<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New Version of dnsmap out!</title>
	<atom:link href="http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: meathive</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-128595</link>
		<dc:creator>meathive</dc:creator>
		<pubDate>Sat, 26 Jun 2010 07:51:00 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-128595</guid>
		<description>The PHP port for those interested. https://kinqpinz.info/?%C2%B6=cb252860#index</description>
		<content:encoded><![CDATA[<p>The PHP port for those interested. <a href="https://kinqpinz.info/?%C2%B6=cb252860#index" rel="nofollow">https://kinqpinz.info/?%C2%B6=cb252860#index</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: VydÃ¡n dnsmap 0.22 &#8211; brute force nÃ¡stroj pro subdomÃ©ny &#124; Hacking PortÃ¡l</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-128121</link>
		<dc:creator>VydÃ¡n dnsmap 0.22 &#8211; brute force nÃ¡stroj pro subdomÃ©ny &#124; Hacking PortÃ¡l</dc:creator>
		<pubDate>Thu, 28 Jan 2010 12:25:59 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-128121</guid>
		<description>[...] Po staÅ¾enÃ­ je potÅ™eba prejmenovat soubor na dnsmap-0222.tar.gz.Â  DalÅ¡Ã­ informace naleznete zde.  19. BÅ™ezen 2009 &#124; Tagy: enumerace dns &#124; Kategorie: programy &#124; Zanechte [...]</description>
		<content:encoded><![CDATA[<p>[...] Po staÅ¾enÃ­ je potÅ™eba prejmenovat soubor na dnsmap-0222.tar.gz.Â  DalÅ¡Ã­ informace naleznete zde.  19. BÅ™ezen 2009 | Tagy: enumerace dns | Kategorie: programy | Zanechte [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zee</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-127624</link>
		<dc:creator>Zee</dc:creator>
		<pubDate>Tue, 14 Jul 2009 14:01:24 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-127624</guid>
		<description>My resolver does ~400-600k per minute on core 2 duo, 5 mbit.</description>
		<content:encoded><![CDATA[<p>My resolver does ~400-600k per minute on core 2 duo, 5 mbit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: new version of dnsmap</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126645</link>
		<dc:creator>new version of dnsmap</dc:creator>
		<pubDate>Fri, 24 Apr 2009 14:01:14 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126645</guid>
		<description>[...] Or maybe it can be added in the repos? http://www.gnucitizen.org/blog/new-v&#8230;of-dnsmap-out/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Or maybe it can be added in the repos? <a href="http://www.gnucitizen.org/blog/new-v&#8230;of-dnsmap-out/" rel="nofollow">http://www.gnucitizen.org/blog.....nsmap-out/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126395</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Sat, 28 Mar 2009 18:58:30 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126395</guid>
		<description>pdp: the only reason why i haven&#039;t cared much about input validation on dnsmap is because it doesn&#039;t require the SUID bit to be on, where tools like nmap do require to be run with root privileges. i.e.: for SYN portscans. nevertheless, as DK pointed out, if someone created a web gui for dnsmap, it could lead to remote command exec. i&#039;d hope that if someone did implement a web gui for dnsmap, they filtered malicious input from the server-side script itself, unless they want their site to be owned :)</description>
		<content:encoded><![CDATA[<p>pdp: the only reason why i haven&#8217;t cared much about input validation on dnsmap is because it doesn&#8217;t require the SUID bit to be on, where tools like nmap do require to be run with root privileges. i.e.: for SYN portscans. nevertheless, as DK pointed out, if someone created a web gui for dnsmap, it could lead to remote command exec. i&#8217;d hope that if someone did implement a web gui for dnsmap, they filtered malicious input from the server-side script itself, unless they want their site to be owned :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126391</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 27 Mar 2009 21:07:14 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126391</guid>
		<description>as far as I know nmap has been (still is) vulnerable to all sorts of attacks for years, and it is more likely to end up with a suid bit than dnsmap. of course, it is always good to fix the bugs, ap :)</description>
		<content:encoded><![CDATA[<p>as far as I know nmap has been (still is) vulnerable to all sorts of attacks for years, and it is more likely to end up with a suid bit than dnsmap. of course, it is always good to fix the bugs, ap :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126389</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Fri, 27 Mar 2009 10:45:59 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126389</guid>
		<description>lols. thought i fixed most of those! will fix it probably when i update other things in the code i was planning to fix. thanks for that DK. we should post a working PoC, that&#039;d be cool :)</description>
		<content:encoded><![CDATA[<p>lols. thought i fixed most of those! will fix it probably when i update other things in the code i was planning to fix. thanks for that DK. we should post a working PoC, that&#8217;d be cool :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126363</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Mon, 23 Mar 2009 20:38:48 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126363</guid>
		<description>Yo AP, its not that serious considering its run from the command line, but argv[1] is vulnerable to a buffer overflow.

The problem is in: &lt;code&gt;wildcarddetect(char *dom)&lt;/code&gt;
VULNERABLE LINE: &lt;code&gt;strcat(s, dom);&lt;/code&gt;
FIXED: &lt;code&gt;strncat(s, dom, sizeof(s));&lt;/code&gt;

&lt;pre&gt;&lt;code&gt;Program received signal SIGSEGV, Segmentation fault.
0x41414141 in ?? ()
(gdb) info reg
eax            0x0      0
ecx            0xffffffe0       -32
edx            0x3      3
ebx            0x41414141       1094795585
esp            0xbf90c600       0xbf90c600
ebp            0x41414141       0x41414141
esi            0x41414141       1094795585
edi            0x41414141       1094795585
eip            0x41414141       0x41414141
eflags         0x200282 2097794
cs             0x73     115
ss             0x7b     123
ds             0x7b     123
es             0x7b     123
fs             0x0      0
gs             0x33     51&lt;/code&gt;&lt;/pre&gt;

I can just imagine someone using this tool on a web frontend or something and getting themselves in trouble ;)

Cheers for the cool tool.

DK</description>
		<content:encoded><![CDATA[<p>Yo AP, its not that serious considering its run from the command line, but argv[1] is vulnerable to a buffer overflow.</p>
<p>The problem is in: <code>wildcarddetect(char *dom)</code><br />
VULNERABLE LINE: <code>strcat(s, dom);</code><br />
FIXED: <code>strncat(s, dom, sizeof(s));</code></p>
<pre><code>Program received signal SIGSEGV, Segmentation fault.
0x41414141 in ?? ()
(gdb) info reg
eax            0x0      0
ecx            0xffffffe0       -32
edx            0x3      3
ebx            0x41414141       1094795585
esp            0xbf90c600       0xbf90c600
ebp            0x41414141       0x41414141
esi            0x41414141       1094795585
edi            0x41414141       1094795585
eip            0x41414141       0x41414141
eflags         0x200282 2097794
cs             0x73     115
ss             0x7b     123
ds             0x7b     123
es             0x7b     123
fs             0x0      0
gs             0x33     51</code></pre>
<p>I can just imagine someone using this tool on a web frontend or something and getting themselves in trouble ;)</p>
<p>Cheers for the cool tool.</p>
<p>DK</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNa</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126335</link>
		<dc:creator>GNa</dc:creator>
		<pubDate>Wed, 18 Mar 2009 20:00:20 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126335</guid>
		<description>i should also note that opendns users get the whole wordlist resolved, so they should filter out the ip 67.215.65.132 , or disable the nxdomain capture in their opendns account :)</description>
		<content:encoded><![CDATA[<p>i should also note that opendns users get the whole wordlist resolved, so they should filter out the ip 67.215.65.132 , or disable the nxdomain capture in their opendns account :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNa</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126334</link>
		<dc:creator>GNa</dc:creator>
		<pubDate>Wed, 18 Mar 2009 19:53:01 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126334</guid>
		<description>kanedaaa&#039;s patch is great for opendns users :)

for the 0.22.2 there is 1 thing to correct:
&lt;pre&gt;&lt;code&gt;-       unsigned short int i=0, j=0, found=0, ipCount=0, wordlist=FALSE, results=FALSE;
+       unsigned short int i=0, j=0, found=0, ipCount=0, wordlist=FALSE, results=FALSE, forcewildcard=FALSE;&lt;/code&gt;&lt;/pre&gt;

notice the unsigned short at the beginning</description>
		<content:encoded><![CDATA[<p>kanedaaa&#8217;s patch is great for opendns users :)</p>
<p>for the 0.22.2 there is 1 thing to correct:</p>
<pre><code>-       unsigned short int i=0, j=0, found=0, ipCount=0, wordlist=FALSE, results=FALSE;
+       unsigned short int i=0, j=0, found=0, ipCount=0, wordlist=FALSE, results=FALSE, forcewildcard=FALSE;</code></pre>
<p>notice the unsigned short at the beginning</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dnsmap 0.22 Released - Subdomain Bruteforcing Tool at bLackhammer.org</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126328</link>
		<dc:creator>dnsmap 0.22 Released - Subdomain Bruteforcing Tool at bLackhammer.org</dc:creator>
		<pubDate>Tue, 17 Mar 2009 23:50:58 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126328</guid>
		<description>[...] Or read more here. [...]</description>
		<content:encoded><![CDATA[<p>[...] Or read more here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126327</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 17 Mar 2009 16:12:25 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126327</guid>
		<description>should be fixed now!</description>
		<content:encoded><![CDATA[<p>should be fixed now!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Varun</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126322</link>
		<dc:creator>Varun</dc:creator>
		<pubDate>Tue, 17 Mar 2009 10:54:37 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126322</guid>
		<description>The &quot;dnsmap&quot; link in the first sentence seems to have broken after this post was made. Leads to &quot;http://lab.gnucitizen.org/projects/dnsmap-1&quot; which gives a &quot;Page not found&quot;. Thanks!</description>
		<content:encoded><![CDATA[<p>The &#8220;dnsmap&#8221; link in the first sentence seems to have broken after this post was made. Leads to &#8220;http://lab.gnucitizen.org/projects/dnsmap-1&#8243; which gives a &#8220;Page not found&#8221;. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Links for March 14, 2009 &#171; iStoleYour.info</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126300</link>
		<dc:creator>Links for March 14, 2009 &#171; iStoleYour.info</dc:creator>
		<pubDate>Sat, 14 Mar 2009 08:26:38 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126300</guid>
		<description>[...] New Version of dnsmap out! [...]</description>
		<content:encoded><![CDATA[<p>[...] New Version of dnsmap out! [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126206</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Sun, 01 Mar 2009 16:55:01 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126206</guid>
		<description>@kanedaaa: thanks for the patch, haven&#039;t tested it yet, but wanted to let u know that i fixed a few bugs reported by users, so it&#039;d be cool if the patch also worked on version 0.22.1: http://lab.gnucitizen.org/projects/dnsmap (downloads on bottom of page)</description>
		<content:encoded><![CDATA[<p>@kanedaaa: thanks for the patch, haven&#8217;t tested it yet, but wanted to let u know that i fixed a few bugs reported by users, so it&#8217;d be cool if the patch also worked on version 0.22.1: <a href="http://lab.gnucitizen.org/projects/dnsmap" rel="nofollow">http://lab.gnucitizen.org/projects/dnsmap</a> (downloads on bottom of page)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meathive</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126204</link>
		<dc:creator>meathive</dc:creator>
		<pubDate>Sun, 01 Mar 2009 09:02:59 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126204</guid>
		<description>Well done. https://kinqpinz.info/lib/2009/feb/#09c81545</description>
		<content:encoded><![CDATA[<p>Well done. <a href="https://kinqpinz.info/lib/2009/feb/#09c81545" rel="nofollow">https://kinqpinz.info/lib/2009/feb/#09c81545</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kanedaaa</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126189</link>
		<dc:creator>kanedaaa</dc:creator>
		<pubDate>Fri, 27 Feb 2009 22:02:26 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126189</guid>
		<description>Small patch add -fw option to scan even wildcard is detected.

&lt;pre&gt;&lt;code&gt;dnsmap-0.22$ patch &lt; dnsmap.patchwildcard.patch&lt;/code&gt;&lt;/pre&gt;

http://kaneda.bohater.net/files/dnsmap.patchwildcard.diff</description>
		<content:encoded><![CDATA[<p>Small patch add -fw option to scan even wildcard is detected.</p>
<pre><code>dnsmap-0.22$ patch < dnsmap.patchwildcard.patch</code></code></pre>
<p><a href="http://kaneda.bohater.net/files/dnsmap.patchwildcard.diff" rel="nofollow">http://kaneda.bohater.net/file.....dcard.diff</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126116</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Tue, 24 Feb 2009 23:19:19 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126116</guid>
		<description>yeah, multi-threading among other features are mentioned in the included TODO file. will eventually implement them all hopefully!</description>
		<content:encoded><![CDATA[<p>yeah, multi-threading among other features are mentioned in the included TODO file. will eventually implement them all hopefully!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Interesting Information Security Bits for 02/23/2009 &#124; Infosec Ramblings</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126089</link>
		<dc:creator>Interesting Information Security Bits for 02/23/2009 &#124; Infosec Ramblings</dc:creator>
		<pubDate>Mon, 23 Feb 2009 20:39:42 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126089</guid>
		<description>[...] released a new version of dnsmap. dnsmap is a subdomain bruteforcer for stealth enumeration.&#8221; New Version of dnsmap out! &#124; GNUCITIZEN Tags: ( tools dnsmap [...]</description>
		<content:encoded><![CDATA[<p>[...] released a new version of dnsmap. dnsmap is a subdomain bruteforcer for stealth enumeration.&#8221; New Version of dnsmap out! | GNUCITIZEN Tags: ( tools dnsmap [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/new-version-of-dnsmap-out/comment-page-1/#comment-126074</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sun, 22 Feb 2009 23:22:37 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2622#comment-126074</guid>
		<description>now you need to make it multi-threaded :)</description>
		<content:encoded><![CDATA[<p>now you need to make it multi-threaded :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
