Checking if a host is known for malicious activities
System administrators hosting users often struggle with monitoring their servers against malware distribution. Nmap allows us to systematically check if a host is known for distributing malware or being used in phishing attacks, with some help from the Google Safe Browsing API.
This recipe shows system administrators how to check if a host has been flagged by Google's Safe Browsing Service as being used in phishing attacks or distributing malware.
Getting ready
The script http-google-malware
depends on Google's Safe Browsing service and it requires you to register to get an API key. Register at http://code.google.com/apis/safebrowsing/key_signup.html.
How to do it...
Open your favorite terminal and type:
$nmap -p80 --script http-google-malware --script-args http-google-malware.api=<API> <target>
The script will return a message indicating if the server is known by Google's Safe Browsing for distributing malware or being used in...