Re: [Full-Disclosure] How to obtain hostname lists

From: Harlan Carvey (keydet89_at_yahoo.com)
Date: 09/28/04

  • Next message: DanB UK: "Re: [Full-Disclosure] Re: Full-Disclosure digest, Vol 1 #1933 - 20 msgs"
    To: Full-Disclosure <full-disclosure@lists.netsys.com>
    Date: Tue, 28 Sep 2004 09:36:43 -0700 (PDT)
    
    

    None of this is really magic, and is publicly
    available via a variety of sources...

    > I would like to know what techniques can Intruders
    > use to obtain a lists
    > of hostname and attack them with exploits code?
    > For example, a huge list like:
    > www.foo.com
    > www.bar.com

    Scanning, mostly. Also, DNS zone transfers, but many
    times it's just plugging a class C or B address range
    into a scanner and hitting enter.

    > And so on. Also, they can have a lists with certain
    > criteria in common
    > (os, httpdver) and do a more selective attack. I
    > want to know how they
    > can obtain hostnames asnd create a huge database for
    > potencial host victims?

    Besides the usual scanning techniques, throw Googling
    and searches via Netcraft for httpd's into the mix.

    =====
    ------------------------------------------------------------------------
    Harlan Carvey, CISSP
    "Windows Forensics and Incident Recovery"
    http://www.windows-ir.com
    http://groups.yahoo.com/group/windowsir/
    ------------------------------------------------------------------------

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: DanB UK: "Re: [Full-Disclosure] Re: Full-Disclosure digest, Vol 1 #1933 - 20 msgs"

    Relevant Pages

    • [Full-Disclosure] How to obtain hostname lists
      ... I would like to know what techniques can Intruders use to obtain a lists ... of hostname and attack them with exploits code? ... and do a more selective attack. ...
      (Full-Disclosure)
    • Re: Developmental Dictionary Attack
      ... Do you have any idea where people get their lists of common ... use your data gathering method as an input to a real world attack. ... high security systems can have physical lockouts, ... word dictionaries aren't too unusual for this) and then you iterate ...
      (sci.crypt)
    • Re: Why misc.survivalism should keep on talking about _THREAT MODELS_
      ... threat models and how to deal with them. ... big attack - the one we won't recover from. ... participants to do a smallpox vaccine study, ... you have done the same with your "lists". ...
      (misc.survivalism)
    • Re: Agendas
      ... and uses falses identities like ianhillsmith to attack ... copies stuff from all over for your postings. ... One who sets up blogs and mails to lists about how evil and horrible ... exist as long as yahoo groups and usenet groups have online archives, ...
      (sci.astro.amateur)
    • Re: Publishing Nimda Logs == BAD IDEA
      ... >we will NOT, however, be publishing a comprehensive list of infected ... these worm infection attempts ... by the fact that the sources for such an attack would have already been ... if you have your own lists of infected hosts, ...
      (Vuln-Dev)