I made some speed bumps to the source code for metagoofil by adding in some threading code to speed up the downloading process.
The below tests were done on a vmware guest with 4GB of ram with 1 processor (2 cores).
Results might varies on your machine.
For the below test, I ran metagoofil against microsoft.com for 100 pdfs.
Results show that you can get quite a significant speed improvement if you are downloading a lot of documents for analysis with metagoofil.
If you adventurous enough to try the patch, you can download the patch or the updated metagoofil.py file from the below links
Let me know if you face any issues.
Metagoofil is a useful tool to use for the passive reconnaissance in the intelligence gathering phrase of penetration testing.
Metagoofil is available for download at http://code.google.com/p/metagoofil
It allows you to extract useful metadata from public documents belong to a target company from search engine.
You can learn about using Metagoofil at Irongeek’s site http://www.irongeek.com/i.php?page=videos/using-metagoofil-to-extract-metadata-from-public-documents-found-via-google
I was trying to use metagoofil today. The results show that there are 7 files found but they are actually invalid links.
How to apply the patch?
You can download the patch from http://pastebin.com/prHBxqfK
Save the file from pastebin as parser.patch in the metagoofil-read-only folder.
To apply the patch, type “patch -i parser.patch” as shown in the below screenshot.
You should see the below lines in your updated parser.py file in your metagoofil-read-only folder.
Thank you for reading this post and enjoy having fun with using Metagoofil as much as I do.
- BeEF Project
- Captcha Cracking
- Client Side Attacks
- Featured Publications
- Intelligence Gathering
- iPhone Apps
- iPhone Espionage
- Location Tracking
- Misc Security
- Password Cracking
- Penetration Testing
- Pentest Scripts
- Post Exploitation
- Reversing Firmwares
- SQL Injection
- Medusa ‘combo’ word lists (default usernames and passwords) for SSH and Telnet services
- Extended functionality for Burp Plugin – Carbonator
- Oracle Exploitation – Interesting Data Finder/Data Dumper
- Oracle Exploitation – Privilege Escalation
- WordPress Plugin NextGEN Gallery 1.9.12 Arbitrary File Upload vulnerability (CVE-2013-3684)
- NIST vetting guide helps in testing mobile apps zite.to/1sX11cq 4 hours ago
- Black Hat Arsenal USA 2014 – Wrap up Day 1 zite.to/1twpt1j 4 hours ago
- Binary diffing zite.to/1tpY1mB 4 hours ago
- Announcing CERT Tapioca for MITM Analysis reddit.com/r/netsec/comme… 14 hours ago
- RT @0xdabbad00: Usenix security and WOOT slides: usenix.org/conference/use… and usenix.org/conference/woo… #sec14 15 hours ago
- Hackers easily seize control of nearly 100 traffic lights (Wired UK) zite.to/1wcu51U 18 hours ago