The harvester: Discovering & Leveraging. 10-23-2012, 06:28 PM
#1
ThE hARvESTER: DISCOvERING AND LEvERAGING E-MAIL ADDRESSES
If you are using an operating system other than Backtrack, you can download the tool directly from Edge Security at: http://www.edge-security.com.
An excellent tool to use in reconnaissance is the Harvester. the Harvester is
a simple but highly effective Python script written by christian martorella at
edge security. this tool allows us to quickly and accurately catalog both e-mail
addresses and subdomains that are directly related to our target.
It is important to always use the latest version of the Harvester as many search
engines regularly update and change their systems. even subtle changes to a
search engine’s behavior can render automated tools ineffective. in some cases,
search engines will actually filter the results before returning information to
you. many search engines also employ throttling techniques that will attempt
to prevent you from running automated searches.
The Harvester can be used to search google, Bing, and PgP servers for e-mails,
hosts, and subdomains. it can also search linkedin for user names. most peo-
ple assume their e-mail address is benign. we have already discussed the dan-
gers of posting to public forums using your corporate e-mail address; however,
there are additional hazards you should be aware of. let us assume during your
reconnaissance you discover the e-mail address of an employee from your tar-
get organization. By twisting and manipulating the information before the “@”
symbol, we should be able to create a series of potential network usernames.
it is not uncommon for organizations to use the exact same user names and
e-mail addresses (before the “@” symbol). with a handful of prospective user-
names, we can attempt to brute force our way into any services, like ssH, VPns,
or ftP, that we (will) discover during the next step 2 (scanning).
The Harvester is built into Backtrack. to access the Harvester, use the following
steps:
1. click on the kstart dragon, located in the lower left corner of your screen.
2. Highlight “Backtrack” at the top of the menu.
3. Highlight “information gathering.”
4. Highlight “All.”
5. select “theHarvester” (note, tools are listed in alphabetical order).
You can also open a terminal window and navigate to the Harvester directory
by issuing the following command:
cd /pentest/enumeration/google/theharvester
regardless of whether you have downloaded the Harvester or used the ver-
sion installed in Backtrack, we will use it to collect additional information
about our target. Be sure you are in theHarvester folder and run the following
command:
./theHarvester.py –d syngress.com –l 10 –b google
this command will search for e-mails, subdomains, and hosts that belong to
syngress.com. figure in the end of the article shows our results.
Before discussing the results of our tool, let us examine the command a little
closer. “./theHarvester.py” is used to invoke the tool. A lowercase “–d” is
used to specify the target domain. A lowercase “–l” (that is an l not a 1) is
used to limit the number of results returned to us. in this case, the tool was
instructed to return only 10 results. the “–b“ is used to specify what public
repository we want to search. we can choose among google, Bing, PgP, or
linkedin—for this example, we chose to search using google.
now that you fully understand the command that was run, let us take a look at
the results.
As you can see, the Harvester was effective in locating at least two e-mail
addresses that could be of value to us. Please note, the e-mail addresses in the
screenshot have been circled and obfuscated. the Harvester was also successful in finding at least two additional subdomains. Both “booksite.syngress.com”
and “ebook__www.syngress.com” need to be fully recon’d. we simply add these
new domains to our target list and begin the reconnaissance process again.
step 1 of reconnaissance is very cyclical because in-depth reconnaissance often
leads to the discovery of new targets, which, in turn, leads to additional recon-
naissance. As a result, the amount of time to complete this phase will vary
from several hours to several weeks. remember, a determined malicious hacker
understands not only the power of good reconnaissance but also that of a
nearly limitless amount of time. As an aspiring penetration tester, you should
devote as much time as possible to practicing and conducting information
gathering.
![[Image: 2537759-0iap.png]](http://is100.imagesocket.com/images/2012/10/23/2537759-0iap.png)
NOTE :
If you are using an operating system other than Backtrack, you can download the tool
directly from Edge Security at: http://www.edge-security.com. Once you have got it
downloaded, you can unpack the downloaded tar file by running the following command
in a terminal:
tar xf theHarvester
Please note the capital “H” that is used when untarring the code. Linux is case
sensitive, so the operating system sees a difference between “theHarvester” and
“theharvester.” You will need to pay attention to the executable to determine if you
should use a capital or lowercase “h.” If the cases do not match exactly, you will
typically get a message saying “no such file or directory.” This is a good indication that
you have mistyped the name of the file.
If you are using an operating system other than Backtrack, you can download the tool directly from Edge Security at: http://www.edge-security.com.
An excellent tool to use in reconnaissance is the Harvester. the Harvester is
a simple but highly effective Python script written by christian martorella at
edge security. this tool allows us to quickly and accurately catalog both e-mail
addresses and subdomains that are directly related to our target.
It is important to always use the latest version of the Harvester as many search
engines regularly update and change their systems. even subtle changes to a
search engine’s behavior can render automated tools ineffective. in some cases,
search engines will actually filter the results before returning information to
you. many search engines also employ throttling techniques that will attempt
to prevent you from running automated searches.
The Harvester can be used to search google, Bing, and PgP servers for e-mails,
hosts, and subdomains. it can also search linkedin for user names. most peo-
ple assume their e-mail address is benign. we have already discussed the dan-
gers of posting to public forums using your corporate e-mail address; however,
there are additional hazards you should be aware of. let us assume during your
reconnaissance you discover the e-mail address of an employee from your tar-
get organization. By twisting and manipulating the information before the “@”
symbol, we should be able to create a series of potential network usernames.
it is not uncommon for organizations to use the exact same user names and
e-mail addresses (before the “@” symbol). with a handful of prospective user-
names, we can attempt to brute force our way into any services, like ssH, VPns,
or ftP, that we (will) discover during the next step 2 (scanning).
The Harvester is built into Backtrack. to access the Harvester, use the following
steps:
1. click on the kstart dragon, located in the lower left corner of your screen.
2. Highlight “Backtrack” at the top of the menu.
3. Highlight “information gathering.”
4. Highlight “All.”
5. select “theHarvester” (note, tools are listed in alphabetical order).
You can also open a terminal window and navigate to the Harvester directory
by issuing the following command:
cd /pentest/enumeration/google/theharvester
regardless of whether you have downloaded the Harvester or used the ver-
sion installed in Backtrack, we will use it to collect additional information
about our target. Be sure you are in theHarvester folder and run the following
command:
./theHarvester.py –d syngress.com –l 10 –b google
this command will search for e-mails, subdomains, and hosts that belong to
syngress.com. figure in the end of the article shows our results.
Before discussing the results of our tool, let us examine the command a little
closer. “./theHarvester.py” is used to invoke the tool. A lowercase “–d” is
used to specify the target domain. A lowercase “–l” (that is an l not a 1) is
used to limit the number of results returned to us. in this case, the tool was
instructed to return only 10 results. the “–b“ is used to specify what public
repository we want to search. we can choose among google, Bing, PgP, or
linkedin—for this example, we chose to search using google.
now that you fully understand the command that was run, let us take a look at
the results.
As you can see, the Harvester was effective in locating at least two e-mail
addresses that could be of value to us. Please note, the e-mail addresses in the
screenshot have been circled and obfuscated. the Harvester was also successful in finding at least two additional subdomains. Both “booksite.syngress.com”
and “ebook__www.syngress.com” need to be fully recon’d. we simply add these
new domains to our target list and begin the reconnaissance process again.
step 1 of reconnaissance is very cyclical because in-depth reconnaissance often
leads to the discovery of new targets, which, in turn, leads to additional recon-
naissance. As a result, the amount of time to complete this phase will vary
from several hours to several weeks. remember, a determined malicious hacker
understands not only the power of good reconnaissance but also that of a
nearly limitless amount of time. As an aspiring penetration tester, you should
devote as much time as possible to practicing and conducting information
gathering.
![[Image: 2537759-0iap.png]](http://is100.imagesocket.com/images/2012/10/23/2537759-0iap.png)
NOTE :
If you are using an operating system other than Backtrack, you can download the tool
directly from Edge Security at: http://www.edge-security.com. Once you have got it
downloaded, you can unpack the downloaded tar file by running the following command
in a terminal:
tar xf theHarvester
Please note the capital “H” that is used when untarring the code. Linux is case
sensitive, so the operating system sees a difference between “theHarvester” and
“theharvester.” You will need to pay attention to the executable to determine if you
should use a capital or lowercase “h.” If the cases do not match exactly, you will
typically get a message saying “no such file or directory.” This is a good indication that
you have mistyped the name of the file.
it wasn't me nobody saw me you can't prove anything
Knowledge is free
Knowledge is free


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)

