Information Security

Backtrack 4: Information Gathering: Searchengine: The Harvester – Email, User Names, Subdomain & Hostnames Finder

The next tool on Backtrack 4 I am going to review is The Harvester which was written by the guys over at Edge Security. The Harvester is a tool for gathering e-mail accounts, user names and hostnames/subdomains from different public sources. It’s a really simple tool, but very effective.

The supported sources are:

  • Google – emails,subdomains/hostnames
  • Bing search – emails, subdomains/hostnames
  • Pgp servers – emails, subdomains/hostnames
  • Linkedin – user names

Below I will go through a few examples of data mining some common search engines for usernames, email address’s and subdomains. The information gained in passive reconnaissance can be a invaluable resource for the penetration tester.

Technology Insights

Install Backtrack 4 On Windows 7 In A Virtual Machine Using Windows Virtual PC

I have been using a Windows 7 laptop for quite awhile as my daily driver and recently wanted to install Backtrack 4 in a virtual machine so I wasn’t required to dual boot or use a different laptop for BT4. I thought about using VMware as Martin wrote an article a couple months ago about installing Backtrack in a VM on Windows 7 but a couple months ago I discovered Windows Virtual PC during a Windows XP VM install. So far I have been really happy with Windows Virtual PC and decided to try installing Backtrack 4 in a Windows Virtual PC virtual machine. Below are the details on how to setup the Windows Virtual PC virtual machine and then information on how to install Backtrack 4 in that VM.

Technology Errors

Backtrack 4 Installation StartX Error: AddScreen/ScreenInit Failed For Driver 0

When installing Backtrack 4 on a Windows Virtual PC VM this afternoon I got an error when attempting to start the X server. After initially booting the DVD inside the virtual machine I set up for the Backtrack 4 installation I got the error starting X with the startx command. Resolving it was easy for me though I don’t know that it would always be as easy for others. Below I describe the error received when starting X and what I did to resolve the problem.