<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-21869293</id><updated>2011-11-27T16:46:07.348-08:00</updated><title type='text'>serversniff</title><subtitle type='html'>sniff sniff snort. hatschi.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default?start-index=101&amp;max-results=100'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>127</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-21869293.post-8693906030367016226</id><published>2011-02-03T23:44:00.000-08:00</published><updated>2011-02-03T23:44:14.178-08:00</updated><title type='text'>Transfer Files and Data via DNS-Requests</title><content type='html'>Most of you might know &lt;a href="http://www.dnstunnel.de/"&gt;dnstunnel&lt;/a&gt;. Johannes Ullrich from Sans lists a &lt;a href="http://isc.sans.edu/diary.html?storyid=10306"&gt;poor mans dns-filetransfer using xxd &lt;/a&gt;which i think is a nice idea working on most unix boxes for xxd seems to be commonly installed.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-8693906030367016226?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/8693906030367016226/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=8693906030367016226' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8693906030367016226'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8693906030367016226'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2011/02/transfer-files-and-data-via-dns.html' title='Transfer Files and Data via DNS-Requests'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4373637962576936329</id><published>2011-02-02T05:13:00.000-08:00</published><updated>2011-02-02T05:13:57.054-08:00</updated><title type='text'>How Egypt cut itself off - and how it got back</title><content type='html'>Heise.de hosts a nice video derived from &lt;a href="http://bgplay.routeviews.org/"&gt;bgplay&lt;/a&gt; showing how the egyptian BGP-Routes vanished.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.heise.de/newsticker/meldung/Aegypten-Massenproteste-gehen-weiter-Update-1181273.html"&gt;http://www.heise.de/newsticker/meldung/Aegypten-Massenproteste-gehen-weiter-Update-1181273.html&lt;/a&gt; (sorry - much german text, but the video speaks for itself...)&lt;br /&gt;&lt;br /&gt;Ripe also has some static infos here: h&lt;a href="ttp://stat.ripe.net/egypt/"&gt;ttp://stat.ripe.net/egypt/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Egypt is currently coming back on the internet, see a video of the newly announced routes here:&lt;br /&gt;&lt;a href="http://www.heise.de/newsticker/meldung/Aegypten-ist-wieder-online-Update-1182195.html"&gt;http://www.heise.de/newsticker/meldung/Aegypten-ist-wieder-online-Update-1182195.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The situation in Egypt and the currently proposed "Internet-Kill-Switches" throughout Europe made me think. In the days before Trumpet Winsock i used to be a FIDO-Net-Point, polling twice per day via modem. Maybe it's time to wipe the dust of the old sportsters and see, if we can remember the basics of the AT Commandset and if the boxes are still working, even without a serial card with a 16550-FIFO.&lt;br /&gt;&lt;br /&gt;I wonder if FroDo2.02/FastEcho still run within a WinXP Commandshell. And if there is any local Fido-Node supporting Modem Calls left...&lt;br /&gt;&lt;br /&gt;For those willing to try: http://www.softeq.de/old/Download/download.html&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4373637962576936329?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4373637962576936329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4373637962576936329' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4373637962576936329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4373637962576936329'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2011/02/how-egypt-cut-itself-off-and-how-it-got.html' title='How Egypt cut itself off - and how it got back'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5125642201009730795</id><published>2011-02-02T02:59:00.000-08:00</published><updated>2011-02-02T02:59:19.378-08:00</updated><title type='text'>Why unsolicited reporting of vulnerabilities is a bad idea</title><content type='html'>Almost all young hackers come at some point of their hacker-life to the conclusion that finding and unsolicited reporting of vulnerabilities would be a fine idea:&lt;br /&gt;&lt;br /&gt;The owner of the website might be thankful or even hire the young hacker to check the site further or fix the vulnerabilities.&lt;br /&gt;&lt;br /&gt;Almost everyone in the IT-Sec-Business I know had this idea - and most of us learned the more or less hard way, that it is in fact a bad one. Not all potential customers are nice people. And be honest: Would you really hire someone who did an unsolicited hack of your infrastructure?&lt;br /&gt;&lt;br /&gt;Some "IT-Sec-Professionals" take longer to learn their lessons - I remembered my own experiences when I read about Chris Russo and his &lt;a href="http://grumomedia.com/plenty-of-fish-hacked-chris-russos-explains-how-he-did-it/"&gt;plentyoffish-hack&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;In my opinion both partys made mistakes and are leaving a really bad impression in this case. Maybe something to learn from, regardless on which side of the net you work?&lt;br /&gt;&lt;br /&gt;Some of the comments over at slashdot &lt;a href="http://slashdot.org/story/11/01/31/1856202/PlentyofFish-Hacked-Founder-Emails-Hackers-Mom"&gt;http://slashdot.org/story/11/01/31/1856202/PlentyofFish-Hacked-Founder-Emails-Hackers-Mom&lt;/a&gt; are worth reading.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5125642201009730795?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5125642201009730795/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5125642201009730795' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5125642201009730795'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5125642201009730795'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2011/02/why-unsolicited-reporting-of.html' title='Why unsolicited reporting of vulnerabilities is a bad idea'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-3084876560640193209</id><published>2010-12-16T02:54:00.000-08:00</published><updated>2010-12-16T02:55:53.528-08:00</updated><title type='text'>Passwordlists with John the Ripper</title><content type='html'>Creating Passwordlists with John the Ripper&lt;br /&gt;&lt;br /&gt;Whilst bringing hashcrack.com back up to work i had to create passwordlists for checking the scripts and the database. For those that don't know: John the Ripper does quite a good Job creating passwordlists out of the blue or mangling existing lists. The --stdout-parameters are somewhat tricky:&lt;br /&gt;&lt;br /&gt;john --i --stdout &lt;br /&gt;&lt;br /&gt;creates passwords up to the length configured in MaxLen (and MinLen) in john.conf.&lt;br /&gt;&lt;br /&gt;john --i --stdout:2 &lt;br /&gt;&lt;br /&gt;creates password up to the length of 2 chars.&lt;br /&gt;&lt;br /&gt;If it comes to working with existing password-lists according to the defined rules, you can use&lt;br /&gt;&lt;br /&gt;john --stdout --wordlist=file.txt &lt;br /&gt;&lt;br /&gt;to echo the plain wordlist.&lt;br /&gt;&lt;br /&gt;To mangle the list according to john's rules, you might use&lt;br /&gt;&lt;br /&gt;john --stdout --wordlist=file.txt --rules&lt;br /&gt;&lt;br /&gt;With a plain john-config this increases your amount of passwords by a factor of approximately 7, mangling "password" to stuff like Password, Password1, 1password etc.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-3084876560640193209?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/3084876560640193209/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=3084876560640193209' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3084876560640193209'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3084876560640193209'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2010/12/passwordlists-with-john-ripper.html' title='Passwordlists with John the Ripper'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-2920491784984701067</id><published>2009-10-20T00:59:00.000-07:00</published><updated>2009-10-20T01:05:13.812-07:00</updated><title type='text'>Rather useful E-Book</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_L52Vgx7c_mo/St1uf6xyJKI/AAAAAAAACB8/eNl8U-q6eao/s1600-h/security_analysis_and_data_visualization.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 134px;" src="http://1.bp.blogspot.com/_L52Vgx7c_mo/St1uf6xyJKI/AAAAAAAACB8/eNl8U-q6eao/s200/security_analysis_and_data_visualization.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5394589423292785826" /&gt;&lt;/a&gt;&lt;br /&gt;Those of you readers who occasionaly do pentests, vulnerability checks or network analyses might be interested in this E-Book. Unlike most other free ebooks there is no advertising stuff and not the 101th description of nmap-switches, but a bunch of (imho) genuine and up to date information about few not so well known tools and methods. 316 colored Sites packed with information. Definitely a recommendation.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://inverse.com.ng/sadv/Security_Analysis_and_Data_Visualization.pdf"&gt;http://inverse.com.ng/sadv/Security_Analysis_and_Data_Visualization.pdf&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;tom&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-2920491784984701067?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/2920491784984701067/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=2920491784984701067' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2920491784984701067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2920491784984701067'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/10/rather-useful-e-book.html' title='Rather useful E-Book'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_L52Vgx7c_mo/St1uf6xyJKI/AAAAAAAACB8/eNl8U-q6eao/s72-c/security_analysis_and_data_visualization.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-3126367941566954256</id><published>2009-10-13T06:28:00.000-07:00</published><updated>2009-10-13T06:32:46.013-07:00</updated><title type='text'>My hotmail-account is hacked. And now?</title><content type='html'>You're lost.&lt;div&gt;Not really. Microsoft set up a form to regain access to your inbox. I just tried to find it - took me (and I consider myself to be a routined google-hacker) about 5 minutes to find.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I doubt that a normal user would find it (btw: it's here: &lt;a href="https://support.live.com/eform.aspx?productKey=wlidvalidation&amp;amp;ct=eformcs&amp;amp;scrx=1"&gt;https://support.live.com/eform.aspx?productKey=wlidvalidation&amp;amp;ct=eformcs&amp;amp;scrx=1&lt;/a&gt;).&lt;/div&gt;&lt;div&gt;Now I'm curios what yahoo did to enable users to reclaim their inbox. Any hints or links? - Post a comment if you can help.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;tom&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-3126367941566954256?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/3126367941566954256/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=3126367941566954256' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3126367941566954256'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3126367941566954256'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/10/my-hotmail-account-is-hacked-and-now.html' title='My hotmail-account is hacked. And now?'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5730258783475828916</id><published>2009-10-13T02:09:00.000-07:00</published><updated>2009-10-13T02:12:35.944-07:00</updated><title type='text'>slashdotted</title><content type='html'>due to massive media-echo on our check of compromised accounts serversniff is currently almost non-avaiable. slashdotted. twittered. heised. media-ddos. bear with us, times will get better and serversniff will be respond again when the massive load (traffic is currently &gt;100 times over average) will decrease.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;tom&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5730258783475828916?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5730258783475828916/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5730258783475828916' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5730258783475828916'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5730258783475828916'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/10/slashdotted.html' title='slashdotted'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5670181569686688070</id><published>2009-10-10T15:02:00.000-07:00</published><updated>2009-10-10T15:10:44.068-07:00</updated><title type='text'>Check for compromised account</title><content type='html'>I hacked a quick check together to check a mailaccount if it is compromised. All you have to enter is the first part of the mailadress - no password, no complete mailadress.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://beta.serversniff.de/mailaccounts"&gt;http://beta.serversniff.de/mailaccounts&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;tom&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5670181569686688070?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5670181569686688070/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5670181569686688070' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5670181569686688070'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5670181569686688070'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/10/check-for-compromised-account.html' title='Check for compromised account'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6884008839627487619</id><published>2009-10-09T05:07:00.000-07:00</published><updated>2009-10-09T05:10:21.926-07:00</updated><title type='text'>Is your mailaccount compromised?</title><content type='html'>I got quite a few questions to look up peoples mailaccounts in the list of compromised accounts.&lt;div&gt;I created a lookup-interface for anybody to look up if a mailaccount belongs to the compromised accounts, i'll set this live on serversniff in a few hours.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;cheers,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;tom&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6884008839627487619?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6884008839627487619/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6884008839627487619' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6884008839627487619'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6884008839627487619'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/10/is-your-mailaccount-compromised.html' title='Is your mailaccount compromised?'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6864911911001090825</id><published>2009-10-08T14:43:00.000-07:00</published><updated>2009-10-08T16:13:35.283-07:00</updated><title type='text'>How security-teams deal with leaking passwords</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_L52Vgx7c_mo/Ss5l78duxvI/AAAAAAAACB0/9pPBIH53EqA/s1600-h/pw_hotmail.jpg"&gt;&lt;/a&gt;&lt;div style="text-align: left;"&gt;Finally: I have "The List" - I even posted where it is to find, for what I read was, that the security-teams of the major providers affected did their work properly deactivating all the affected accounts. &lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://windowslivewire.spaces.live.com/blog/cns!2F7EB29B42641D59!41528.entry?wa=wsignin1.0&amp;amp;sa=363915619"&gt;http://windowslivewire.spaces.live.com/blog/cns!2F7EB29B42641D59!41528.entry?wa=wsignin1.0&amp;amp;sa=363915619&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://news.bbc.co.uk/2/hi/technology/8292928.stm"&gt;http://news.bbc.co.uk/2/hi/technology/8292928.stm&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;This is currently, three days after (early October 9th) NOT true. I removed the links from the previous posting, even if it is not so hard to find the lists using your favorite searchengine.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;First of all, a bit of statistics:&lt;/div&gt;&lt;div&gt;The one BIG list is around 24.530 lines long, hosting a few double accounts. A quick check reveals (amongst many others):&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;592 gmail.com-accounts with password&lt;/li&gt;&lt;li&gt;22 googlemail.com-accounts with password&lt;/li&gt;&lt;li&gt;13.098 hotmail.com-accounts with password&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;~800 other hotmail-tld-accounts with password&lt;/li&gt;&lt;li&gt;477 msn-com-accounts with password&lt;/li&gt;&lt;li&gt;3.717 yahoo.com-accounts with password&lt;/li&gt;&lt;li&gt;971 aol.com-accounts with password&lt;/li&gt;&lt;li&gt;347 comcast.net-accounts with password&lt;/li&gt;&lt;li&gt;41 facebook-accounts with password&lt;/li&gt;&lt;li&gt;2 amazon-com accounts with password&lt;/li&gt;&lt;li&gt;6 ebay-accopunts with password&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;A phishing-scam is likely to be the source, lines like &lt;/div&gt;&lt;div&gt;Not Telling!&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;michelle!&lt;/div&gt;&lt;div&gt;indicate that at least a few victims were clever enough not to enter their real mailadress.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The bad guys obviously checked the at least some of the victims inboxes and extracted facebook, amazon, ebay and bulletinboard-stuff manually to put it on the list. This is very incomplete and only done for a handful of  the listed accouts.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Tonight I took some time to dig deeper, i couldn't resist to check a few accounts. I found the results quite interesting:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Google did a fine work. None of the gmail-accounts checked did work. And i checked quite a few.&lt;/div&gt;&lt;div&gt;Surprisingly Ebay did a fine work too. All checked ebay-accounts had either the password changed or the account locked.  This looks like this:&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_L52Vgx7c_mo/Ss5it_1Eg8I/AAAAAAAACBk/eNjPTIyfVbI/s1600-h/pw_ebay.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_L52Vgx7c_mo/Ss5it_1Eg8I/AAAAAAAACBk/eNjPTIyfVbI/s400/pw_ebay.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5390354346376725442" style="cursor: pointer; width: 400px; height: 287px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I checked further. Major media told that microsoft did suspend or otherwise protect the affected hotmail-accounts.&lt;/div&gt;&lt;div&gt;This is obviously not completely true, for i found a few of the hotmail-accounts still working, funny enough many of them swedish!&lt;/div&gt;&lt;div&gt;Hence whats to be found in the inbox of the poor guys:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_L52Vgx7c_mo/Ss5l78duxvI/AAAAAAAACB0/9pPBIH53EqA/s1600-h/pw_hotmail.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/_L52Vgx7c_mo/Ss5l78duxvI/AAAAAAAACB0/9pPBIH53EqA/s320/pw_hotmail.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5390357884526577394" style="float: left; margin-top: 0px; margin-right: 10px; margin-bottom: 10px; margin-left: 0px; cursor: pointer; width: 320px; height: 194px; " /&gt;&lt;/a&gt;A security-warning with account-suspension from facebook.com. Good guys, too. But ugly, if the warning is sent to a Mailaccount that is also compromised.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I got really disturbed when i checked the yahoo-accounts: A huge load of them is working.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Many of these InBoxes are stuffed with password-resets, security-hints or abuse-reports from other sites: Onlineshops, Bulletin-Boards, Web20-stuff. This leads to the conclusion that the accounts are circulating and actively exploited: Not only the mails, but also all other accounts depending on these inboxes. Password-Reset-Mails get sent there...&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Yahoooooo. Wakeup-Call. Any security or customer service-stuff left at your offices?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I censored the links in my earlier blogposting, for i realized that so many accounts still work.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;To sum it up:&lt;/div&gt;&lt;div&gt;&lt;div&gt;Some, even if not really affected, acted fast and complete: Ebay suspended the accounts. Facebook sent warnings.  Google seems to have fixed all accounts listed.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Security-guys over at Microsoft did a rather incomplete work, while the company pretends to have blocked all of the accounts listed.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;Yahoo seems to have done nothing. (Did anybody at yahoo do anything in the last 2 years??)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span"  style="color:#0000EE;"&gt;&lt;span class="Apple-style-span"  style="color:#000000;"&gt;Compliments go to google, facebook and ebay: I  admit that i don't like the whole trio, but they silently did a fine job where others failed.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Note: This data is only gathered by examining ONE of the two lists mentioned by the bbc-article.&lt;/div&gt;&lt;div style="text-align: left;"&gt;The second list has 10.030 lines and is also still publicly available. It hosts accountnames in alphanumeric order starting with A and B (ending with blan____13@hotmail.com:an_____ey) - this leads to the suggestion that there must be more HUGE lists containg accounts with C to Z.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Tom&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6864911911001090825?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6864911911001090825/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6864911911001090825' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6864911911001090825'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6864911911001090825'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/10/security-teams-and-their-work.html' title='How security-teams deal with leaking passwords'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_L52Vgx7c_mo/Ss5it_1Eg8I/AAAAAAAACBk/eNjPTIyfVbI/s72-c/pw_ebay.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6605344574434021079</id><published>2009-10-08T04:47:00.000-07:00</published><updated>2009-10-08T15:56:46.829-07:00</updated><title type='text'>List of passwords for Gmail, Hotmail &amp; co</title><content type='html'>As told in the previous posting: the passwordlists start to leak ... &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;~25.000 hotmail/gmail &amp;amp; others here: &lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;&lt;span class="Apple-style-span"  style="color:#FF6666;"&gt;self-censored&lt;/span&gt;&lt;/span&gt;&lt;censored&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Others here: &lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;&lt;span class="Apple-style-span"  style="color:#FF6666;"&gt;self-censored&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;censored&gt;&lt;/censored&gt;&lt;/div&gt;&lt;div&gt;&lt;censored&gt;&lt;/censored&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;More locations to be found up to your imagination.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This list mentioned here will disappear at the mentioned location and pop up elsewhere. Dissapear there and pop up somewhere else. The internet won't ever forget. Welcome, you arrived in modern times.&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;cheers,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;tom&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/censored&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6605344574434021079?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6605344574434021079/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6605344574434021079' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6605344574434021079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6605344574434021079'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/10/list-of-passwords-for-gmail-hotmail-co.html' title='List of passwords for Gmail, Hotmail &amp; co'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6349479954036629353</id><published>2009-10-08T02:09:00.000-07:00</published><updated>2009-10-08T02:33:39.078-07:00</updated><title type='text'>Passwords on the Web</title><content type='html'>Somebody tried to post some 10.000 mailaccounts with passwords to &lt;a href="http://pastebin.com"&gt;pastebin.com&lt;/a&gt;. Bad idea, the post was truncated after ~ 10.000 lines, making the alphanumerically sorted list ending with B***.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Paul Dixon, aka Lordelph, the owner of pastebin.com (great idea for a website, btw) posted a blogentry about this here: &lt;a href="http://blog.dixo.net/2009/10/07/pastebin-com-and-password-lists/"&gt;http://blog.dixo.net/2009/10/07/pastebin-com-and-password-lists&lt;/a&gt;, you might get the rest of the story out of major media coverage.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;While i really like the pastebin-concept i also like making fun of users contents: Doing a google-search for mailaccounts or password does reveal quite a few posts hosting passwords of different origins: There is are bulletin-boards complete userdatabase-dump, published by hacker-kids dissing other hacker-kids. There are gmail-accounts with passwords stored in scripts using the account for automatically sending emails or attachments.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I found a working facebook-account in another script.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;And finally i found that google is not only indexing, but also caching the pastebin-entrys. So if you tag your pastebin-text with a lifetime of one day, or if you delete your pastebin-entry it is rather likely that searchengines have already indexed and cached your entry, thus totally subverting the TTL-concept of pastebin.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Seems like pastebin.com and its sisterprojects in other tlds (Thanks Paul for making the source available!) would be a nice place to spend the next procrastrinated afternoon.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Back to work now.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;tom&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6349479954036629353?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6349479954036629353/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6349479954036629353' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6349479954036629353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6349479954036629353'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/10/passwords-on-web.html' title='Passwords on the Web'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-7453350597200939198</id><published>2009-09-14T14:26:00.000-07:00</published><updated>2009-09-14T14:28:26.130-07:00</updated><title type='text'>Perltweak: fast and easy matching text with index()</title><content type='html'>&lt;div&gt;The best tool in Perl for finding exact strings in another string (scalar) is not the match operator m//, but the much faster index() function. Use it whenever the text you are looking for is straight text. Whenever you don't need additional metanotation like "at the beginning of the string" or "any character," use index():&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;$index = index($T, $P); # T is the text, P is the pattern.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The returned $index is the index of the start of the first occurrence of $p in the $T. The first character of $T is at index 0. If the $P cannot be found, -1 is returned. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you want to skip early occurrences of $P and start later in $T, use the three-argument version:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;$index = index($T, $P, $start_index);&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you need to find the last occurrence of the $p, use rindex(), which begins at the end of the string and proceeds leftward. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you do need to specify information beyond the text itself, use regular expressions.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Why do I tell you this?&lt;/div&gt;&lt;div&gt;Large parts of Serversniff use perl for its backend - be it the site-analyzer or the domain-database. Like most of us I never really learned perl - i was thrown right into a project using eperl and and a bulletin-board-system based on perl and had to maintain and evolve the projects code out nothing. While have used I use perl since then for more than 10 years now I still do find simple tweaks making my perl-life easier almost every week.&lt;/div&gt;&lt;div&gt;Thanks to O'Reilly's "Mastering Algorithms with Perl" for this one.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;tom&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-7453350597200939198?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/7453350597200939198/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=7453350597200939198' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7453350597200939198'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7453350597200939198'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/09/perltweak-fast-and-easy-matching-text.html' title='Perltweak: fast and easy matching text with index()'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-7998813973414757073</id><published>2009-08-28T08:20:00.000-07:00</published><updated>2010-12-16T04:09:36.325-08:00</updated><title type='text'>Extracting Files from a tcpdump</title><content type='html'>&lt;div&gt;I'm working as consultant, pentester and sometimes still as second-level-security guy for a rather huge company.&lt;/div&gt;&lt;div&gt;Occasionally I have to analyze tcp-streams, and occasionally I came to a point where i had to extract files out of huge dumps. What I found during my last research about a year ago was not really usable - i hacked together a few lines of perl to extract exactly what i wanted - this didn't deliver exact files, but was enough to help me solve a problem.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jim Clausing, one of the more practical guys over at ISC described the same problem recently and asked the readers of the ISC-Blog for software that is able to extract files from pcap-dump. People came out with a load of promising solutions:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;* NetworkMiner &lt;a href="http://networkminer.sourceforge.net"&gt;http://networkminer.sourceforge.ne&lt;/a&gt;/&lt;/div&gt;&lt;div&gt;* tcpxtract &lt;a href="http://tcpxtract.sourceforge.net/"&gt;http://tcpxtract.sourceforge.net/&lt;/a&gt;)&lt;/div&gt;&lt;div&gt;* bro &lt;a href="http://www.bro-ids.org/"&gt;http://www.bro-ids.org/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;* tcpflow &lt;a href="http://www.circlemud.org/~jelson/software/tcpflow/"&gt;http://www.circlemud.org/~jelson/software/tcpflow/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;* foremost &lt;a href="http://foremost.sourceforge.net/"&gt;http://foremost.sourceforge.net/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;* dsniff &lt;a href="http://www.monkey.org/~dugsong/dsniff/"&gt;http://www.monkey.org/~dugsong/dsniff/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;* Chaosreader &lt;a href="http://chaosreader.sourceforge.net/"&gt;http://chaosreader.sourceforge.net/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;* pyflag &lt;a href="http://www.pyflag.net/cgi-bin/moin.cgi"&gt;http://www.pyflag.net/cgi-bin/moin.cgi&lt;/a&gt;&lt;/div&gt;&lt;div&gt;* tcptrace &lt;a href="http://www.tcptrace.org/"&gt;http://www.tcptrace.org/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;* tcpick &lt;a href="http://tcpick.sourceforge.net/"&gt;http://tcpick.sourceforge.net/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;* xtract.py &lt;a href="http://www.malforge.com/npeid/xtract.py"&gt;http://www.malforge.com/npeid/xtract.py&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Not all of them might do exactly what you want - but this is defintely the best overview on pcap-file-extractors I ever came across.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Tom&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-7998813973414757073?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/7998813973414757073/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=7998813973414757073' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7998813973414757073'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7998813973414757073'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/08/extracting-files-from-tcpdump.html' title='Extracting Files from a tcpdump'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6671687870932874963</id><published>2009-08-27T08:20:00.000-07:00</published><updated>2009-08-27T08:21:31.346-07:00</updated><title type='text'>Network-Cheatsheets</title><content type='html'>&lt;div&gt;I'm on my way to become a friend of cheatsheets. A nice suite of network-related sheets is here: http://packetlife.net/cheatsheets/&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Tom&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6671687870932874963?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6671687870932874963/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6671687870932874963' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6671687870932874963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6671687870932874963'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/08/network-cheatsheets.html' title='Network-Cheatsheets'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-3521428580498077386</id><published>2009-08-04T02:20:00.000-07:00</published><updated>2009-08-04T02:42:39.043-07:00</updated><title type='text'>How to find Elite-Security-People</title><content type='html'>Ever wondered where to find those real elite-security-people?&lt;div&gt;&lt;br /&gt;&lt;div&gt;Maybe look for those who did their cissp-certification years ago: &lt;a href="http://attrition.org/misc/ee/20050426-cissp.txt"&gt;http://attrition.org/misc/ee/20050426-cissp.txt&lt;/a&gt;&lt;/div&gt;&lt;div&gt;~4.700 Names, employers, functions, addresses etc pp. of all those early CISSPs.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Real elite? - look for those who have an account at osvdb.org - especially check their id - the smaller the ID, the more 4337 they are. Get the (huge!) db here: &lt;a href="https://www.metricscenter.net/amCharts/osvdb-metrics/raw/osvdb-csv.latest"&gt;https://www.metricscenter.net/amCharts/osvdb-metrics/raw/osvdb-csv.latest&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Around 5.000 names here - but it reads like a who's who of those it-security-swamp. Also look here if you look for a human security-contact at some soft- or hardware-company - you find quite a few in those database.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_L52Vgx7c_mo/SngA147_QGI/AAAAAAAAB9k/i8VCaGl_dew/s1600-h/osvdb-data2.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 243px;" src="http://1.bp.blogspot.com/_L52Vgx7c_mo/SngA147_QGI/AAAAAAAAB9k/i8VCaGl_dew/s400/osvdb-data2.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5366039881829007458" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_L52Vgx7c_mo/SngACW2V85I/AAAAAAAAB9c/PvieovEygo8/s1600-h/osvdb-data.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 243px;" src="http://1.bp.blogspot.com/_L52Vgx7c_mo/SngACW2V85I/AAAAAAAAB9c/PvieovEygo8/s400/osvdb-data.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5366038996505195410" /&gt;&lt;/a&gt;&lt;br /&gt;Ever wondered how to find elite-security-guys, the leading edge security professionals?&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You know other security-pro-listings? - Write a comment.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="  line-height: 23px; font-family:georgia, arial, sans-serif;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;"The reason people search for themselves is that they're curious about what other people see when they search for their name," says Joe Kraus, Google's director of product management. (&lt;/span&gt;&lt;a href="http://www.time.com/time/business/article/0,8599,1893965,00.html"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;)&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:georgia, arial, sans-serif;"&gt;&lt;span class="Apple-style-span" style=" line-height: 23px;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:georgia, arial, sans-serif;font-size:130%;"&gt;&lt;span class="Apple-style-span"  style=" line-height: 23px;font-size:15px;"&gt;&lt;span class="Apple-style-span"   style="  line-height: normal; font-family:Georgia, serif;font-size:16px;"&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Funny, those public databases.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;tom&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-3521428580498077386?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/3521428580498077386/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=3521428580498077386' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3521428580498077386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3521428580498077386'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/08/how-to-find-elite-security-people.html' title='How to find Elite-Security-People'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_L52Vgx7c_mo/SngA147_QGI/AAAAAAAAB9k/i8VCaGl_dew/s72-c/osvdb-data2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4099616823194224904</id><published>2009-08-02T06:00:00.000-07:00</published><updated>2009-08-02T06:49:15.627-07:00</updated><title type='text'>How to check a site for E-Mail authentication</title><content type='html'>&lt;div&gt;Working as a pentester, i often check webshops and well-established brands. I expect them to have some kind of &lt;a href="http://en.wikipedia.org/wiki/E-mail_authentication"&gt;E-Mail-Authentication&lt;/a&gt; in place - be it Domain-Keys or an SPF-Record.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Not because I want to make the world a spam-free-place - I believe mail-authentication a worthwile measure against phishing-scams abusing a company-brand. I a company has mail-authentication like SPF in place, almost all spam-filters are able to and will separate legitimate company-mail and newsletters from phishing-scams, that are usually sent via untrusted ip's or without proper DKIM.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I was recently asked how to check this in a realworld-scenario. SPF is fairly easy - just get TXT and SPF-record for the domain in question. DIG is your friend, or just use serversniff's dns-report.&lt;/div&gt;&lt;div&gt;DKIM is more complicated: You need a realworld mail from the customer - be it a newsletter or an errormessage or anything else.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;But how to verify SPF-Records and Domain-Key-Sigs?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I found it the easiest to use &lt;a href="http://mail.google.com/"&gt;googlemail &lt;/a&gt;for this task - open an email in question, press the small arrow up right (next to the upper "reply") and select "Show Original". GMail will show you the complete Mail-Headers then, including validated SPF- and DKIM-Records. These might look like this:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_L52Vgx7c_mo/SnWOTa7NmZI/AAAAAAAAB9U/2TCJ_dY1Ffs/s1600-h/spf-true.png"&gt;&lt;img style="cursor: pointer; width: 400px; height: 38px;" src="http://2.bp.blogspot.com/_L52Vgx7c_mo/SnWOTa7NmZI/AAAAAAAAB9U/2TCJ_dY1Ffs/s400/spf-true.png" alt="" id="BLOGGER_PHOTO_ID_5365350995378149778" border="0" /&gt;&lt;/a&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_L52Vgx7c_mo/SnWOTa7NmZI/AAAAAAAAB9U/2TCJ_dY1Ffs/s1600-h/spf-true.png"&gt;&lt;/a&gt;SPF pass: Google verified an SPF-Record for this mail.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWONiVu4bI/AAAAAAAAB9M/n51YJN7oVn0/s1600-h/spf-neutral.png"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWONiVu4bI/AAAAAAAAB9M/n51YJN7oVn0/s1600-h/spf-neutral.png" style="text-decoration: none;"&gt;&lt;img style="cursor: pointer; width: 400px; height: 35px;" src="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWONiVu4bI/AAAAAAAAB9M/n51YJN7oVn0/s400/spf-neutral.png" alt="" id="BLOGGER_PHOTO_ID_5365350894289215922" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;SPF neutral: Google can't verify an SPF-Record for this mail.&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWONiVu4bI/AAAAAAAAB9M/n51YJN7oVn0/s1600-h/spf-neutral.png" style="text-decoration: none;"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWONgzWiFI/AAAAAAAAB9E/4Opu67YVlwI/s1600-h/spf-bestguess.png"&gt;&lt;img style="cursor: pointer; width: 400px; height: 33px;" src="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWONgzWiFI/AAAAAAAAB9E/4Opu67YVlwI/s400/spf-bestguess.png" alt="" id="BLOGGER_PHOTO_ID_5365350893876578386" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;SPF pass by "best guess": There is no SPF-Record, but google was able to verify that the originating machine belongs to the originating domain.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWONgzWiFI/AAAAAAAAB9E/4Opu67YVlwI/s1600-h/spf-bestguess.png"&gt;&lt;/a&gt;And now for different DKIM-Headers:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWONX6TxPI/AAAAAAAAB88/LF30fm_1X54/s1600-h/dkim-test.png"&gt;&lt;img style="cursor: pointer; width: 400px; height: 73px;" src="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWONX6TxPI/AAAAAAAAB88/LF30fm_1X54/s400/dkim-test.png" alt="" id="BLOGGER_PHOTO_ID_5365350891489838322" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWONX6TxPI/AAAAAAAAB88/LF30fm_1X54/s1600-h/dkim-test.png"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_L52Vgx7c_mo/SnWONOnj6vI/AAAAAAAAB80/G3zlQl5kKFw/s1600-h/dkeysig-pass.png"&gt;&lt;img style="cursor: pointer; width: 400px; height: 224px;" src="http://3.bp.blogspot.com/_L52Vgx7c_mo/SnWONOnj6vI/AAAAAAAAB80/G3zlQl5kKFw/s400/dkeysig-pass.png" alt="" id="BLOGGER_PHOTO_ID_5365350888995285746" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_L52Vgx7c_mo/SnWONOnj6vI/AAAAAAAAB80/G3zlQl5kKFw/s1600-h/dkeysig-pass.png"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWOM7C1qbI/AAAAAAAAB8s/TFl5E4kYDvs/s1600-h/dkeysig.png"&gt;&lt;img style="cursor: pointer; width: 400px; height: 192px;" src="http://4.bp.blogspot.com/_L52Vgx7c_mo/SnWOM7C1qbI/AAAAAAAAB8s/TFl5E4kYDvs/s400/dkeysig.png" alt="" id="BLOGGER_PHOTO_ID_5365350883740985778" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I'm still not sure what google's spamfilter means with these headers, but it seems to be fairly accurate with even detecting a domain in "test-mode".&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I'd be happy to hear from any other solution for verifying Mail-Authentication - write a comment or drop me a mail to tom@serversniff.net.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;tom&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4099616823194224904?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4099616823194224904/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4099616823194224904' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4099616823194224904'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4099616823194224904'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/08/how-to-check-site-for-e-mail.html' title='How to check a site for E-Mail authentication'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_L52Vgx7c_mo/SnWOTa7NmZI/AAAAAAAAB9U/2TCJ_dY1Ffs/s72-c/spf-true.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-3714492955121546728</id><published>2009-07-30T01:09:00.000-07:00</published><updated>2009-07-30T01:21:04.864-07:00</updated><title type='text'>DNS-Redirects</title><content type='html'>Nobody likes DNS-Redirects. Even IETF said recently (http://www.icann.org/en/committees/security/sac041.pdf):&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;The redirection and synthesizing of DNS responses by TLDs poses a clear and significant&lt;br /&gt;danger to the security and stability of the domain name system. The consequences of&lt;br /&gt;synthesized DNS responses range from erosion of trust relationships to the creation of&lt;br /&gt;new opportunities for malicious attacks, without the ability of the affected party(ies) to mitigate these problems.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Serversniff stumbles over this shit, too. Currently the TLDs .mobi, .jobs and .asia use this - they answer every dns-request with an ip, even if a domain won't exist.&lt;br /&gt;&lt;br /&gt;They don't dare to present a  http-landing-page (like e.g. t-online.de does) - but in fact they resolve every query to an IP, misleading quite a few of serversniff's scripts. We're workin to fix this - but this takes time, for we need to fix every ip-lookup-routine.&lt;br /&gt;&lt;br /&gt;totally useless shit.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-3714492955121546728?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/3714492955121546728/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=3714492955121546728' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3714492955121546728'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3714492955121546728'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/dns-redirects.html' title='DNS-Redirects'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5958052899939209383</id><published>2009-07-21T03:17:00.000-07:00</published><updated>2009-07-22T04:28:32.323-07:00</updated><title type='text'>to be unique or not</title><content type='html'>Way back in 2004 I created serversniff &lt;br /&gt;* to help myself managing and doing my pentests&lt;br /&gt;* to help others checking their sites&lt;br /&gt;* to help myself understanding stuff. cryptology, protocols etc&lt;br /&gt;* to help others understanding stuff. cryptology, protocols etc&lt;br /&gt;&lt;br /&gt;and finally, to create something unique and new.&lt;br /&gt;&lt;br /&gt;Why should i reinvent the wheel, why invest time to offer services that others already offer for free?&lt;br /&gt;&lt;br /&gt;I'm a bit puzzled about the occasional inquirys to "donate" sourcecode for somebody's public site. People are not ashamed to ask for ready-to-run code to implement serversniff's functions on their sites. And no, it's not just one or to mails coming in with such requests. Anyway, i still see serversniff as more or less academic, and primary educational stuff. I give out advice, concepts and snippets of code as long as the request is friendly and nice.&lt;br /&gt;&lt;br /&gt;But still: It wouldn't come to my mind to ask anybody to donate code of his website so that i can implement it in any of my sites.  I'm still eager to learn necessary stuff before i start coding php-scripts, i'm still committed to create unique services that aren't to be found anywhere else in this flavour or quality.&lt;br /&gt;&lt;br /&gt;While serversniff's script use crappy php-code and the server itself is unstable like a one-legged stool i'd never try to release a service unless i'm convinced that it has something unique or does its job better than all other sites.&lt;br /&gt;&lt;br /&gt;Maybe there's just somehting wrong with my mind.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5958052899939209383?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5958052899939209383/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5958052899939209383' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5958052899939209383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5958052899939209383'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/to-be-unique-or-not.html' title='to be unique or not'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-2851003918338126234</id><published>2009-07-21T03:03:00.000-07:00</published><updated>2009-07-21T03:08:48.670-07:00</updated><title type='text'>Serversniff on Twitter</title><content type='html'>We're implementing and fixing quite a lot on what we call "Serversniff 2.0", currently hosted on &lt;a href="http://webwiki.de"&gt;http://webwiki.de&lt;/a&gt;. Since it's plain to much to blog it all in detail, we decided to put the updates and fixes on a twitter-feed hosted at &lt;a href="http://twitter.com/serversniff"&gt;http://twitter.com/serversniff&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Follow there if you want to stay tuned about news and fixes concerning serversniff.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-2851003918338126234?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/2851003918338126234/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=2851003918338126234' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2851003918338126234'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2851003918338126234'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/serversniff-on-twitter.html' title='Serversniff on Twitter'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5633740738276110888</id><published>2009-07-15T03:00:00.001-07:00</published><updated>2009-07-15T03:00:27.385-07:00</updated><title type='text'>Site-Analyzer: Added Page-Rank detection - http://webwiki.de/taglists/pagerank-8</title><content type='html'>Added a page-rank-detection for sites. &lt;br /&gt;If a site has a page-rank, it is displayed at site-analyzer. &lt;br /&gt;Page-Ranks of 5 and higher get tagged, so we'll build up a list of &lt;br /&gt;sites with high-pageranks. Since the feature is brand new, there is &lt;br /&gt;not really much in there right now - but you might try to list all &lt;br /&gt;sites having a Google-Page-Rank of 8 here: &lt;br /&gt;&lt;a href="http://webwiki.de/taglists/pagerank-8"&gt;http://webwiki.de/taglists/pagerank-8&lt;/a&gt; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;tom        &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5633740738276110888?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5633740738276110888/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5633740738276110888' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5633740738276110888'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5633740738276110888'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/site-analyzer-added-page-rank-detection.html' title='Site-Analyzer: Added Page-Rank detection - http://webwiki.de/taglists/pagerank-8'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-2773053310671596831</id><published>2009-07-14T14:43:00.001-07:00</published><updated>2009-07-14T14:43:44.872-07:00</updated><title type='text'>New links in Site-Analyzer</title><content type='html'>I just implemented links to Symantec/Norton's SafeWeb-Analyzer &lt;br /&gt;(&lt;a href="https://safeweb.norton.com/)"&gt;https://safeweb.norton.com/)&lt;/a&gt;, McAfee's SiteAdvisor &lt;br /&gt;(&lt;a href="https://www.siteadvisor.com/)"&gt;https://www.siteadvisor.com/)&lt;/a&gt; and Googles SafeBrowsing &lt;br /&gt;(&lt;a href="http://google.com/safebrowsing/diagnostic?site=www.bayern.de"&gt;http://google.com/safebrowsing/diagnostic?site=www.bayern.de&lt;/a&gt;). &lt;br /&gt;&amp;nbsp;&lt;br /&gt;If you're in doubt wether to trust a site you might check it first on &lt;br /&gt;these sites. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;Do you know any other relevant malware-checks? &lt;br /&gt;&amp;nbsp;&lt;br /&gt;Comment here or drop me a mail: &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="mailto:tom@serversniff.net"&gt;tom@serversniff.net&lt;/a&gt;        &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-2773053310671596831?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/2773053310671596831/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=2773053310671596831' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2773053310671596831'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2773053310671596831'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/new-links-in-site-analyzer.html' title='New links in Site-Analyzer'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-1205420041654325266</id><published>2009-07-14T14:28:00.001-07:00</published><updated>2009-07-14T14:28:09.358-07:00</updated><title type='text'>experiment: switched from http://thumbshots.com to  http://shrinktheweb.com</title><content type='html'>we switched the site-image-hosting from thumbshots.com to &lt;br /&gt;&lt;a href="http://shrinktheweb.com"&gt;http://shrinktheweb.com&lt;/a&gt; &lt;br /&gt;pictures are bigger and it seems faster. shrinktheweb.com has tighter &lt;br /&gt;limits for the free version - we'll see if this is enough. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;tom        &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-1205420041654325266?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/1205420041654325266/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=1205420041654325266' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/1205420041654325266'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/1205420041654325266'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/experiment-switched-from.html' title='experiment: switched from http://thumbshots.com to  http://shrinktheweb.com'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-7048732611090286082</id><published>2009-07-14T09:16:00.001-07:00</published><updated>2009-07-14T09:16:44.570-07:00</updated><title type='text'>added wp-post-ratings and wp-quotes-collection</title><content type='html'>Added support for random Wordpress-Plugins.        &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-7048732611090286082?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/7048732611090286082/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=7048732611090286082' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7048732611090286082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7048732611090286082'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/added-wp-post-ratings-and-wp-quotes.html' title='added wp-post-ratings and wp-quotes-collection'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6563535049011604363</id><published>2009-07-14T09:04:00.001-07:00</published><updated>2009-07-14T09:04:28.248-07:00</updated><title type='text'>bugfix: fixed site-analyzer-api-output with multiple site-analyzers</title><content type='html'>i can't imagine why anybody wants to use more than one tracking-pixel.... &lt;br /&gt;anyway, i fixed the api-output as well.        &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6563535049011604363?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6563535049011604363/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6563535049011604363' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6563535049011604363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6563535049011604363'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/bugfix-fixed-site-analyzer-api-output.html' title='bugfix: fixed site-analyzer-api-output with multiple site-analyzers'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-8208617772422694408</id><published>2009-07-14T08:56:00.001-07:00</published><updated>2009-07-14T08:56:20.118-07:00</updated><title type='text'>implemented statcount.com-tracker. poc: http://webwiki.de/i/ik/ikb/www.ikbenanders.nl/htmlreport</title><content type='html'>Implemented the &lt;a href="http://statcount.com"&gt;http://statcount.com&lt;/a&gt; tracking-script. &lt;br /&gt;Example here: &lt;a href="http://webwiki.de/i/ik/ikb/www.ikbenanders.nl/htmlreport"&gt;http://webwiki.de/i/ik/ikb/www.ikbenanders.nl/htmlreport&lt;/a&gt; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;tom        &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-8208617772422694408?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/8208617772422694408/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=8208617772422694408' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8208617772422694408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8208617772422694408'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/implemented-statcountcom-tracker-poc.html' title='implemented statcount.com-tracker. poc: http://webwiki.de/i/ik/ikb/www.ikbenanders.nl/htmlreport'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-8863585814643378964</id><published>2009-07-14T08:54:00.001-07:00</published><updated>2009-07-14T08:54:21.898-07:00</updated><title type='text'>fixed site-analyzer-bug (mutliple site-statistics)</title><content type='html'>Identified and fixed a site-analyzer bug that prevented multiple &lt;br /&gt;site-statistics to be parsed when google-analytics was involved. &lt;br /&gt;Multiple-Stats are working now. Example (google-analytics AND &lt;br /&gt;statcount.com) here: &lt;a href="http://webwiki.de/analyze/www.simonwakeman.com"&gt;http://webwiki.de/analyze/www.simonwakeman.com&lt;/a&gt; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;Cheers, &lt;br /&gt;&amp;nbsp;&lt;br /&gt;tom        &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-8863585814643378964?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/8863585814643378964/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=8863585814643378964' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8863585814643378964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8863585814643378964'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/fixed-site-analyzer-bug-mutliple-site.html' title='fixed site-analyzer-bug (mutliple site-statistics)'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-2062278298633631782</id><published>2009-07-14T06:49:00.001-07:00</published><updated>2009-07-14T06:49:29.753-07:00</updated><title type='text'>todo: add statcounter at site-analyzer - http://www.statcounter.com</title><content type='html'>example-site using statcounter (&lt;a href="http://www.statcounter.com"&gt;www.statcounter.com&lt;/a&gt;, my.statcounter.com): &lt;br /&gt;&lt;a href="http://www.ikbenanders.nl"&gt;http://www.ikbenanders.nl&lt;/a&gt;        &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-2062278298633631782?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/2062278298633631782/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=2062278298633631782' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2062278298633631782'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2062278298633631782'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/todo-add-statcounter-at-site-analyzer.html' title='todo: add statcounter at site-analyzer - http://www.statcounter.com'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-1978687803944725599</id><published>2009-07-14T01:02:00.001-07:00</published><updated>2009-07-14T01:02:56.585-07:00</updated><title type='text'>Nice tools: http://www.gwebtools.com/</title><content type='html'>Nice Tools on gwebtools.com. Not really much unique stuff, and not &lt;br /&gt;really "Amazing tools to increase your Network and Website &lt;br /&gt;performance", but still fast and with some nice ideas. &lt;br /&gt;Personally i don't like totally anonymous sites like gwebtools without &lt;br /&gt;any name on it - but the author might have his/her reasons. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://webwiki.de/g/gw/gwe/www.gwebtools.com/htmlreport"&gt;http://webwiki.de/g/gw/gwe/www.gwebtools.com/htmlreport&lt;/a&gt; &lt;br /&gt;&lt;a href="http://webwiki.de/b/bl/blo/blog.gwebtools.com/htmlreport"&gt;http://webwiki.de/b/bl/blo/blog.gwebtools.com/htmlreport&lt;/a&gt; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;Be sure to check out the hosts-on-ns-function. It supports only &lt;br /&gt;.com/.net, but it's using the .com/.net-zonefiles and is therefore &lt;br /&gt;much more complete than Serversniffs NS-Catalog at &lt;br /&gt;&lt;a href="http://serversniff.net/nscatalog"&gt;http://serversniff.net/nscatalog&lt;/a&gt; when it comes to these two tlds. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;tom        &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-1978687803944725599?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/1978687803944725599/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=1978687803944725599' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/1978687803944725599'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/1978687803944725599'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/nice-tools-httpwwwgwebtoolscom.html' title='Nice tools: http://www.gwebtools.com/'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6516197244927830034</id><published>2009-07-12T05:35:00.000-07:00</published><updated>2009-07-12T05:39:29.728-07:00</updated><title type='text'>We're getting faster</title><content type='html'>We are into tuning and speeding up Serversniff 2.0. &lt;br /&gt;* The &lt;a href="http://webwiki.de/website-report"&gt;SiteReport&lt;/a&gt; got a new section: Other Hosts on this ip&lt;br /&gt;* The &lt;a href="http://webwiki.de/domain-report"&gt;DomainReport&lt;/a&gt; is half-optimized and now much faster&lt;br /&gt;* We changed the directory-structure to waste less space and make it easier for you to see what information is already there about a host.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6516197244927830034?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6516197244927830034/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6516197244927830034' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6516197244927830034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6516197244927830034'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/were-getting-faster.html' title='We&apos;re getting faster'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-8257246309505042846</id><published>2009-07-07T04:26:00.000-07:00</published><updated>2009-07-07T04:26:14.492-07:00</updated><title type='text'>Crypt-Functions are back</title><content type='html'>Some might have noticed: The Crypto-Functions didn't work for some time.&lt;br /&gt;I'm happy to announce that most hashes and checksums are back online at our new beta-site:&lt;br /&gt;&lt;br /&gt;&lt;a href='http://4.bp.blogspot.com/_L52Vgx7c_mo/SlMw1Z0Ro2I/AAAAAAAABzw/nXw0I0c0VgI/s1600-h/hash_strings+%5BSERVERSNIFF.net%5D+-+Google+Chrome+07.07.2009+130831.jpg'&gt;&lt;img src='http://4.bp.blogspot.com/_L52Vgx7c_mo/SlMw1Z0Ro2I/AAAAAAAABzw/nXw0I0c0VgI/s400/hash_strings+%5BSERVERSNIFF.net%5D+-+Google+Chrome+07.07.2009+130831.jpg' border='0' alt='' /&gt;&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;Some checksums are still missing - bear with us, we will expand functionality there soon. Both checksums and hashes are faster, for we switched the implementation from &lt;a href="http://www.jonelo.de/"&gt;jonelos &lt;/a&gt; great java-application &lt;a href="http://www.jonelo.de/java/jacksum/"&gt;jacksum&lt;/a&gt; to a binary implementation eating far less ram and cpu-power.&lt;br /&gt;&lt;br /&gt;Currently the &lt;a href="http://csrc.nist.gov/index.html"&gt;NIST&lt;/a&gt;-Competition for a new &lt;a href="http://csrc.nist.gov/groups/ST/hash/index.html"&gt;SHA3-Algorithm&lt;/a&gt; is in a hot phase, there are several candidates pending. We implemented two of them, &lt;a href="http://en.wikipedia.org/wiki/Skein_Hash_Function"&gt;SKEIN &lt;/a&gt;and &lt;a href="http://en.wikipedia.org/wiki/MD6"&gt;MD6&lt;/a&gt; (in fact: just one, for md6 is already withdrawn from the competition) in Serversniff's Hash Calculator and will implement the other candiates soon.&lt;br /&gt;&lt;br /&gt;If you want to check out what an MD6 Hash looks like, check our &lt;a href="http://serversniff.net/crypt-hash"&gt;Online Hash Calculator&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;tom&lt;div style='clear:both; text-align:NONE'&gt;&lt;a href='http://picasa.google.com/blogger/' target='ext'&gt;&lt;img src='http://photos1.blogger.com/pbp.gif' alt='Posted by Picasa' style='border: 0px none ; padding: 0px; background: transparent none repeat scroll 0% 50%; -moz-background-clip: initial; -moz-background-origin: initial; -moz-background-inline-policy: initial;' align='middle' border='0' /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-8257246309505042846?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/8257246309505042846/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=8257246309505042846' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8257246309505042846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8257246309505042846'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/07/crypt-functions-are-back.html' title='Crypt-Functions are back'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_L52Vgx7c_mo/SlMw1Z0Ro2I/AAAAAAAABzw/nXw0I0c0VgI/s72-c/hash_strings+%5BSERVERSNIFF.net%5D+-+Google+Chrome+07.07.2009+130831.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-7105306679529364936</id><published>2009-02-27T05:41:00.000-08:00</published><updated>2009-02-27T05:45:13.476-08:00</updated><title type='text'>Serversniff 2.0</title><content type='html'>After serveral tries: Serversniff 2.0 is on its way. As we believe it is better than Serversniff.net as we know it, we put the beta online: We will add functionality as we build it. Check it out: &lt;a href="http://dw.serversniff.de/start"&gt;http://dw.serversniff.de/start&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-7105306679529364936?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/7105306679529364936/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=7105306679529364936' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7105306679529364936'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7105306679529364936'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2009/02/serversniff-20.html' title='Serversniff 2.0'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-3915488941534297076</id><published>2008-10-15T14:47:00.000-07:00</published><updated>2008-10-15T14:49:46.079-07:00</updated><title type='text'>another dead day</title><content type='html'>somewhere on the raid-array something crashed - two disks went offline, don't know why. cables? mice? no clue.&lt;br /&gt;took a few hours until i found the time to fix this and import the old config again.&lt;br /&gt;&lt;br /&gt;stuff's up and running again since about an hour.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-3915488941534297076?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/3915488941534297076/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=3915488941534297076' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3915488941534297076'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3915488941534297076'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/10/another-dead-day.html' title='another dead day'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6954835834928357273</id><published>2008-09-04T02:24:00.000-07:00</published><updated>2008-09-04T03:04:28.843-07:00</updated><title type='text'>Answer from PriceWaterhouseCoopers</title><content type='html'>I sent an EMail to PwC asking about my data and my account that may have leaked from their career-site. I wonder if only the login and password leaked, or if all my personal data, cv etc leaked as well. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The answer i got from PwC (sorry again: german only) speaks for itself:&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="border-collapse: collapse;   font-family:arial;font-size:13px;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;Sehr geehrter Herr Springer,&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;vielen Dank für Ihre Anfrage. Wir werden Ihnen in Kürze Informationen zur Verfügung stellen können und Sie umgehend unterrichten. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;Bis dahin bitten wir Sie, das Passwort,&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size:85%;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:85%;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;das Sie für die Jobdatenbank bei PwC benutzt haben, umgehend zu ändern, um einem potentiellen Missbrauch von Daten vorzubeugen. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;Wir danken für Ihr Verständnis.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-family:'courier new';"&gt;Mit freundlichen Grüßen&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;  "&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;-------&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="border-collapse: collapse;  font-family:arial;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;tom&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;  "&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;Update: finally they published a press-release:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="border-collapse: collapse;   font-style: italic;font-family:'courier new';"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;&lt;a href="http://www.presseportal.de/pm/8664/1258775/pwc_pricewaterhousecoopers"&gt; &lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="border-collapse: separate;  font-style: normal; line-height: 15px; font-family:Arial;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;&lt;a href="http://www.presseportal.de/pm/8664/1258775/pwc_pricewaterhousecoopers"&gt;http://www.presseportal.de/pm/8664/1258775/pwc_pricewaterhousecoopers &lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6954835834928357273?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6954835834928357273/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6954835834928357273' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6954835834928357273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6954835834928357273'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/09/answer-from-pricewaterhousecoopers.html' title='Answer from PriceWaterhouseCoopers'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-3841178580317972976</id><published>2008-09-03T13:47:00.000-07:00</published><updated>2008-09-03T13:58:44.774-07:00</updated><title type='text'>And the Winner is:</title><content type='html'>&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;And the Winner is: Price Waterhouse Coopers.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Some people believe that the account-database of their carreer-site leaked mailaccounts and passwords, causing the mail issued by ZDF cited in my previous posting. I don't know if this is true. I don't state that this is the case. Others do. It is possible: I have an account there. PWC might believe this as well: their carreer-login-page is currently closed.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_L52Vgx7c_mo/SL75LcaN8oI/AAAAAAAAA1o/Lk97Xt-EStM/s1600-h/pwc.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_L52Vgx7c_mo/SL75LcaN8oI/AAAAAAAAA1o/Lk97Xt-EStM/s400/pwc.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5241900991305872002" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;Funny.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Tom&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-3841178580317972976?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/3841178580317972976/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=3841178580317972976' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3841178580317972976'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3841178580317972976'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/09/and-winner-is.html' title='And the Winner is:'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_L52Vgx7c_mo/SL75LcaN8oI/AAAAAAAAA1o/Lk97Xt-EStM/s72-c/pwc.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5968139555463393648</id><published>2008-09-03T13:13:00.000-07:00</published><updated>2008-09-04T03:21:35.784-07:00</updated><title type='text'>funny email from ZDF</title><content type='html'>&lt;span class="Apple-style-span"   style="border-collapse: collapse;   font-family:arial;font-size:13px;"&gt;&lt;div&gt;Sorry - German only. No fake - the passwort was a real password i used ages ago for useless boards and sites.&lt;/div&gt;&lt;div&gt;I'd have to send thousands, sometimes even millions of E-Mails like this around twice a month if i'd react on every userbase i get access to. (update: I don't do this. usually because i stumble upon this data whilst pentesting on behalf of the affected company itself). anyway - nice to read.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style=" ;font-size:16px;"&gt;&lt;div class="ObUWHc un3FG ckChnd"  style=" padding-left: 4px; padding-bottom: inherit; padding-right: 0px; font-size:80%;"&gt;&lt;table class="BwDhwd" style="border-collapse: collapse; width: 100%; "&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="zyVlgb XZlFIc"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-bottom: 0px; padding-left: 0px; text-align: left; white-space: nowrap; padding-right: 8px; vertical-align: top; width: 100%; padding-top: 3px; font-family:arial, sans-serif;"&gt;&lt;table class="BwDhwd" style="border-collapse: collapse; width: 100%; "&gt;&lt;tbody&gt;&lt;tr class="UszGxc"&gt;&lt;td class="UdFq5e"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; text-align: right; color: rgb(136, 136, 136); white-space: nowrap; vertical-align: top; width: 0%; font-family:arial, sans-serif;"&gt;&lt;span class="HcCDpe" style="cursor: auto; white-space: nowrap; "&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); text-decoration: underline;"&gt;from&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td colspan="2" class="sA2K5"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; white-space: normal; vertical-align: top; width: 100%; font-family:arial, sans-serif;"&gt;&lt;span class="HcCDpe" style="cursor: auto; "&gt;&lt;span class="JDpiNd" style="vertical-align: top; position: relative; top: -1px; "&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); white-space: nowrap; text-decoration: underline;"&gt;&lt;img width="16px" height="16px" class=" QrVm3d" id="upi" name="upi" jid="wiso-datendiebstahl@wiso.de" src="http://mail.google.com/mail/images/cleardot.gif" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span email="wiso-datendiebstahl@wiso.de" class="EP8xU"  style="color: rgb(0, 104, 28);  font-weight: bold; white-space: nowrap; display: inline; font-size:100%;"&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); text-decoration: underline;"&gt;Zweites Deutsches Fernsehen / Redaktion WISO&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); white-space: nowrap; text-decoration: underline;"&gt; &lt;/span&gt;&lt;span class="lDACoc" style="color: rgb(136, 136, 136); "&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); white-space: nowrap; text-decoration: underline;"&gt;&lt;wiso-datendiebstahl@wiso.de&gt;&lt;/wiso-datendiebstahl@wiso.de&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2" class="UdFq5e"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; text-align: right; color: rgb(136, 136, 136); white-space: nowrap; vertical-align: top; width: 0%; font-family:arial, sans-serif;"&gt;&lt;span class="HcCDpe" style="cursor: auto; white-space: nowrap; "&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); text-decoration: underline;"&gt;to&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td colspan="2" class="sA2K5"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; white-space: normal; vertical-align: top; width: 100%; font-family:arial, sans-serif;"&gt;&lt;span class="HcCDpe" style="cursor: auto; "&gt;&lt;span class="JDpiNd" style="vertical-align: top; position: relative; top: -1px; "&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); white-space: nowrap; text-decoration: underline;"&gt;&lt;img width="16px" height="16px" class=" QrVm3d" id="upi" name="upi" jid="thomas@echt-pervers.de" src="http://mail.google.com/mail/images/cleardot.gif" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); white-space: nowrap; text-decoration: underline;"&gt;tom@serversniff.net&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2" class="UdFq5e"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; text-align: right; color: rgb(136, 136, 136); white-space: nowrap; vertical-align: top; width: 0%; font-family:arial, sans-serif;"&gt;&lt;span class="HcCDpe" style="cursor: auto; white-space: nowrap; "&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); text-decoration: underline;"&gt;date&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td colspan="2" class="sA2K5"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; white-space: normal; vertical-align: top; width: 100%; font-family:arial, sans-serif;"&gt;&lt;span class="HcCDpe" style="cursor: auto; "&gt;&lt;span class="JDpiNd" style="vertical-align: top; position: relative; top: -1px; "&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); white-space: nowrap; text-decoration: underline;"&gt;&lt;img width="16px" height="16px" src="http://mail.google.com/mail/images/cleardot.gif" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); white-space: nowrap; text-decoration: underline;"&gt;Wed, Sep 3, 2008 at 5:27 PM&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2" class="UdFq5e"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; text-align: right; color: rgb(136, 136, 136); white-space: nowrap; vertical-align: top; width: 0%; font-family:arial, sans-serif;"&gt;&lt;span class="HcCDpe" style="cursor: auto; white-space: nowrap; "&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); text-decoration: underline;"&gt;subject&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td colspan="2" class="sA2K5"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; white-space: normal; vertical-align: top; width: 100%; font-family:arial, sans-serif;"&gt;&lt;span class="HcCDpe" style="cursor: auto; "&gt;&lt;span class="JDpiNd" style="vertical-align: top; position: relative; top: -1px; "&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); white-space: nowrap; text-decoration: underline;"&gt;&lt;img width="16px" height="16px" src="http://mail.google.com/mail/images/cleardot.gif" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); white-space: nowrap; text-decoration: underline;"&gt;Hinweis auf Datenmissbrauch&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-family:arial, sans-serif;"&gt;&lt;span class="HcCDpe" style="cursor: auto; "&gt;&lt;div class="pj1vZc"&gt;&lt;/div&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;td class="i8p5Ld"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; text-align: right; white-space: nowrap; vertical-align: top; font-family:arial, sans-serif;"&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/td&gt;&lt;td class="i8p5Ld cY8xve"  style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;  padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; text-align: right; white-space: nowrap; vertical-align: top; font-family:arial, sans-serif;"&gt;&lt;span class="Apple-style-span" style="color: rgb(132, 170, 255); text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="text-align: right;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;Hallo, Eigentümer der E-Mailadresse &lt;span class="Apple-style-span" style="color: rgb(0, 0, 204); text-decoration: underline;"&gt;tom@serversniff.net&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Sie erhalten diese Mail von uns, weil wir auf einen datenschutzrechtlich problematischen Sachverhalt aufmerksam gemacht wurden, der Ihre E-Mail-Adresse betrifft.&lt;br /&gt;&lt;br /&gt;Ihre E-Mail-Adresse und das Passwort *xundat* (Zu Ihrer Sicherheit wurde das Passwort gekürzt) befinden sich nach unseren Recherchen auf einem im Internet frei zugänglichen, in China beheimateten Server.&lt;br /&gt;&lt;br /&gt;Die Daten scheinen aus einem Datendiebstahl zu stammen, die Datendiebe haben versucht, sich mit Hilfe dieser Kombination aus Mail-Adresse und Passwort Zugang zu Online-Bezahldiensten zu verschaffen.&lt;br /&gt;&lt;br /&gt;Die Daten selbst stammen nach ersten Erkenntnissen aus einer Datenbank, die nichts mit Finanzdienstleistungen zu tun hat und bei der Sie sich in der Vergangenheit einmal angemeldet haben.&lt;br /&gt;&lt;br /&gt;Möglicherweise nutzen Sie diese Kombination aus E-Mail-Adresse und Passwort für weitere Internet-Dienste, etwa für Ihren Mail-Account, zum Anmelden bei Online-Shops oder auf anderen Webseiten. In diesem Fall raten wir Ihnen dringend, auf jeder einzelnen dieser Seiten Ihr Passwort unverzüglich zu ändern, bevor irgendjemand aus dem Vorhandensein dieser Daten im Internet einen Vorteil ziehen kann.&lt;br /&gt;&lt;br /&gt;Hinweise zur Verwendung von Passwörtern und für die sichere Passworterstellung erhalten Sie untenstehend.&lt;br /&gt;&lt;br /&gt;Diese Mail geht zurück auf Recherchen der ZDF-Sendung WISO, die am Montag den 8. September ausführlich über diesen Datendiebstahl berichten wird. Informationen erhalten Sie spätestens dann auch unter &lt;a href="http://www.wiso.de/" target="_blank" style="color: rgb(0, 0, 204); "&gt;http://www.wiso.de/&lt;/a&gt;  Bitte beachten Sie, dass wir keine Einzelfallberatung durchführen können - E-Mails an diese Versandadresse werden nicht beantwortet.&lt;br /&gt;&lt;br /&gt;Wir werden die uns vorliegenden Daten nach Ausstrahlung des Beitrags löschen, Sie erhalten keine weitere Mail von uns an diese Adresse (es sei denn, Sie haben sich bei einem ZDF-Informationsdienst angemeldet.) Wir informieren das vom Datendiebstahl betroffene Unternehmen sowie die entsprechende für den Datenschutz zuständige Behörde von dem Vorfall. Allerdings haben wir keinen Einfluss darauf, die auf einem chinesischen Webserver liegenden Daten zu löschen.&lt;br /&gt;&lt;br /&gt;Um über die Brisanz des Datendiebstahls qualifiziert berichten zu können bittet Sie die WISO-Redaktion, an einer kurzen Umfrage zum Datendiebstahl teilzunehmen, selbstverständlich anonym (Beachten Sie die Hinweise am Ende der Mail).&lt;br /&gt;Ihre Angaben können dabei helfen, dass die Zuschauer der Sendung für Probleme rund um die Datensicherheit im Internet sensibilisiert werden.&lt;br /&gt;&lt;a href="http://vote.wiso.zdf.de/" target="_blank" style="color: rgb(0, 0, 204); "&gt;http://vote.wiso.zdf.de/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Mit freundlichen Grüßen&lt;br /&gt;&lt;br /&gt;Zweites Deutsches Fernsehen / Redaktion WISO&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hier die Tipps zu einem sicheren Umgang mit Passwörtern, entnommen der Webseite &lt;a href="http://www.bsi-fuer-buerger.de/" target="_blank" style="color: rgb(0, 0, 204); "&gt;http://www.bsi-fuer-buerger.&lt;wbr&gt;de/&lt;/a&gt; mit freundlicher Genehmigung des Bundesamtes für Sicherheit in der Informationstechnik.&lt;br /&gt;&lt;br /&gt;1. Ein gutes Passwort&lt;br /&gt;... sieht so aus: Es sollte mindesttens acht Zeichen lang sein. Tabu sind allerdings Namen von Familienmitgliedern, des Haustieres, des besten Freundes, des Lieblingsstars usw. Und wenn möglich sollte es nicht in Wörterbüchern vorkommen. Zusätzlich sollte es auch Sonderzeichen (?!%...?) und Ziffern enthalten. Dabei sollten allzu gängige Varianten vermieden werden, also nicht 1234abcd usw. Einfache Ziffern am Ende des Passwortes anhängen oder eines der üblichen Sonderzeichen $, !, ?, #, am Anfang oder Ende eines ansonsten simplen Passwortes ist auch nicht empfehlenswert.&lt;br /&gt;&lt;br /&gt;Aber wie merkt man sich ein solches Passwort? Auch dafür gibt es Tricks. Eine beliebte Methode funktioniert so: Man denkt sich einen Satz aus und benutzt von jedem Wort nur den 1. Buchstaben (oder nur den 2. oder letzten, etc.). Anschließend verwandelt man bestimmte Buchstaben in Zahlen oder Sonderzeichen.&lt;br /&gt;Hier ein Beispiel:&lt;br /&gt;"Morgens stehe ich auf und putze meine Zähne." Nur die 1. Buchstaben: "MsiaupmZ". "i" sieht aus wie "1", "&amp;amp;" ersetzt das "und": "Ms1a&amp;amp;pmZ".&lt;br /&gt;Auf diese Weise hat man sich eine gute "Eselsbrücke" gebaut. Natürlich gibt es viele andere Tricks und Methoden, die genauso gut funktionieren.&lt;br /&gt;&lt;br /&gt;2. Passwörter regelmäßig ändern&lt;br /&gt;Jedes Passwort sollte in regelmäßigen Zeitabständen geändert werden. Viele Programme erinnern Sie automatisch daran, wenn Sie das Passwort z. B. schon ein halbes Jahr benutzen. Diese Aufforderung nicht gleich wegklicken - sondern ihr am besten gleich nachkommen! Natürlich ist es da schwer, sich alle Passwörter zu merken. Womit wir beim nächsten Punkt sind.&lt;br /&gt;&lt;br /&gt;3. Passwörter nicht notieren&lt;br /&gt;Auch wenn es bei selten genutzen Zugangsdaten schwerfällt - grundsätzlich sollten Sie sich Passwörter nicht aufschreiben.&lt;br /&gt;&lt;br /&gt;4. Keine einheitlichen Passwörter verwenden&lt;br /&gt;Problematisch ist die Gewohnheit, einheitliche Passwörter für viele verschiedene Zwecke bzw. Zugänge (Accounts) zu verwenden. Denn gerät das Passwort einer einzelnen Anwendung in falsche Hände, so hat der Angreifer freie Bahn für Ihre übrigen Anwendungen. Das können z. B. die Mailbox oder alle Informationen auf dem PC sein.&lt;br /&gt;&lt;br /&gt;5. Voreingestellte Passwörter ändern&lt;br /&gt;Bei vielen Softwareprodukten werden bei der Installation (bzw. im Auslieferungszustand) in den Accounts leere Passwörter oder allgemein bekannte Passwörter verwendet. Hacker wissen das: Bei einem Angriff probieren sie zunächst aus, ob vergessen wurde, diese Accounts mit neuen Passwörtern zu versehen. Deshalb ist es ratsam, in den Handbüchern nachzulesen, ob solche Accounts vorhanden sind und wenn ja, diese unbedingt mit individuellen Passwörtern abzusichern.&lt;br /&gt;&lt;br /&gt;6. Bildschirmschoner mit Kennwort sichern&lt;br /&gt;Bei den gängigen Betriebssystemen haben Sie die Möglichkeit, Tastatur und Bildschirm nach einer gewissen Wartezeit zu sperren. Die Entsperrung erfolgt erst nach Eingabe eines korrekten Passwortes. Diese Möglichkeit gibt es nicht umsonst. Deshalb: Nutzen Sie sie! Ohne Passwortsicherung können unbefugte Dritte sonst bei vorübergehender Abwesenheit des rechtmäßigen Benutzers Zugang zu dessen PC erlangen. Natürlich ist es ziemlich störend, wenn die Sperre schon nach weniger Zeit erfolgt. Unsere Empfehlung: 5 Minuten nach der letzten Benutzereingabe. Zusätzlich gibt es die Möglichkeit, die Sperre im Bedarfsfall auch sofort zu aktivieren (z.B. bei einigen Windows-Betriebssystemen: Strg+Alt+Entf drücken).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hinweise zu unserer Umfrage:&lt;br /&gt;Die Teilnahme erfolgt anonym, persönliche Daten werden durch das Webformular nicht erhoben. Aus technischen Gründen protokollieren Webserver allerdings, von welchen IP-Adressen aus das Formular aufgerufen wurde - das Erstellen dieser Logdateien lässt sich nicht unterbinden. Diese Daten werden allerdings nicht zusammen mit den Umfrageergebnissen protokolliert, eine Rückverfolgung der Daten wäre nur sehr aufwendig möglich. Wer seine Anonymität beim Besuch von Webseiten wie dieser Umfrage umfassender gewahrt sehen möchte, der kann die folgenden Web-Anonymisierer nutzen. Für diese Dienste und deren Nutzung übernimmt das ZDF keine Haftung:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.megaproxy.com/freesurf/" target="_blank" style="color: rgb(0, 0, 204); "&gt;http://www.megaproxy.com/&lt;wbr&gt;freesurf/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://anonymouse.org/anonwww.html" target="_blank" style="color: rgb(0, 0, 204); "&gt;http://anonymouse.org/anonwww.&lt;wbr&gt;html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.anonymsurfen.com/surfen.htm" target="_blank" style="color: rgb(0, 0, 204); "&gt;http://www.anonymsurfen.com/&lt;wbr&gt;surfen.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5968139555463393648?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5968139555463393648/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5968139555463393648' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5968139555463393648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5968139555463393648'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/09/funny-email-from-zdf.html' title='funny email from ZDF'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-2583107180607276458</id><published>2008-09-03T03:04:00.000-07:00</published><updated>2008-09-03T03:16:50.309-07:00</updated><title type='text'>cracking hashes</title><content type='html'>we updated our servers recently - the db is running on an intel quadcore, and there is plenty of computingpower for adding new hashes to the database for our site &lt;a href="http://hashcrack.com"&gt;hashcrack.com&lt;/a&gt;. a friendly guy sent me a rather huge wordlist created mainly out of several wikipedia-dumps which we are importing since a few days. we limited speed to around 1 million words per day, but i consider the figures with 31.000.000 words and &lt;span class="Apple-style-span" style="color: rgb(0, 0, 100); font-family: Verdana; font-size: 13px; "&gt;189.405.954 &lt;span class="Apple-style-span" style="color: rgb(0, 0, 0); font-family: Georgia; font-size: 16px; "&gt;known hashes rather impressive yet - the database is still running fast with this load.&lt;/span&gt;&lt;/span&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I don't know any other hashcrack-base offering more words AND supporting more than md5 and sha1. In fact i do support md5 and lm-hashes only to be complete. If you want to look up md5 or lm-hashes, you should really use one of the few sites offering rainbow-tables. They know alomst every lm-hash and at least all md5-hashes up to 7 or 8 characters. When it comes to reverse-lookup NTLM-Hashes for Windows NT or Mysql-Password-Hashes for mysql3, mysql4 and mysql5, hashcrack.com is still the biggest database i know of.  I'd be happy to link to any other database knowing more hashes!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;tom&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;tom&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-2583107180607276458?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/2583107180607276458/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=2583107180607276458' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2583107180607276458'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2583107180607276458'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/09/cracking-hashes.html' title='cracking hashes'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-2939407522496389599</id><published>2008-08-07T01:52:00.000-07:00</published><updated>2008-08-07T02:03:09.630-07:00</updated><title type='text'>murphy 2</title><content type='html'>no, not only did the database pass away, file-info also died despite having nothing to do with the database at all.&lt;br /&gt;&lt;br /&gt;the reason here was our provider &lt;a href="http://strato.de/"&gt;strozzo&lt;/a&gt; updating their crappy virtuozzo-hosts, which cutted for some crazy reason the balls of our perl-core.&lt;br /&gt;no more perl-modules left.&lt;br /&gt;no more file-info there, for this relies in parts on Phil Harveys &lt;a href="http://owl.phy.queensu.ca/%7Ephil/exiftool/"&gt;Image::Exifinfo&lt;/a&gt;, a really great piece of software.&lt;br /&gt;&lt;br /&gt;thanks to an anonymous comment moaning about the nunfunctional file-info. the perl-modules are reinstalled, file-info is working again as it did.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-2939407522496389599?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/2939407522496389599/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=2939407522496389599' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2939407522496389599'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2939407522496389599'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/08/murphy-2.html' title='murphy 2'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5564665332336095234</id><published>2008-08-04T06:41:00.000-07:00</published><updated>2008-08-04T06:59:32.628-07:00</updated><title type='text'>murphys law</title><content type='html'>some might have noticed: serversniffs half dead since 72 hours.&lt;br /&gt;the ups failed, power failed and the raid got corrupt. time to restore from a db-dump.&lt;br /&gt;&lt;br /&gt;and time to upgrade: our postgresql-database did run on windows 2000, which is rather fine unless your database won't grow to bloated. postgresql won't eat more than ~ 6o0MB Shared Memory on windows 2000, wich is fine, unless your database wont grow to bloated... - because the vacuum-process needs more RAM. So I ended up with an ever increasingly fragmented database.&lt;br /&gt;&lt;br /&gt;time to switch to linux. i tried to build the system as guest on VMWare ESXi - which i was able to manage - but there must have been something horribly wrong with the filesystem: all disk-transfers were slow as hell, usually below 10MByte/s. After 60 hours of setting up ESXi, a Linux-Guest and the database i threw the stuff away and started all over installing plain Linux Sunday evening, 48 hours after the database initially crashed.&lt;br /&gt;&lt;br /&gt;Since then i installed linux on the machine, prepared raid-array, database and everything else. currently the data is restored from a dump and the indexes are generated - 6 of ~20 are already done, the rest might be finished by tomorrow. to what i see right now the database is considerably faster using linux and 1 GB of Shared RAM.&lt;br /&gt;&lt;br /&gt;I apologize for the downtime, especially to the folks at blackhat.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5564665332336095234?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5564665332336095234/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5564665332336095234' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5564665332336095234'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5564665332336095234'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/08/murphys-law.html' title='murphys law'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6245411367669236094</id><published>2008-07-29T13:27:00.000-07:00</published><updated>2008-07-29T13:32:22.199-07:00</updated><title type='text'>Camellia</title><content type='html'>Firefox 3.0 no longer uses AES256 as default-cipher for https - it's using &lt;a href="http://en.wikipedia.org/wiki/Camellia_%28cipher%29"&gt;camellia&lt;/a&gt; instead. I can't imagine why the mozilla-developers changed this - but a few weeks ago I updated Serversniffs SSL-scripts to support camellia and a few others (idea again, and seed) as well.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6245411367669236094?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6245411367669236094/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6245411367669236094' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6245411367669236094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6245411367669236094'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/07/camellia.html' title='Camellia'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5075595521674712489</id><published>2008-05-30T01:19:00.000-07:00</published><updated>2008-05-30T01:29:13.869-07:00</updated><title type='text'>How to check SSH and SSL Certificates for the debian flaw</title><content type='html'>I had quite a few questions from people how to check their SSH- and SSL-certificate for the recent debian-flaw. As i had to check a few hundred customer-sites too, i did a little webinterface for checking SSHCerts and SSLCerts for the PRNG-Bug.&lt;br /&gt;&lt;br /&gt;See them at work at &lt;a href="http://serversniff.net/sshreport.php"&gt;http://serversniff.net/sshreport.php&lt;/a&gt; and &lt;a href="http://serversniff.net/sslcert.php"&gt;http://serversniff.net/sslcert.php&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;No magic behind - just debians ssh-vulnkey and a php-rippoff from the chksslkey-shellscript written by Michael Holzt. Maybe this will help the average rootserver-admin checking their sites.&lt;br /&gt;&lt;br /&gt;Both scripts use standard-sets for verifying the keys, checking only standard-dsa/rsa-keys for ssh and 1024/2048-bit-keys on the ssl-check. Drop me a line to tom@serversniff.net if you really need to check for any different keysizes.&lt;br /&gt;&lt;br /&gt;tom&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5075595521674712489?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5075595521674712489/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5075595521674712489' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5075595521674712489'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5075595521674712489'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/05/how-to-check-ssh-and-ssl-certificates.html' title='How to check SSH and SSL Certificates for the debian flaw'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-7442330425494219296</id><published>2008-05-16T02:54:00.000-07:00</published><updated>2008-05-16T04:33:26.324-07:00</updated><title type='text'>Mapped the net... in parts.</title><content type='html'>"Mapping the net" did we call our little project to map as many known hosts, ips and domains as possible some two years ago. Some laughed, others smiled. And we mapped. Thousands of hosts daily, running into a steadily growing postgresql-database built out of junk-hardware, running on a single cheap dsl-connection.&lt;br /&gt;&lt;br /&gt;I started some bencharking using search-engines to see how many hosts we really know, and i was surprised to see that we already know between 70 and 80 percent of all known hosts of major international hosts indexed on rank 1-1000 in common search-engines. And we've still far more than 10 million hostnames listed to sort in. I didn't expect to get so far when i started this funny project.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-7442330425494219296?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/7442330425494219296/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=7442330425494219296' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7442330425494219296'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7442330425494219296'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/05/mapped-net-in-parts.html' title='Mapped the net... in parts.'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6075881832927702152</id><published>2008-03-08T05:57:00.000-08:00</published><updated>2008-03-09T15:55:30.068-07:00</updated><title type='text'>Whois dropped</title><content type='html'>Some germans consider whois via serversniff&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;a breach of law&lt;br /&gt;&lt;/li&gt;&lt;li&gt;a breach of privay. &lt;/li&gt;&lt;/ul&gt;No more whois. I have to do better than argueing with any [censored] about obvious stuff.&lt;br /&gt;Get your whois-info at one of the thousands of sites around the net hosted somewhere outside germany or directly at the nic listed on serversniffs-domain-report.&lt;br /&gt;&lt;br /&gt;For the breach of privay: There was a guy, amongst others, writing me an email to "immediately remove my  Name from the page http://serversniff.net/dnr-webmasterinformation.&amp;lt;censored&amp;gt;. He didn't like the realname to show up in the whois-information. Hey - I deeply understand this request: If I'd operate a site like http://www.webmasterinformation.xx, I wouldn't want to have my name assigned to it, too. LOL!&lt;br /&gt;&lt;br /&gt;Maybe somebody's williing to tell him about whois at all?&lt;br /&gt;&lt;br /&gt;The net's a crazy place.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6075881832927702152?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6075881832927702152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6075881832927702152' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6075881832927702152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6075881832927702152'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/03/whois-dropped.html' title='Whois dropped'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5039681802132175198</id><published>2008-02-23T08:21:00.000-08:00</published><updated>2008-02-23T08:25:09.214-08:00</updated><title type='text'>offlinetime while rebuilding db</title><content type='html'>we switched the domain-database to new, hopefully faster hdd's sponsored by roelof temmingh (and me).&lt;br /&gt;since postgresql still denies a parallel installation i took the opportunity to rebuild the database, update the server and switch the stuff to the new sata-raid. it'll take a few hours until the database is rebuilt and restarted, but it's weekend - you don't work anyway, do you?&lt;br /&gt;&lt;br /&gt;we'll be back again soon.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5039681802132175198?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5039681802132175198/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5039681802132175198' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5039681802132175198'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5039681802132175198'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/02/offlinetime-while-rebuilding-db.html' title='offlinetime while rebuilding db'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-8465788446348668325</id><published>2008-02-23T00:42:00.000-08:00</published><updated>2008-02-23T00:52:38.257-08:00</updated><title type='text'>facts and figures</title><content type='html'>our current lookup-lag: 237.405 days.&lt;br /&gt;current number of known domains: 39.163.435&lt;br /&gt;&lt;br /&gt;still sorting in ~100.000 domains per day from queues, mainly generic .com-domains.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-8465788446348668325?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/8465788446348668325/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=8465788446348668325' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8465788446348668325'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8465788446348668325'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/02/facts-and-figures_23.html' title='facts and figures'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-8478842069991416189</id><published>2008-02-06T01:23:00.000-08:00</published><updated>2008-02-06T01:33:53.122-08:00</updated><title type='text'>facts and figures</title><content type='html'>For the historic records:&lt;br /&gt;we still lag with re-lookups of our hostnames - current time between a renewal of the IP-Lookup for a hostname is 238,749 days.&lt;br /&gt;&lt;br /&gt;We know 36.314.321 domains, the queue with hostnames to sort in decreased to 71.000.000.&lt;br /&gt;The "offline-queue" with not yet queued hostnames is around 5 million hosts.&lt;br /&gt;&lt;br /&gt;We're still on an SCSI-Array straight out of the hardware-museum with 8 hdds, 31 of 141 GB free. Over ten year old hardware, still working fine and reasonably fast.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-8478842069991416189?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/8478842069991416189/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=8478842069991416189' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8478842069991416189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8478842069991416189'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/02/facts-and-figures.html' title='facts and figures'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6930091426487275675</id><published>2008-02-05T12:53:00.000-08:00</published><updated>2008-02-05T12:58:15.257-08:00</updated><title type='text'>Cuill</title><content type='html'>Cuill started crawling Serverniff a few days ago. It does crawl slow, but very steady.&lt;br /&gt;&lt;br /&gt;I don't know if this is good news for serversniff, but they have a friendly and steady crawler.&lt;br /&gt;I wonder, when and if they go public - and i'd bet whatever you hold against me that they will be bought by a major company (there are not too many of them left) maximum 6 months after they open their search to the general public.&lt;br /&gt;&lt;br /&gt;Anybody willing to bet against?&lt;br /&gt;&lt;br /&gt;If you don't know &lt;a href="http://cuill.com"&gt;cuill&lt;/a&gt; - &lt;a href="http://www.google.de/search?num=100&amp;amp;hl=en&amp;amp;q=cuill&amp;amp;btnG=Suche&amp;amp;meta=lr%3D"&gt;google &lt;/a&gt;and &lt;a href="http://www.techcrunch.com/2007/09/04/cuill-super-stealth-search-engine-google-has-definitely-noticed/"&gt;teccrunch &lt;/a&gt;will tell more.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6930091426487275675?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6930091426487275675/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6930091426487275675' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6930091426487275675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6930091426487275675'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/02/cuill.html' title='Cuill'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-8243860811353321077</id><published>2008-01-22T01:20:00.000-08:00</published><updated>2008-01-22T01:31:11.387-08:00</updated><title type='text'>Kick-Ass Feedback</title><content type='html'>A swedish user kicked my ass to remind me that serversniff's AS-Report is not always reporting hat it should report.&lt;br /&gt;&lt;br /&gt;Yah. I ceased working on the stuff to get the domain-database fixed way back in Oktober 2007. Some of the mess is fixed now. Data is up-to-date again, I added more than 17.000 new subnets and i'm goin to build a complete BGP-Parser soon. I reactivadted the daily updates after i fixed database and scripts to work again.&lt;br /&gt;&lt;br /&gt;We're currently analyzing BGP-Tables from &lt;a href="http://www.routeviews.org"&gt;routeviews.org&lt;/a&gt; and &lt;a href="http://www.linx.net"&gt;LINX &lt;/a&gt;once a day, we might implement KIX and &lt;a href="http://de-cix.de"&gt;DE-CIX&lt;/a&gt; as well.&lt;br /&gt;&lt;br /&gt;I'd be happy to get more feedback - but it seems that most of you are plain happy with serversniff or just to bored to bother if something doesn't work out at all.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-8243860811353321077?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/8243860811353321077/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=8243860811353321077' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8243860811353321077'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8243860811353321077'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2008/01/kick-ass-feedback.html' title='Kick-Ass Feedback'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5844526180788860628</id><published>2007-12-09T14:05:00.000-08:00</published><updated>2007-12-09T14:11:51.777-08:00</updated><title type='text'>outage</title><content type='html'>our chinese little ups does a nice job: its shutting down the database after 10 minutes whithout electricity. this means, the database and its raid-array will stay in sync. but it also means, half of serversniff is dead, until i'm @home to restart the server. hours, usually.&lt;br /&gt;still this is way faster and less time-consuming than rebuilding raid array and database.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5844526180788860628?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5844526180788860628/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5844526180788860628' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5844526180788860628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5844526180788860628'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/12/outage.html' title='outage'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-2010585018844957358</id><published>2007-11-11T11:37:00.000-08:00</published><updated>2007-11-11T11:44:35.245-08:00</updated><title type='text'>Now Reports</title><content type='html'>I added a new line of functions to serversniff: Reports. Currently there are NS-Reports, AS-Reports and, new today, Domainreports.&lt;br /&gt;&lt;br /&gt;While the domain-report is still under heavy development i feel like its just perfect for visualizing the host- and network-structure of a domain. Try it out with stuff like  http://serversniff.de/dnr-norge.no. You can easily identify external hosts or specialized routing. Try it out and have fun and insights.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-2010585018844957358?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/2010585018844957358/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=2010585018844957358' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2010585018844957358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2010585018844957358'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/11/now-reports.html' title='Now Reports'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4415976080102881067</id><published>2007-10-28T04:06:00.000-07:00</published><updated>2007-10-28T04:28:37.516-07:00</updated><title type='text'>New: AS-Report</title><content type='html'>I've been rather busy the last weeks - at home, at work, everywhere, i didn't have much time to pet serversniff. I just finished a new script: asreport. This shows you infos about an AS.&lt;br /&gt;&lt;br /&gt;You feed it with an IP, a hostname or an AS-number, and serversniff tells you&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Uplink-ASses&lt;/li&gt;&lt;li&gt;Downlink-ASses&lt;/li&gt;&lt;li&gt;Known subnets on this as&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Those of you familiar with AS-geography might argue that there is no real way to determine, which of the peered AS are uplinks and downlinks. You are right: We are guessing. But try it out: We're usually guessing right.&lt;br /&gt;&lt;br /&gt;Like always, this is not entirely my own work.&lt;br /&gt;Serversniff has a routing-database that relys on routing-table from de-cix and routeviews.  Thanks to those guys for providing the routes. The routing data is parsed with Marco d'Itri's Zebra-Parser. Thanks Marco! The uplink/downlink-guess is relying on Geoff Hustons &lt;a href="http://www.cidr-report.org/as2.0/"&gt;CidrReport&lt;/a&gt;. Thanks Geoff.&lt;br /&gt;&lt;br /&gt;Please note that we do cache whois-data for the networks shown, and the routing-data might also be rather outdated, though we usually update the routing-table once a day.&lt;br /&gt;&lt;br /&gt;I tried to fix what annoyed me on other AS-related sites:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cidr-report.org/cgi-bin/as-report?as=AS3320&amp;amp;view=2.0"&gt;cidr-report&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://clez.net/net.whois?ip=3220&amp;amp;t=as"&gt;clez.net&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.robtex.com/bgp/as3320.html"&gt;robtex.com&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;Robtex seems to work on new, yet unlinked scripts, see http://www.robtex.com/asmacro/as-tiscalicust.html.&lt;br /&gt;&lt;br /&gt;What's left to do is some graphs (i'm working on these) and a maybe bit of speed (it's fast enough for me, though).&lt;br /&gt;&lt;br /&gt;If you know any other as-analyzers or if you feel i missed something: drop me a note at &lt;a href="mailto:thomas.springer@serversniff.net"&gt;thomas.springer@serversniff.net&lt;/a&gt; or leave a comment.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4415976080102881067?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4415976080102881067/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4415976080102881067' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4415976080102881067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4415976080102881067'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/10/new-as-report.html' title='New: AS-Report'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-606465730409002038</id><published>2007-09-28T14:33:00.000-07:00</published><updated>2007-09-28T14:59:08.192-07:00</updated><title type='text'>finally graphs</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_L52Vgx7c_mo/Rv146Q2SbVI/AAAAAAAAAIk/NekIY7_23vk/s1600-h/ts620.png"&gt;&lt;img style="cursor: pointer;" src="http://bp2.blogger.com/_L52Vgx7c_mo/Rv146Q2SbVI/AAAAAAAAAIk/NekIY7_23vk/s320/ts620.png" alt="" id="BLOGGER_PHOTO_ID_5115377694113164626" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I was always jealous on robtex.com for those crazy graphs that took me a few hours to understand completely.&lt;br /&gt;&lt;br /&gt;I herby confess publicly: i did a wrapper long time ago for just reaping the robtex-graphic for a domain, to use them for my daily work.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;and finally, serversniff comes up with those crazy graphs, too. as i'm always trying to make things better i did split rob's big picture in several smaller graphs, for they are easier to understand.&lt;br /&gt;&lt;br /&gt;serversniff uses &lt;a href="http://www.graphviz.org/"&gt;graphwiz &lt;/a&gt;like rob and many others do. seems that there is not really much more there on the market for those directed graphs.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_L52Vgx7c_mo/Rv15Eg2SbWI/AAAAAAAAAIs/_s4I0CBvBcc/s1600-h/ts619.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_L52Vgx7c_mo/Rv15Eg2SbWI/AAAAAAAAAIs/_s4I0CBvBcc/s320/ts619.png" alt="" id="BLOGGER_PHOTO_ID_5115377870206823778" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;crazy syntax, lousy docs, but works like a charm.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-606465730409002038?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/606465730409002038/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=606465730409002038' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/606465730409002038'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/606465730409002038'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/09/finally-graphs.html' title='finally graphs'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_L52Vgx7c_mo/Rv146Q2SbVI/AAAAAAAAAIk/NekIY7_23vk/s72-c/ts620.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6502505625447795129</id><published>2007-09-07T11:08:00.000-07:00</published><updated>2007-09-07T11:28:21.851-07:00</updated><title type='text'>new styles</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://serversniff.de/image/chuchu4.gif"&gt;&lt;img style="cursor: pointer; width: 192px; height: 116px;" src="http://serversniff.de/image/chuchu4.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;we're tryin to revamp serversniff a little bit and we started out with a little mascot. dave decided to name it chuchu, and i'm fine with that. no more need to have jealous looks over to the &lt;a href="http://www.snort.org/"&gt;snort&lt;/a&gt;-guys, for i always wanted serversniff to have sth like their old mascot snorty. thanks, &lt;a href="http://dwave.myria.de/content/index.php?page=about"&gt;dave&lt;/a&gt;.&lt;br /&gt;serversniff will stay as simple as it is - we're working to make it even simpler. really, a glance over to the guys at &lt;a href="http://www.domaintools.com/"&gt;whois.sc&lt;/a&gt; makes me feel funny: am i really the only one feeling totaly lost with five (!) menubars, different colors and even different font-familys on one page?&lt;br /&gt;i'll keep serversniff mostly black and white. like it or not, i still do.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6502505625447795129?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6502505625447795129/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6502505625447795129' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6502505625447795129'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6502505625447795129'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/09/new-styles.html' title='new styles'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6600250095104045939</id><published>2007-08-30T14:47:00.000-07:00</published><updated>2007-08-30T14:50:03.315-07:00</updated><title type='text'>donations and raisins...</title><content type='html'>for somebody asked for an adress to donate: i have a paypal-account, its thomas.springer@gmail.com.&lt;br /&gt;&lt;br /&gt;i'd be glad for anything i can get - it will be spent on hardware, connectivity and electricity anyway.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6600250095104045939?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6600250095104045939/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6600250095104045939' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6600250095104045939'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6600250095104045939'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/08/donations-and-raisins.html' title='donations and raisins...'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4589854149966077345</id><published>2007-08-30T13:02:00.000-07:00</published><updated>2007-08-30T13:06:05.911-07:00</updated><title type='text'>back online again</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://zugpferde.com/bild1.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://zugpferde.com/bild1.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;the domain-database took almost two days outtime - and its back online again. a few scripts like ip-info are still down, but will be online again soon.&lt;br /&gt;&lt;br /&gt;i did not only rebuild the database, but also rewired the whole thing and drilled loads of wholes throughout my house to do the network. things take time here, for its not only the network that needs some attention, but also the kids and them.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4589854149966077345?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4589854149966077345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4589854149966077345' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4589854149966077345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4589854149966077345'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/08/back-online-again.html' title='back online again'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4814044117804034863</id><published>2007-08-29T07:21:00.000-07:00</published><updated>2007-08-29T07:24:01.465-07:00</updated><title type='text'>downtime</title><content type='html'>The domain-database is currently unavailable for i pulled the plug accidentally. I'm on my way to rebuild the db - and i used the opportunity to triple the server's ram. Maybe stuff gets faster this way.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4814044117804034863?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4814044117804034863/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4814044117804034863' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4814044117804034863'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4814044117804034863'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/08/downtime.html' title='downtime'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-3729898887880763127</id><published>2007-08-27T10:20:00.000-07:00</published><updated>2007-08-27T10:31:25.151-07:00</updated><title type='text'>SEO with serversniff</title><content type='html'>Search-Engine-Spammers discovered that &lt;a href="http://serversniff.net"&gt;Serversniff.net&lt;/a&gt; is a lovely site where they can produce a page with links to their pages to be optimized. How does this work?&lt;br /&gt;&lt;br /&gt;If you call a page like FileInfo you get an output with a link to your page or at least with a http://somedomain/file, that google will interpret as link to follow. The spammer do exactly this.&lt;br /&gt;&lt;br /&gt;Serversniff uses google-adds to get at least a few bucks supporting the servercosts. Google-Bot does follow every customer, indexing the called page a few seconds later. The spamers use serverfarms or, more likely trojanized machines to call their page 5 times in a row from different machines all over the world. Crazy.&lt;br /&gt;&lt;br /&gt;I dropped the links on some pages, and I will put on a noindex-Header in the metatags of all relevant Serversniff-pages, hoping to stop these totally useless crapsters from abusing my machine. Seems like nothing is too crazy on the internet.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-3729898887880763127?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/3729898887880763127/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=3729898887880763127' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3729898887880763127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3729898887880763127'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/08/seo-with-serversniff.html' title='SEO with serversniff'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4216279260791041381</id><published>2007-08-19T10:03:00.000-07:00</published><updated>2007-08-19T10:54:59.932-07:00</updated><title type='text'>I still don't like solaris.</title><content type='html'>I recently did a pentest. Whilst torturing a webapplication i came across a file-inclusion-vulnerability, allowing me a glance on /etc/passwd via opening &lt;span style="font-style: italic;font-family:courier new;" &gt;http://tortured-site.xx/safe.php?file=/index.php&lt;/span&gt;.&lt;br /&gt;I tried /etc/shadow, but no luck, apache was not running as root. I poked around to see that i was on a solaris-machine. F*ck.&lt;br /&gt;I remembered that years ago, when i used to work as a webmaster, they gave me a sun E something. A horrible fast machine, but i had no clue from solaris. After two weeks I gave up with the awful thing and got a copy of the first beta-version of Suse-Linux for Sun. I don't like Suse either, but after installing Linux on it the Sun turned from a constant source of anger and stress into a horrible fast database-machine. I decided that solaris an me will never get friends.&lt;br /&gt;So, what now? I knew i had to come up with something reasonable, not just a list of accounts to make the customers webmasters really aware of the problem. I tried to find other logs - but no way. Solaris' not Linux, and the Apache was homegrown installed in some funny directory i couldn't find.&lt;br /&gt;Finally I came up with a promising solution: I had the accounts from /etc/password, and it was written there, that they all used /bin/bash. I went for /home/&lt;user&gt;/.bash_history. No luck on the first two accounts, but then, bingo, there it was: the admin deploying new software-versions, connecting to the database with user and password on the commandline and finally grepping through the apache-logs.&lt;br /&gt;The webapp suffered from another minor vulnerability: All https-transactions were done via GET-Requests. I already pointed this out in my report that it's a really bad idea to transfer bank-account details and creditcard-numbers and cvcs in an URL, even if it is transferred via HTTPS.&lt;br /&gt;From there on stuff was easy: I used the file-inclusion to download a days logfile, filtered the relevant requests via get and had lovely stuff to present:&lt;br /&gt;&lt;/user&gt;&lt;ul&gt;&lt;li&gt;A list with thousands of CreditCards with CVC, Dates and Names.&lt;/li&gt;&lt;li&gt;A nice record of what the various admins did over the last years. Some proved to be knowledgable and exact, even verified md5-sums of uploaded files to ensure their integrity, some proved to be unix-analphabets like me.&lt;/li&gt;&lt;li&gt;A few passwords for accounts and the locations of ssh-keyfiles i didn't bother to download.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;What we can learn from this is:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;It is a nice idea to make sure your webserver can't read anywhere on your partition outside the webroot.&lt;/li&gt;&lt;li&gt;It is a nice idea to keep your bash_history-file small.          Putting "export HISTFILESIZE=0"  in your ~/.bashrc will do the trick.&lt;/li&gt;&lt;li&gt;Consider all user input as dirty.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;The vulnerable safe.php proved to be a quick-and-dirty solution: 6 lines of custom code killing an otherwise really good webapp. Safe.php is fixed now, but hey, the site is huge, consists of many servers and I'm still keen on getting access to more user-data. Pentesting sometimes reminds me on an interactive version of mistery-stories and whodunits like "The three investigators" when i was young. I still like this part of my job. And, for i'm using zsh instead of bash, err, anybody can tell me how to disable .zsh_history on my machines?&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4216279260791041381?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4216279260791041381/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4216279260791041381' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4216279260791041381'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4216279260791041381'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/08/i-still-dont-like-solaris.html' title='I still don&apos;t like solaris.'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4721238307337511677</id><published>2007-07-08T13:17:00.000-07:00</published><updated>2007-07-08T13:29:58.439-07:00</updated><title type='text'>How nice</title><content type='html'>Usually people use serversniff. And they complain, when somethings completely not workin. Otherwise they don't give a shit. Really.&lt;br /&gt;&lt;br /&gt;Ok, no real matter - &lt;a href="http://serversniff.net"&gt;serversniff &lt;/a&gt;is a hobby and the API is there to ease my daily work. Nothing more. But really, sometimes i wish people would care more.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.paterva.com/evolution-e.html"&gt;Roelof Temmingh&lt;/a&gt; does care occasionally, for he uses parts of serversniff for his evolution. He contributed valuable code and (unknowingly) many many ideas and thoughts, and he's constantly begging for new functions. Roelof, if i had the time, i'd implement far more of your requests.&lt;br /&gt;&lt;br /&gt;I had somebody asking for an API-Password recently - and a day after i had a bugreport. I was so glad that someone cared about the bugs that i fixed them right away. When I started with serversniff i had a dream of people bringing great ideas and great scripts helping me earn big $$$. Serversniff's live for around 2 years now - about 98% of the code is still mine, and the $$$ still don't pay for hardware, electricity and servercosts. Maybe i should stop ranting here.&lt;br /&gt;&lt;br /&gt;Have a nice week,&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4721238307337511677?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4721238307337511677/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4721238307337511677' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4721238307337511677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4721238307337511677'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/07/how-nice.html' title='How nice'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-8973140425644826081</id><published>2007-06-22T05:34:00.000-07:00</published><updated>2007-06-22T05:41:11.589-07:00</updated><title type='text'>Statistics B</title><content type='html'>We're far from complete, but getting better:&lt;br /&gt;&lt;br /&gt;The DB knows ns/mx-records for 12.829.155 domains. More is added daily until we're complete.&lt;br /&gt;The DB knows currently 1.074.097 nameservers (counted by hostname, not ip!).&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-8973140425644826081?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/8973140425644826081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=8973140425644826081' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8973140425644826081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/8973140425644826081'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/06/statistics-b.html' title='Statistics B'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6335032351744261840</id><published>2007-06-22T04:45:00.000-07:00</published><updated>2007-06-22T04:59:37.298-07:00</updated><title type='text'>Statistic-Figure A: 19.155.784</title><content type='html'>I'm not really into statistics and i don't do them regurlarly. But i'd like to remind myself that serversniff.net currently knows more than 19.155.784 unique domains with at least one resolving host. This should be around 15 percent of all known domains on the internet.&lt;br /&gt;&lt;br /&gt;we're still adding around 100.000 new domainnames per day, focussing on domains outside of the .com/.net-space. To get a glimpse of domains added take a look at &lt;a href="http://tomdns.net/"&gt;http://tomdns.net&lt;/a&gt; - there you can see the newest domains added in realtime.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6335032351744261840?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6335032351744261840/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6335032351744261840' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6335032351744261840'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6335032351744261840'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/06/statistic-figure-19155784.html' title='Statistic-Figure A: 19.155.784'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-7643878031566540935</id><published>2007-06-22T03:55:00.000-07:00</published><updated>2007-06-22T04:00:23.026-07:00</updated><title type='text'>Spam from serversniff.net</title><content type='html'>Some asshole sent out a spam-wave with random Serversniff.net-Senderadresses. The little sucker put in a return-path and a sender with &lt;randomname&gt;@serversniff.net. Since i have defined a "catch-all"-mailaccount for serversniff.net, i get all those nice complaints and returned mails. Hundreds of them! Argh.&lt;br /&gt;&lt;br /&gt;And yes Sir, no M'am, neither my webserver nor my mailservers are hacked, take a look at the mailheaders:&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;&lt;br /&gt;Return-Path: &lt;&lt;/span&gt;&lt;a style="font-family: courier new;" onclick="return top.js.OpenExtLink(window,event,this)" href="mailto:stasIsaev@serversniff.net"&gt;stasIsaev@serversniff.net&lt;/a&gt;&lt;span style="font-family: courier new;"&gt;&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Received: (qmail 25562 invoked by uid 0); 22 Jun 2007 12:17:06 +0300&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Received: from &lt;/span&gt;&lt;a style="font-family: courier new;" onclick="return top.js.OpenExtLink(window,event,this)" href="http://220.125.204.181/" target="_blank"&gt;220.125.204.181&lt;/a&gt;&lt;span style="font-family: courier new;"&gt; by post (envelope-from &lt;&lt;/span&gt;&lt;a style="font-family: courier new;" onclick="return top.js.OpenExtLink(window,event,this)" href="mailto:stasIsaev@serversniff.net"&gt;stasIsaev@serversniff.net&lt;/a&gt;&lt;span style="font-family: courier new;"&gt;&gt;, uid 92) with qmail-scanner-2.01&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; (clamdscan: 0.90/2659.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; Clear:RC:0(&lt;/span&gt;&lt;a style="font-family: courier new;" onclick="return top.js.OpenExtLink(window,event,this)" href="http://220.125.204.181/" target="_blank"&gt;220.125.204.181&lt;/a&gt;&lt;span style="font-family: courier new;"&gt;):.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; Processed in 0.239443 secs); 22 Jun 2007 09:17:06 -0000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Received: from unknown (HELO ?220.125.204.181?) (&lt;/span&gt;&lt;a style="font-family: courier new;" onclick="return top.js.OpenExtLink(window,event,this)" href="http://220.125.204.181/" target="_blank"&gt;220.125.204.181&lt;/a&gt;&lt;span style="font-family: courier new;"&gt;)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  by &lt;/span&gt;&lt;a style="font-family: courier new;" onclick="return top.js.OpenExtLink(window,event,this)" href="http://post.ziniur.lt/" target="_blank"&gt;post.ziniur.lt&lt;/a&gt;&lt;span style="font-family: courier new;"&gt; with SMTP; 22 Jun 2007 12:17:04 +0300&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Received: from [&lt;/span&gt;&lt;a style="font-family: courier new;" onclick="return top.js.OpenExtLink(window,event,this)" href="http://220.125.204.181/" target="_blank"&gt;220.125.204.181&lt;/a&gt;&lt;span style="font-family: courier new;"&gt;] (&lt;/span&gt;&lt;a style="font-family: courier new;" onclick="return top.js.OpenExtLink(window,event,this)" href="http://183.178.25.193/" target="_blank"&gt;183.178.25.193&lt;/a&gt;&lt;span style="font-family: courier new;"&gt;)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;        by &lt;/span&gt;&lt;a style="font-family: courier new;" onclick="return top.js.OpenExtLink(window,event,this)" href="mailto:stasIsaev@serversniff.net"&gt;stasIsaev@serversniff.net&lt;/a&gt;&lt;span style="font-family: courier new;"&gt; with SMTP;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;        for &lt;&lt;/span&gt;&lt;a style="font-family: courier new;" onclick="return top.js.OpenExtLink(window,event,this)" href="mailto:gvitkauskasd@ziniur.lt"&gt;gvitkauskasd@ziniur.lt&lt;/a&gt;&lt;span style="font-family: courier new;"&gt;&gt;; Fri, 22 Jun 2007 19:17:22 +0100&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;MIME-Version: 1.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;None of these sender-IPs belong to serversniff.net's infrastructure. Seems that it's time to drop the catch-all-adress for serversniff.net.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-7643878031566540935?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/7643878031566540935/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=7643878031566540935' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7643878031566540935'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7643878031566540935'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/06/spam-from-serversniffnet.html' title='Spam from serversniff.net'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6212211213455779880</id><published>2007-06-18T11:12:00.001-07:00</published><updated>2007-06-19T06:53:45.457-07:00</updated><title type='text'>For the records</title><content type='html'>For the records: Our update-lag with domainnames is at 443,017 days, and it's increasing. It will continue to increase for some time, for 450 days back was a time where we did bulk-updates: inserting many many new hosts from big lists at once, without to much handling of domains and ips at all. There wasn't too much data or trigger-overhead, and the database was not yet public. I hope to catch up the update-lag to 400 days in about a month and be around 200 days by the end of the 2007. I don't really believe than we can get smaller update-cycles with our current network-bandwidth. But you always have the option to filter outdated records from beeing displayed, regardless if you use &lt;a href="http://serversniff.net/"&gt;serversniff.net&lt;/a&gt;, &lt;a href="http://tomdns.net/"&gt;tomdns.net&lt;/a&gt; or serversniffs api.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6212211213455779880?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6212211213455779880/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6212211213455779880' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6212211213455779880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6212211213455779880'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/06/for-records.html' title='For the records'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-7768587642970379738</id><published>2007-06-17T10:12:00.000-07:00</published><updated>2007-06-19T06:54:12.774-07:00</updated><title type='text'>Serversniff deLux</title><content type='html'>If you ever wondered what serversniff looks like:&lt;br /&gt;&lt;br /&gt;Its located in the attic upstairs from the garage, where it's hot in the summer and cold in the winter. Its made of a cheaposystem with an Athlon 3Something with one Gig RAM and an old Perc2-sc-scsi-controller ripped from a Dell-server and a Proliant-HDD-array from ebay.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://lh3.google.de/image/thomas.springer/RnVsXFI1q2I/AAAAAAAAABs/n6bnQ-ei3HI/100C2634.JP"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px;" src="http://lh3.google.de/image/thomas.springer/RnVsXFI1q2I/AAAAAAAAABs/n6bnQ-ei3HI/100C2634.JP" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I suffered occasional blackouts when lightning stroke, doing damage to the database - so i ordered a brandnew UPS, the small thingy standing right, coming straight from china. We're prepared now.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-7768587642970379738?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/7768587642970379738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=7768587642970379738' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7768587642970379738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7768587642970379738'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/06/serersniff-delux.html' title='Serversniff deLux'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-3805404897272930810</id><published>2007-06-02T00:54:00.000-07:00</published><updated>2007-06-02T01:15:28.445-07:00</updated><title type='text'>crazy ideas</title><content type='html'>around 500 days ago i had a crazy idea: mapping the net in a database. all domains, all hostnames, all relations of ns- and mx-servers.&lt;br /&gt;&lt;br /&gt;i knew a few sites who should have this data but would not really let you look it up - whois.sc and netcraft.com were amongst them. that was all i knew. oh and yes, i knew mysql, i worked with sqlite and microsofts sql-server for years.&lt;br /&gt;&lt;br /&gt;i expected this to be an adventure. a textadventure, fun.&lt;br /&gt;&lt;br /&gt;and hence, it was fun. the database crashed, servers got blocked, i had errors in my harvesting scripts and i was overwhelmed when i got around 100 million domains with even more hosts at once.&lt;br /&gt;&lt;br /&gt;and now i'm sitting on a bunch of data that gets older. my time is limited, my hardware-ressources are as well. data is getting old. i started updating the hostname/IP-entries these days. I should have done this earlyier, i know - but i didn't. time is limited - remember?&lt;br /&gt;&lt;br /&gt;a bit frustrating: the "update-lag", the time between the last update of a hostentry is currently exactly at 427,167 days. most frustrating: it's still increasing.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_L52Vgx7c_mo/RmEm-sYSp_I/AAAAAAAAABQ/B1tOLx0zWbs/s1600-h/2.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_L52Vgx7c_mo/RmEm-sYSp_I/AAAAAAAAABQ/B1tOLx0zWbs/s400/2.png" alt="" id="BLOGGER_PHOTO_ID_5071377513902680050" border="0" /&gt;&lt;/a&gt;hmpf.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-3805404897272930810?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/3805404897272930810/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=3805404897272930810' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3805404897272930810'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3805404897272930810'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/06/crazy-ideas.html' title='crazy ideas'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_L52Vgx7c_mo/RmEm-sYSp_I/AAAAAAAAABQ/B1tOLx0zWbs/s72-c/2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-2109135913448614026</id><published>2007-05-29T06:21:00.000-07:00</published><updated>2007-05-29T06:34:03.407-07:00</updated><title type='text'>China blocks serversniff.net</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_L52Vgx7c_mo/RlwrbPFB4PI/AAAAAAAAABI/VdhUpHeP6SA/s1600-h/ts215.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_L52Vgx7c_mo/RlwrbPFB4PI/AAAAAAAAABI/VdhUpHeP6SA/s400/ts215.png" alt="" id="BLOGGER_PHOTO_ID_5069975027416424690" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Maybe this is something we shouldn't be proud of: Chinese authorities block serversniff completely at their "great firewall of china" - even a few totally passive vhosts with a few pics and texts sitting on serversniff's ip-address get blocked by chinese censorship.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Check yourself &lt;a href="http://www.greatfirewallofchina.org/test/"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-2109135913448614026?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/2109135913448614026/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=2109135913448614026' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2109135913448614026'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2109135913448614026'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/05/china-blocks-serversniffnet.html' title='China blocks serversniff.net'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_L52Vgx7c_mo/RlwrbPFB4PI/AAAAAAAAABI/VdhUpHeP6SA/s72-c/ts215.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-7314882329208139060</id><published>2007-05-21T03:49:00.000-07:00</published><updated>2007-05-21T04:05:50.948-07:00</updated><title type='text'>Language-Flags and a new check</title><content type='html'>Occasiónally we see english users referring to the &lt;a href="http://serversniff.de/"&gt;german version&lt;/a&gt; of Serversniff and vice versa, germans using the &lt;a href="http://serversniff.net/"&gt;english version&lt;/a&gt;. Both versions are functionally identic for most of hour language-specific stuff is stored in a language-file. I added a language-button next to the logo - maybe this will help people getting serversniff in a language that fits their needs best.&lt;br /&gt;&lt;br /&gt;I can't really say that i had a lazy weekend, but i ended up throwing together another check: &lt;a href="http://serversniff.net/content.php?do=nsreport"&gt;DNS-Report&lt;/a&gt; will do a few checks on all nameservers that are in charge for a domain. Basically this is a fraction of Scott Perrys great &lt;a href="http://www.dnsreport.com/"&gt;dnsreport.com&lt;/a&gt; - but with added zonetransfer-functionallity. We'll add more functionality some day, doing cache-checks and stuff you won't really find on other sites.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-7314882329208139060?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/7314882329208139060/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=7314882329208139060' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7314882329208139060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7314882329208139060'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/05/language-flags-and-new-check.html' title='Language-Flags and a new check'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-551735547687661067</id><published>2007-05-19T23:14:00.000-07:00</published><updated>2007-05-21T03:46:57.561-07:00</updated><title type='text'>New: Filesearch</title><content type='html'>It's a sunny sunday and i burned my back yesterday working outside building a wooden house for the kids. Time for an indoor-day and a few words.&lt;br /&gt;We recently released a new script sitting in the webserver-part of serversniffs menu: FILE-SEARCH.&lt;br /&gt;FileSearch is a companion to our FILE-INFO: Imagine you want to see all .DOCs on a webserver and you even want to have a look if there is any interesting stuff hidden in these files.&lt;br /&gt;Have a look at this &lt;a href="http://www.serversniff.de/file-search.php?server=blogspot.com&amp;amp;filetype=doc"&gt;demo&lt;/a&gt; showing DOCs on blogspot-blogs.&lt;br /&gt;This script (ab)uses major search-engines. You scriptkids might end up seeing nothing if you (ab)use it too often searching for sites hosting phpBB-security-holes.&lt;br /&gt;&lt;br /&gt;I limited the script to 100 results. Drop me a friendly line if (and why!) you feel that this number is too low for your personal needs and i might tell you the secret switch to increase the max-result-count to googles maximum of 1.000 results.&lt;br /&gt;&lt;br /&gt;&lt;a href="mailto:thomas.springer@serversniff.net"&gt;tom&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-551735547687661067?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/551735547687661067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/551735547687661067'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/05/new-filesearch.html' title='New: Filesearch'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4811208329536212918</id><published>2007-05-17T03:56:00.000-07:00</published><updated>2007-05-17T04:13:46.180-07:00</updated><title type='text'>New AS-Lookup</title><content type='html'>Serversniff offers a new script and &lt;a href="http://www.serversniff.net/wiki_en/index.php?title=API#AS-Number_for_IP"&gt;API-script&lt;/a&gt; doing lookups for the Autonomous-System of an IP or hostname.&lt;br /&gt;&lt;br /&gt;Backend for this script is currently team cymrus very fine &lt;a href="http://www.cymru.com/BGP/asnlookup.html"&gt;AS-Lookup&lt;/a&gt; - this should be fine unless we see a really huge demand for this. We used to operate a &lt;a href="http://pwhois.org"&gt;pwhois-like&lt;/a&gt; BGP-Parser that offered a bit more information, but the work/requestcount-ratio brought us to drop this service. Finally, we brought it back on using the cymru-backend.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4811208329536212918?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4811208329536212918/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4811208329536212918' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4811208329536212918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4811208329536212918'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/05/new-as-lookup.html' title='New AS-Lookup'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4000882734863656569</id><published>2007-05-10T04:31:00.000-07:00</published><updated>2007-05-10T04:42:39.692-07:00</updated><title type='text'>Back to the net</title><content type='html'>The database is back, t-offline was kind enough to send a technician fixing the DSL-line. Seems that the DSL-Splitter died. I still think about a colocation in a datacanter for database-machine.&lt;br /&gt;The database is currently readonly. I took the offline-time to do some database-maintenance and found a bad block in a 17GB-sized table.&lt;br /&gt;&lt;br /&gt;I'm working to identify the affected rows and will then decide wehter to restore the old backup or restore all but the affected rows.&lt;br /&gt;&lt;br /&gt;cheers&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4000882734863656569?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4000882734863656569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4000882734863656569' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4000882734863656569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4000882734863656569'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/05/back-to-net.html' title='Back to the net'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-3860302776528610225</id><published>2007-05-09T02:00:00.000-07:00</published><updated>2007-05-09T02:10:51.967-07:00</updated><title type='text'>Serversnoffline</title><content type='html'>Deutsche Telekom is still on strike. No technician yet, day 7 without phone, dsl and internet. Did i mention that i just hate monopolist-companys?&lt;br /&gt;&lt;br /&gt;No real wonder, that they are the owners of t-offline.de:&lt;br /&gt;&lt;br /&gt;&lt;pre class="simple"&gt;Domain:      t-offline.de&lt;br /&gt;Nserver:     support.mesch.dtag.de&lt;br /&gt;Nserver:     pns.dtag.de&lt;br /&gt;Nserver:     secondary006.dtag.net&lt;br /&gt;Status:      connect&lt;br /&gt;Changed:     2007-03-06T22:35:34+01:00&lt;br /&gt;&lt;br /&gt;[Holder]&lt;br /&gt;Type:         ORG&lt;br /&gt;Name:         Deutsche Telekom AG, Domainmanagement&lt;br /&gt;Address:      Friedrich-Ebert-Allee 140&lt;br /&gt;Pcode:        53113&lt;br /&gt;City:         Bonn&lt;br /&gt;Country:      DE&lt;br /&gt;Changed:      2005-06-07T10:29:07+02:00&lt;br /&gt;&lt;br /&gt;[Admin-C]&lt;br /&gt;Type:         PERSON&lt;br /&gt;Name:         Marion Schoeberl&lt;br /&gt;Address:      Deutsche Telekom AG, Domainmanagement&lt;br /&gt;Address:      Friedrich-Ebert-Allee 140&lt;br /&gt;Pcode:        53113&lt;br /&gt;City:         Bonn&lt;br /&gt;Country:      DE&lt;br /&gt;Changed:      2004-08-24T10:10:06+02:00&lt;br /&gt;&lt;br /&gt;[Tech-C]&lt;br /&gt;Type:         PERSON&lt;br /&gt;Name:         Wolfgang Linke&lt;br /&gt;Organisation: T-Systems CSM GmbH&lt;br /&gt;Address:      Feldstr. 34&lt;br /&gt;Pcode:        59872&lt;br /&gt;City:         Meschede&lt;br /&gt;Country:      DE&lt;br /&gt;Phone:        +49 291 90227 7575&lt;br /&gt;Fax:          +49 291 90227 7609&lt;br /&gt;Email:        domain@mesch.telekom.de&lt;br /&gt;Changed:      2006-01-25T10:52:53+01:00&lt;br /&gt;&lt;br /&gt;[Zone-C]&lt;br /&gt;Type:         PERSON&lt;br /&gt;Name:         Wolfgang Linke&lt;br /&gt;Organisation: T-Systems CSM GmbH&lt;br /&gt;Address:      Feldstr. 34&lt;br /&gt;Pcode:        59872&lt;br /&gt;City:         Meschede&lt;br /&gt;Country:      DE&lt;br /&gt;Phone:        +49 291 90227 7575&lt;br /&gt;Fax:          +49 291 90227 7609&lt;br /&gt;Email:        domain@mesch.telekom.de&lt;br /&gt;Changed:      2006-01-25T10:52:53+01:00&lt;br /&gt;&lt;/pre&gt;Frustrated,&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-3860302776528610225?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/3860302776528610225/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=3860302776528610225' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3860302776528610225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3860302776528610225'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/05/serversnoffline.html' title='Serversnoffline'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4877202336004848448</id><published>2007-05-07T01:35:00.000-07:00</published><updated>2007-05-09T07:55:10.569-07:00</updated><title type='text'>t-offline</title><content type='html'>Parts of Serversniff.net are offline. Lightning stroke friday evening.&lt;br /&gt;&lt;br /&gt;The Domain-Database and some Utilities are hosted at my attic - a diskarray and a desktop-pc running beteween stored camping-equipment, Skates, old books and old electronics and cables, all connected via DSL, operated by german monopolist-telco &lt;a href="http://telekom.de/"&gt;Deutsche Telekom&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I live in a rural area with occasional thunderstorms and lightning strikes near my house every now and then. I might have got a bad line: Whenever a lightning strikes near my line, i'm offline. No Phone, no DSL, no Internet. It's dead, Jim.&lt;br /&gt;&lt;br /&gt;No, don't even think about Telekom monitoring the lines functionality. You'll have to contact their callcenter - by phone or internet. If you're lucky, you get a nice phone-computer, and after repeating "STÖRUNG" again and again unless the shitty machine understands, you will hear that all lines are busy. I had this Friday, i had this Saturday, i had this Sunday - about a hundred calls, unless i finally got through sunday afternoon.&lt;br /&gt;&lt;br /&gt;The phone-computer-odyssee continues: you have to enter your phone-number twice. Again, you have to confirm the number by yelling YESYESYES and you have to confirm the AreaCode by yelling YESYESYES and then you get a nice lady that is able to tell you, yeah, the line is dead ("lady, thats why I am calling!!"), and yeah, she will appoint this to a technician, but , oh well, Deutsche Telekom is on strike. Yeah, Tuesday morning.&lt;br /&gt;&lt;br /&gt;It'll be like it was the times before: The technican will replace a fuse in the local switch-unit, call in to say that everything's fine again, and the familiy will have phone and internet again.&lt;br /&gt;&lt;br /&gt;I do pay around €100 a month for phone and internet - this is defintely not the service i expect for ~1.000 Bucks a year - but since Telekom is still the only one to provide infrastructure where i live, things will stay like this until i find a place to colocate serversniffs backend for electricity-costs only. If you can offer space (no need for a rack, just around 1 MBit connectivity) you're welcome to drop me a mail at &lt;a href="mailto:thomas.springer@servernsiff.net"&gt;thomas.springer@serversniff.net&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Until then you might experience a few outages during thunderstorm-season in our german summer. If you're annoyed by the outage, please keep in mind: It's a free service.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4877202336004848448?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4877202336004848448/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4877202336004848448' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4877202336004848448'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4877202336004848448'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/05/t-offline.html' title='t-offline'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-7397873333932499244</id><published>2007-04-27T00:58:00.000-07:00</published><updated>2007-04-27T02:16:50.488-07:00</updated><title type='text'>abuse won't pay</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_L52Vgx7c_mo/RjGto3JN3TI/AAAAAAAAABA/MyUzpzHJ-SQ/s1600-h/ts171.png"&gt;&lt;img style="cursor: pointer;" src="http://bp3.blogger.com/_L52Vgx7c_mo/RjGto3JN3TI/AAAAAAAAABA/MyUzpzHJ-SQ/s400/ts171.png" alt="" id="BLOGGER_PHOTO_ID_5058014774022757682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Dear indian guy,&lt;br /&gt;&lt;br /&gt;this is a view on our internal log-display.&lt;br /&gt;&lt;br /&gt;You're simply wasting bandwith and router-resources. Yours, and ours.&lt;br /&gt;&lt;br /&gt;The requests  behind the ABUSE-Lines simply result in an ASCII-Page beeing displayed instead of real results. A(b/m)used,&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-7397873333932499244?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/7397873333932499244/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=7397873333932499244' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7397873333932499244'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/7397873333932499244'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/04/abuse-wont-pay.html' title='abuse won&apos;t pay'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_L52Vgx7c_mo/RjGto3JN3TI/AAAAAAAAABA/MyUzpzHJ-SQ/s72-c/ts171.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4835283621410808132</id><published>2007-04-26T11:47:00.000-07:00</published><updated>2007-04-26T12:01:01.389-07:00</updated><title type='text'>Automated use...</title><content type='html'>It took two years, but now people start to use serversniff.net automated - despite the crazy redirect-mechanism. Some indian guy or gal put effort into doing a script to milk serversniff.net.&lt;br /&gt;&lt;br /&gt;I expected this much earlier. Until now we had only very rudimentary abuse-checks to prevent serversniff.net beeing used for a denial of service against a host or a network. Now we tightened our abuse-checks to catch automated use on some scripts.&lt;br /&gt;&lt;br /&gt;We encourage automated use of serversniffs functionalities, sites like &lt;a href="http://www.paterva.com"&gt;www.paterva.com&lt;/a&gt; do this already - but please guys, talk to us before. We can make stuff easier for you. No need to write crazy perl-scripts or ugly curl-commandlines. We won't bite, really.&lt;br /&gt;&lt;br /&gt;&lt;a href="mailto:thomas.springer@serversniff.net"&gt;tom&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4835283621410808132?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4835283621410808132/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4835283621410808132' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4835283621410808132'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4835283621410808132'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/04/automated-use.html' title='Automated use...'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5792275093388673103</id><published>2007-03-25T09:27:00.000-07:00</published><updated>2007-03-25T09:35:12.721-07:00</updated><title type='text'>Fletcher-Checksums added</title><content type='html'>Following a user-request I added fletcher-checksums (8Bit-Fletcher and 16Bit-Fletcher) to &lt;a href="http://serversniff.de/crypt-checksum.php"&gt;http://serversniff.de/crypt-checksum.php.&lt;/a&gt;&lt;br /&gt;I couldn't find any ready-to-use implementation, so recoded it in php. for the sake of having a fletcher-implementation in php online:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family: courier new;"&gt;# 8 bit-fletcher&lt;br /&gt;# codes an 8bit-fletcher-hash out of an&lt;br /&gt;# hexencoded input-string&lt;br /&gt;# consider this code public domain&lt;br /&gt;#&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;$x="10111214" #hexecoded input-string&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;$twochunks=str_split($x,2); # split string into chunks&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;$lastleft=1; $lastright=0;       # init&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;$modulo=65535; # fletcher-modulus&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;foreach($twochunks as $char)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    $lastleft=fmod(($lastleft+hexdec($char)),$modulo); #left&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    $lastright=fmod(($lastright+$lastleft),$modulo); #right&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;$hexright=dechex($lastright); # make a hexval out of the old dec-val&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;$hexleft=dechex($lastleft);      # make a hexval out of the old dec-val&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;$fletcher8="$hexright"."$hexleft";  # combine the two&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;print $fletcher8;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;exit;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family: courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5792275093388673103?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5792275093388673103/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5792275093388673103' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5792275093388673103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5792275093388673103'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/03/fletcher-checksums-added.html' title='Fletcher-Checksums added'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5018235870278734570</id><published>2007-03-25T08:16:00.000-07:00</published><updated>2007-03-25T08:32:47.694-07:00</updated><title type='text'>Twisting and Tuning</title><content type='html'>We tweaked the &lt;a href="http://serversniff.net/content.php?do=ipinfo"&gt;ip-info-script&lt;/a&gt;: It's working properly with icmp now, while a bug prevented it from workin correctly with icmp. Reinhard tweaked it to add a few flags, but until now i'm not really sure if they do make any sense. We'll see from the log or comments.&lt;br /&gt;We also got rid of the redirect, which seemed to have prevent the page beeing used with konqueror. May there be no more bugs in there...&lt;br /&gt;&lt;br /&gt;cheers,&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5018235870278734570?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5018235870278734570/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5018235870278734570' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5018235870278734570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5018235870278734570'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/03/twisting-and-tuning.html' title='Twisting and Tuning'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-1847361242482845891</id><published>2007-03-23T07:31:00.000-07:00</published><updated>2007-03-23T08:05:34.113-07:00</updated><title type='text'>spinnoffs, volume one or "size DOES matter"</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_L52Vgx7c_mo/RgPoGXvEgXI/AAAAAAAAAAM/O0x3Tc0RF_A/s1600-h/ts137.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_L52Vgx7c_mo/RgPoGXvEgXI/AAAAAAAAAAM/O0x3Tc0RF_A/s320/ts137.png" alt="" id="BLOGGER_PHOTO_ID_5045131203733389682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;We're currently working on some small serversniff-spinoffs. Very focussed microsites with limited functionality. The first to be launched a few days ago was &lt;a href="http://www.hashcrack.com/"&gt;&lt;span style="font-weight: bold;"&gt;www.hashcrack.com&lt;/span&gt;&lt;/a&gt;, a site dedicated to reverse-lookups for several hashtypes.&lt;br /&gt;&lt;br /&gt;We know quite a lot of hash-crackers and reverse-lookup-sites - but none of them was the thing we really wanted. Most of them have a limited count of hashes - the biggest we found were &gt;200.000.000 words. There are a few bigger ones supporting crackers like &lt;a href="http://www.openwall.com/"&gt;john the ripper&lt;/a&gt; or rainbow-tables.&lt;br /&gt;&lt;br /&gt;But almost all are limited to MD5-Lookups. Hey guys, it's 2007 and we do it-security. Occasionally i need to reverse other unsalted hashes: MySQL, SHA1 or plain old Windows, be it NTLM or LanMananger. Computingpower and harddrives are cheap - so were working on the ultimate site for database-driven hashlookus, supporting&lt;br /&gt;&lt;ul&gt;&lt;li&gt;MD5&lt;/li&gt;&lt;li&gt;SHA1&lt;/li&gt;&lt;li&gt;LanManager&lt;/li&gt;&lt;li&gt;NTLM&lt;/li&gt;&lt;li&gt;MySQL 3&lt;/li&gt;&lt;li&gt;MySQL 4&lt;/li&gt;&lt;/ul&gt;We were looking for wordlists. We gathered what we could get hold of, threw it together and did a little sorting. We ended up with 250MB of plaintext. We used john the ripper to create a list with all possible character-combinations for 1-4 chars length. Another 410 MB plaintext. I did want more, so i downloaded almost all wikipedia-databases, threw them together in a huge textfile, sorted out very long and very short strings, sorted out some wiki-formatting, sorted out all the millions of dupes and ended up with a gzipped file with a size of 202 MB that we simply call the mother of all wordlists. We're in the process of importing all three lists into our hash database.&lt;br /&gt;Hashcrack.com currently lists 11.000.000 Words with ~ 65.000.000 Hashes on a (nearly) static database for we needed some data to experiment with. When we're finished with creating all those hashes we'll simply upgrade hashcrack.com to far more than 1.000.000.000 known hashes, hoping that it'll be of any use.&lt;br /&gt;We welcome any opinions, comments and listings of your favourite reverse-lookup-sites.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-1847361242482845891?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/1847361242482845891/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=1847361242482845891' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/1847361242482845891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/1847361242482845891'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/03/spinnoffs-volume-one-or-size-does.html' title='spinnoffs, volume one or &quot;size DOES matter&quot;'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_L52Vgx7c_mo/RgPoGXvEgXI/AAAAAAAAAAM/O0x3Tc0RF_A/s72-c/ts137.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4138197972241635700</id><published>2007-03-21T07:51:00.000-07:00</published><updated>2007-03-21T07:56:57.549-07:00</updated><title type='text'>encryption is online again</title><content type='html'>our encrypter/decrypter is online again. while &lt;a href="http://www.edv-weidacher.de/"&gt;reinhard &lt;/a&gt;is workin hard to learn cryptography for his ceh-exam he fixed the script and put it online again. thanks reinhard!&lt;br /&gt;reinhard also promised to work on new dns-scripts, too! go boy, go!&lt;br /&gt;&lt;br /&gt;and, how nice: spammers read our blog - there were no new requests asking to sell our domainbase to obscure partys during the last week.&lt;br /&gt;&lt;br /&gt;cheers,&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4138197972241635700?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4138197972241635700/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4138197972241635700' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4138197972241635700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4138197972241635700'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/03/encryption-is-online-again.html' title='encryption is online again'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-4629232872174581437</id><published>2007-03-02T02:59:00.000-08:00</published><updated>2007-03-02T03:15:06.302-08:00</updated><title type='text'>domainnames for sale....</title><content type='html'>we got quite a few requests to sell our domain-database during the last weeks. we continue to refuse almost all of them.&lt;br /&gt;&lt;br /&gt;please: don't bother to ask unless you agree to serversniff's &lt;a href="http://www.serversniff.net/wiki_en/index.php?title=Terms_of_use"&gt;terms of use&lt;/a&gt;.&lt;br /&gt;don't bother to ask unless you can't prove in any way that you are willing to abide by this terms.&lt;br /&gt;&lt;br /&gt;like anyone else having an emailadress we get more than enough email-spam. we're not really interested in domainname-business and SEO (which would better be spelled SESpam) and we do not consider this business to create any added value for internet-security or the internet itself.&lt;br /&gt;&lt;br /&gt;maybe i won't make the world any better, but i'll keep tryin not to make it any worse than it already is.&lt;br /&gt;&lt;br /&gt;cheers,&lt;br /&gt;&lt;br /&gt;&lt;a href="mailto:thomas.springer@serversniff.net"&gt;tom&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-4629232872174581437?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/4629232872174581437/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=4629232872174581437' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4629232872174581437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/4629232872174581437'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/03/domainnames-for-sale.html' title='domainnames for sale....'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-2771146117594523431</id><published>2007-02-21T02:19:00.000-08:00</published><updated>2007-02-21T02:33:12.272-08:00</updated><title type='text'>Back to "normal" operation</title><content type='html'>We're back to normal operation, all tools should work fine now. Still missing are the "Crypt-Decode", Crypt-Encrypt/Decrypt and the Virus-Check.&lt;br /&gt;&lt;br /&gt;Crypt-Decode will come back in a few days. Crypt-Encrypt/Decript too. The Virus-Check will be implemented into the new File-Info-Tool we're working on.&lt;br /&gt;&lt;br /&gt;We're currently developing new tools and improving old ones.&lt;br /&gt;The crypto- and encoding-Scripts already support a few new Hash/CRC/Encoding-Algorithms, more will follow.&lt;br /&gt;The SSL-Check will soon support even more ciphers, making it the best SSL-Check we know, checking more ciphers and functionality than any other SSL-Check, be it offline or online.&lt;br /&gt;We're currently working on a sort of "decompiler" for unpacking and decompiling a bunch of different formats ranging from macromedia flash (.swf) or Microsofts Winword (including macros and plaintext) to fullblown java-applets.&lt;br /&gt;We consider a bunch of other applications making live of security-guys easier - but we'd love to have your input: can you think of a (not yet available) tool to ease your work? - Drop us a &lt;a href="mailto:thomas.springer@serversniff.net"&gt;mail &lt;/a&gt;or write a comment - we're open to anything.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-2771146117594523431?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/2771146117594523431/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=2771146117594523431' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2771146117594523431'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/2771146117594523431'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/02/back-to-normal-operation.html' title='Back to &quot;normal&quot; operation'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-5413019738603215079</id><published>2007-02-19T07:26:00.000-08:00</published><updated>2007-02-19T07:39:46.024-08:00</updated><title type='text'>serversnoffline</title><content type='html'>Serversniff was down, and is up again. With a reduced toolset, still. I kicked the old installation in a fit of rage when a bunch of tools failed to compile due to &lt;a href="http://www.suse.com/"&gt;Suse&lt;/a&gt;'s crazy path-structure.&lt;br /&gt;&lt;br /&gt;I always hated Suse, and since years \me refuses to work with any non-&lt;a href="http://www.debian.org/"&gt;debian&lt;/a&gt;-system whenever possible. We had to choose Suse for Serversniffs hoster &lt;a href="http://www.strato.de"&gt;Strato &lt;/a&gt;didn't offer anything else a year ago.&lt;br /&gt;&lt;br /&gt;Things have changed, Strato offers other distributions. We set up a new system on debian sarge, updated from sid to be more up2date. We did a restore from backup, which worked quite well, despite some upgrade-hassle with mysql (4-&gt;5) or some changed network-functionalities or text-output from commandlinetools like ping.&lt;br /&gt;&lt;br /&gt;We're still missing the SSL- and the Crypto-Functions, and many API-Functions still fail or behave a bit strange - We will restore these during the next few days - they had to be revamped anyway, so expect more api-functions and public stuff to run a bit smoother when it's all restored. We apologize for any inconvinience.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-5413019738603215079?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/5413019738603215079/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=5413019738603215079' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5413019738603215079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/5413019738603215079'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/02/serversnoffline.html' title='serversnoffline'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6421733839255125758</id><published>2007-02-15T02:29:00.000-08:00</published><updated>2007-02-15T02:32:01.180-08:00</updated><title type='text'>Showing hidden Meta-Information in DOC, PDF and more than 100 other file-formats</title><content type='html'>Did you hear about hidden information in formats like Microsofts .doc?&lt;br /&gt;&lt;br /&gt;We did. Yeah. You too. For most of us this is old news. Read &lt;a href="http://www.stc-psc.org/Newsletter/archivedNewsletters/May_June_2005/newsletter_article.2006-01-06.5409202925"&gt;here &lt;/a&gt;or &lt;a href="http://www.enewsbuilder.net/techcommanager/e_article000507288.cfm?x=b11,0,w"&gt;here&lt;/a&gt;, or ask your favourite &lt;s&gt;big brother&lt;/s&gt;search-engine.&lt;br /&gt;Everybody should know this - but people everywhere, from government to No Such Agencys keep publishing winword-documents on their websites.&lt;br /&gt;&lt;br /&gt;During our penetration tests (and during our internal FileInfo-tests) we came across quite many websites with chatty files, especial .doc. We were fed up to explain this again and again and created a nifty little tool to analyze as many file-formats as possible. If you want to give it a beta-try, check by at Serversniffs "&lt;a href="http://serversniff.net/file-info.php"&gt;FileInfo&lt;/a&gt;". Currently this does ONLY files on webservers, this means the file to be checked has to be on some public webserver. Beware: The check is more than slow and supports only files with a size smaller than 1 MB. It also fails on filenames with blanks or %20. It's BETA. Stuff will get better with our next serverupgrade, which will finally kick SuSe-Linux into /dev/nul.&lt;br /&gt;&lt;br /&gt;Examples in Winword, containing a bit of hidden information (and no, we won't post any files with hidden text here!)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://serversniff.net/image/blog_fileinfo1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px;" src="http://serversniff.net/image/blog_fileinfo1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://serversniff.net/image/blog_fileinfo2.png"&gt;&lt;img style="cursor: pointer; width: 400px;" src="http://serversniff.net/image/blog_fileinfo2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;It's not only winword that is chatty - we also found loads of PDF-files on websites  containing Windows-Usernames of the people who created them. This might get dangerous when you are able to determine the user-structure and naming-convention of an organisation. While many pdfs are clean, there seem to a few PDF-Creator-Tools that we found to be vulnerable by default.&lt;br /&gt;&lt;br /&gt;Especially Acrobat Distiller puts realnames or Windows-Usernames into the PDFs Meta-Information: (examples: http://www.verfassungsschutz.de/download/SHOW/symp_2006_abstract_pet.pdf or http://www.nsa.gov/publications/publi00010.pdf, both showing usernames in "Author" and "Creator"-Fields.&lt;br /&gt;This seems to be configurable: Google did a better job, see http://www.google.com/ads/techb2b_news.pdf, while Yahoo puts usernames in many files, like this here http://publisher.yahoo.com/rss/RSS_whitePaper1004.pdf.&lt;br /&gt;&lt;br /&gt;Feel free to experiment. FileInfo will display internal Meta-Information for more than 100 File-Formats.&lt;br /&gt;&lt;br /&gt;Please drop us a &lt;a href="mailto:thomas.springer@serversniff.net"&gt;mail &lt;/a&gt;you're stumbling over something funny or if you just like the tool- we'll do our best trying to fix stuff or add more file-formats and functionality, and we're waiting for any user-input.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6421733839255125758?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6421733839255125758/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6421733839255125758' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6421733839255125758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6421733839255125758'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/02/showing-hidden-meta-information-in-doc.html' title='Showing hidden Meta-Information in DOC, PDF and more than 100 other file-formats'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-3426667226036287855</id><published>2007-02-14T00:52:00.000-08:00</published><updated>2007-02-14T00:58:40.919-08:00</updated><title type='text'>The Big Big AXFR</title><content type='html'>I like the global AXFRS posted in one of the comments to my previos posting. Have a look at Maximilian Dornseifs well-hidden blogentry at &lt;a href="http://blogs.23.nu/disLEXia/stories/10092/"&gt;http://blogs.23.nu/disLEXia/stories/10092/&lt;/a&gt; to get an idea on how to automate this. Maximilian missed, that there is a hell of secondary-TLDs like co.uk, ac.uk etc. etc.&lt;br /&gt;He also missed that there are a few real big hosters and providers who return far more entrys than many TLDs.&lt;br /&gt;&lt;br /&gt;But all in all this blogentry was one of the reasons to create &lt;a href="http://tomdns.net"&gt;tomdns.net&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Thanks, Maximilian.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-3426667226036287855?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/3426667226036287855/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=3426667226036287855' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3426667226036287855'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/3426667226036287855'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/02/big-big-axfr.html' title='The Big Big AXFR'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-6744757039482980931</id><published>2007-02-13T00:52:00.000-08:00</published><updated>2007-02-13T00:52:06.167-08:00</updated><title type='text'>Where do i get domains....</title><content type='html'>Dear kids,&lt;br /&gt;&lt;br /&gt;I understand completely that you  ask me where to download a list of 100.000.000 domains.&lt;br /&gt;&lt;br /&gt;I did, and this drove a few GB traffic to a website. Can you imagine what would happen if i'd post any such url here? Boys, i guess you can. So please, have a look at &lt;a href="http://johnny.ihackstuff.com/"&gt;http://johnny.ihackstuff.com/&lt;/a&gt; and try to have fun with our favourite search-engine as well.&lt;br /&gt;&lt;br /&gt;Another option: Since most of the URLs listed on the site are .com/.net, you might also get them directly from verisign. The TOS there are roughly the same as the TOS at www.serversniff.net, in fact i derived serversniffs Terms of Service from Versign, for the last what i wanted to do is support f*cking spammers.&lt;br /&gt;&lt;br /&gt;Or: Create something on your own. Something to offer, me or the "community". Then come back on me and ask. I'd be happy to support you with a list of domains if you're able to explain what you're workin on. I'd be happy to team up with you if there is any win-win-situation.&lt;br /&gt;&lt;br /&gt;If you're working for a company: I'd be happy to support you with hostnames, domainnames or known IP's, filtered by whatever you want, given that you're willing to agree to our &lt;a href="http://www.serversniff.net/wiki_en/index.php?title=Terms_of_use"&gt;ToS&lt;/a&gt;.  Drop me a mail and I'm quite sure we'll negotiate a reasonable agreement.&lt;br /&gt;&lt;br /&gt;Tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-6744757039482980931?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/6744757039482980931/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=6744757039482980931' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6744757039482980931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/6744757039482980931'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/02/where-do-i-get-domains.html' title='Where do i get domains....'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-117067103758802619</id><published>2007-02-05T01:52:00.000-08:00</published><updated>2007-02-05T02:23:57.606-08:00</updated><title type='text'>before the flood....</title><content type='html'>We are in the process of updating our domain-database: we just started an insert of roughly 150.000.000 hostnames, bringing our db-system to the limit.&lt;br /&gt;&lt;br /&gt;We ceased "regular" spidering and updates for a while to catch up with this bulk-data. Currently we run at a rate of about 1.000.000 new domains per day, which we consider not really bad, but still unsatisfying. We are currently testing a NAS-Array running on 6 SCSI-Disks (currently as an experiment - we will invest in more hardware if this proves to be faster than the current system).&lt;br /&gt;&lt;br /&gt;thomas&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-117067103758802619?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/117067103758802619/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=117067103758802619' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/117067103758802619'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/117067103758802619'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2007/02/before-flood.html' title='before the flood....'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-116678454971055486</id><published>2006-12-22T02:37:00.000-08:00</published><updated>2006-12-22T02:52:53.326-08:00</updated><title type='text'>Encryption added</title><content type='html'>Its christmas and we are working on extending and finetuning serversniff.net. We added a bunch of encryption-functions recently to check how common ciphers treat your text. While this is not designed to be used in a productive environment, it might be useful to check some other implementation of these ciphers.&lt;br /&gt;&lt;br /&gt;Please be aware of  possible keylengths and used blockmodes!&lt;br /&gt;&lt;br /&gt;We are currently workin with the mcrypt-lib and support AES (Several Modes), Blowfish, CAST, DES, 3DES (TripleDES), GOST, LOKI97, RC2, RC4, Saferplus, Serpent, Twofish, Wake and XTEA.&lt;br /&gt;&lt;br /&gt;Expect more Ciphers (and Blockmodes) to come when we gathered some experience with the current set.&lt;br /&gt;&lt;br /&gt;tom&lt;br /&gt;&lt;table&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-116678454971055486?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/116678454971055486/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=116678454971055486' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116678454971055486'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116678454971055486'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/12/encryption-added.html' title='Encryption added'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-116663851882463451</id><published>2006-12-20T10:12:00.000-08:00</published><updated>2006-12-20T10:15:18.836-08:00</updated><title type='text'>Encryption</title><content type='html'>We changed our hash-pages and updated stuff:&lt;br /&gt;&lt;br /&gt;We do support Hashes (Strings, Files), Checksums (Strings), Several Encodings (Strings) and finally a bunch of cryptographic function. Just have a look at the new "Crypto"-Submenu on &lt;a href="http://serversniff.net"&gt;serversniff.net&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-116663851882463451?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/116663851882463451/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=116663851882463451' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116663851882463451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116663851882463451'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/12/encryption.html' title='Encryption'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-116540766086006592</id><published>2006-12-06T04:15:00.000-08:00</published><updated>2006-12-06T04:21:00.873-08:00</updated><title type='text'>Yes, we are...</title><content type='html'>we got a request to sell serversniff.net. hey, we are bribable. direct your offers to sales@serversniff.net - we'll negotiate all the rest.&lt;br /&gt;If you  just  find serversniff to be useful or want to implement functions in your website, there is no need to buy the whole stuff. Just drop us a mail to get access to our api-functions. We still don't charge nothing for its use as long as you are using it reasonably.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-116540766086006592?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/116540766086006592/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=116540766086006592' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116540766086006592'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116540766086006592'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/12/yes-we-are.html' title='Yes, we are...'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-116531915311205028</id><published>2006-12-05T03:42:00.000-08:00</published><updated>2006-12-06T04:23:10.166-08:00</updated><title type='text'>Finetuning and cleaning up</title><content type='html'>We started finetuning serversniff a little bit - fixing the ton of bugs still laying around, adding a bit of sorting or optics here and there or extend the explanations of a few scripts. Switched a few scripts from a generic approach to using serversniff's API - stuff like that. Not really noticable at all, but eating up enough time on our side.&lt;br /&gt;We're dreaming of many many new functions to come - if only time would allow...&lt;br /&gt;&lt;br /&gt;Tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-116531915311205028?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/116531915311205028/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=116531915311205028' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116531915311205028'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116531915311205028'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/12/finetuning-and-cleaning-up.html' title='Finetuning and cleaning up'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-116186269086249558</id><published>2006-10-26T04:32:00.000-07:00</published><updated>2006-10-26T04:38:10.936-07:00</updated><title type='text'>New HTTP-API-Functions</title><content type='html'>We updated our HTTP-checks and added new API-Funktions. You can craft your own HTTP-requests now, e.g. do a GET with HTTP 1.0 with or without Host-Header and check the response, either only the HTTP-Servers header-info or the complete file, you can even filter for some special lines e.g. to get only the Server-Header or so.&lt;br /&gt;This check does support servers listening on multiple IPs and is also capable of doing https.&lt;br /&gt;We started implementing this backend to Serversniffs frontend - you might expect more HTTP-Checks based on this backendscript to come.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-116186269086249558?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/116186269086249558/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=116186269086249558' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116186269086249558'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116186269086249558'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/10/new-http-api-functions.html' title='New HTTP-API-Functions'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-116023288107957571</id><published>2006-10-07T07:50:00.000-07:00</published><updated>2006-10-07T07:54:41.090-07:00</updated><title type='text'>New Scripts</title><content type='html'>The IP-Scripts are coming back.&lt;br /&gt;&lt;br /&gt;We are on our way to extend serversniff with some new IP-Scripts. We started  today with a simple icmp-ping, that simply sends 4 ICMP-Echo-Requests to a given host.&lt;br /&gt;&lt;br /&gt;Additionally, for a simple ping would be quite lame, we implented what we call a "Ping-Row", that sends about 16 ICMP-Echo-Requests with increasing packetsizes. You'll be surprised how many sites allow small pings, while their routers or firewalls sort out the hugeICMP-Packets.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-116023288107957571?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/116023288107957571/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=116023288107957571' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116023288107957571'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/116023288107957571'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/10/new-scripts.html' title='New Scripts'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-115918380845992217</id><published>2006-09-25T04:13:00.000-07:00</published><updated>2006-09-25T04:30:12.973-07:00</updated><title type='text'>Extending the API</title><content type='html'>Our domain-database seems to be up and running: the scripts run very stable, we run a few background-tasks that are feeding the database with around 50.000 new domains per day.&lt;br /&gt;&lt;br /&gt;We are working on further extensions of our API in combination with our checkomatik. Although we missed owasp's "automn of code" we are confident that we will release a full-featured version of checkomatik by the end of this year.&lt;br /&gt;&lt;br /&gt;While we are using it internally since months, it still lacks a real user-dependent interface, security, translation and, most important, automation.&lt;br /&gt;&lt;br /&gt;We got a few steps up the ladder with creating more api-functions, stuff like the "&lt;a href="http://www.serversniff.net/wiki_en/index.php?title=API#ICMP-Pingrow"&gt;pingrow&lt;/a&gt;" or a complete &lt;a href="http://www.serversniff.net/wiki_en/index.php?title=API#All_SSL-Ciphers"&gt;ssl-check&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-115918380845992217?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/115918380845992217/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=115918380845992217' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115918380845992217'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115918380845992217'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/09/extending-api.html' title='Extending the API'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-115489219476237971</id><published>2006-08-06T12:02:00.000-07:00</published><updated>2006-08-06T12:24:31.056-07:00</updated><title type='text'>Domain Kiting - how many hosts fit on one ip?</title><content type='html'>Bob Parson wrote in his noteworthy blog about Domain-Kiting - see &lt;a href="http://www.bobparsons.com/DomainKiting.html"&gt;http://www.bobparsons.com/DomainKiting.html&lt;/a&gt; - and i thought it should be possible to identify kited domains easily by querying Serversniff.net's host-database: A kited domain i thought will share its IP with many many other hosts. So i started gathering a list of known ips sorted by the count of known hostnames living on this ip. I ended up with the following list:&lt;br /&gt;&lt;br /&gt;Known&lt;br /&gt;Hostnames  -  IP&lt;br /&gt;---------------------&lt;br /&gt;    142643 | 194.159.245.16&lt;br /&gt;    132972 | 64.72.112.11&lt;br /&gt;    123455 | 127.0.0.1&lt;br /&gt;     59117 | 67.108.253.121&lt;br /&gt;     46819 | 66.165.220.18&lt;br /&gt;     40765 | 213.29.7.212&lt;br /&gt;     36617 | 70.84.80.195&lt;br /&gt;     34971 | 81.94.227.213&lt;br /&gt;     32697 | 219.153.13.42&lt;br /&gt;     32415 | 203.36.59.60&lt;br /&gt;     31617 | 134.58.241.14&lt;br /&gt;     29830 | 66.102.15.101&lt;br /&gt;     29142 | 209.163.113.99&lt;br /&gt;     27024 | 217.76.128.34&lt;br /&gt;     25405 | 70.84.48.227&lt;br /&gt;     23997 | 212.227.34.3&lt;br /&gt;     22636 | 70.85.132.35&lt;br /&gt;     19653 | 209.249.170.10&lt;br /&gt;     19553 | 216.200.145.43&lt;br /&gt;     19543 | 216.200.145.44&lt;br /&gt;     19168 | 209.185.12.47&lt;br /&gt;     19036 | 195.117.6.10&lt;br /&gt;     18994 | 70.86.121.3&lt;br /&gt;     18387 | 66.220.2.7&lt;br /&gt;     18311 | 66.220.2.9&lt;br /&gt;     17638 | 211.239.151.191&lt;br /&gt;     17459 | 61.142.254.216&lt;br /&gt;     17360 | 66.98.195.129&lt;br /&gt;     17132 | 205.178.189.131&lt;br /&gt;     17018 | 203.74.57.13&lt;br /&gt;     16961 | 82.208.4.213&lt;br /&gt;     16677 | 65.98.98.75&lt;br /&gt;     16253 | 70.86.143.154&lt;br /&gt;     15815 | 134.58.126.198&lt;br /&gt;     15807 | 134.58.126.199&lt;br /&gt;     13998 | 209.25.170.64&lt;br /&gt;     13952 | 64.202.189.170&lt;br /&gt;     13597 | 213.29.7.211&lt;br /&gt;     13565 | 217.116.0.144&lt;br /&gt;     13142 | 213.21.186.51&lt;br /&gt;     13131 | 65.98.98.59&lt;br /&gt;     12883 | 213.4.134.161&lt;br /&gt;     12711 | 213.239.203.47&lt;br /&gt;     12458 | 207.217.96.28&lt;br /&gt;     12444 | 207.217.96.29&lt;br /&gt;     12439 | 207.217.96.30&lt;br /&gt;     12437 | 207.217.96.32&lt;br /&gt;     12437 | 207.217.96.31&lt;br /&gt;     12436 | 207.217.96.33&lt;br /&gt;&lt;br /&gt;So the Hostnames hosted at 127.0.0.1 might not be kited but the rest: the impressive figures for  64.72.112.11 e.g.: 132972 hostnames. Kited? - No, not at all. Whatever host- and domainname we checked on this domain was not kited, not even parked, but operational. It might be a loadbalancer behind - but i find this count of hostnames for one single IP still impressive.&lt;br /&gt;&lt;br /&gt;Checking the other hosts we found a lot of parked and not too many kited domains. By explicitly checking known kited domainnames like namenddomain.com we found, that most kited domains live together with parked domain-names on one host - often with as less as 4.000 known hostnames for this special ip. But still: on the named IPs you might (or might not) found a lot of kited domains. If you bring a few minutes of patiences, you might use the "&lt;a href="http://serversniff.net/content.php?do=hostonip"&gt;host-on-ip&lt;/a&gt;"-function on http://serversniff.net to check these ips for hostnames living there.&lt;br /&gt;Restart your query if you don't get an answer after about a minute - it'll be faster then, for the database has stuff in its cache.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-115489219476237971?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/115489219476237971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=115489219476237971' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115489219476237971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115489219476237971'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/08/domain-kiting-how-many-hosts-fit-on.html' title='Domain Kiting - how many hosts fit on one ip?'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-115434513863070497</id><published>2006-07-31T04:23:00.001-07:00</published><updated>2006-07-31T04:28:20.423-07:00</updated><title type='text'>Statistics</title><content type='html'>We know:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;       20.032.470 Hosts &lt;/li&gt;&lt;li&gt; 5.357.250 Domains &lt;/li&gt;&lt;li&gt; 7.812.218 IPs &lt;/li&gt;&lt;li&gt; 224.337 Nameservers &lt;/li&gt;&lt;li&gt; 39.914 Mailservers&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;(We just started with sorting in Mail- and Nameservers - we are sorting in MX- and NS-Records for around 200.000 Domains per Day, so MX- and NS- figures will continue to increase for about 20 to 30 days.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-115434513863070497?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/115434513863070497/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=115434513863070497' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115434513863070497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115434513863070497'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/07/statistics_31.html' title='Statistics'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-115391232597365633</id><published>2006-07-26T03:59:00.000-07:00</published><updated>2006-07-26T04:12:05.993-07:00</updated><title type='text'>5 Million Domains</title><content type='html'>We cracked the 5-Million-Mark on our domain-database. Serversniff know knows more than 5 million unique domain-names, which should represent around 5 percent of all globally registered domainnames.&lt;br /&gt;&lt;br /&gt;We will keep inserting new hosts and domains daily, and the more you look up the more we will know. The update-speed might decrease slightly for we are on the run to update our data with NS- and MX-records. We might finish this in a few months and serversniff will offer many new functions then.&lt;br /&gt;&lt;br /&gt;A domainsearch is implemented, a hostnamesearch looking up hosts in our 35-million-hostnames-db will be in place soon - both functions are available via our API only at the moment. Access to our API-services is free, but requires a formless registration - send an EMail to &lt;a href="mailto:thomas.springer@serversniff.net"&gt;thomas.springer@serversniff.net&lt;/a&gt; to get a free personal account.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-115391232597365633?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/115391232597365633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=115391232597365633' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115391232597365633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115391232597365633'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/07/5-million-domains.html' title='5 Million Domains'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-115218595193752998</id><published>2006-07-06T04:30:00.000-07:00</published><updated>2006-07-06T04:39:11.960-07:00</updated><title type='text'>Unstable Server</title><content type='html'>Serversniff doesn't like &lt;a href="http://www.sw-soft.com"&gt;virtuozzo&lt;/a&gt;. You might imagine that we call a lot of backend-programms to let serversniff do it's job. When there are too many background-processes and not enough (shared) RAM, the apache-process is silently dying and can't be restarted, it can't even be killed.&lt;br /&gt;&lt;br /&gt;Virtuozzo is nice, but is nothing compared to stuff like VMWare. Providers like virtuozzo, for it make every virtual machine on a host run on only one system-installation, while each vmware-engine has its own os and eats therefore much more ram and hd-space.&lt;br /&gt;&lt;br /&gt;We decided that we don't like virtuozzo - so serversniff will (again) move to another server with the old one simply acting as some kind of proxy. while we move we will do some quality assurance and internal updates, it might take a few weeks until everything is moved completely.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-115218595193752998?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/115218595193752998/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=115218595193752998' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115218595193752998'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115218595193752998'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/07/unstable-server.html' title='Unstable Server'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-115078892813431263</id><published>2006-06-20T00:11:00.000-07:00</published><updated>2006-06-20T00:43:35.090-07:00</updated><title type='text'>hacked</title><content type='html'>nice.&lt;br /&gt;&lt;br /&gt;serversniff  has a bunch of security-holes, and we are watching closely what people are doing here - and really, someone noticed that it was quite easy to get a glimpse of the mysql-log-database.&lt;br /&gt;&lt;br /&gt;the evil hacker might have been a scriptkid, for he obviously got acces to the mysql-db, used an unkown (at least to major search-engines) mysql-exploit-script trying to create files on the system. the mysql-db died on the way to his goal.&lt;br /&gt;&lt;br /&gt;the attacker created (and then deleted or emptied) several tables in the db mysql:&lt;br /&gt;&lt;br /&gt;"SNOWHILL"&lt;br /&gt;"db" - nice - contains all passwords from table "user" in cleartext!&lt;br /&gt;"dat" - used to execute commands on the host&lt;br /&gt;"fm" - contains php-code to upload files and execute commands&lt;br /&gt;local - slightly different from "dat"&lt;br /&gt;sploitdb - slightly different from "dat"&lt;br /&gt;wip3r - slightly different from "dat"&lt;br /&gt;&lt;br /&gt;It seems, that the guy used at least 4 slightly different exploits targeting to the same problem.&lt;br /&gt;&lt;br /&gt;Better luck next time.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-115078892813431263?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/115078892813431263/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=115078892813431263' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115078892813431263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/115078892813431263'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/06/hacked.html' title='hacked'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-114814927668901439</id><published>2006-05-20T11:17:00.000-07:00</published><updated>2006-07-20T08:30:05.766-07:00</updated><title type='text'>sorting it all in</title><content type='html'>we're still importing hosts, this time from zonetransfers from toplevel-domains.&lt;br /&gt;in parallel we're sorting in domains - expect more functions to come.&lt;br /&gt;we crosschecked our data with whois.sc - while we still lack many .com-domains, it seems that we have many hostnames that they don't have.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-114814927668901439?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/114814927668901439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=114814927668901439' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/114814927668901439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/114814927668901439'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/05/sorting-it-all-in.html' title='sorting it all in'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-114716655581899713</id><published>2006-05-09T02:15:00.000-07:00</published><updated>2006-05-09T02:22:35.843-07:00</updated><title type='text'>fixing bugs</title><content type='html'>I'm pleased to announce that a simple forum-posting at &lt;a href="http://www.dnsstuff.com"&gt;dnsstuff.com&lt;/a&gt;  made me finally fix a few bugs in the subdomain-lookup that were resultin from the migration of serversniff to the f*cking virtuozzo-server.&lt;br /&gt;&lt;br /&gt;The migration of our Hostname-DB nearly comes to an end - we are around 18 million known hostnames now with around 1 million hosts left in the queue. After this we have a few million hostnames from zonefiles waiting to get in. In parallel we started to build a domain-database, but this will take some time - we are around a million known domains by now, adding around 70.000 new domains each day. Expect more functions to come when we extracted broader data from our database.&lt;br /&gt;&lt;br /&gt;And hey, we are still looking for Postgresql/Perl-Geek willing to speed up things here.&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-114716655581899713?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/114716655581899713/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=114716655581899713' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/114716655581899713'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/114716655581899713'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/05/fixing-bugs.html' title='fixing bugs'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21869293.post-114707608380632816</id><published>2006-05-08T00:48:00.000-07:00</published><updated>2006-05-08T01:14:43.833-07:00</updated><title type='text'>News</title><content type='html'>I did a few Bugfixes, mostly relating to the fact, that the crazy &lt;a href="http://www.swsoft.com/de/products/virtuozzo/"&gt;virtuozzo&lt;/a&gt;-system of our shared-server acts silly and resolves nonexisting hostnames as localhost or with it's own ip-number. i had to adjust many errorhandlers to this.&lt;br /&gt;&lt;br /&gt;A User noticed some "can't write to log"-errors on the IP-Stack-check. These are noncritical, in fact we don't really need the log anymore for the check does it's job quite well. We'll fix em by removing the detailed-logging that was initally used for debugging-purposes. Please be aware that the IP-Check is sitting on a separate host that is rather slow, for the above mentioned virtuozzo-stuff won't interact with &lt;a href="http://www.hping.org/"&gt;hping2&lt;/a&gt;, the programm this check is based upon.&lt;br /&gt;&lt;br /&gt;We expanded our API to many with many new serverchecks. We are offering 16 different, configurable checks now - a list is available at &lt;a href="http://www.serversniff.de/wiki_en/index.php/API"&gt;http://www.serversniff.de/wiki_en/index.php/API&lt;/a&gt;. Send us an &lt;a href="mailto:thomas.springer@gmail.com"&gt;E-Mail&lt;/a&gt; to get free access to the API. We want to know who's using our resources, but we're still offering all this for free.&lt;br /&gt;&lt;br /&gt;We also expanded Serversniffs capabilities and are offering scripts to &lt;a href="http://www.serversniff.de/httppage.php"&gt;show HTML-Sourcecode&lt;/a&gt; of webpages, &lt;a href="http://www.serversniff.de/httpcomments.php"&gt;HTML-Comments&lt;/a&gt; inside webpages, &lt;a href="http://www.serversniff.de/httplinks.php"&gt;Hyperlinks inside of weppages&lt;/a&gt;, &lt;a href="http://www.serversniff.de/httpcookies.php"&gt;Cookies set&lt;/a&gt; when visiting a Site and a &lt;a href="http://www.serversniff.de/httprobots.php"&gt;websites robots.txt&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Have fun and stay secure,&lt;br /&gt;&lt;br /&gt;tom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21869293-114707608380632816?l=serversniff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://serversniff.blogspot.com/feeds/114707608380632816/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21869293&amp;postID=114707608380632816' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/114707608380632816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21869293/posts/default/114707608380632816'/><link rel='alternate' type='text/html' href='http://serversniff.blogspot.com/2006/05/news.html' title='News'/><author><name>thomas</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
