interfaces to perform actions and sniff traffic. I might post that if anyone is interested. Mostly I have been hacking around on blockchain stuff and creating full course content recently so keep a look out for that in the future. 

Read more
  1. Pentest Tools Download
  2. Hacking Tools Mac
  3. How To Make Hacking Tools
  4. Hacking Tools Online
  5. Hak5 Tools
  6. Physical Pentest Tools
  7. Free Pentest Tools For Windows
  8. Hacker Tools Online
  9. Hacker Tools Apk Download
  10. Pentest Tools Android
  11. Ethical Hacker Tools
  12. Pentest Box Tools Download
  13. Pentest Tools
  14. Hacker Tools Linux
  15. Hack Website Online Tool
  16. Hackers Toolbox
  17. Hacking Apps
  18. Hacking Tools Hardware
  19. Pentest Tools For Mac
  20. Pentest Tools Free
  21. Hacker Tools Windows
  22. Bluetooth Hacking Tools Kali
  23. Hacking Tools Kit
  24. Pentest Reporting Tools
  25. Pentest Tools Bluekeep
  26. Hacking Tools Hardware
  27. Pentest Tools Android
  28. Hacking Tools For Windows Free Download
  29. Hack Apps
  30. Pentest Tools Find Subdomains
  31. Hacking Tools Hardware
  32. Pentest Recon Tools
  33. Kik Hack Tools
  34. Hacker Tools List
  35. Hack Tools
  36. Hacking Tools Software
  37. Pentest Tools Free
  38. Physical Pentest Tools
  39. Hacking Tools Free Download
  40. Hacker Hardware Tools
  41. Pentest Tools Kali Linux
  42. Hacker Search Tools
  43. What Are Hacking Tools
  44. Free Pentest Tools For Windows
  45. Hacking App
  46. Tools For Hacker
  47. Pentest Tools Framework
  48. What Is Hacking Tools
  49. Pentest Tools Port Scanner
  50. Hacker Tools Software
  51. Hacking Tools Windows 10
  52. Pentest Tools Github
  53. Pentest Tools Download
  54. Pentest Tools Website Vulnerability
  55. Hacker Tools Hardware
  56. Hacking Tools 2019
  57. Nsa Hacker Tools
  58. Hacking Tools Usb
  59. Hacker Tools Github
  60. Hacker Tools
  61. Hacker
  62. Hacking Tools For Games
  63. Hack Apps
  64. Pentest Tools Open Source
  65. Free Pentest Tools For Windows
  66. Hacking Tools For Kali Linux
  67. Pentest Tools Android
  68. Hack Tools 2019
  69. Wifi Hacker Tools For Windows
  70. Pentest Tools Tcp Port Scanner
  71. Hacker Tools 2020
  72. Game Hacking
  73. Ethical Hacker Tools
  74. Growth Hacker Tools
  75. Hack Tool Apk No Root
  76. Pentest Tools Review
  77. Hack Tools For Pc
  78. Nsa Hack Tools Download
  79. Hacking Tools For Windows
  80. Hacking Tools Github
  81. Hack Tools For Windows
  82. Hack Tools Online
  83. Best Hacking Tools 2019
  84. Pentest Tools For Mac
  85. Tools Used For Hacking
  86. Hacker Tools Free
  87. Hacking Tools 2019
  88. Hackrf Tools
  89. Hacker Tools Apk
  90. Hacking Tools For Windows Free Download
  91. Hak5 Tools
  92. Hack Rom Tools
  93. Pentest Tools Open Source
  94. Hacker Tools 2020
  95. Hacker Tools Linux
  96. Pentest Tools Nmap
  97. Hacker Tools 2019
  98. Pentest Tools Free
  99. Hacking Tools Windows
  100. Blackhat Hacker Tools
  101. Nsa Hack Tools Download
  102. Hacking Tools Name
  103. Hacker Tools Github
  104. Hacker Tool Kit
  105. Install Pentest Tools Ubuntu
  106. Pentest Tools Website Vulnerability
  107. Pentest Tools
  108. New Hacker Tools
  109. Hack Tool Apk No Root
  110. Hacker Tools 2020
  111. Hacking Tools
  112. Pentest Recon Tools
  113. Hack Rom Tools
  114. New Hacker Tools
  115. Hacker Techniques Tools And Incident Handling
  116. Pentest Tools Nmap
  117. Hack Tools For Ubuntu
  118. Pentest Tools For Android
  119. World No 1 Hacker Software
  120. Hacker Tools
  121. How To Install Pentest Tools In Ubuntu
  122. Hacker Tools Online
  123. Hacking Tools For Mac
  124. Hacker Tools 2019
  125. Pentest Tools For Android
  126. Hacking Tools
  127. Pentest Tools For Ubuntu
  128. Hack Tools
  129. Hacking Tools
  130. Hacker
  131. Pentest Recon Tools
  132. Hacking Tools Windows 10
  133. Pentest Tools For Windows
  134. Hack Tools For Games
  135. Hacker Tools Hardware
  136. Hacker Hardware Tools
  137. Game Hacking
  138. Tools Used For Hacking
  139. Pentest Tools For Mac

Security Surprises On Firefox Quantum

This morning I've found an scaring surprise on my Firefox Quantum. Casually it was connected to a proxy when an unexpected connection came up, the browser  was connecting to an unknown remote site via HTTP and downloading a ZIP that contains an ELF shared library, without any type of signature on it.

This means two things

1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.


Ubuntu Version:


Firefox Quantum version:



The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip




The zip contains these two files:
  3f201a8984d6d765bc81966842294611  libgmpopenh264.so
  44aef3cd6b755fa5f6968725b67fd3b8  gmpopenh264.info

The info file:
  Name: gmpopenh264
  Description: GMP Plugin for OpenH264.
  Version: 1.6.0
  APIs: encode-video[h264], decode-video[h264]

So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.

In this case the shared library is a video decoder, but it would be a vector to distribute malware o spyware massively, or an attack vector for a MITM attacker.




More info


Quando eu te falei em amor

Quando os meus olhos te tocaram
Eu senti que encontrara
A outra, metade de mim
Tive medo de acordar
Como se vivesse um sonho
Que não pensei em realizar
E a força do desejo
Faz me chegar perto de ti

Quando eu te falei em amor
Tu sorriste para mim
E o mundo ficou bem melhor
Quando eu te falei em amor
Nos sentimos os dois
Que o amanha vem depois
E não no fim

Estas linhas que hoje escrevo
São do livro da memória
Do que eu sinto por ti
E tudo o que tu me das
É parte da história que eu ainda não vivi
E a força do desejo
Faz me chegar de ti

Quando eu te falei em amor
Tu sorriste para mim
E o mundo ficou bem melhor
Quando eu te falei em amor
Nos sentimos os dois
Que o amanha vem depois e não no fim

André Sardet

Collide

The dawn is breaking
A light shining through
You're barely waking
And I'm tangled up in you
Yeah

But I'm open, you're closed
Where I follow, you'll go
I worry I won't see your face
Light up again

Even the best fall down sometimes
Even the wrong words seem to rhyme
Out of the doubt that fills my mind
I somehow find, you and I collide

I'm quiet, you know
You make a first impression
I've found I'm scared to know
I'm always on your mind

Even the best fall down sometimes
Even the stars refuse to shine
Out of the back you fall in time
I somehow find, you and I collide

Don't stop here
I've lost my place
I'm close behind

Even the best fall down sometimes
Even the wrong words seem to rhyme
Out of the doubt that fills your mind

You finally find, you and I collide
You finally find You and I collide
You finally findYou and I collide

Howie Day


Everything

You're a falling star, You're the get away
car.

You're the line in the sand when I go too
far.

You're the swimming pool, on an August day.
And You're the perfect thing to see.

And you play it coy, but it's kinda cute.
Ah, When you smile at me you know exactly what you
do.

Baby don't pretend, that you don't know it's
true.

Cause you can see it when I look at you.

And in this crazy life, and through these crazy
times

It's you, it's you, You make me sing.
You're every line, you're every word, you're
everything.


You're a carousel, you're a wishing well,
And you light me up, when you ring my bell.
You're a mystery, you're from outer space,
You're every minute of my everyday.

And I can't believe, uh that I'm your man,
And I get to kiss you baby just because I
can.

Whatever comes our way, ah we'll see it
through,

And you know that's what our love can do.

And in this crazy life, and through these crazy
times

It's you, it's you, You make me sing
You're every line, you're every word, you're
everything.


So, La, La, La, La, La, La, La
So, La, La, La, La, La, La, La

And in this crazy life, and through these crazy
times

It's you, it's you, You make me sing.
You're every line, you're every word, you're
everything.

You're every song, and I sing along.
Cause you're my everything.
yeah, yeah

So, La, La, La, La, La, La, La
So, La, La, La, La, La, La, La

Michael Bublé