Re: Audit Research - WHOIS?

From: John Daniele (johnd@tsintel.com)
Date: 01/30/02


Date: Tue, 29 Jan 2002 19:58:17 -0500 (EST)
From: John Daniele <johnd@tsintel.com>
To: Dee Harrod <dee_harrod@yahoo.com>


Well.. probably better suited question for pentest@securityfocus.com,
but find the server that is authoritative for your company's corporate
web site, and hope that you can perform a zone domain transfer.
You may also get lucky if your company's provider hasn't secured the
DNS server that is responsible for delegating authority and try to
perform a zone transfer on the reverse arpa of your company's netblock.
Then try each server, recursively.

----------------------------------
John Daniele
Technical Security & Intelligence
Toronto, ON
Voice: (416) 605-2041
Email: johnd@tsintel.com
Web: http://www.tsintel.com
----------------------------------

On Tue, 29 Jan 2002, Dee Harrod wrote:

> True enough. This is for auditing purposes, though,
> and I'm trying to approach it as a hacker would - not
> using insider information. I've found a number of
> domains that point back to us, but I'd like to find
> all of them. Thanks, though.
>
> -- DS
>
> --- Cavell.McDermott@apw.com wrote:
> >
> > Do you guys host your own dns? If so, on your dns
> > server there should be
> > zone files for every domain you manage.
> >
> > Cavell McDermott
> > Domino Admin
> > APW Ltd. - Texas Campus
> > 214-343-1400 - Main
> > 214-355-2022 - Direct
> > 214-341-9950 - Fax
> > http://www.apw.com
> >
> >
> >
> >
> >
> > Dee Harrod
> >
> >
> > <dee_harrod@y To:
> > security-basics@securityfocus.com
> >
> > ahoo.com> cc:
> >
> >
> > Subject:
> > Audit Research - WHOIS?
> >
> > 01/28/2002
> >
> >
> > 03:36 PM
> >
> >
> >
> >
> >
> >
> >
> >
> >
> >
> >
> >
> > I'm doing an audit on my corporate network. One of
> > the
> > things I'm trying to get is a list of all domains
> > registered to the company. There are a lot of them.
> >
> > The problem is that I'm finding it increasingly
> > difficult to track down that information. There are
> > numerous servers out there that will do whois checks
> > against a domain name. There are even a number that
> > will do it against a word, and bring up all the
> > domain
> > names that match it. But I'd like to, say, query
> > against a registration ID, or an email address, etc.
> > That way I could find all domains registered by our
> > registeration address.
> >
> > Any suggestions on how I might better approach this?
> >
> > -- Dee
> >
> > __________________________________________________
> > Do You Yahoo!?
> > Great stuff seeking new owners in Yahoo! Auctions!
> > http://auctions.yahoo.com
> >
> >
> >
> >
>
> __________________________________________________
> Do You Yahoo!?
> Great stuff seeking new owners in Yahoo! Auctions!
> http://auctions.yahoo.com
>



Relevant Pages

  • RE: exchange server cannot mount mailbox store
    ... What's the exact detailed DNS Events ... Type desired internal IP address of your SBS server. ... it will delete the reverse lookup zone if the zone no longer ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Simple DNS For Private LAN -- SOLVED
    ... I used your examples and the "view" statement mentioned my Mathew Seaman to build a BIND 9 DNS server that is authoritative for mykitchentable.net. ... a local "master zone" visible only to my private LAN as you describe ... internal home network. ... which points to the root DNS servers. ...
    (freebsd-questions)
  • Re: DNS Redesign Issue
    ... -Using DNS console you can right-click the zone and export to a File, ... -To export a Zone and import that Zone in another DNS Server you need to use ... Create a child zone dallas on the DNS server in the child domain ...
    (microsoft.public.windows.server.dns)
  • Re: RWW not connecting to desktop BOSS
    ... Open DHCP server, right click the server's FQDN and select Properties. ... Navigate to DNS tab. ... To configure the zone to permit dynamic updates, ... click Non-secure and secure in the Dynamic updates ...
    (microsoft.public.windows.server.sbs)
  • Re: Event 4515 :another copy of zone has been found
    ... running on the old 2000 server. ... I then installed DNS on ... I seem to remember hearing that if you just delete/remove the zone it ... Container), the Configuration Partition, and the Schema Partition. ...
    (microsoft.public.windows.server.dns)