DMitry (Deepmagic Information Gathering Tool) is a UNIX/(GNU) Linux Command Line program coded purely in C with the ability to gather as much information as possible about a host.
DMitry has a base functionality with the ability to add new functions, the basic functionality of DMitry allows for information to be gathered about a target host from a simple whois lookup on the target to UpTime reports and TCP portscans.
The application is considered a tool to assist in information gathering when information is required quickly by removing the need to enter multiple commands and the timely process of searching through data from multiple sources.
Base functionality is able to gather possible sub-domains, email addresses, uptime information, TCP port scan, WHOIS lookups, and more.
Features
The information is gathered with following methods:
- Perform an Internet Number whois lookup.
- Retrieve possible uptime data, system and server data.
- Perform a SubDomain search on a target host.
- Perform an E-Mail address search on a target host.
- Perform a TCP Portscan on the host target.
- A Modular program allowing user specified modules
Usage
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
|
-o filename
Create an ascii text output of the results to the "filename"
specified. If no output filename is specified then output will
be saved to "target.txt". If this option is not specified in
any form output will be sent to the standard output (STDOUT) by
default. This option MUST trail all other options, i.e.
"./dmitry -winseo target".
-i Perform an Internet Number whois lookup on the target. This
requires that the target be in the form of a 4 part Internet
Number with each octal seperated using the ‘.’ notation. For
example, "./dmitry -i 255.255.255.255".
-w Perform a whois lookup on the ’host’ target. This requires that
the target be in a named character format. For example,
"./dmitry -w target" will perform a standard named whois lookup.
-n Retrieve netcraft.com data concerning the host, this includes
Operating System, Web Server release and UpTime information
where available.
-s Perform a SubDomain search on the specified target. This will
use serveral search engines to attempt to locate sub-domains in
the form of sub.target. There is no set limit to the level of
sub-domain that can be located, however, there is a maximum
string length of 40 characters (NCOL 40) to limit memory usage.
Possible subdomains are then reversed to an IP address, if this
comes back positive then the resulting subdomain is listed.
However, if the host uses an asterisk in their DNS records all
resolve subdomains will come back positive.
-e Perform an EmailAddress search on the specified target. This
modules works using the same concept as the SubDomain search by
attempting to locate possible e-mail addresses for a target
host. The e-mail addresses may also be for possible sub-domains
of the target host. There is a limit to the length of the e-
mail address set to 50 characters (NCOL 50) to limit memory
usage.
-p Perform a TCP Portscan on the host target. This is a pretty
basic module at the moment, and we do advise users to use some‐
thing like nmap (www.insecure.org/nmap/) instead. This module
will list open, closed and filtered ports within a specific
range. There will probably be little advancement upon this mod‐
ule, though there will be some alterations to make it a little
more user friendly. There are also other options for this mod‐
ule that can affect the scan and its relative output.
-f This option will cause the TCP Portscan module to report/display
output of filtered ports. These are usually ports that have
been filtered and/or closed by a firewall at the specified
host/target. This option requires that the ’-p’ option be
passed as a previous option. For example, "./dmitry -pf tar‐
get".
-b This option will cause the TCP Portscan module to output Banners
if they are received when scanning TCP Ports. This option
requres that the ’-p’ option be passed as a previous option.
For example, "./dmitry -pb target".
-t This sets the Time To Live (TTL) of the Portscan module when
scanning individual ports. This is set to 2 seconds by default.
This is usually required when scanning a host that has a fire‐
wall and/or has filtered ports which can slow a scan down.
|
You can download DMitry here: