Module 3 - Information Gathering / Reconnaissance Flashcards
RobTex
WHOIS (name and IP)WHOIS lookups by name and IP address
Checks of IP addresses for DNS reverse lookups and forwards
Searches of DNS registration records
Searches of Autonomous System (AS) numbers
Identification of neighboring domain names
Searches of domain names that share a common IP address
CentralOps.net
Domain dossiers Domain name checks PINGs to servers Trace routes to servers WHOIS lookups
Way Back Machine
archive.org
Alexa.org
Web Metrics
netcraft.com
IP address for DNS server and website/application
Domain name registration information
OS footprinting information (This information may be dated.)
domaintools.com
domain name and whois
DNSstuff.com
Domain names
IP addresses
Trace routes
DNS resolution times
infosniper.net
locations of IP - may be different than registration
Pages cached by Google
archive
Sources of Operations Info
SEC filings Help forums Press releases Job postings Pastebin Social Networks
Robtex Records
Domain names IP Addresses Name servers Mail servers AS information Graphs Shared WhoIs