AndrewNohawk

Blog

General

Facebook GraphAPI and Maltego

So a while back facebook released their graph API a way for websites and other to integrate with facebook, things like: Searching Profile enumeration ( status / feed / info ) Friend enumeration You can read the entirety of the functions at the Graph API documentation section on facebook. So the first thing you notice…

Coding

Hello Webcam!

So i figured i’d drop a quick update on what i’ve been messing around with, firstly ZACon II was awesome! I’m really dissapointed i didn’t submit a better talk and get a chance again, however i did win the badge competition and get to make my own cool badge: Some of the talks i really…

CodingSecurity

Persistent XSS: more than a popup :)

So a while ago I asked if I was allowed to play with http://www.bravadogaming.com/ and I got a positive response, I kinda looked around at their custom CMS,  didnt see anything immediately available, playing with cookies, changing values here and there, got some SQL errors on http://www.bravadogaming.com/articles/%27%20OR%201=1%20#/ but nothing really spectacular: I looked around some…

Coding

NLP/NER: First views

So recently we have really been struggling at work with NLP/tags/phrases relating to a specific person/phrase. For example, you put down something like “Maltego” and you would like it to return things like the company (Paterva),  Information mining, Open source forensics, etc etc So i started looking around for NER/NLP API’s online and i found…

Security

ZaCon ’09

So we had a little security con here in .za (South Africa), www.zacon.org.za – basically an uncon styled conference: An unconference is a facilitated, participant-driven conference centered around a theme or purpose. The term “unconference” has been applied, or self-applied, to a wide range of gatherings that try to avoid one or more aspects of…