<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" 
  xmlns:content="http://purl.org/rss/1.0/modules/content/" 
  xmlns:dc="http://purl.org/dc/elements/1.1/" 
  xmlns:atom="http://www.w3.org/2005/Atom" 
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
  xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>Tool on Untrusted Network</title>
    <link>https://untrustednetwork.net/en/tag/tool/</link>
    <description>Recent content in Tool on Untrusted Network</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>&amp;copy; Jan Kopriva 2015 - {year}</copyright>
    <lastBuildDate>Wed, 11 Jan 2023 11:50:00 +0100</lastBuildDate>
    <sy:updatePeriod>weekly</sy:updatePeriod>
    <sy:updateFrequency>weekly</sy:updateFrequency>
    
        <atom:link href="https://untrustednetwork.net/en/tag/tool/index.xml" rel="self" type="application/rss+xml" />
    
    
    

      
      <item>
        <title>TriOp update - version 1.5</title>
        <link>https://untrustednetwork.net/en/2023/01/11/triop-update-version-1.5/</link>
        <pubDate>Wed, 11 Jan 2023 11:50:00 +0100</pubDate>
        
        <atom:modified>Wed, 11 Jan 2023 11:50:00 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2023/01/11/triop-update-version-1.5/</guid>
        <description>I’ve published version 1.5 of TriOp today. Besides the addition of several CVEs into the internal list of vulnerabilities, a new feature was also introduced, which enables automatic generation of Shodan queries for the current list of vulnerabilities from the CISA Known Exploited Vulnerabilities (KEV) Catalog.
As alway, you may download the latest version of TriOp from my GitHub.</description>
        <content:encoded>&lt;p&gt;I’ve published version 1.5 of &lt;a href=&#34;https://untrustednetwork.net/en/triop/&#34;&gt;TriOp&lt;/a&gt; today. Besides the addition of several CVEs into the internal list of vulnerabilities, a new feature was also introduced, which enables automatic generation of Shodan queries for the current list of vulnerabilities from the &lt;a href=&#34;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&#34;&gt;CISA Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As alway, you may download the latest version of TriOp from &lt;a href=&#34;https://github.com/NettleSec/TriOp&#34;&gt;my GitHub&lt;/a&gt;.&lt;/p&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        
        
        
        
          
            
              <category>Tool</category>
            
          
            
              <category>TriOp</category>
            
          
            
              <category>Shodan</category>
            
          
            
              <category>CISA</category>
            
          
            
              <category>Vulnerability</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2023</category>
            
          
        
        
      </item>
      
      <item>
        <title>TriOp update - version 1.4 (and Shodan Trends)</title>
        <link>https://untrustednetwork.net/en/2021/10/28/triop-update-version-1.4-and-shodan-trends/</link>
        <pubDate>Thu, 28 Oct 2021 14:00:00 +0200</pubDate>
        
        <atom:modified>Thu, 28 Oct 2021 14:00:00 +0200</atom:modified>
        <guid>https://untrustednetwork.net/en/2021/10/28/triop-update-version-1.4-and-shodan-trends/</guid>
        <description>I’ve published version 1.4 of TriOp today. The only change in this version is the addition of CVE-2021-31206 (vulnerability used in the ProxyShell attack) to the relevant search list.
One additional point that deserves a mention is that Shodan has recently opened access to a new service called Shodan Trends, which enables users to generate trend charts for (probably) arbitrary Shodan queries. Although these charts are based on monthly averages and are therefore not as precise as charts generated from data collected on a daily basis using TriOp, they can certainly provide one with an interesting look at long-term trends.</description>
        <content:encoded>&lt;p&gt;I’ve published version 1.4 of &lt;a href=&#34;https://untrustednetwork.net/en/triop/&#34;&gt;TriOp&lt;/a&gt; today. The only change in this version is the addition of CVE-2021-31206 (vulnerability used in the ProxyShell attack) to the relevant search list.&lt;/p&gt;
&lt;p&gt;One additional point that deserves a mention is that Shodan has recently opened access to a new service called &lt;a href=&#34;https://trends.shodan.io/&#34;&gt;Shodan Trends&lt;/a&gt;, which enables users to generate trend charts for (probably) arbitrary Shodan queries. Although these charts are based on monthly averages and are therefore not as precise as charts generated from data collected on a daily basis using TriOp, they can certainly provide one with an interesting look at long-term trends. If you therefore only require general information about trends related to one or more Shodan queries and don&amp;rsquo;t need a detailed view at how things change on a day-to-day basis, then this service might be a viable alternative to TriOp for you&amp;hellip;&lt;/p&gt;
&lt;p&gt;As alway, you may download the latest version of TriOp from &lt;a href=&#34;https://github.com/NettleSec/TriOp&#34;&gt;my GitHub&lt;/a&gt;.&lt;/p&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        
        
        
        
          
            
              <category>Tool</category>
            
          
            
              <category>TriOp</category>
            
          
            
              <category>Shodan</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2021</category>
            
          
        
        
      </item>
      
      <item>
        <title>TriOp update - version 1.3</title>
        <link>https://untrustednetwork.net/en/2021/08/12/triop-update-version-1.3/</link>
        <pubDate>Thu, 12 Aug 2021 17:25:00 +0200</pubDate>
        
        <atom:modified>Thu, 12 Aug 2021 17:25:00 +0200</atom:modified>
        <guid>https://untrustednetwork.net/en/2021/08/12/triop-update-version-1.3/</guid>
        <description>I’ve published version 1.3 of TriOp today. The only change in this version is the addition of vulnerabilities used in the ProxyShell attack (CVE-2021-31207, CVE-2021-34473 and CVE-2021-34523) to the relevant search list.
Chaining of the vulnerabilities in question may lead to an unauthenticated RCE, so one would hope that given the recent media attention that was given to them, most organizations would patch them quickly. However, so far, the daily increases in number of their detections on Shodan seem to paint a slightly less optimistic picture&amp;hellip;</description>
        <content:encoded>&lt;p&gt;I’ve published version 1.3 of &lt;a href=&#34;https://untrustednetwork.net/en/triop/&#34;&gt;TriOp&lt;/a&gt; today. The only change in this version is the addition of vulnerabilities used in the &lt;a href=&#34;https://isc.sans.edu/diary/27732&#34;&gt;ProxyShell attack&lt;/a&gt; (CVE-2021-31207, CVE-2021-34473 and CVE-2021-34523) to the relevant search list.&lt;/p&gt;
&lt;p&gt;Chaining of the vulnerabilities in question may lead to an unauthenticated RCE, so one would hope that given the recent &lt;a href=&#34;https://www.securityweek.com/internet-scanned-microsoft-exchange-servers-vulnerable-proxyshell-attacks&#34;&gt;media attention&lt;/a&gt; that was given to them, most organizations would patch them quickly. However, so far, the daily increases in number of their detections on Shodan seem to paint a slightly less optimistic picture&amp;hellip;&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/2021/triop13/proxyshell-210812.png&#34; alt=&#34;ProxyShell detections - August 9 to August 12, 2021&#34; style=&#34;width:700px; border:1px solid grey&#34;&gt;
&lt;br&gt;
&lt;p&gt;As alway, you may download the latest version of TriOp from &lt;a href=&#34;https://github.com/NettleSec/TriOp&#34;&gt;my GitHub&lt;/a&gt;.&lt;/p&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.net/images/2021/triop13/proxyshell-210812.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>Tool</category>
            
          
            
              <category>TriOp</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2021</category>
            
          
        
        
      </item>
      
      <item>
        <title>TriOp update - version 1.2</title>
        <link>https://untrustednetwork.net/en/2021/03/14/triop-update-version-1.2/</link>
        <pubDate>Sun, 14 Mar 2021 14:00:00 +0100</pubDate>
        
        <atom:modified>Sun, 14 Mar 2021 14:00:00 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2021/03/14/triop-update-version-1.2/</guid>
        <description>I’ve published version 1.2 of TriOp today. A bug was present in the &amp;ldquo;add&amp;rdquo; mode in version 1.1, which resulted in incorrect behavior when parameterized queries were present in search files, and this update fixes it.
When using the &amp;ldquo;add&amp;rdquo; mode, it is now possible to specify a filter (&amp;ndash;filter), which determines what parameter from the original search file will be added to every new query. If filter is ommited, no parameter will be appended to newly added queries.</description>
        <content:encoded>&lt;p&gt;I’ve published version 1.2 of &lt;a href=&#34;https://untrustednetwork.net/en/triop/&#34;&gt;TriOp&lt;/a&gt; today. A bug was present in the &amp;ldquo;add&amp;rdquo; mode in version 1.1, which resulted in incorrect behavior when parameterized queries were present in search files, and this update fixes it.&lt;br /&gt;
When using the &amp;ldquo;add&amp;rdquo; mode, it is now possible to specify a filter (&amp;ndash;filter), which determines what parameter from the original search file will be added to every new query. If filter is ommited, no parameter will be appended to newly added queries.&lt;/p&gt;
&lt;p&gt;As alway, you may download the latest version of TriOp from &lt;a href=&#34;https://github.com/NettleSec/TriOp&#34;&gt;my GitHub&lt;/a&gt;.&lt;/p&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        
        
        
        
          
            
              <category>Tool</category>
            
          
            
              <category>TriOp</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2021</category>
            
          
        
        
      </item>
      
      <item>
        <title>TriOp update - version 1.1</title>
        <link>https://untrustednetwork.net/en/2021/03/08/triop-update-version-1.1/</link>
        <pubDate>Mon, 08 Mar 2021 11:00:00 +0100</pubDate>
        
        <atom:modified>Mon, 08 Mar 2021 11:00:00 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2021/03/08/triop-update-version-1.1/</guid>
        <description>I’ve published version 1.1 of TriOp today. I’ve added CVEs for the recent Exchange vulnerabilities to the vulnerability search list, since Shodan is now capable of detecting systems affected by them. In response to a request from the CSIRT community, I’ve also added the option for use of arbitrary filter along with a list of parameters.
In version 1.0, it was only possible to generate composite searches based on list of countries, however in version 1.</description>
        <content:encoded>&lt;p&gt;I’ve published version 1.1 of &lt;a href=&#34;https://untrustednetwork.net/en/triop/&#34;&gt;TriOp&lt;/a&gt; today. I’ve added CVEs for the recent &lt;a href=&#34;https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server/&#34;&gt;Exchange vulnerabilities&lt;/a&gt; to the vulnerability search list, since Shodan is now &lt;a href=&#34;https://twitter.com/shodanhq/status/1367525621065261062&#34;&gt;capable of detecting systems affected by them&lt;/a&gt;. In response to a request from the CSIRT community, I’ve also added the option for use of arbitrary filter along with a list of parameters.&lt;br /&gt;
In version 1.0, it was only possible to generate composite searches based on list of countries, however in version 1.1, one may specify any filter (i.e. not just “country”) for use with the list of parameters.&lt;br /&gt;
Previously, one could specify a list of searches (-s/-S) and a list of countries (-c/-C) and TriOp would run each search for each specified country and even potentially output results for each country into a specific file (&amp;ndash;country_names).&lt;br /&gt;
In the updated version, one may specify an arbitrary filter (&amp;ndash;filter) and a list of parameters for that filter (-p/-P) along with a list of searches (-s/-S) and the result will be the same. The “one output file per parameter” option is available as well (&amp;ndash;filter_names).&lt;br /&gt;
What I assume will be of most useful when it comes to this feature, will be the filter “net” – the following example shows how a command using it might look:&lt;/p&gt;
&lt;pre&gt;&lt;code class=&#34;language-command&#34; data-lang=&#34;command&#34;&gt;triop.py -s &amp;quot;port:80,port:443&amp;quot; --filter net -p &amp;quot;200.0.0.0/16,200.1.0.0/16&amp;quot;
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;in which case, the output might look similar to:&lt;/p&gt;
&lt;pre&gt;&lt;code class=&#34;language-triop&#34; data-lang=&#34;triop&#34;&gt;Current IP count for query port:80 net:&amp;quot;200.0.0.0/16&amp;quot; is 1643
Current IP count for query port:443 net:&amp;quot;200.0.0.0/16&amp;quot; is 1474
Current IP count for query port:80 net:&amp;quot;200.1.0.0/16&amp;quot; is 819
Current IP count for query port:443 net:&amp;quot;200.1.0.0/16&amp;quot; is 798
&lt;/code&gt;&lt;/pre&gt;&lt;br&gt;
&lt;p&gt;A country search could be done in the following manner:&lt;/p&gt;
&lt;pre&gt;&lt;code class=&#34;language-command&#34; data-lang=&#34;command&#34;&gt;triop.py -s &amp;quot;port:22,port:23&amp;quot; --filter country -p &amp;quot;CZ,DE&amp;quot;
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;and the output would be the same as with the use of the -c option:&lt;/p&gt;
&lt;pre&gt;&lt;code class=&#34;language-triop&#34; data-lang=&#34;triop&#34;&gt;Current IP count for query port:22 country:&amp;quot;CZ&amp;quot; is 83007
Current IP count for query port:23 country:&amp;quot;CZ&amp;quot; is 21143
Current IP count for query port:22 country:&amp;quot;DE&amp;quot; is 1467418
Current IP count for query port:23 country:&amp;quot;DE&amp;quot; is 31595
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;The original “country” options are still present but will be removed in future versions.&lt;/p&gt;
&lt;p&gt;You may download the latest version of TriOp from &lt;a href=&#34;https://github.com/NettleSec/TriOp&#34;&gt;my GitHub&lt;/a&gt;.&lt;/p&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        
        
        
        
          
            
              <category>Tool</category>
            
          
            
              <category>TriOp</category>
            
          
            
              <category>Shodan</category>
            
          
            
              <category>Vulnerability</category>
            
          
            
              <category>Exchange</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2021</category>
            
          
        
        
      </item>
      
      <item>
        <title>TriOp - Tool for quickly gathering statistical information from Shodan.io</title>
        <link>https://untrustednetwork.net/en/triop/</link>
        <pubDate>Tue, 26 Jan 2021 07:30:00 +0100</pubDate>
        
        <atom:modified>Tue, 26 Jan 2021 07:30:00 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/triop/</guid>
        <description>TriOp is a tool for quickly gathering information from Shodan.io about the number of IPs which satisfy large number of different queries. Generally, it may be useful to security researchers who wish to use data gathered from Shodan over time as a part of their research (e.g. to show how number of systems exposing remote access protocols to the internet changed as a reaction to new movement restrictions connected to the Covid-19 pandemic) and to CSIRTs, especially national ones, that wish to monitor their constituencies for changes and/or vulnerabilities, but lack the technical tooling that would enable them to periodically scan all of their external IP ranges.</description>
        <content:encoded>&lt;p&gt;TriOp is a tool for quickly gathering information from Shodan.io about the number of IPs which satisfy large number of different queries. Generally, it may be useful to security researchers who wish to use data gathered from Shodan over time as a part of their research (e.g. to show &lt;a href=&#34;https://isc.sans.edu/forums/diary/Couple+of+interesting+Covid19+related+stats/26374/&#34;&gt;how number of systems exposing remote access protocols to the internet changed as a reaction to new movement restrictions connected to the Covid-19 pandemic&lt;/a&gt;) and to CSIRTs, especially national ones, that wish to monitor their constituencies for changes and/or vulnerabilities, but lack the technical tooling that would enable them to periodically scan all of their external IP ranges.&lt;/p&gt;
&lt;p&gt;In its most basic mode of operation, TriOp takes a list of searches as an input and displays number of systems, which Shodan sees, which satisfy the search. The outputs may be saved in a CSV, which enables you to monitor &amp;ldquo;counts&amp;rdquo; for the same set of searches over time.&lt;/p&gt;
&lt;p&gt;TriOp also enables you to quickly generate list(s) of searches from parameters, which are relevant for you (e.g. if you provide a list of searches and a list of countries, the tool will generate a relevant search list for each of the countries).&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/misc/triop.png&#34; alt=&#34;TriOp&#34; style=&#34;width:400px&#34;&gt;
&lt;br&gt;
&lt;p&gt;All that is necessary to use TriOp is a valid API key, which comes with every Shodan.io account (even a free one), and to have Python 3 with the &lt;a href=&#34;https://pypi.org/project/shodan/&#34;&gt;Shodan Python library&lt;/a&gt; installed.&lt;/p&gt;
&lt;p&gt;The tool may be downloaded from &lt;a href=&#34;https://github.com/NettleSec/TriOp&#34;&gt;my GitHub page&lt;/a&gt; and bellow you may find a short tutorial showing its use in greater detail.&lt;/p&gt;
&lt;p align=&#34;center&#34;&gt;&lt;iframe width=&#34;560&#34; height=&#34;315&#34; src=&#34;https://www.youtube.com/embed/pp9lD58Dc-w&#34; frameborder=&#34;0&#34; allow=&#34;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture&#34; allowfullscreen&gt;&lt;/iframe&gt;&lt;br&gt;
&lt;kbd&gt;Direct URL: &lt;a href=&#34;https://www.youtube.com/watch?v=pp9lD58Dc-w&#34;&gt;https://www.youtube.com/watch?v=pp9lD58Dc-w&lt;/a&gt;&lt;/kbd&gt;&lt;/p&gt;</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        
        
        
        
          
            
              <category>Tool</category>
            
          
            
              <category>TriOp</category>
            
          
            
              <category>Shodan</category>
            
          
        
        
        
      </item>
      

    
  </channel>
</rss>