Pentesting a Web Applicaton behind Akamai Technology



Hi everybody,

I'm doing a Pentest on a Web Application for a client. The only information I have is the DNS name of the website. After doing the basic steps of footprint and enumeration, I found out that the IP adress of the website is not in the IP range of the client and is owned by Akamai Technology. It means that if I'm going on with the furter steps of pentesting, I'll pentest Akamai and not the "real" website of the client.

Is there a way to find the "real" IP address of the website ?

Has everyone faced this kind of configuration ?

For information, this is the header of the website when attempting a page that doesn't exist :

HTTP/1.0 400 Bad Request
Server: AkamaiGHost
Mime-Version: 1.0
Content-Type: text/html
Content-Length: 186
Expires: Wed, 16 May 2007 13:39:42 GMT
Date: Wed, 16 May 2007 13:39:42 GMT
Connection: close

Thanks,

Greg

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------



Relevant Pages

  • Re: deploying website VS 2005
    ... Thank you for explanation but I'm trying to run my website and get error: ... Server Error in '/' Application. ... An error occurred during the processing of a configuration file ... you must uninstall the WAP add-on first! ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Visual Studio 2005 Web Site <-> Visual Source Safe Problems...
    ... Part of the security on our website requires that the URL be correct. ... The other things I'd not expect to hear in a pro setup were "opening up SourceSafe" and "going into IIS manager and setting the root directory". ... You also didn't make clear the exact folder structure of the IIS servers that reside on your multiple client machines and the configuration thereof? ...
    (microsoft.public.vsnet.general)
  • Re: Livna Usability Assessment (Was: Re: cursed nvidia fedora my lack of knowledgeness)
    ... > The website really isn't the point here. ... give you the information needed to accomplish much. ... "How to enable the Livna repository on your system". ... that's Configuration, but we're both too technical to understand others ...
    (Fedora)
  • [IIS 6] A summary of my strange situation
    ... security-related configuration, so maybe someone can help me out of this. ... OWA on my domain's main website), then I created a "web sites" dir on my D: ... other website or subdirectory I try to enable Windows authentication on ... administrators, web developers and SYSTEM, and I gave read permissions to ...
    (microsoft.public.inetserver.iis.security)
  • Re: [IIS 6] A summary of my strange situation
    ... security-related configuration, so maybe someone can help me out of this. ... Then I created new subdirs for every website I'm ... other website or subdirectory I try to enable Windows authentication on ... administrators, web developers and SYSTEM, and I gave read permissions to ...
    (microsoft.public.inetserver.iis.security)