Ferret Version 1.1 – Data Seepage Detection Tool

Use Netsparker


Ferret works on the concept of “data seepage”: bits of benign data that people willingly broadcast to the world (as opposed to “leakage”, which is data people want to hide from the world).

Examples of data seepage are what happens when you power-on your computer. It will broadcast to the world the list of WiFi access-points you’ve got cached on your computer, the previous IP address you used (requested by DHCP), your NetBIOS name, your login ID, and a list of servers (via NetBIOS request) you want connections to.

Even if you then establish a VPN connection to hide everything else, you’ve already broadcasted this information to everyone on the local network.

The FERRET tool gathers this broadcasted information and correlates it. It demonstrates how much you expose to hackers.

The latest version of the Data Seepage detection tool, Ferret, is available for download. It is still in a rough form but compiles cleanly on Linux and Windows. A number of bug fixes have been introduced as well as new functionality.

You can download the Blackhat slides here:

BH_DC_07_Data_seepage.ppt

Get Ferret 1.1 here:

Ferret-1_1.zip

Or read more here.

Posted in: Hacking Tools, Networking Hacking

, , ,


Latest Posts:


snallygaster - Scan For Secret Files On HTTP Servers snallygaster – Scan For Secret Files On HTTP Servers
snallygaster is a Python-based tool that can help you to scan for secret files on HTTP servers, files that are accessible that shouldn't be public and can pose a s
Portspoof - Spoof All Ports Open & Emulate Valid Services Portspoof – Spoof All Ports Open & Emulate Valid Services
The primary goal of the Portspoof program is to enhance your system security through a set of new camouflage techniques which spoof all ports open and also emulate valid services on every port.
Cambridge Analytica Facebook Data Scandal Cambridge Analytica Facebook Data Scandal
One of the biggest stories of the year so far has been the scandal surrounding Cambridge Analytica that came out after a Channel 4 expose that demonstrated the depths they are willing to go to profile voters, manipulate elections and much more.
GetAltName - Discover Sub-Domains From SSL Certificates GetAltName – Discover Sub-Domains From SSL Certificates
GetAltName it's a little script to discover sub-domains that can extract Subject Alt Names for SSL Certificates directly from HTTPS websites which can provide you with DNS names or virtual servers.
Memcrashed - Memcached DDoS Exploit Tool Memcrashed – Memcached DDoS Exploit Tool
Memcrashed is a Memcached DDoS exploit tool written in Python that allows you to send forged UDP packets to a list of Memcached servers obtained from Shodan.
QualysGuard - Vulnerability Management Tool QualysGuard – Vulnerability Management Tool
QualysGuard is a web-based vulnerability management tool provided by Qualys, Inc, which was the first company to deliver vulnerability management services as a SaaS-based web-service.


7 Responses to Ferret Version 1.1 – Data Seepage Detection Tool

  1. ZaD MoFo March 7, 2008 at 11:15 am #

    Curiosity kill cats – I might get a try with FERRET 1.1 to correlate what is captured before initialisation and capture with Wireshark…

    I am using Wireshark as a monitor tool. A neat piece of software! On the other hand, it does not capture well thoses first bytes sent unless asked after a router purge and other arcane “twiddles” forcing re-interrogation. Even to late in autostart mode (Am I missing tomething?)

  2. zupakomputer March 7, 2008 at 6:40 pm #

    How about an OS that doesn’t automatically cache any of those things. They must exist already (ie – pre-configured, of course you can make your own versions); I’m new to all this and yet to get to play with most of the toys.

  3. Pantagruel March 9, 2008 at 9:43 pm #

    MMM linux compiled ok but doesn’t want to work with the onboard eth of my epia box :( (keep nagging ERR:libpcap: no adapters found, are you sure you are root? eventhough I am root.

    MS visual suite 2008 gives lot’s of warnings and some fatal errors
    (among which ../ferret.exe : fatal error LNK1120: 1 unresolved externals)

    Any of you had any luck yet??

  4. elpeor March 10, 2008 at 10:48 am #

    In gentoo compiled well and works perfect.
    I just discovered that I forgot to use ssl for a mail account, hahaha, and the password appeared in the output…

  5. James C March 10, 2008 at 4:41 pm #

    im have no luck compiling it on XP, could use cygwin i guess. working on ubuntu with no trouble.

  6. mauro February 16, 2009 at 10:09 pm #

    have someone compiled ferret 1.1 successfully?
    i cant do it with dev c++, gives me erros.
    can somoene help me?

  7. mauro February 16, 2009 at 10:10 pm #

    i use vista and ferret v1.0 works fine