Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | SensePost Aura - aka Solving the Google API Key Problem.. |
|---|---|
| Date: | Wed, 18 Apr 2007 20:43:31 +0200 |
Hiya (Sorry for the cross post - but this question has popped up on all of these lists the past while..) (im guessing moderators on moderated lists can make the call to can/pass this through).. http://www.sensepost.com/research/aura No this is not us getting all spiritual or striving to reach any sort of astral plane... A while back Google encouraged developers to make use of their API. Many people built applications around the API, but alas Google has stopped issuing API keys.. This means that those applications (like wikto / etc) are effectively killed... SensePost AURA (Api Usable / Re-usable Again) will help to get those tools working again. Aura runs as an executable on your windows machine and by default listens only on 127.0.0.1:80. Simply create a host entry (%WINDIR%\system32\drivers\etc\hosts for api.google.com as 127.0.0.1). All tools that reference the api will now talk to Aura which will accept requests and return results exactly like the API used to. (You can give it your API key, but really.. it doesn't care and will play with you just as happily if you don't.) Currently Aura only supports the API method (doGoogleSearch) we were using in SensePost tools (we suspect most tools are just using this one anyway.) So give it a spin, send us feedback (research@sensepost.com), etc.. /mh PS: Full readme in the .zip should clear up any questions PPS: This has been tested on the new Wikto release (which is currently in testing, and should hit the Internet Pipes shortly) -- Haroon Meer, SensePost Information Security PGP: http://www.sensepost.com/pgp/haroon.txt Tel: +27 83786 6637 ------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Vulnerability - Tracking and Remediation, Kevin Reiter |
|---|---|
| Next by Date: | Infosec 2007 London, Roman Shirokov |
| Previous by Thread: | Reminder: HITBSecConf2007 - Malaysia: Call for Papers closing in 2 weeks, Praburaajan |
| Next by Thread: | Infosec 2007 London, Roman Shirokov |
| Indexes: | [Date] [Thread] [Top] [All Lists] |