Full Disclosure mailing list archives

Re: vhost enumeration


From: trains () doctorunix com
Date: Mon, 24 Oct 2005 16:33:34 -0500

Quoting unknown unknown <unknown.pentester () gmail com>:


I'm very interested in the idea of finding vhosts given an IP address. So
far, the only way to do this is by querying open source facilities such as
search engines and online statistic databases.


I think a zone transfer would be the only authoritative resource. Anything else is some degree of guesswork and is bound to miss unlinked sites ,etc. there are still lots of older DNS servers out there which allow zone xfers, but the number is shrinking every day. Check all the secondary, tertiary, etc servers.


t

-------------------------------------------------
Email solutions, MS Exchange alternatives and extrication,
security services, systems integration.
Contact:    services () doctorunix com


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: