RE: Find out the subnetting of a company

From: Rob J Meijer (rmeijer_at_xs4all.nl)
Date: 07/21/04

  • Next message: Tim: "Re: Find out the subnetting of a company"
    Date: Wed, 21 Jul 2004 09:54:47 +0200 (CEST)
    To: Dieter Sarrazyn <dsr@ascure.com>
    
    

    I would sugest starting out at a lower level, you are on a directly
    connected segment with routers to talk to directly, just using the
    'remote' methods of testing is throwing away lots of information available
    by being on the same segment as some of the routers.

    With ARP Just sweep the full /8 for arp responses as in many cases routing
    boxes will respond to the IP of one interface on an other interface, in
    some cases they will even respond to any routable adress, and
    in any case you will locate routers by 'router only vendors' by
    looking at their MAC prefix.
    After this you will have a probably (almost) complete list of available
    routers on your segment.
    Ones you have the MAC adress of the routers, you can try to communicate
    with it using any of the normaly available router protocols in order
    to get you starting information on subnet routing.
    Ones you know (or have a viable hypothesis about) what subnets are
    available truegh what routers, you can adjust your own routing table
    accordingly and you can start using the different type
    of 'remote' scans available to locate systems on the subnets and try to
    use traceroute to the subnets. If traceroute fails, you can try to use the
    TTL of IP to at least find the hopcount, although this isn't reliable
    anymore for 'remote' tests, when directly connected to a simple routing
    architecture, the results tend te be usable.

    Rob

    On Tue, 20 Jul 2004, Dieter Sarrazyn wrote:

    > Hi,
    >
    > You can find lot's of the subnet structure with ping & traceroute scans
    > already. First, you can use the ping functionality of nmap (nmap -sP)
    > which should give you information about network and broadcast addresses.
    > If you found these parts, you already know how the subnetting is done.
    > With traceroute, you'll find out how these subnets are connected to
    > eachother.
    >
    > Of course, if there's a router that has snmp enabled, try to find one of
    > the community strings & dump the routing table of this router...
    >
    > Hope this helps.
    >
    > regards,
    > Dieter
    >
    > > -----Original Message-----
    > > From: il.prof@virgilio.it [mailto:il.prof@virgilio.it]
    > > Sent: donderdag 15 juli 2004 10:17
    > > To: pen-test@securityfocus.com
    > > Subject: Find out the subnetting of a company
    > >
    > > During an internal black-box penetration test, from a subnet
    > > of a company (with or without DHCP), how do you find out the
    > > structure of the other subnets of network? In particular, how
    > > do you determine/discover the subnetting of the IP space of a company?
    > >
    > > An example:
    > >
    > > - IP network of the company XYZ: 10.0.0.0/8 (I use a private
    > > class to avoid the use of a real address space)
    > > - I?m in the subnet 10.0.0.0/24
    > >
    > > How do you find out the structure of other subnets that are
    > > part of the network 10.0.0.0/8?
    > >
    > > Il Prof.
    > >
    > >
    > >
    > >
    >


  • Next message: Tim: "Re: Find out the subnetting of a company"

    Relevant Pages

    • Re: Router to router VPN remote site login to Office domain?
      ... The basic problem is that your routers are set up to route between the ... two private subnets. ... address and make it the default gateway of the LAN. ... > We think we are really close to having the new remote location ...
      (microsoft.public.win2000.ras_routing)
    • Re: Best solution to segment subnets
      ... i have a no clear idea of this scenario, maybe so nat routers are confusing me. ... subnet 1 and subnet 2 are two room in the second floor, i need isolate them from subnet 3 and from each other. ... Three subnets need internet. ... It won't isolate the subnets if the switches are uplinked to each other. ...
      (microsoft.public.win2000.ras_routing)
    • Re: Best approach for broadcasting a notifivation to another progr
      ... I think that normally routers block all broadcasts by default, ... I have found that many admins will allow broadcasts between them (at least ... As for the Terminal server issue, I don't know how that would do. ... I have a customer that has two subnets joined by Cisco pix ...
      (microsoft.public.vb.general.discussion)
    • Re: EIGRP Configuration Help
      ... all single-homed locations are configured as stub. ... Subnets again much similar. ... The network design is archaic and a relic of the past in terms of subnets, ... stub routing on each of these routers. ...
      (comp.dcom.sys.cisco)
    • Re: Network Configuration
      ... You have the physical topology, the logical topology, and ... cross routers, therefore the routers will recover lost bandwith. ... > We currently have three router/hub/switches one, for each floor of our> building. ... I am contemplating going to DHCP and am> interested in knowing if there is a technical reason, why I should try to> keep the subnets focused on each floor. ...
      (microsoft.public.win2000.networking)