MobutuPehuenche's comments

MobutuPehuenche | 8 years ago | on: Web Application Penetration Testing Cheat Sheet

"The search relies on data from our crawls of the Alexa Top 1 Million sites, Search Engines, Common Crawl, Certificate Transparency, Max Mind, Team Cymru, Shodan and scans.io."

So probably CT logs.

Also, if you've ever sent a cold-cache query to a recursive resolver that didn't employ QNAME minimization (few do), it was likely harvested by pDNS replication at the TLD nameserver level and shared with a number of commercial and research parties' databases to which DNSDumpster may subscribe.

MobutuPehuenche | 8 years ago | on: Facebook Secretly Saved Videos Users Deleted

I would think this is common practice.

I know that YouTube, for example, retains videos indefinitely, because I've personally been able to retrieve videos that were deleted in as early as 2006.

It was possible for anyone to do this until some time in 2017, when they started requiring signatures for RTSP streams. All that was needed was the video ID (the eleven characters in every YouTube video URL). Didn't matter if they were private (IDs for these could be enumerated if the channel ID was known), "deleted" over ten years ago, or behind a paywall.

From ~2008 until 2015, you could do the same but with higher quality streams through the now-retired Apple TV API.

page 1