For historical data about domain hosting or what IP a site was running from, on what platforms, etc I always start with
http://netcraft.com I find it useful to fingerprint patching lag time as well.

You may want to be mindful of any NDA you've signed if part of an official test. I know some folks who would consider certain activities as a breach of that agreement.