<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>JW Network Consulting &#187; username generation</title>
	<atom:link href="http://www.jwnetworkconsulting.com/tag/username-generation/feed" rel="self" type="application/rss+xml" />
	<link>http://www.jwnetworkconsulting.com</link>
	<description>Watching the network so you don't have to.</description>
	<lastBuildDate>Thu, 22 Jul 2010 01:23:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Reconnoiter Updated with Metasploit Module</title>
		<link>http://www.jwnetworkconsulting.com/security/reconnoiter-updated-with-metasploit-module</link>
		<comments>http://www.jwnetworkconsulting.com/security/reconnoiter-updated-with-metasploit-module#comments</comments>
		<pubDate>Tue, 15 Jun 2010 17:04:23 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Metasploit module]]></category>
		<category><![CDATA[reconnoiter project]]></category>
		<category><![CDATA[username generation]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=358</guid>
		<description><![CDATA[Just a quick note today. I finished working on a Metasploit module to create usernames the same way that the other two scripts in Reconnoiter does. However, this module is able to search Yahoo or Google and does not require separate scripts to do so. It also provides the option to use msfweb to get [...]]]></description>
			<content:encoded><![CDATA[<p>Just a quick note today.  I finished working on a Metasploit module to create usernames the same way that the other two scripts in Reconnoiter does.  However, this module is able to search Yahoo or Google and does not require separate scripts to do so.  It also provides the option to use msfweb to get a web interface to run it from and lets you chose whether to dump the output to the console or text files in a directory of your choosing.  It has been tested on version 3.4 and 3.3 of Metasploit, so it should be good to go.  You can download it from <a href="https://sourceforge.net/projects/reconnoiter/files/">https://sourceforge.net/projects/reconnoiter/files/</a>.</p>
<p>So far it looks to be working very well.  A big thanks to Robin Wood (digininja), Larry Pesce (haxorthematrix) and Carlos Perez (Carlos_Perez or darkoperator) for their help.  All three were extremely willing to help me add functions, correct bugs and provide advice.</p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Metasploit+module' rel='tag' target='_self'>Metasploit module</a>, <a class='technorati-link' href='http://technorati.com/tag/reconnoiter+project' rel='tag' target='_self'>reconnoiter project</a>, <a class='technorati-link' href='http://technorati.com/tag/username+generation' rel='tag' target='_self'>username generation</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/reconnoiter-updated-with-metasploit-module/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reconnoiter featured on Pauldotcom Podcast</title>
		<link>http://www.jwnetworkconsulting.com/security/reconnoiter-on-pauldotcom-podcast</link>
		<comments>http://www.jwnetworkconsulting.com/security/reconnoiter-on-pauldotcom-podcast#comments</comments>
		<pubDate>Wed, 14 Oct 2009 03:05:34 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[pauldotcom episode 170]]></category>
		<category><![CDATA[reconnoiter project]]></category>
		<category><![CDATA[security tools]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[username generation]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=280</guid>
		<description><![CDATA[The last week was really busy while I prepared to do my presentation at the Utah Open Source Conference.  While I was engaged in this process I got a message from Larry Pesce of the Pauldotcom Podcast.  He had some updates to Reconnoiter and wanted to shoot them over to me.  He said that he [...]]]></description>
			<content:encoded><![CDATA[<p>The last week was really busy while I prepared to do my presentation at the Utah Open Source Conference.  While I was engaged in this process I got a message from Larry Pesce of the Pauldotcom Podcast.  He had some updates to Reconnoiter and wanted to shoot them over to me.  He said that he would be doing a tech segment on harvesting usernames via social media and was going to use the script as part of it.  I thought that was quite cool and figured that it would be one of the tools he mentioned.  I checked the <a href="http://pauldotcom.com/wiki/index.php/Episode170" target="_blank">show notes </a>after the recording and found that the entire segment was built around Reconnoiter!</p>
<p>One of the things that I really liked about the podcast was that the guys spent some time on how it could be better.  The requests I heard were the following:</p>
<ul>
<li>Configure what format it generates the user names into.  Perhaps you already know the format a client uses and need just want a dictionary.  Why have a bunch of user names that you know are bad.</li>
<li>Add some kind of GUI or website.  Good point.  Particularly for the Yahoo version of the script.  That API key is insanely long to put in as a command line argument.</li>
<li>Instead of spewing to STDOUT, save it to a file.  Larry has already provided the code for this and implemented it into both scripts.</li>
</ul>
<p>I&#8217;ve been kicking around a couple other ideas, but will need to get some time to implement them.  I&#8217;ve also got another script in mind that may or may not help deduce what the user name format for a company might be.  Depends on how the target has their email server configured.  No hacking, just taking note of what the email server tells me.</p>
<p>You can check out the episode at <a href="http://pauldotcom.com/2009/10/pauldotcom-security-weekly---e-29.html" target="_blank">pauldotcom.com</a>.  Thanks guys!</p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/pauldotcom+episode+170' rel='tag' target='_self'>pauldotcom episode 170</a>, <a class='technorati-link' href='http://technorati.com/tag/reconnoiter+project' rel='tag' target='_self'>reconnoiter project</a>, <a class='technorati-link' href='http://technorati.com/tag/security+tools' rel='tag' target='_self'>security tools</a>, <a class='technorati-link' href='http://technorati.com/tag/social+media' rel='tag' target='_self'>social media</a>, <a class='technorati-link' href='http://technorati.com/tag/username+generation' rel='tag' target='_self'>username generation</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/reconnoiter-on-pauldotcom-podcast/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scripts to Generate Usernames</title>
		<link>http://www.jwnetworkconsulting.com/security/scripts-to-generate-usernames</link>
		<comments>http://www.jwnetworkconsulting.com/security/scripts-to-generate-usernames#comments</comments>
		<pubDate>Wed, 02 Sep 2009 05:00:15 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[username generation]]></category>
		<category><![CDATA[username generator]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=249</guid>
		<description><![CDATA[I&#8217;ve written a couple of posts about a script I wrote to generate usernames.  Since then I&#8217;ve written another script that uses Yahoo&#8217;s XML API and both of them have been included in SamuraiWTF.  It&#8217;s been pretty cool to see people try out something that I wrote and find it useful to them.  The scripts [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve written a couple of posts about a script I wrote to generate usernames.  Since then I&#8217;ve written another script that uses Yahoo&#8217;s XML API and both of them have been included in <a title="SamuraiWTF" href="http://samurai.inguardians.com/" target="_blank">SamuraiWTF</a>.  It&#8217;s been pretty cool to see people try out something that I wrote and find it useful to them.  The scripts are still pretty rough and need some work.</p>
<p>I&#8217;d like to make the Yahoo script less ugly to use.  Putting a huge API key in as a command argument strikes me as kinda lame.  The results from it are very consistent though.  So I actually prefer using it to the google version of the script.  You can download the Yahoo script here:  <a title="usernameGenYahoo-v1.1.txt" href="http://www.jwnetworkconsulting.com/downloads/usernameGenYahoo-v1.1.txt" target="_self">usernameGenYahoo.txt</a> The Google script is here:  <a title="usernameGen.py V 2.1.1" href="http://www.jwnetworkconsulting.com/downloads/usernameGen-v2.1.1.txt">usernameGen-v2.1.1.txt</a></p>
<p>Please let me know if you find any bugs with them, want additional functionality or if you just found them useful.</p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/penetration+testing' rel='tag' target='_self'>penetration testing</a>, <a class='technorati-link' href='http://technorati.com/tag/username+generation' rel='tag' target='_self'>username generation</a>, <a class='technorati-link' href='http://technorati.com/tag/username+generator' rel='tag' target='_self'>username generator</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/scripts-to-generate-usernames/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Need usernames?  Ask Google what Linkedin has!</title>
		<link>http://www.jwnetworkconsulting.com/security/need-usernames-ask-google-what-linkedin-has</link>
		<comments>http://www.jwnetworkconsulting.com/security/need-usernames-ask-google-what-linkedin-has#comments</comments>
		<pubDate>Fri, 12 Jun 2009 05:44:49 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[username generation]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=237</guid>
		<description><![CDATA[I wanted to do some testing on access controls to a SQL server recently, but I needed to a decent password list and username list. Password lists are fairly straight forward to find and I used an excellent how to from the Pauldotcom Podcast to create my password list. Next I needed a list of [...]]]></description>
			<content:encoded><![CDATA[<p>I wanted to do some testing on access controls to a SQL server recently, but I needed to a decent password list and username list.  Password lists are fairly straight forward to find and I used an excellent how to from the <a href="http://pauldotcom.com/wiki/index.php/Episode129">Pauldotcom Podcast</a> to create my password list.  Next I needed a list of usernames.  To be effective, it would be better to have a list targeted to the environment I was working in.  I wanted to do this with fairly public information so that no one could accuse me of using insider knowledge.  So I decided to see what LinkedIn had.</p>
<p>Now Linkedin generally lets people decide how much information they want displayed to people they don&#8217;t know.  If you aren&#8217;t connected to them, all you may see is their description if you find them by company.  No names.  In my case, I&#8217;m connected with a lot of people, so this pollutes the process.  So, I logged out of Linkedin to see how an outside might do this.  </p>
<p>For this scenario, I&#8217;m an attacker who wants to find out about Company XYZ.  I&#8217;m not employed by them, but they have something I want.  I&#8217;m not connected to anyone on Linkedin at the target.  In fact, I may not even have a Linkedin account.  How do I get this information?  <a href="http://twitter.com/secureideas">Kevin Johnson</a> at <a href="http://www.inguardians.com/">InGuardians</a> has already done some awesome work on how people are willing to accept invitations on social networking sites from almost anyone.  But lets say that I don&#8217;t want to get connected to my target.  Who would have this information?  </p>
<p>Google of course!  Everyone wants Google to be able to find things on their website.  Linkedin is no different.  So I do a query on the company name like this &#8220;site:linkedin.com Company XYZ&#8221;.  Sure enough, I get pages of people who work at or did work at Company XYZ.  With a bit of Python scripting I download the results, mix the names into common username variations and I have my username list.</p>
<p>Here&#8217;s the script I hacked up to make this work.  <a href="http://www.jwnetworkconsulting.com/downloads/usernameGen.txt">usernameGen.txt</a>  PDP at <a href="http://www.gnucitizen.org/">gnucitizen.org</a> wrote the original script.  I just polished up the regular expression and pointed the starting URL to Google&#8217;s mobile search to simplify the HTML.  Then I added the username generation.  Was a fun little puzzle for the evening. </p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/social+networking' rel='tag' target='_self'>social networking</a>, <a class='technorati-link' href='http://technorati.com/tag/username+generation' rel='tag' target='_self'>username generation</a>, <a class='technorati-link' href='http://technorati.com/tag/web+security' rel='tag' target='_self'>web security</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/need-usernames-ask-google-what-linkedin-has/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
