02.03.2018 Views

Sybex CEH Certified Ethical Hacker Version 8 Study Guide

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

90 Chapter 4 ■ Footprinting and Reconnaissance<br />

Netcraft Actually a suite of related tools, you can use Netcraft to obtain web server version,<br />

IP address, subnet data, OS information, and subdomain information for any URL.<br />

Remember this tool—it will come in handy later.<br />

A subdomain is a domain that is a child of a parent domain. An example<br />

would be support.oriyano.com, where the parent is oriyano.com. Subdomains<br />

are useful because they can clue us in to projects and other goingson.<br />

In the past I have been able to find beta versions of company websites,<br />

company extranets, and plenty of other items companies would have<br />

rather kept hidden.<br />

Link Extractor This utility locates and extracts the internal and external URLs for a<br />

given location.<br />

Public and Restricted Websites<br />

Websites that are intended not to be public but to be restricted to a few can provide you<br />

with valuable information. Because restricted websites—such as technet.microsoft.com<br />

and developer.apple.com—are not intended for public consumption, they are kept in a<br />

subdomain that is either not publicized or that has a login page. (See Exercise 4.2.)<br />

EXERCISE 4.2<br />

Examining a Site<br />

This exercise shows you how to learn more about your target by finding out what they are<br />

running, additional IP information, server data, and DNS information.<br />

1. In your web browser, open the website www.netcraft.com.<br />

2. In the box labeled “What’s that site running?” enter the name of a website. Note that<br />

this is a passive activity so you do not have to request permission, but if you plan a<br />

more aggressive activity consider asking for permission.<br />

3. On the results page, note the list of sites that appear. The results may include a list of<br />

subdomains for the domain you entered. Not every site will have subdomains, so if<br />

you don’t see any don’t be alarmed. In some cases if there is only a single result for a<br />

domain name, you may in fact go directly to a page with details about the domain.<br />

4. On the results page, click the Site Report icon next to a domain name to go to the Site<br />

Report page for that domain.<br />

5. On the Site Report page, note the information provided. This includes data such as<br />

e-mail address, physical addresses, OS and web server information, and IP information.<br />

You may find yourself in practice repeating these steps for multiple domains and subdomains.<br />

Make this process easy on yourself and just print copies of the reports as they will be<br />

useful in later stages.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!