Home > -Chinese-, Security > [Chinese]Maltego – 揭示互联网隐藏的情报

[Chinese]Maltego – 揭示互联网隐藏的情报

Maltego 不是一个黑客工具 – 而是用来对来自互联网的信息进行收集、组织、可视化的工具。 它可以收集某个人的在线数据信息 – 包括电子邮件地址、博客、Facebook中的朋友,个人爱好、地理位置、工作描述,然后可以一种更为有用、全面的形式展现出来。Peterva公司的创始人Temmingh说:“我们在开发这个工具时,我就相信所有这些信息都可能会以这样那样的方式互相关联着。这个工具就是用来证明这个信念。”

下载试用地址:http://www.paterva.com/malv2/MaltegoInstaller-v2-210-CE.exe

Microsoft Blue Hat: Researcher Demos No-Hack Attack
Wealth of available online data on individuals, businesses can be used in targeted attacks
By Kelly Jackson Higgins,  Senior Editor, Dark Reading

A researcher at Microsoft’s closed-door Blue Hat summit last week demonstrated how seemingly mundane information available online about an individual or a business can be used against them in a targeted attack.

Roelof Temmingh, founder of Paterva, demonstrated how hackers don’t need traditional hacking tools given all of the information that’s freely available about people and organizations on the Internet. With a little reconnaissance and the use of a handy information-collection, correlation, and visualization tool he built called Maltego, Temmingh showed how an attacker wouldn’t have to bother with a port scan or other hacking tools to hack a person or a business.

Maltego is not a hacker tool — it’s for gathering, organizing and visualizing information from the Internet. It basically collects that accessible information online about an individual — his email address, blogs, Facebook friends, hobbies, geographic location, job description — and presents it in a usable, comprehensive profile of a potential target. “When I started developing this tool… I had the idea that all pieces of information out there were connected in some way or another,” Temmingh says. “This tool proves that [they are].”

The problem, of course, is that users want instant access to information, and to be accessible via social networking sites and other online resources. And there’s always a way for someone to abuse that interconnected information.

Attackers hack either to get control over a system, or to grab data. “You don’t [necessarily] need to break into anything to get the information you need… It may be just a click,” he says. “With some applications, the data you can get from them is the vulnerability.”

// 这里实际上是一种流量分析的攻击,借助于分析流量的数据统计来获取信息。
Even PGP-encrypted email messages between two organizations can leak some useful clues. Piecing together the email addresses in the domain and the signed keys by specific email addresses can provide useful information, he says. “If five people at one organization sent mail to five others at a second organization and all mail was PGP-encrypted, this is telling us” something about the relationship between these two organizations, he says.

“If you think about an attack, the exploit itself is maybe 5 percent of the whole equation, Temmingh says. “It doesn’t have to end in ‘now you can ‘own’ someone.’”

Temmingh also demonstrated at Blue Hat how easy it is for an attacker to manipulate the inherent trust on the Internet — and the lack of real identity verification. “If you’re not on Facebook, I can [pose as you] on Facebook and put up content,” he says. “I can invent anyone I want using your name” and information gathered, he says.

Bottom line: There’s no real enforcement for privacy on the Internet today, he says. “If you want to keep something private, keep it off the Internet. Even if you encrypt it… you could be leaking more information” like with the PGP-encrypted email example, he says.

Have a comment on this story? Please click “Discuss” below. If you’d like to contact Dark Reading’s editors directly, send us a message.

Share To:
  • Digg
  • del.icio.us
  • Google Bookmarks
  • Facebook
  • Slashdot
  • Technorati
  • Live
  • Reddit
  • LinkedIn
  • FriendFeed
  • Yahoo! Bookmarks
  1. No comments yet.
  1. No trackbacks yet.