HardCIDR will query ARIN and a pool of BGP route servers
github.com
github.com
If you have a subdirectory where you run it named after your email hostname (such as "example/" for "example.com"), then it will prompt you to "overwrite the contents of the directory" and then, if you accept, it will not only overwrite the contents, it will remove the entire contents with:
cd $outdir
rm * 2>/dev/null
There's a slight violation of user expectations here. Removing and replacing the contents isn't quite the same as overwriting the contents. It may be a fine line, but it's better to err on the side of protecting the user's files, not deleting them, when deciding where to come down on that fine line.And if $outdir is empty or not there, it tries to detect that by first doing a check for -d $outdir, but this won't save the user if $outdir gets moved aside by another process while they are reading the prompt and before the cd happens, leaving them in another directory. Hopefully the user has rm aliased to rm -i but that still won't help since the rm is being run in its own shell in the script.
I know we're not supposed to focus on the negative here on HN. I'm sure the script is awesome for whatever it does. Just be careful out there!
I'm sure this is excessive paranoia, but I have never been confident to release a script that classes a directory, I'm to worked about things like subtle differences in how mktemp works on linux and mac for example.
- enter a user and mount namespace
- mount a tmpfs, e.g. over /tmp
- remount everything else as readonly
alternatively firejail --overlay-tmpfs <command>Edit: the header from the script is good, toss it into the README for great success.
> HardCidr is written by Jason Ashton, Senior Security Consultant at TrustedSec
I'm guessing it was written with pen-testing in mind.
I'm generally pretty not okay with scripts that curl | tar things (or apt-get install things, which this does if it's run on a linux) from the interwebs without my explicit consent.
By running it as root, I'd argue that you did give explicit consent for the script to do anything it wants.
If one downloads and blindly runs some random script as root, however, you are effectively allowing it to do anything it wants.
It sounds like javajosh took the time to look the script over first which, of course, is exactly what one should do.
https://iptoasn.com/ https://pypi.python.org/pypi/pyasn
I've been working on tweaking pyasn a bit and building a service around that.
$ curl ipinfo.io/8.8.8.8
{
"ip": "8.8.8.8",
"hostname": "google-public-dns-a.google.com",
"city": "Mountain View",
"region": "California",
"country": "US",
"loc": "37.3860,-122.0840",
"org": "AS15169 Google Inc.",
"postal": "94035",
"phone": "650"
}
$ curl ipinfo.io/8.8.8.8/org
AS15169 Google Inc.
And ASN details are available on the web, eg https://ipinfo.io/AS15169Also, it's not clear what they're (ipinfo.io) using as their source for the ASN. Are they simply reporting the ASN as provided by ARIN, etc., or are they actually running BGP and reporting the origin ASN as they see it in announcements. My money would be on the former, in which case any prefix hijacking would not affect the data reported by ipinfo.io.
Regardless, if you want it, that data is available from the RIRs. Go crazy.
There's often a disconnect between something like that which works for one address, and something I could actually use to do bulk lookups on 5,000,000 addresses to generate reports.
I'm a network engineer at an ISP and it's pretty common to use something like this for analyzing traffic network when considering peering sessions, for example. Even if you don't run BGP, you could use it for answering questions like "how much traffic do we send to/receive from Facebook?" and such.
RIPE's RIS dumps are performed every five minutes from more than a dozen different "vantage points" across the Internet.
ARIN used to provide an "originAS" file [1] but it looks like they quit doing that a few years ago. You may be able to find some interesting stuff browsing around /pub on their FTP server, though [2].
[0]: https://www.ripe.net/analyse/internet-measurements/routing-i...
[1]: ftp://ftp.arin.net/pub/originAS/
[2]: ftp://ftp.arin.net/pub/
> A tool to enumerate CIDRs by querying RIRs & BGP ASN prefix lookups
> Currently queries: ARIN, RIPE NCC, APNIC, AfriNIC, LACNIC
>
> Queries are made for the Org name, network handles, org handles, customer handles,
> BGP prefixes, PoCs with target email domain, and 'notify' email address - used by
> some RIRs.
>
> Note that severl RIRs currently limit query results to 256 or less, so large
> target orgs may not return all results.
>
> LACNIC only allows query of ASN or IP address bloks & cannot search for Org names
> directly. The entire DB as been downloaded to a separate file for queries to this RIR.
> The file will be periodically updated to maintain accurate information.
>
> Output saved to two csv files - one for org & one for PoCs
> A txt file is also output with a full list of enumerated CIDRs
>
> Author: Jason Ashton (@ninewires)
> Created: 09/19/2016
> ARIN, RIPE NCC, APNIC, AfriNIC, LACNIC
These are the global agencies that manage the IP address allocations
As far as "bibles" go, however, Halabi's _Internet Routing Architectures_ is the BGP variant.
TCP/IP Illustrated might not mention CIDR since it was still pretty new when those books were written. My copies haven't been opened in years so I can't be sure.
If you've performed any subnetting in the last 15 years or so, however, I fully expect that you have encountered CIDR.
The very first line has enough information to know what it does:
"A tool to enumerate CIDRs by querying RIRs & BGP ASN prefix lookups"
In other words, it queries two sources (regional Internet registries -- the organizations referred to above -- and information from the BGP protocol) to enumerate blocks of IP addresses.
Just because you're "in the industry" doesn't mean you know everything about everything. I'm not a developer so half the things discussed here on HN are waaaaay over my head.
To what end?