Quick Tip: Pastebin Monitoring & Recon
Happy Thanksgiving!
On the heels of Dr. Ullrich's diary regarding SCADA hacks published on Pastebin I thought I'd mention some Pastebin monitoring and recon resources that you may find useful.
One reader wrote in to say that you could use Google Alerts to monitor Pastebin for names and keywords of interest to you, but you may prefer a Google Custom Search instead. Configure it to monitor Pastebin and other similar sites; set names and keywords that are relevant for your needs.
Or, as Lenny pointed out in his July blog entry, you could use Andrew's PasteLert or PasteBin Scraper. And in case you weren't following along, Andrew --> Paterva --> Maltego --> Pastebin Transforms.
More than one SANS certification track curriculum discusses Maltego use for good reason. :-)
Any useful Pastebin crawling/scraping tactics you'd like to share? We await your comments or contact.
Comments
http://www.shellguardians.com/2011/07/monitoring-pastebin-leaks.html
James
Nov 24th 2011
1 decade ago
Alex
Nov 24th 2011
1 decade ago
http://www.elilabs.com/~rj/dice_date.html
Similar techniques can be used to scrape just about anything from anywhere. This scraper is coded as a bash shell script, but perl would have looked nicer in the source file.
Moriah
Nov 25th 2011
1 decade ago
Additionally the API's for the various pastebins unfortunately dont offer the level of searching and alerting just yet. I tried to contact a few of them but got no reply. Scraping breaks most terms of use, however the chaps from pastie.org said that it would be okay (which is why the pastebin scraper still works for that).
But if you are looking for a cmd line version you are welcome to hack up any of the code I hacked up for the pastebin/pastelert stuff, its all free to do whatever you feel like (aka the i-dont-know-licensing-and-dont-care license):
http://andrewmohawk.com/tag/pastebin/
Cheers
-AM
Andrew
Nov 25th 2011
1 decade ago
dayglo
Nov 25th 2011
1 decade ago
Moriah
Nov 26th 2011
1 decade ago