{"id":7552,"date":"2020-11-15T17:54:05","date_gmt":"2020-11-15T17:54:05","guid":{"rendered":"https:\/\/www.hexacorn.com\/blog\/?p=7552"},"modified":"2020-11-15T17:54:05","modified_gmt":"2020-11-15T17:54:05","slug":"when-good-urls-are-bad-for-business","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2020\/11\/15\/when-good-urls-are-bad-for-business\/","title":{"rendered":"When good URLs are bad for business"},"content":{"rendered":"\n<p>Analyzing memory dumps comes with a price &#8211; &#8216;good&#8217; information overload. One that annoys me a lot is running URl\/domain extraction tools over the memdump and finding tones of legitimate URLs that make it harder to find the juicy stuff I am after. I mean, things like:<\/p>\n\n\n\n<ul><li>http:\/\/www.w3.org\/2001\/XMLSchema-instance<\/li><li>http:\/\/www.w3.org\/2000\/svg<\/li><li>http:\/\/www.w3.org\/1999\/xlink<\/li><li>http:\/\/www.w3.org\/XML\/1998\/namespace<\/li><li>http:\/\/www.w3.org\/1999\/xhtml<\/li><li>http:\/\/www.w3.org\/2000\/xmlns\/<\/li><li>http:\/\/www.w3.org\/TR\/xhtml1\/DTD\/xhtml1-strict.dtd<\/li><li>http:\/\/update.microsoft.com<\/li><li>http:\/\/schemas.microsoft.com\/rtc\/2009\/05\/simplejoinconfdoc<\/li><\/ul>\n\n\n\n<p>There is a lot of &#8216;good&#8217; URLs embedded in manifests, various resources (e.g. HTML\/XML\/Json\/CSS files), certificates, and many are introduced as a side-effect of linking with static libraries that often include copyright information and URL to author&#8217;s page. And of course, there is vendor information either directly in the resources or in binary or its config files.<\/p>\n\n\n\n<p>Not only memory dump analysis suffer from it. The same goes for network log analysis &#8211;  lots of requests that &#8216;hide&#8217; the juicy stuff are related to authentication checks, downloads from certificate stores, etc..<\/p>\n\n\n\n<p>In an effort to help with analysis I started building a small repository of these &#8216;good&#8217; URL (at the moment primarily related to certificates). I extracted these from my &#8216;good&#8217; sample repository so I believe all of them are legitimate. If you find any error, please let me know.<\/p>\n\n\n\n<p>You can download the repo <a href=\"https:\/\/hexacorn.com\/d\/good_urls.txt\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Analyzing memory dumps comes with a price &#8211; &#8216;good&#8217; information overload. One that annoys me a lot is running URl\/domain extraction tools over the memdump and finding tones of legitimate URLs that make it harder to find the juicy stuff &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2020\/11\/15\/when-good-urls-are-bad-for-business\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[19,46,9,33],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/7552"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=7552"}],"version-history":[{"count":4,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/7552\/revisions"}],"predecessor-version":[{"id":7556,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/7552\/revisions\/7556"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=7552"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=7552"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=7552"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}