Re: Find out the subnetting of a company

From: Tim (tim-security_at_sentinelchicken.org)
Date: 07/21/04

  • Next message: David M. Zendzian: "Re: Find out the subnetting of a company"
    Date: Tue, 20 Jul 2004 18:26:23 -0700
    To: il.prof@virgilio.it
    
    

    > During an internal black-box penetration test, from a subnet of a company
    > (with or without DHCP), how do you find out the structure of the other subnets
    > of network? In particular, how do you determine/discover the subnetting
    > of the IP space of a company?

    I just ran across this today, while trying to figure out what ICMP
    requests I wanted to let through my firewall.

    http://www.networksorcery.com/enp/protocol/icmp/msg17.htm

    Perhaps by doing traceroutes to various IPs, followed by a subnet
    request to the routers that show up would be helpful. I don't know how
    well it is even supported, but would save you lots of work if it worked.

    Needless to say, I didn't allow this one through the ol' firewall... ;-)

    tim


  • Next message: David M. Zendzian: "Re: Find out the subnetting of a company"

    Relevant Pages

    • RE: SBS2003 and DHCP
      ... firewall, which also administers forced virus protection ... SBS2003 on its own subnet 2) Use the SBS2003 DHCP server ... DNS comes from SBS2003) 3) Point the ...
      (microsoft.public.windows.server.sbs)
    • Re: dhclient blues
      ... This dhcp stuff had me in a bad ... There's an application running on one of the LAN machines, ... Yes, correct, but it is not *my* subnet; ... I'm trying an alternative solution now by turning the firewall ...
      (comp.os.linux.networking)
    • SUMMARY: bootpd...IP address not found
      ... this kind of makes sense as there is a DHCP server on ... this subnet so all DHCP requests should go to this subnet. ...
      (SunManagers)
    • Re: Firewall where internal hosts have non-reserved IPs?
      ... You just run the firewall as a router with no masquerading. ... |addresses via DHCP. ... You have to ask for a subnet of the University's IP range so that your ...
      (comp.os.linux.security)
    • URGENT: boot-image from network-boot server does not apply netmask on V440, doesnt contact gateway t
      ... to that same boot-server which returns properly the gateway's IP-address ... initial Solaris must be retrieved from. ... sending out ARP requests to 255.255.255.255 to find out ... The boot-server in this subnet is 45.217.2.49 ...
      (SunManagers)

  • Quantcast