Owner of IP-address range Technical Contact Public Server's Banner Information. Address Range Business Partners DNS Servers Domain Names Administrative Contacts WEB Servers Computing Platforms Email Addresses SMTP Servers Network Architecture Technology being used Zones & Sub-domains User(name) Information Phone No's Locate Firewalls/Perimeter devices. Physical Location Route to target's Active Services Internet Accessible data
Techniques
Target's Website DNS SMTP
Mirror the web AXFR vrfy; email_enumeration Use Grep or Similar Version Banner information Scan for keywords Zones & Sub-domains Bounced Emails Banner Information Nmap -sL Email Header Applications DNSDig expn; email mapping Cgi's Nslookup Cookie style Dig commands Job Databases Scripting language Host commands Job requirements Code-reading Active services Employee profile Weblogs info [e.g. MRTG] Hardware information Traceroute Software information Search Engines (Google) ISP information intitle: "index of /etc" Locate Firewalls Personal Website inurl: "config.php.bak" Network Infrastructure Employee job profile site:"target.com" Tcptraceroute Hardware information filetype:".bak" Firewalk Software information Cross-Links Search for group postings Finger News Articles Ping List of live systems SamSpade RTT, delays Whois N/W connectivity Netcraft