Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
Jan 2009 Free Giveaway Sponsor - Black Hat DC
Scooby Doo and the Crypto Caper - Answers and Winners
Daemon - A Contest Revealed
Hacking: The Art of Exploitation 2nd Edition
Nov 2008 Free Giveaway - Winners
Dec 2008 Free Giveaway Sponsor - SANS
Santa Claus is Hacking to Town
Plug-N-Play Network Hacking
Nov 2008 Free Giveaway Sponsor - CWNP
Daemon - A Contest Begins Now
It Happened One Friday - Answers and Winners
Daemon - A Contest
Scooby Doo and the Crypto Caper
MS Blue Hat Hackers Headline Chicago Security Con
The Pen Testing Perfect Storm Webcast Series with Skoudis, Wright, Johnson
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 23 guests and 1 member online
EH-Net Donations
Enter Amount:
$
CAD
USD
GBP
AUD
JPY
EUR
Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations
You are here:
Home
Forum
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
IP Address Block Enumeration
Ethical Hacker Community Forums
January 08, 2009, 03:52:31 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100!
www.chicagocon.com/content/view/103/51/
Home
Help
Calendar
Login
Register
Ethical Hacker Community Forums
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
IP Address Block Enumeration
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: IP Address Block Enumeration (Read 2618 times)
0 Members and 1 Guest are viewing this topic.
SynJunkie
Newbie
Offline
Posts: 24
IP Address Block Enumeration
«
on:
November 06, 2008, 12:19:20 PM »
I would like to what tools and methods other people may use for IP address block enumeration. I have used qtrace.pl in the past but i'm not aware of any other tools / websites that may be of use.
I find that in books, articles and websites there is often very little emphasis on clearly identify the network boundaries of the target.
Does anyone have any suggestions?
Thanks
SynJunkie
«
Last Edit: November 06, 2008, 12:27:35 PM by SynJunkie
»
Logged
----------------------------------
http://synjunkie.blogspot.com
BillV
Hero Member
Offline
Posts: 883
Re: IP Address Block Enumeration
«
Reply #1 on:
November 06, 2008, 01:07:29 PM »
I guess I'm a bit confused on what you're looking for. Are you looking for owners of IP blocks? A simple whois command/lookup won't work?
Logged
SynJunkie
Newbie
Offline
Posts: 24
Re: IP Address Block Enumeration
«
Reply #2 on:
November 07, 2008, 12:03:14 PM »
I find that in general a whois might give me the isp assigned block. but where i have found a host in a range by using something like Fierce, i want to find the size of that range assigned to the target network..
Logged
----------------------------------
http://synjunkie.blogspot.com
RoleReversal
Hero Member
Offline
Posts: 507
Re: IP Address Block Enumeration
«
Reply #3 on:
November 09, 2008, 09:50:44 AM »
SynJunkie,
in
theory
whois should provide the inform you require as BillV states. However not all LIR's keep the whois database updated to that level despite the rules and regs stating that they should so your mileage may vary.
As an alternative you could try pinging some potential network boundaries, often (not always) I have seen a broadcast IP create multiple ICMP replies to a single request.
Logged
A little bit of sanity:
http://www.infosanity.co.uk
SynJunkie
Newbie
Offline
Posts: 24
Re: IP Address Block Enumeration
«
Reply #4 on:
November 09, 2008, 05:29:02 PM »
Thanks RoleReversal. That was one of my methods (nmap xxx.xxx.xxx.xxx/24 -sP) and then look for typical boundary type devices such as routers or firewalls. Obviously this method isn't that reliable and I was hoping that there was another more reliable option for footprinting the target.
Oh well, worth a try.
Cheers.
Syn
Logged
----------------------------------
http://synjunkie.blogspot.com
jimbob
Sr. Member
Offline
Posts: 332
Re: IP Address Block Enumeration
«
Reply #5 on:
November 10, 2008, 08:29:19 AM »
It may also be of use to enumerate any DNS hostnames you can find and see where they resolve to. This could help define the size of the network. You can start by trying reverse lookups of the IP addreses you think are in the network. Results for an unexpected domain might indicate you are beyond the network boundaries.
If you can do a zone transfer then check the addresses where the hostnames point to. Check out DNS records such as MX and NS. Using data from separate sources and queries can help build a better understanding and increase your confidence in the results.
Jimbob
Logged
SynJunkie
Newbie
Offline
Posts: 24
Re: IP Address Block Enumeration
«
Reply #6 on:
November 10, 2008, 10:52:23 AM »
Thanks Jimbob. Again, these are methods I already use. Maybe I was looking for a tool that does the same as Senseposts qtrace.pl but it doesn't exist.
Thanks for the reply though.
Logged
----------------------------------
http://synjunkie.blogspot.com
ChrisG
EH-Net Columnist
Hero Member
Offline
Posts: 1049
Re: IP Address Block Enumeration
«
Reply #7 on:
November 10, 2008, 07:25:14 PM »
a combination of maltego and fierce should do the trick for you
Logged
...tests i took go here...
http://carnal0wnage.blogspot.com/
slimjim100
EH-Net Columnist
Sr. Member
Offline
Posts: 365
Re: IP Address Block Enumeration
«
Reply #8 on:
November 10, 2008, 09:36:25 PM »
Another thing I do because I am a router guy is to ping and trace route the range you suspect. With ISP's some times using there own host names you can find smaller subnet ranges with ping times. Host normally have very different reply times than routers and ture network devices. So the wire address and the network broadcast of a smaller network inside a class C IP network can some times be identified by a similar ping time. Also trace route will give you host names. I think it was already stated but reverse DNS also can help ID a smaller subnet range.
my 2 cents
Brian
aka Slimjim100
Logged
CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
SynJunkie
Newbie
Offline
Posts: 24
Re: IP Address Block Enumeration
«
Reply #9 on:
November 13, 2008, 05:34:03 PM »
The reverse DNS i was well aware ofbut the traceroute and ping method is pretty interesting. I had thought that traceroute might be useful for certain types of mapping or helping to ID honeynets but your method certainly sounds useful.
Thanks.
Logged
----------------------------------
http://synjunkie.blogspot.com
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Special Events
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009
=> News Items and General Discussion About EH-Net
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> Certification
===> The Charter Study Group - Pen Test
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
=====> CEH - Official Course Modules v4
=====> CEH - Official Course Modules v5
=====> CEH - Official Course Modules v6
===> CPTS - Certified Pen Testing Specialist
=====> CPTS - Official Course Modules v5
===> CPTE - Certified Pen Testing Expert
=====> CPTE - Official Course Modules v1
===> ECSA - EC-Council Certified Security Analyst
=====> ECSA - Official Course Modules v1.2
=====> ECSA / LPT - Official Course Modules v3
===> OSCP - Offensive Security Certified Professional
===> GPEN - GIAC Certified Penetration Tester
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
=====> CHFI - Official Course Modules v2
===> EnCE - EnCase® Certified Examiner
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Hardware
=> Malware
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Gates
=> Heffner
=> Hoffman
=> RichM
=> Murray
=> J. Peltier
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
Loading...
Sponsors
Polls
How many security events including conferences and training do you attend a year:
1 - 2
3 - 4
5 - 6
7+
None - But want to
None - Choose not to
Support EH-Net
Support EH-Net by
Buying all of your
Amazon items using
the search bar above.
Try CBT Nuggets Free!
Recent Forum Topics
CEH - Certified Ethical Hacker
: Helow... help some tutorials...
(7) by
K3lV1n
CEH - Certified Ethical Hacker
: CEH is a scam
(20) by
K3lV1n
Malware
: uninstall trend mciro officescan clients
(0) by
Hack_80
Mass Media
: Daniel Suarez Interview
(9) by
blackazarro
Malware
: Security Forecast for 2009
(5) by
jason
News from the Outside World
: Is this acceptable?
(9) by
jason
Wireless
: Wireless Pen Testing Cards
(6) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Technical
(1) by
jason
Gates
: Oracle version module for metasploit
(2) by
BillV
Book Reviews
: [Article]-Mitnick - The Art Of Intrusion: Ch 1 - Hacking The Casinos For A Million Bu...
(5) by
jason
Links to cool sites.
: Free Computer Engineering Classes From Stanford
(3) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Creative
(1) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: [Article]-Scooby Doo and the Crypto Caper - Answers and Winners
(2) by
jason
News Items and General Discussion About EH-Net
: [Article]-Jan 2009 Free Giveaway Sponsor - Black Hat DC
(1) by
jason
Book Reviews
: Need a book suggestion!
(2) by
jason
News Items and General Discussion About EH-Net
: EH-Net Milestone - 2 Articles Cross 1 Million Page Views
(3) by
BillV
Other
: What kind of lab, machines you have for your security testing?
(12) by
charlottebandit
Malware
: Network Virus Problem
(9) by
RoleReversal
Wireless
: WUSB600N good usb ?
(2) by
nap191
Other
: FBI code cracking challenge
(3) by
jimbob
Calendar Of Events
: RSA 2009
(0) by
don
Forensics
: Network Forensic tools/practice/techniques
(2) by
jimbob
Malware
: Autoplay when i try to open the drive.
(4) by
jimbob
Physical Security
: Magnetic stripe card spoofing
(4) by
jimbob
Malware
: THe website is Evil but what to do??
(1) by
jimbob
Other
: Insanity?
(3) by
jason
CEH - Certified Ethical Hacker
: Any Practice Environment for learning tool for CEH?
(15) by
don
Wireless
: a petri-dish bridge
(2) by
don
CEH - Certified Ethical Hacker
: TFTP Tranfer time out
(5) by
jason
Tools
: tool to trace users
(8) by
pseud0
Malware
: Malware Challenge 2008 Analysis
(0) by
blackazarro
Programming
: Python 3.0 Released
(0) by
don
Forensics
: SANS SIFT Forensic toolkit
(1) by
don
Links to cool sites.
: Omgili Hacking - Another Search Engine dedicated to Hacking Related Forums
(2) by
RoleReversal
Tools
: Insecure.org's 2006 Top 100 Security Tools List Released
(10) by
shednik
Other
: Happy New Year!
(8) by
vijay2
CEH - Official Course Modules v6
: Community-built CEH Wiki
(2) by
yehg
Vote For EH-Net
progenic.com
binarica.com
technorati fave
Privacy Notice
for TDCC & All Properties
© 2009 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.