Слайд 3Clowns and faggots
01
Whoever doesn't want to work as a clown for a
faggot will work as a faggot for a clown. For the same small price. Victor Pelevin.
Слайд 4Main mission
Identify the owner of the website with picrelated article compromat.group
Слайд 5Enumerating similar domains
We started looking for the websites mirroring content from compromat.group
website. Successfully identified:
http://kompromat.group/
https://compromat.pro/
http://Compromat.ws
Слайд 10VIEWDNS.INFO
Framework for technical OSINT. Reverse IP Lookup, Whois lookup, IP History etc.
Слайд 11IP History results
For compromat.pro website
Russian IP addresses is a win for law
enforcement, but we needed to go deeper
Слайд 12Bypassing Cloudflare IP protection
Most of the websites we have identified used
Cloudflare IP protection. So we came up with using WAF Bypass tool
https://github.com/vincentcox/bypass-firewalls-by-DNS-history
Слайд 13WAF Bypass
This script will try to find:
- the direct IP address
of a server behind a firewall like Cloudflare, Incapsula, SUCURI ...
- an old server which still running the same (inactive and unmaintained) website, not receiving active traffic because the A DNS record is not pointing towards it
Слайд 14Whois Domain Bot
Whois information about IP address or domain in pocket format
Слайд 19Builtwith.com
Find out what websites are built with
Analytics and Tracking
JavaScript Libraries and Functions
Webmaster
Registration
Слайд 20SpiderFoot HX
Framework for website, IP, human names etc. OSINT
Слайд 21A PICTURE IS WORTH A THOUSAND WORDS