Uploaded by Henry Tran

Lab4 submit

advertisement
Lab 4
Part 1
IP Address
129.119.70.169
162.21.1.112
200.74.207.19
FQDN
smu.edu
Point of Contact
noc@smu.edu
www.dj.com.ve
cdn.ceo@gmail.com
70.86.89.34
34.70-8689.falcon.dnsracks.com
www.hackthestack.com N/A
old.qdu.edu.cn
noc@osqdu.org
N/A
211.64.175.201
Location
Dallas, USA
Distrito Capital –
Caracas, Dayco
Telecom
ipadmin@softlayer.com Dallas, Texas, USA
N/A
Beijing, China
How would you defend against this type of information gathering by potential attackers?


Enable WHOIS privacy protection when you process domain registration
Enable domain locking by setting to “Registrar lock” or “Client Transfer Prohibited”
Part 2
Item
Domain Name
Address and phone numbers of corporate
headquarters
Location of Internet Presence
Co-location or branches
Types of Technology Used
Name of CEO or Senior Management
Home address of CEO
Background of CEO
CEO alma matter
Job listing
Description & Findings
Apple.ca
7495 Birchmount Rd, Markham, Ontario, L3R 5G2, CA.
(408) 96-1010
Cupertino, California, 95014, USA
United States
Smart Phones, Desktops, and MacOS(Linux) Software
Tim Cook
Palo Alto, California
An American business executive and industrial engineer
Auburn University
Store Associates, Store Managers, Software Engineers,
and many more
What can you conclude about the amount of information found about the target organization?
The information gathering is easy and was actually quite overwhelming due to the Internet and social
media such as facebook, twitter, blogging. We can use OSINT technique to find information as an
anonymous user for the company and person like Tim Cook.
Part 3: Google Hacking
Google hacking, also named Google dorking, is a computer hacking technique that uses Google Search
and other Google applications to find security holes in the configuration and computer
code that websites use.
Three examples from Google Dork
intext:password filetype:xlsx
intitle:"index of /backup"
inurl:dyn_sensors.htm
filetype:log intext:password
site:edu filetype:key intext:private
Part 4: Banner Grabbing
Using nmap
Using wget
Part 5: Visual Route
Try Seneca College
Download