Gathering Information From Job Websites

M3m0ry

Kıdemli Üye
3 Haz 2017
4,410
126
3
xD
e55ri5.png


Gathering Information From Job Websites

People can leave a trace and be watched from job looking websites and search engines. For example, he/she can leave his/her CV and his/her ad on different job looking websites. We can get his/her e-mail address, phone number, address, hobbies, abilities from that CVs. You can determine your victim's weak points, and you can attack to him/her with social engineering.

Uff66y.png


Example Job Looking Websites;

LinkedIn
Indeed
CareerBuilder Job Board
Monster
SimplyHired
Glassdoor
Handshake
ZipRecruiter

e55ri5.png


Information Gathering Tool For Linkedln

Detailed Expression: https://www.turkhackteam.org/sosyal-muhendislik/1873532-linkedin-bilgi-toplama-p4rs.html

What Is CrossLinked

CrossLinked makes a list of all workers' Linkedln accounts and their ranks (senior pentester etc.) in a company.

CrossLinked Link

https://github.com/m8r0wn/crosslinked

Click this link and go to GitHub adress.

Open terminal and type this;

Kod:
cd Desktop/

We came to Desktop directory. After then,

Kod:
git clone https://github.com/m8r0wn/crosslinked

Type this and download that tool.

After then,

Kod:
cd CrossLinked/

Type this. We are in CrossLinked file now. And,

Kod:
pip3 install -r requirements.txt

Type this for necessary installing steps

It showed example using to us.

Now back to Terminal and start to using.

Kod:
python3 crosslinked.py -f 'twitter{first}.{last}' -t 45 -j 0.5 twitter

Type this. We'll learn Twitter accounts of workers with this

It said it wrote that account usernames in names.txt file. Type this for see them.

Kod:
cat names.txt

As you can see, we found accounts of belong to that company's workers.

Now, we'll make a list of their jobs in company.

Kod:
python3 crosslinked.py -v -f 'twitter\{f}{last}' -t 45 -j 0.5 twitter

Type this. We'll do this process with -v parameter.

Now, we can see that datas.

Let's look to them on Microsoft too.

Kod:
python3 crosslinked.py -f 'microsoft{f}.{last}' microsoft

Type this in Terminal.

As you can see, we reached to datas.

FVtBIb.png


-t : Is about time out, default value is 25 seconds
-j : Is about how deep it's gonna dig, default is 0 but my recommendation is 0.5

I recorded a video for show the results to you. (First video is my)

[ame]https://www.youtube.com/watch?v=x20RigzL0-E[/ame]

[ame]https://www.youtube.com/watch?v=hVQFxzFi9rs[/ame]

e55ri5.png


Is It Illegal Gathering Information on Linkedln

A company which has more than 100 employees in it, can gather all public data in LinkedIn easily by developing a software. It can make this gathering process with continuously for update that informations.

Company must do these 2 processes for gathering information with software: Web Crawling and Web Scraping. The company collect of workers' profile links with Web Crawling in Linkedln. And start to gathering information (username, name and surname etc.) from them with Web Scraping.


Source: https://www.turkhackteam.org/sosyal-muhendislik/1909455-siteleri-uzerinden-veri-toplama.html

Translator: M3m0ry
 
Son düzenleme:
Üst

Turkhackteam.org internet sitesi 5651 sayılı kanun’un 2. maddesinin 1. fıkrasının m) bendi ile aynı kanunun 5. maddesi kapsamında "Yer Sağlayıcı" konumundadır. İçerikler ön onay olmaksızın tamamen kullanıcılar tarafından oluşturulmaktadır. Turkhackteam.org; Yer sağlayıcı olarak, kullanıcılar tarafından oluşturulan içeriği ya da hukuka aykırı paylaşımı kontrol etmekle ya da araştırmakla yükümlü değildir. Türkhackteam saldırı timleri Türk sitelerine hiçbir zararlı faaliyette bulunmaz. Türkhackteam üyelerinin yaptığı bireysel hack faaliyetlerinden Türkhackteam sorumlu değildir. Sitelerinize Türkhackteam ismi kullanılarak hack faaliyetinde bulunulursa, site-sunucu erişim loglarından bu faaliyeti gerçekleştiren ip adresini tespit edip diğer kanıtlarla birlikte savcılığa suç duyurusunda bulununuz.