Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 33 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow How to discovery all ip on a network
EH-Net
May 22, 2013, 01:16:05 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: How to discovery all ip on a network  (Read 11612 times)
0 Members and 1 Guest are viewing this topic.
KH3
Newbie
*
Offline Offline

Posts: 7


View Profile
« on: September 17, 2007, 04:32:28 PM »

As a new pentester - i wonder how to discover all ipīs on a network if you have a connection to the network and donīt know whatīs on the net. Incl. machines on routed network.

Any good hintīs or tools?

KH3
Logged
LSOChris
Guest
« Reply #1 on: September 17, 2007, 05:45:36 PM »

nmap -sP 192.168.0.0/24
Logged
EmanoN
Newbie
*
Offline Offline

Posts: 41


View Profile
« Reply #2 on: September 17, 2007, 06:09:14 PM »

Host discovery is the very first skill for  a security pro or a hacker. The first thing a hacker does when he goes to a coffee shop is connect to the network and ifconfig and see what dhcp gave him. If his IP is something like 192.168.9.105, then he has an idea of the network range and then will attempt a host discovery. He will first try the default -sS nmap option just to look for low hanging fruit. If anything shows up with -sS or -sT then he knows those might be easier targets. If nothing appears then he steps up his scans. Nmap is the premier open source scanner. There was a tut about it posted on this site  and thats how I found this place  from slashdot, but now its gone. No worries because there are many free nmap tuts out there. Make sure its free, I saw this one dude trying to sell the "secret" of nmap and thats total bs. The only secret is to download and start working with it and not just read about it!
« Last Edit: September 17, 2007, 06:16:35 PM by EmanoN » Logged
KH3
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #3 on: September 18, 2007, 01:14:39 AM »

Host discovery is the very first skill for  a security pro or a hacker. The first thing a hacker does when he goes to a coffee shop is connect to the network and ifconfig and see what dhcp gave him. If his IP is something like 192.168.9.105, then he has an idea of the network range and then will attempt a host discovery. He will first try the default -sS nmap option just to look for low hanging fruit. If anything shows up with -sS or -sT then he knows those might be easier targets. If nothing appears then he steps up his scans. Nmap is the premier open source scanner. There was a tut about it posted on this site  and thats how I found this place  from slashdot, but now its gone. No worries because there are many free nmap tuts out there. Make sure its free, I saw this one dude trying to sell the "secret" of nmap and thats total bs. The only secret is to download and start working with it and not just read about it!

Thanks - I know of and use NMAP, the question here is not to discover host on the LAN where you have and ip, but on the coonected WAN. This is on a closed network with branches. So is there a sure and quick way to discover host connected on other segment (via Cisco routers)? I can not asume that that the other ip segment are same class network.
Logged
KH3
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #4 on: September 18, 2007, 01:15:14 AM »

nmap -sP 192.168.0.0/24

Thanks - I know of and use NMAP, the question here is not to discover host on the LAN where you have and ip, but on the coonected WAN. This is on a closed network with branches. So is there a sure and quick way to discover host connected on other segment (via Cisco routers)? I can not asume that that the other ip segment are same class network.
Logged
LSOChris
Guest
« Reply #5 on: September 18, 2007, 06:25:59 AM »

look at the routing table on the exploited host then.

it should tell you other networks that is/has been using regularly
Logged
EmanoN
Newbie
*
Offline Offline

Posts: 41


View Profile
« Reply #6 on: September 18, 2007, 10:39:41 AM »

Depending on how the router is configured, you can sometimes use a tool like Proxycap to tunnel through and then run your scans.
Logged
T3rm1ght
Newbie
*
Offline Offline

Posts: 25



View Profile
« Reply #7 on: October 04, 2007, 06:34:22 PM »

i think cain and abel can help u if the router broadcasts protocal updates

also you can do a traceroute to a public IP after you default gateway the next        1 or 2  hops is the wan link interface IP or the network behind ur Default GW

hope this works
Logged

>>There Is Always A Blind Spot In
>>Every Software, It's Up To Us To Find It
Diablo22
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #8 on: October 05, 2007, 07:39:50 AM »

Not all routers will allow you to scan their Lan!
Logged
T3rm1ght
Newbie
*
Offline Offline

Posts: 25



View Profile
« Reply #9 on: October 05, 2007, 08:04:47 AM »

Not all routers will allow you to scan their Lan!

yes this is because routers separate broadcast domains, but what ever be the case there will by all means be a next hop. if that next hop ip not the interface to the ISP then you have something to start with.
Logged

>>There Is Always A Blind Spot In
>>Every Software, It's Up To Us To Find It
JeffCT
Newbie
*
Offline Offline

Posts: 10


View Profile
« Reply #10 on: October 15, 2007, 08:21:05 PM »

Checking your own IP assigned via DHCP is a good start, and traceroutes. Or, you could just scan all non-routable IPs. They are:

172.16-31.0.0 (or 172.16.0.0/12)
192.168.0.0/16
10.0.0.0/8

Logged

CISSP, CEH
KH3
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #11 on: August 28, 2008, 06:15:31 AM »

God points and answers :O)

Itīs a while ago - but ended up scanning all non routeable subnets anyway (was not the easy solution that I hoped for ) But a clue to others SNMP will give you a pretty god hint of the subnets connected to routers.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.074 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.