Re[2]: Identifying whether 2 IPs are from the same server

From: Thierry Zoller (Thierry_at_Zoller.lu)
Date: 11/28/05

  • Next message: Core FORCE team: "ANN: Free endpoint security software released (Core FORCE 070.105)"
    Date: Mon, 28 Nov 2005 17:25:56 +0100
    To: Max <Reply.to.list@acme.com>
    
    

    Dear Max Max,

    >> I am doing a Penetration Testing for 2 IP addresses.
    >> My findings till now for both the servers are exactly
    >> same. I strongly feel that both the IPs belong to the
    >> same machine. May be a scenario where two NICs are on
    >> the same machine with two Public IPs. I ran HPING to
    >> match their IP IDs but it shows different series for
    >> both of them.

    IP ID
    ISN
    Window Size
    ToS
    TTL
    and many more

    -- 
    http://secdev.zoller.lu
    Thierry Zoller
    Fingerprint : 5D84 BFDC CD36 A951 2C45  2E57 28B3 75DD 0AC6 F1C7
    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner: 
    Hackers are concentrating their efforts on attacking applications on your 
    website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
    futile against web application hacking. Check your website for vulnerabilities 
    to SQL injection, Cross site scripting and other web attacks before hackers do! 
    Download Trial at:
    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------
    

  • Next message: Core FORCE team: "ANN: Free endpoint security software released (Core FORCE 070.105)"

    Relevant Pages

    • RE: New article on SecurityFocus
      ... the vector doesn't exploit vulnerabilities... ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ... login pages, dynamic content etc. Firewalls, SSL and locked-down servers ...
      (Pen-Test)
    • RE: Correlating an IP address with a phone number
      ... Most dial-in servers store the caller-ID info in the MIB. ... MIB and get both the IP address and phone number of a user. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ...
      (Pen-Test)
    • RE: Designing Network Security
      ... network design since we are the ones who actually test the stuff out there ... web servers since a large majority of the ones I've run across doing ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping ...
      (Pen-Test)
    • RE: superscan on win2k vs winxp
      ... >Audit your website security with Acunetix Web Vulnerability Scanner: ... >Hackers are concentrating their efforts on attacking applications on ... Up to 75% of cyber attacks are launched on shopping carts, ... login pages, dynamic content etc. Firewalls, SSL and locked-down servers ...
      (Pen-Test)
    • RE: Hacking to Xp box
      ... Aren't there any more important servers than CEO box? ... In what aspect do you need better security? ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
      (Pen-Test)