Re: Mapping Class A network ( any easy trick?)

alank_at_starbug.net
Date: 02/08/05

  • Next message: Jordan Wiens: "Re: Mapping Class A network ( any easy trick?)"
    Date: Tue, 8 Feb 2005 12:01:25 -0800 (PST)
    To: pen-test@securityfocus.com
    
    

    If you are local to the network, start by seeing if any routing protocols
    are running that you can sniff.

    That will get you started.

    If no routing protocols, then try divide and conquer.

    Traceroute the /16 or /8 subnets of the class A and try to map out what
    the network is setup as. That will give better hints as to what is in
    use/not in use.

    Query the SOA for the DNS servers, this will may give you hints on what
    subnets are used for servers, possibly in other regions.

    If DNS servers are not locked down, you can axfr the zone and go analyze
    the ip address contained.

    Look for hints to other DNS zones in different regions to harvest.

    Alan

    >
    >
    > I am about to do a penetration testing on a “Class A
    > network” and wondering how I can map the network
    > without pinging 17 million IPs.(nmap -Sp 10.0.0.0/8)
    >
    > I did some research and the best information I got is
    > from one of the earlier post on this
    > list(http://seclists.org/lists/pen-test/2004/Jul/0067.html)
    > . It was to use broadcast IPs for pings. But it may miss some subnets.
    >
    > Is that the best way to it? If not, please advise
    >


  • Next message: Jordan Wiens: "Re: Mapping Class A network ( any easy trick?)"

    Relevant Pages

    • Re: dymanic route table problem
      ... There are no other network devices on these systems. ... route learning by the device, that kind of control is needed. ... Virtual Adapters like modems, VPN, and some other types will also create ... Routing Protocols exchange routing tables between devices,...you can not get ...
      (microsoft.public.win2000.networking)
    • RE: Routing protocols, Internet vs Enterprises
      ... Routing protocols, Internet vs Enterprises ... In a Windows 2003 Active Directory "network", is there a way to turn on ... used ospf on every router they had to link all their buildings. ...
      (Security-Basics)
    • RE: Routing protocols, Internet vs Enterprises
      ... Routing protocols, Internet vs Enterprises ... In a Windows 2003 Active Directory "network", is there a way to turn on ... used ospf on every router they had to link all their buildings. ...
      (Security-Basics)
    • Re: Netmasks for dummies
      ... >the routing protocols that were meant to deal with it. ... "You" don't have nitty-gritty access to "my" network, ... as "your" packet gets to the host "you" are trying to connect to. ... I don't know of any assignments there yet, ...
      (comp.os.linux.misc)
    • Re: Cannot connect to the Internet
      ... Connection 2 Status icon shows "Connected" with a speed of 10.0 Mbps, ... The master browser has received a server announcement from the ... service will not use the network to avoid further network performance ... these DNS servers or contact your network administrator. ...
      (microsoft.public.mac.virtualpc)