Penetration Testing mailing list archives

Re: Finding vhosts


From: Martin Mačok <martin.macok () underground cz>
Date: Tue, 25 Oct 2005 09:58:01 +0200

On Mon, Oct 24, 2005 at 04:30:28PM -0000, m123303 () richmond ac uk wrote:

If any of you knows of any other tools or techniques that might help
enumerating vhosts given an IP address please let me know.

Once or twice a year we crawl local search engines catalogues
(directories) for all URLS and we dig out all hostnames. Then we try
to resolve each and save the result (Shell, Lynx, bind-utils, cut & grep).

(Other technique is having friends at local DNS registrator :-)

When AXFR transfer fails I use dictionary attacks for subdomains
(Python script + common hostnames dictionary).

Martin Mačok
ICT Security Consultant

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 

Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: