Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 29 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow What info can be obtained just from IP
Ethical Hacker Community Forums
December 01, 2008, 08:34:18 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: What info can be obtained just from IP  (Read 1935 times)
0 Members and 1 Guest are viewing this topic.
shakuni
Jr. Member
**
Offline Offline

Posts: 78


View Profile
« on: October 03, 2008, 12:57:15 AM »

What info can be obtained just from IP
Logged

There is no rule, law or tradition that apply universally... including this one.
KrisTeason
Full Member
***
Offline Offline

Posts: 112


View Profile
« Reply #1 on: October 03, 2008, 04:06:55 AM »

I think it all depends what you do with the IP. Considering reconnaissance here, we could get the ISP of the IP, find contact information of the ISP. You could always run a few nmap scans to identify/enumerate services on the host. You could also attempt banner grabbing depending on what ports you find open on the machine itself. That's just to name a few though.
Logged
RoleReversal
Sr. Member
****
Offline Offline

Posts: 469


View Profile WWW
« Reply #2 on: October 03, 2008, 04:29:57 AM »

The level of information often depends on the thoroughness of the organisation if they have provider independant (PI) IP space, or the thoroghness of the local internet registrar (LIR) if they have provider aggregated (PA) IP space.

From a whois search on the IP you should be able to get valid information for the organisation actually using the IP (this is a requirement made by the regional internet registrars (RIR) [at least in Europe, RIPE's authority]). However often these records are ambiguous or outdated as they are not updated as regularly as they should be. Also some larger LIR routinely assign IP space from a large allocation (typically a /19-/24) and only update the whois records for the parent block.

Another useful tool for recon work is myipneighbors/, as it allows you to find other domains using the same IP. This is useful for services running virtual hosts on the same server or shared colocation environments.

It's worth noting that the above techniques do not cause any traffic to reach the target from your IP address, so they are silent in that regard. Obviously once you start stepping up a gear with port enumeration and banner grabbing etc. this changes completely.

Hope this is some help.
Logged

A little bit of sanity:
http://www.infosanity.co.uk
toggmeister
Newbie
*
Offline Offline

Posts: 21


View Profile
« Reply #3 on: October 05, 2008, 02:09:55 AM »

Another good useful resource which also allows similar functionality to myipneighbors is:

http://www.yougetsignal.com/ lots more functionality and tools though  Grin

Try also maltego (http://www.paterva.com/maltego/)

All this is done totally passively you should be able to get so much from enumerating a single ip by using these tools which should give you enough personal information on company employees (unless they use privacy protect servcies that is  Cry ) to say think about "spear-phishing" if you want to use this avenue to get into a network from a pen test perspective

Logged
RoleReversal
Sr. Member
****
Offline Offline

Posts: 469


View Profile WWW
« Reply #4 on: October 05, 2008, 03:32:21 AM »

http://www.yougetsignal.com/ lots more functionality and tools though  Grin

Nice catch, hadn't found that one before, cheers Cheesy
Logged

A little bit of sanity:
http://www.infosanity.co.uk
apollo
Newbie
*
Offline Offline

Posts: 43


View Profile WWW
« Reply #5 on: October 05, 2008, 12:52:09 PM »

EH Columnist Chris Gates presented on something similar at ToorCon.  What he presented on was given a domain name, what can you find out.  Depending on what the IP resolves to, this could definitely be useful. Check out the link to the PDF at : http://carnal0wnage.blogspot.com/

One thing that I haven't seen a lot of mentioned was google.  I know it's probably common sense, but I've been able to track down IP's directly to people based on mail archives, IRC logs, etc. 

Logged
shakuni
Jr. Member
**
Offline Offline

Posts: 78


View Profile
« Reply #6 on: October 05, 2008, 11:53:54 PM »

Thanks for the info guys.
Logged

There is no rule, law or tradition that apply universally... including this one.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.049 seconds with 22 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.