Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

RE: Scan virtual hosts

Subject: RE: Scan virtual hosts
Date: Thu, 25 Aug 2005 13:44:30 +1200
Geert, 

-----Original Message-----
From: Geert VAN ACKER [mailto:geert.vanacker@pandora.be] 
Sent: Thursday, 25 August 2005 2:49 a.m.
To: pen-test@securityfocus.com
Subject: Scan virtual hosts

Dear list,

is it possible to enumerate all virtual hosts on a given IP 
address ? I
prefer Linux soft.

As virtual hosts are defined just by a Host: header in client's request, I'm
pretty sure that there is no way (please let me know if there is!) to
enumerate virtual hosts from a remote machine.

The only way is to check the actual configuration file of the HTTP daemon,
for which you need local hosts access, of course.

If you know that only certain domain is hosted on a particular physical
machine, and if you can get the DNS zone for that domain, you can check
which hostnames' pointers go to that physical machine.

Cheers,

Bojan

--
Bojan Zdrnja, CISSP, RHCE
Security Implementation Specialist
Information Technology Systems and Services (ITSS)
The University of Auckland, New Zealand

<Prev in Thread] Current Thread [Next in Thread>