.

[Article]-Doxing and Anti-Doxing – Part I

<<

don

User avatar

Administrator
Administrator

Posts: 4226

Joined: Sun Aug 28, 2005 10:47 pm

Location: Chicago

Post Fri Aug 31, 2012 12:35 pm

[Article]-Doxing and Anti-Doxing – Part I

Jason is about to be on a roll. In addition to this article and then Part II in the works, he's also slated to do some course reviews, a new contest as well as some other ideas for his column. I think I have him jammed for at least the next year. Should be fun.

Speaking of fun, if you can, catch Jason at DerbyCon speaking on this very topic of doxing.

Permanenet link: [Article]-Doxing and Anti-Doxing – Part I


Image


By Jason Andress

For those of us following or taking part in the various hacktivist activities happening around the globe on a regular basis, doxing is a regular feature. We wake up in the morning to find the personal lives of businessmen, hackers who have made target of themselves for one reason or another, government employees, and a host of others spilled out onto the Internet for the entire world to see. Doxing can be a tool for use in security testing, investigation, or research on the positive side. But it can also be a tool for humiliation, harassment, and worse on the negative side.

In the Part I of this article, we will discuss what exactly doxing is and the tools and techniques we might use to carry out such an attack. In the Part II of this article we will talk about the steps we can take to at least lessen its impact, should we find ourselves on the receiving end of such efforts.



Don
CISSP, MCSE, CSTA, Security+ SME
<<

shadowzero

User avatar

Full Member
Full Member

Posts: 120

Joined: Sat Jun 02, 2012 10:03 pm

Post Fri Aug 31, 2012 2:11 pm

Re: [Article]-Doxing and Anti-Doxing – Part I

A good read. Looking forward to part 2.
<<

cyber.spirit

User avatar

Sr. Member
Sr. Member

Posts: 356

Joined: Sun Feb 26, 2012 8:07 am

Location: in your heart!

Post Tue Sep 04, 2012 3:22 am

Re: [Article]-Doxing and Anti-Doxing – Part I

good article im waiting for part two too!
ICS Academy Network Security Certified
<<

rattis

User avatar

Hero Member
Hero Member

Posts: 1172

Joined: Mon Jul 27, 2009 1:25 pm

Post Tue Sep 04, 2012 10:22 am

Re: [Article]-Doxing and Anti-Doxing – Part I

Great refresher, but when I clicked the link for the Google advanced operators, I got a 404 error.

Looking forward to part 2.
OSWP, Sec+
<<

jason

User avatar

Hero Member
Hero Member

Posts: 1013

Joined: Sat Jun 21, 2008 6:23 pm

Location: USA

Post Tue Sep 04, 2012 11:40 am

Re: [Article]-Doxing and Anti-Doxing – Part I

Looks like they've moved things on me. The updated link is:

http://support.google.com/websearch/bin ... wer=136861

Thanks for the heads-up, I'll get Don to tweak the article.
<<

m0wgli

User avatar

Sr. Member
Sr. Member

Posts: 308

Joined: Fri Jul 20, 2012 3:34 pm

Post Tue Sep 04, 2012 3:52 pm

Re: [Article]-Doxing and Anti-Doxing – Part I

Well written article, a good overview for those unfamiliar with the concepts.

I followed some of the well publicised doxes earlier in the year e.g. Lulzsec and UGNazi, and found them to be very useful examples of the techniques involved and how the information gathered can be expanded upon.

Also, as you mention in your article some of these inferences are entirely wrong, which has led to the wrong person getting doxed by mistake.

I don't know what you've got planned for your next contest but requiring a bit of OSINT/information reconnaissance before actually getting to the challenge or being the challenge itself could prove interesting.

Looking forward to part two!
Security + | OSWP | eCPPT (Silver & Gold) | CSTA
<<

don

User avatar

Administrator
Administrator

Posts: 4226

Joined: Sun Aug 28, 2005 10:47 pm

Location: Chicago

Post Tue Sep 04, 2012 4:35 pm

Re: [Article]-Doxing and Anti-Doxing – Part I

Article has been tweaked!

Glad everyone is enjoying it.

Don
CISSP, MCSE, CSTA, Security+ SME
<<

jason

User avatar

Hero Member
Hero Member

Posts: 1013

Joined: Sat Jun 21, 2008 6:23 pm

Location: USA

Post Thu Sep 06, 2012 3:05 pm

Re: [Article]-Doxing and Anti-Doxing – Part I

Just ran across this today:

http://www.powersearchingwithgoogle.com/course

This is a short video course from Google on power searching. Happy doxing  ;D
<<

don

User avatar

Administrator
Administrator

Posts: 4226

Joined: Sun Aug 28, 2005 10:47 pm

Location: Chicago

Post Wed Sep 19, 2012 1:13 pm

Re: [Article]-Doxing and Anti-Doxing – Part I

FYI...

Jason's editorial schedule for his column is as follows:

Sept = Spooky Warfare Hacking Contest
Oct = Course Review: SANS vLive FOR408
Nov = Spooky Warfare Results
Dec = Doxing Part II
Jan or Feb = Course Review: SANS vLive FOR508

Don
CISSP, MCSE, CSTA, Security+ SME
<<

blackazarro

User avatar

Sr. Member
Sr. Member

Posts: 368

Joined: Sun Aug 13, 2006 5:31 pm

Post Wed Sep 19, 2012 1:39 pm

Re: [Article]-Doxing and Anti-Doxing – Part I

Yup, I took that course this summer. I learned some cool tricks. Earned a cert for passing the course. Very easy.
Security+, OSCP, CEH
<<

jason

User avatar

Hero Member
Hero Member

Posts: 1013

Joined: Sat Jun 21, 2008 6:23 pm

Location: USA

Post Wed Sep 19, 2012 4:14 pm

Re: [Article]-Doxing and Anti-Doxing – Part I

Google continues to amaze me (even though they're evil) with the handy things that you can get to with their engine. I just figured out a while back that wikipedia <whatever> will get you right to the link for whatever you're searching on. Its a heck of alot faster than going through the whole route. I've found a few other things that work similarly and are a huge timesaver.

Return to Andress

Who is online

Users browsing this forum: No registered users and 2 guests

.
Powered by phpBB® Forum Software © phpBB Group.
Designed by ST Software