Penetration Testing mailing list archives

Re: Multiple IP on the same server howo to idenfity


From: Paul Johnston <paul () westpoint ltd uk>
Date: Fri, 11 Jun 2004 12:03:50 +0100

Hi,

There's an interesting paper here: http://reports-archive.adm.cs.cmu.edu/anon/2002/CMU-CS-02-146.ps

Regards,

Paul

NetExpress wrote:

Hi, the problem is, if I am doing a penetration test from internte to many servers, probably there should be some IP ont the same server o network adapter like load balancer. In a report, and to avoid false positive, should be usefull to identify which IPs are on the same server, but how? If I should be in the internal network I am testing I'll use arp to find the MAC address of each IP and I should have solved, but from Internet I cannot use arp.

From Internet I could use the banner, but this is not sure, I could have more then one application server on the same server with n-IP on application server A and m-IP on the application server B getting the banner should not be the right choise especialy with proxy.

Any idea?

Thanks

Alessandro Fiorenzi



--
Paul Johnston
Internet Security Specialist
Westpoint Limited
Albion Wharf, 19 Albion Street,
Manchester, M1 5LN
England
Tel: +44 (0)161 237 1028
Fax: +44 (0)161 237 1031
email: paul () westpoint ltd uk
web: www.westpoint.ltd.uk



Current thread: