Wednesday, December 06, 2006

Yes, we are...

we got a request to sell serversniff.net. hey, we are bribable. direct your offers to sales@serversniff.net - we'll negotiate all the rest.
If you just find serversniff to be useful or want to implement functions in your website, there is no need to buy the whole stuff. Just drop us a mail to get access to our api-functions. We still don't charge nothing for its use as long as you are using it reasonably.

tom

Tuesday, December 05, 2006

Finetuning and cleaning up

We started finetuning serversniff a little bit - fixing the ton of bugs still laying around, adding a bit of sorting or optics here and there or extend the explanations of a few scripts. Switched a few scripts from a generic approach to using serversniff's API - stuff like that. Not really noticable at all, but eating up enough time on our side.
We're dreaming of many many new functions to come - if only time would allow...

Tom

Thursday, October 26, 2006

New HTTP-API-Functions

We updated our HTTP-checks and added new API-Funktions. You can craft your own HTTP-requests now, e.g. do a GET with HTTP 1.0 with or without Host-Header and check the response, either only the HTTP-Servers header-info or the complete file, you can even filter for some special lines e.g. to get only the Server-Header or so.
This check does support servers listening on multiple IPs and is also capable of doing https.
We started implementing this backend to Serversniffs frontend - you might expect more HTTP-Checks based on this backendscript to come.

tom

Saturday, October 07, 2006

New Scripts

The IP-Scripts are coming back.

We are on our way to extend serversniff with some new IP-Scripts. We started today with a simple icmp-ping, that simply sends 4 ICMP-Echo-Requests to a given host.

Additionally, for a simple ping would be quite lame, we implented what we call a "Ping-Row", that sends about 16 ICMP-Echo-Requests with increasing packetsizes. You'll be surprised how many sites allow small pings, while their routers or firewalls sort out the hugeICMP-Packets.

tom

Monday, September 25, 2006

Extending the API

Our domain-database seems to be up and running: the scripts run very stable, we run a few background-tasks that are feeding the database with around 50.000 new domains per day.

We are working on further extensions of our API in combination with our checkomatik. Although we missed owasp's "automn of code" we are confident that we will release a full-featured version of checkomatik by the end of this year.

While we are using it internally since months, it still lacks a real user-dependent interface, security, translation and, most important, automation.

We got a few steps up the ladder with creating more api-functions, stuff like the "pingrow" or a complete ssl-check.

tom

Sunday, August 06, 2006

Domain Kiting - how many hosts fit on one ip?

Bob Parson wrote in his noteworthy blog about Domain-Kiting - see http://www.bobparsons.com/DomainKiting.html - and i thought it should be possible to identify kited domains easily by querying Serversniff.net's host-database: A kited domain i thought will share its IP with many many other hosts. So i started gathering a list of known ips sorted by the count of known hostnames living on this ip. I ended up with the following list:

Known
Hostnames - IP
---------------------
142643 | 194.159.245.16
132972 | 64.72.112.11
123455 | 127.0.0.1
59117 | 67.108.253.121
46819 | 66.165.220.18
40765 | 213.29.7.212
36617 | 70.84.80.195
34971 | 81.94.227.213
32697 | 219.153.13.42
32415 | 203.36.59.60
31617 | 134.58.241.14
29830 | 66.102.15.101
29142 | 209.163.113.99
27024 | 217.76.128.34
25405 | 70.84.48.227
23997 | 212.227.34.3
22636 | 70.85.132.35
19653 | 209.249.170.10
19553 | 216.200.145.43
19543 | 216.200.145.44
19168 | 209.185.12.47
19036 | 195.117.6.10
18994 | 70.86.121.3
18387 | 66.220.2.7
18311 | 66.220.2.9
17638 | 211.239.151.191
17459 | 61.142.254.216
17360 | 66.98.195.129
17132 | 205.178.189.131
17018 | 203.74.57.13
16961 | 82.208.4.213
16677 | 65.98.98.75
16253 | 70.86.143.154
15815 | 134.58.126.198
15807 | 134.58.126.199
13998 | 209.25.170.64
13952 | 64.202.189.170
13597 | 213.29.7.211
13565 | 217.116.0.144
13142 | 213.21.186.51
13131 | 65.98.98.59
12883 | 213.4.134.161
12711 | 213.239.203.47
12458 | 207.217.96.28
12444 | 207.217.96.29
12439 | 207.217.96.30
12437 | 207.217.96.32
12437 | 207.217.96.31
12436 | 207.217.96.33

So the Hostnames hosted at 127.0.0.1 might not be kited but the rest: the impressive figures for 64.72.112.11 e.g.: 132972 hostnames. Kited? - No, not at all. Whatever host- and domainname we checked on this domain was not kited, not even parked, but operational. It might be a loadbalancer behind - but i find this count of hostnames for one single IP still impressive.

Checking the other hosts we found a lot of parked and not too many kited domains. By explicitly checking known kited domainnames like namenddomain.com we found, that most kited domains live together with parked domain-names on one host - often with as less as 4.000 known hostnames for this special ip. But still: on the named IPs you might (or might not) found a lot of kited domains. If you bring a few minutes of patiences, you might use the "host-on-ip"-function on http://serversniff.net to check these ips for hostnames living there.
Restart your query if you don't get an answer after about a minute - it'll be faster then, for the database has stuff in its cache.

tom

Monday, July 31, 2006

Statistics

We know:
  • 20.032.470 Hosts
  • 5.357.250 Domains
  • 7.812.218 IPs
  • 224.337 Nameservers
  • 39.914 Mailservers
(We just started with sorting in Mail- and Nameservers - we are sorting in MX- and NS-Records for around 200.000 Domains per Day, so MX- and NS- figures will continue to increase for about 20 to 30 days.)

Wednesday, July 26, 2006

5 Million Domains

We cracked the 5-Million-Mark on our domain-database. Serversniff know knows more than 5 million unique domain-names, which should represent around 5 percent of all globally registered domainnames.

We will keep inserting new hosts and domains daily, and the more you look up the more we will know. The update-speed might decrease slightly for we are on the run to update our data with NS- and MX-records. We might finish this in a few months and serversniff will offer many new functions then.

A domainsearch is implemented, a hostnamesearch looking up hosts in our 35-million-hostnames-db will be in place soon - both functions are available via our API only at the moment. Access to our API-services is free, but requires a formless registration - send an EMail to thomas.springer@serversniff.net to get a free personal account.

tom

Thursday, July 06, 2006

Unstable Server

Serversniff doesn't like virtuozzo. You might imagine that we call a lot of backend-programms to let serversniff do it's job. When there are too many background-processes and not enough (shared) RAM, the apache-process is silently dying and can't be restarted, it can't even be killed.

Virtuozzo is nice, but is nothing compared to stuff like VMWare. Providers like virtuozzo, for it make every virtual machine on a host run on only one system-installation, while each vmware-engine has its own os and eats therefore much more ram and hd-space.

We decided that we don't like virtuozzo - so serversniff will (again) move to another server with the old one simply acting as some kind of proxy. while we move we will do some quality assurance and internal updates, it might take a few weeks until everything is moved completely.

tom

Tuesday, June 20, 2006

hacked

nice.

serversniff has a bunch of security-holes, and we are watching closely what people are doing here - and really, someone noticed that it was quite easy to get a glimpse of the mysql-log-database.

the evil hacker might have been a scriptkid, for he obviously got acces to the mysql-db, used an unkown (at least to major search-engines) mysql-exploit-script trying to create files on the system. the mysql-db died on the way to his goal.

the attacker created (and then deleted or emptied) several tables in the db mysql:

"SNOWHILL"
"db" - nice - contains all passwords from table "user" in cleartext!
"dat" - used to execute commands on the host
"fm" - contains php-code to upload files and execute commands
local - slightly different from "dat"
sploitdb - slightly different from "dat"
wip3r - slightly different from "dat"

It seems, that the guy used at least 4 slightly different exploits targeting to the same problem.

Better luck next time.

tom