01:35 PM

Easy-To-Find Brute-Force Tools

Tools are available to create word lists that can be used for brute-force attacks to nab passwords.

Several free and open source tools are available to create word lists that can be used for brute-force attacks to obtain passwords of social network users. They include:

>> Custom Word List Generator: Security researcher Robin Wood created CeWL as a way to create a custom word list based on spidering a Web site. This functionality is perfect for quickly determining unique words on a social network profile. CeWL is available for download from Wood's Web site, in the Samurai Web Testing Framework, and within the popular BackTrack 4 penetration testing distribution.

>> RSMangler: Robin Wood's RSMangler complements word-list-generating utilities like CeWL. It takes a word list and generates mangled combinations and manipulations of those words. For example, from "tom, eston, social" RSMangler would output: tomeston, tomsocial, estontom, socialeston, socialtom. It can be downloaded from the RandomStorm site.

>> Associative Word List Generator: This site generates word lists based on search terms that are queried from the Web site using typical search engine techniques. For example, if you search for "tom, eston, agent0x0, zombies, spylogic, security, justice," AWLG will search the Internet for those terms and give you back a listing of relevant keywords.

>> Common Users Password Profiler: Muris Kurgas created this word-list-generation script that uses information gathered online to answer a series of questions CUPP asks. Based on those answers, CUPP generates a custom word list. This tool can be quite handy if an attacker has already found out significant information about a potential victim from a social network profile. CUPP is preinstalled in the BackTrack 4 penetration testing distribution.

>> Userpass.py Script: Created by Mark Baggett, this script automatically generates customized word lists for specific targets. For example, a Google search is launched to find LinkedIn profiles of employees at a target company. Then the script spiders any Web sites found in a user's LinkedIn profile. It pulls the user's profile picture and checks a Web site called "tineye" to determine if the picture matches others on the Internet. If it does, those sites are spidered for keyword information. Finally, all the spidered sites are run through CeWL to generate custom word lists. Userpass.py script can be downloaded from the PaulDotCom Web site.

Go to the main story:
Social Networks' Threat To Security

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
According to industry estimates, about a million new IT security jobs will be created in the next two years but there aren't enough skilled professionals to fill them. On top of that, there isn't necessarily a clear path to a career in security. Dark Reading Executive Editor Kelly Jackson Higgins hosts guests Carson Sweet, co-founder and CTO of CloudPassage, which published a shocking study of the security gap in top US undergrad computer science programs, and Rodney Petersen, head of NIST's new National Initiative for Cybersecurity Education.