[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] vhost enumeration



Quoting unknown unknown <unknown.pentester@xxxxxxxxx>:


I'm very interested in the idea of finding vhosts given an IP address. So
far, the only way to do this is by querying open source facilities such as
search engines and online statistic databases.


I think a zone transfer would be the only authoritative resource. Anything else is some degree of guesswork and is bound to miss unlinked sites ,etc. there are still lots of older DNS servers out there which allow zone xfers, but the number is shrinking every day. Check all the secondary, tertiary, etc servers.



t

-------------------------------------------------
Email solutions, MS Exchange alternatives and extrication,
security services, systems integration.
Contact:    services@xxxxxxxxxxxxxx


_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/