Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Enumerate Web Virtual Site |
|---|---|
| Date: | Sat, 18 Nov 2006 23:57:42 +0000 |
This topic was covered with detail in the paper "Exegesis of Virtual Hosts Hacking":
http://www.infosecwriters.com/text_resources/pdf/exegesis.pdf
After reading it you should have a pretty good idea on how to find different virtual sites hosted behind the same IP address.
There is no way to enumerate all virtual hosts relyable and complete (unless you have access to the webserver-config).
A good guess is the already mentioned ip-search from msn. There are also a handful of databases on the net that know about ip-numbers and hostnames. The best known might be http://dnstools.com (formerly whois.sc), another option is http://webhosting.info.
Both databases focus on .com/.net/.org - domains. If you are interested in a broader tld-range you might also try http://www.tomdns.net - the site is currently in heavy beta. tomdns does some active researching after you start a query - so you might get more results when you repeat your search a few minutes later.
tom
Roger Liu wrote: > Dear all, > I'm testing the security of a computer which is used for a web site, but > I just get an IP address. Now I need to know how many virtual sites > running on this computer. How do I enumerate all the virtual site? Any > good idea/tools to do this ? > Thanks > > >
-- pagvac [http://ikwt.com/]
------------------------------------------------------------------------- Sponsored by: Watchfire
https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008YTU --------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [WEB SECURITY] Java Swing Application Security, Jeff Robertson |
|---|---|
| Next by Date: | [Full-disclosure] CSRF with MS Word, David Kierznowski |
| Previous by Thread: | Re: [WEB SECURITY] Java Swing Application Security, Jeff Robertson |
| Next by Thread: | [Full-disclosure] CSRF with MS Word, David Kierznowski |
| Indexes: | [Date] [Thread] [Top] [All Lists] |