- Notifications
You must be signed in to change notification settings - Fork70
A tool for IDN homograph attacks and detection.
License
evilsocket/ditto
Folders and files
| Name | Name | Last commit message | Last commit date | |
|---|---|---|---|---|
Repository files navigation
Ditto is a small tool that accepts a domain name as input and generates all its variants for anhomograph attack as output, checking which ones are available and which are already registered.
PoC domains
Theimage on docker hub is updated on every push, you can just:
docker run evilsocket/ditto -hCompiling from sources requires the go compiler, this will install the binary in$GOPATH/bin:
# make sure go modules are usedGO111MODULE=on go get github.com/evilsocket/ditto/cmd/dittoTo only transform a string:
ditto -string googleFor a domain:
ditto -domain facebook.comUse more concurrent workers to increase speed (WARNING: might cause a temporary IP ban from the WHOIS servers):
ditto -workers 4 -domain facebook.comIf instead of mutating the domain name you want to check other TLDs (throttle is set to 1s in order to avoid beingblocked by WHOIS servers due to the many requests in a short timeframe):
ditto -domain facebook.com -tld -throttle 1000 -limit 100Only show available domains:
ditto -domain facebook.com -availableOnly show registered domains:
ditto -domain facebook.com -registeredOnly show registered domains that resolve to an IP:
ditto -domain facebook.com -liveShow WHOIS information:
ditto -domain facebook.com -live -whoisSave to CSV file with extended WHOIS information:
ditto -domain facebook.com -whois -csv output.csvKeep running and monitoring for changes every hour:
ditto -domain facebook.com -monitor 1hThe same but also keep and store the changes as JSON files:
ditto -domain facebook.com -monitor 1h -changes /some/path -keep-changesExecute a command if changes have been detected (see example send-email-report.sh in this repo, automatically added to the docker image):
ditto -domain facebook.com \ -monitor 1h \ -trigger "/usr/bin/send-email-report.sh {{.Domain}} {{.ChangesFile}} your@email.com"For more options:
ditto -helpReleased under the GPL3 license.
About
A tool for IDN homograph attacks and detection.
Resources
License
Uh oh!
There was an error while loading.Please reload this page.
Stars
Watchers
Forks
Releases
Packages0
Uh oh!
There was an error while loading.Please reload this page.