This is not the document you are looking for? Use the search form below to find more!

Report home > Computer / Internet

Next Generation Web Scanning

5.00 (1 votes)
Document Description
Conference presentation slides on Next Generation Web Scanning. Includes new techniques for scanning the websites of an entire nation and shocking statistics on the state of website security.
File Details
Submitter
Embed Code:

Add New Comment




Related Documents

Global Next Generation Biometric Technologies Market worth $13.89 Billion by 2017

by: marketreports, 2 pages

Next Generation Biometric Technologies Market – Global Forecast & Analysis (2012 – 2017) By Types (Fingerprint, Palm, Face, Iris / Retina, Vein, Voice, Signature and others), ...

Next Generation Network (NGN) Solutions and Market Opportunities

by: benturner, 2 pages

Telecommunications service providers expect the NGN framework to provide them with tools that would ensure customer loyalty.

The Next Generation of Immersive, Online Brand Building

by: lian, 29 pages

The Next Generation of Immersive, Online Brand Building

Flash Lite 3 - Next Generation Flash Mobile

by: janet, 36 pages

Flash Lite 3 - Next Generation Flash Mobile

How to Speed Time to Market in a Next-Generation World

by: williamstt, 10 pages

To survive in this increasingly competitive market, companies will need to establish a competitive advantage at every opportunity. Fully leveraging time-to-market advantages from next-generation ...

Next Generation Business Analytics Technology Trends

by: kaseeb, 17 pages

Next Generation Business Analytics Technology Trends

Next Generation LOB (Line of Business) Applications

by: tadeusz, 182 pages

Next Generation LOB (Line of Business) Applications

Social Architecture: Modeling the Next Generation

by: ronja, 60 pages

Social Architecture: Modeling the Next Generation

Next-Generation Science Journals: Challenges and Opportunities by Janet Carter, UCLA Louise M. Darling Biomedical Library

by: secondo, 23 pages

Next- Generation Science JournalsChallenges & OpportunitiesJanet D. carterUCLA Louise M. Darling Biomedical Library2010 Charleston ConferenceNovember 5, 2010 About UCLA

Cloud Computing and the Next-Generation of Enterprise Architecture - Cloud Computing Expo 2008

by: molly, 27 pages

Cloud Computing and the Next Generation of Enterprise Architecture Stuart Charlton Chief Software Architect & VP ...

Content Preview
Next generation web scanning
New Zealand: A case study
First presented at KIWICON III 2009
By Andrew Horton
aka urbanadventurer

NZ Web Recon
Goal: To scan all of New Zealand's web-space to see
what's there.
Requirements:
– Targets
– Scanning
– Analysis
Sounds easy, right?
urbanadventurer (Andrew Horton)
www.morningstarsecurity.com

Targets
urbanadventurer (Andrew Horton)
www.morningstarsecurity.com

Targets
What does 'NZ web-space' mean?
It could mean:
•Geographically within NZ regardless of the TLD
•The .nz TLD hosted anywhere
•All of the above
For this scan it means, IPs geographically within
NZ
urbanadventurer (Andrew Horton)
www.morningstarsecurity.com

Finding Targets
We need creative methods to find targets
urbanadventurer (Andrew Horton)
www.morningstarsecurity.com

DNS Zone Transfer
urbanadventurer (Andrew Horton)
www.morningstarsecurity.com

Find IP addresses on IRC and by
resolving lots of NZ websites
58.*.*.*
60.*.*.*
65.*.*.*
91.*.*.*
110.*.*.*
111.*.*.*
113.*.*.*
114.*.*.*
115.*.*.*
116.*.*.*
117.*.*.*
118.*.*.*
119.*.*.*
120.*.*.*
121.*.*.*
122.*.*.*
123.*.*.*
124.*.*.*
125.*.*.*
130.*.*.*
131.*.*.*
132.*.*.*
138.*.*.*
139.*.*.*
143.*.*.*
144.*.*.*
146.*.*.*
150.*.*.*
153.*.*.*
156.*.*.*
161.*.*.*
162.*.*.*
163.*.*.*
165.*.*.*
166.*.*.*
167.*.*.*
192.*.*.*
198.*.*.*
202.*.*.*
203.*.*.*
210.*.*.*
218.*.*.*
219.*.*.*
222.*.*.*
729,580,500 IPs. More than we want to try.
urbanadventurer (Andrew Horton)
www.morningstarsecurity.com

IP address blocks in the IANA IPv4
Address Space Registry
Prefix Designation Date Whois
Status [1]
-----
------
----
-----
----------
000/8 IANA - Local Identification 1981-09 RESERVED
001/8 IANA UNALLOCATED
002/8 RIPE NCC 2009-09 whois.ripe.net ALLOCATED
003/8 General Electric Company 1994-05 LEGACY
201/8 LACNIC 2003-04 whois.lacnic.net ALLOCATED
202/8 APNIC 1993-05 whois.apnic.net ALLOCATED
203/8 APNIC 1993-05 whois.apnic.net ALLOCATED
204/8 ARIN 1994-03 whois.arin.net ALLOCATED
205/8 ARIN 1994-03 whois.arin.net ALLOCATED
206/8 ARIN 1995-04 whois.arin.net ALLOCATED
207/8 ARIN 1995-11 whois.arin.net ALLOCATED
208/8 ARIN 1996-04 whois.arin.net ALLOCATED
209/8 ARIN 1996-06 whois.arin.net ALLOCATED
210/8 APNIC 1996-06 whois.apnic.net ALLOCATED
211/8 APNIC 1996-06 whois.apnic.net ALLOCATED
This list has 663,255,000 IPs. More than we want to try.
urbanadventurer (Andrew Horton)
www.morningstarsecurity.com

Failed methods to find targets
• DNS Zone transfers from top level domain
name servers
• Learn IP address ranges for well known
national websites and networks
• All IP addresses allocated to APNIC (Asia
Pacific NIC)
We need new methods to find IP addresses and
website hostnames for New Zealand
urbanadventurer (Andrew Horton)
www.morningstarsecurity.com

geoipgen and the
MaxMind GeoIP database
Use MaxMind’s free database of IP to Country allocations
Homepage: www.morningstarsecurity.com/research/geoipgen
Produces 6,319,348 New Zealand IP addresses
urbanadventurer (Andrew Horton)
www.morningstarsecurity.com

Download
Next Generation Web Scanning

 

 

Your download will begin in a moment.
If it doesn't, click here to try again.

Share Next Generation Web Scanning to:

Insert your wordpress URL:

example:

http://myblog.wordpress.com/
or
http://myblog.com/

Share Next Generation Web Scanning as:

From:

To:

Share Next Generation Web Scanning.

Enter two words as shown below. If you cannot read the words, click the refresh icon.

loading

Share Next Generation Web Scanning as:

Copy html code above and paste to your web page.

loading