=======================================================

Friday, September 7, 2012

INFORMATION GATHERING

Introduction of IG ( Information Gathering ) 
==> IG is method to search any informations of target from any source which possible to get informations. 

Kinds of method IG: 
==> Active IG
==> Passive IG 

I try to get every information from www.is2c-dojo.com and www.spentera.com, This information which i got:
  
ACTIVE  IG
==>> Using: #nmap, #whatweb, #dnsenum.

Result:
Using Nmap
root@bt:~# nmap -v -A www.spentera.com

Nmap scan report for www.spentera.com (108.162.195.184)
Host is up (0.066s latency).
Other addresses for www.spentera.com (not scanned): 108.162.195.84
Not shown: 997 filtered ports
PORT     STATE  SERVICE     VERSION
80/tcp   open   http?
443/tcp  closed https
8080/tcp open   http-proxy?
Device type: firewall|VoIP adapter|broadband router|WAP|general purpose|storage-misc
Running (JUST GUESSING): Fortinet embedded (89%), Vonage embedded (89%), Cisco embedded (88%), Linksys embedded (88%), Linux 2.4.X|2.6.X (88%), Netgear RAIDiator 4.X (88%), Sun OpenSolaris (88%), Sun Solaris 8 (88%)
OS CPE: cpe:/o:linux:kernel:2.4 cpe:/o:linux:kernel:2.6 cpe:/o:linux:kernel:2.6.18 cpe:/o:netgear:raidiator:4 cpe:/o:sun:opensolaris cpe:/o:sun:sunos:5.8
Aggressive OS guesses: Fortinet FortiGate-50B or 310B firewall (89%), Fortinet FortiGate-60B or -100A firewall (89%), Vonage V-Portal VoIP gateway (89%), Cisco Unified Communications Manager VoIP gateway (88%), Linksys WRV200 wireless broadband router (88%), DD-WRT v23 (Linux 2.4.36) (88%), DD-WRT v24-sp2 (Linux 2.4.36) (88%), Vyatta router (Linux 2.6.26) (88%), Linux 2.6.18 (88%), Linux 2.6.22 (Kubuntu, x86) (88%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 12 hops

TRACEROUTE (using port 443/tcp)
HOP RTT      ADDRESS
1   5.26 ms  192.168.1.1
2   29.50 ms 1.subnet110-136-180.speedy.telkom.net.id (110.136.180.1)
3   ... 11
12  62.50 ms 108.162.195.184

NSE: Script Post-scanning.
Read data files from: /usr/local/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 313.70 seconds
           Raw packets sent: 2270 (105.832KB) | Rcvd: 16 (744B)

===========================================================

Nmap scan report for is2c-dojo.com (108.162.199.80)
Host is up (0.064s latency).
Other addresses for is2c-dojo.com (not scanned): 108.162.199.180
Not shown: 997 filtered ports
PORT     STATE  SERVICE     VERSION
80/tcp   open   http?
|_http-title: 503 Service Unavailable
|_http-favicon: Unknown favicon MD5: D41D8CD98F00B204E9800998ECF8427E
443/tcp  closed https
8080/tcp open   http-proxy?
Device type: WAP|general purpose|firewall|broadband router
Running (JUST GUESSING): Linux 2.4.X|2.6.X (97%), Sun Solaris 9 (93%), Check Point embedded (90%), Linksys embedded (90%), Act
OS CPE: cpe:/o:linux:kernel:2.4 cpe:/o:sun:sunos:5.9 cpe:/o:linux:kernel:2.6.36
Aggressive OS guesses: DD-WRT v24-sp2 (Linux 2.4.36) (97%), Sun Solaris 9 (93%), Check Point ZoneAlarm Z100G firewall (90%), Ls WRV200 wireless broadband router (90%), DD-WRT v23 (Linux 2.4.34) (90%), Linux 2.6.23 (90%), Linux 2.6.32 - 2.6.33 (90%), DD
No exact OS matches for host (test conditions non-ideal).
Uptime guess: 2.790 days (since Wed Sep  5 07:12:03 2012)
Network Distance: 9 hops

TRACEROUTE (using port 443/tcp)
HOP RTT      ADDRESS
1   4.77 ms  192.168.1.1
2   35.23 ms 1.subnet110-136-180.speedy.telkom.net.id (110.136.180.1)
3   ...
4   32.12 ms 61.94.114.121
5   ...
6   61.81 ms 62.subnet118-98-61.astinet.telkom.net.id (118.98.61.62)
7   ... 8
9   64.85 ms 108.162.199.80

NSE: Script Post-scanning.
Read data files from: /usr/local/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 223.79 seconds
           Raw packets sent: 2189 (101.568KB) | Rcvd: 28 (1.892KB)
==========================================================

Using Dnsenum
Result : 

With Dnsenum ==>dnsenum.pl   
Result

root@bt:/pentest/enumeration/dns/dnsenum# ./dnsenum.pl -v www.is2c-dojo.com
dnsenum.pl VERSION:1.2.2

-----   www.is2c-dojo.com   -----                                                                                          
                                                                                                                           
                                                                                                                           
Host's addresses:                                                                                                          
__________________                                                                                                          
                                                                                                                           
is2c-dojo.com                            300      IN    A        108.162.199.180                                            
is2c-dojo.com                            300      IN    A        108.162.199.80

                                                                                                                           
Name Servers:                                                                                                              
______________                                                                                                              
                                                                                                                           
rita.ns.cloudflare.com                   15389    IN    A        173.245.58.140                                            
rita.ns.cloudflare.com                   15389    IN    A        173.245.58.212
ivan.ns.cloudflare.com                   26267    IN    A        173.245.59.120

                                                                                                                           
Mail (MX) Servers:                                                                                                          
___________________                                                                                                        
                                                                                                                           
aspmx.l.google.com                       293      IN    A        209.85.225.27                                              

                                                                                                                           
Trying Zone Transfers and getting Bind Versions:                                                                            
_________________________________________________                                                                          
                                                                                                                           

Trying Zone Transfer for www.is2c-dojo.com on rita.ns.cloudflare.com ...                                                                                                                      
AXFR record query failed: SERVFAIL                                                                                                                                                            
Unable to obtain Server Version for rita.ns.cloudflare.com : SERVFAIL                                                                                                                        
                                                                                                                                                                                             
Trying Zone Transfer for www.is2c-dojo.com on ivan.ns.cloudflare.com ...                                                                                                                      
AXFR record query failed: SERVFAIL                                                                                                                                                            
Unable to obtain Server Version for ivan.ns.cloudflare.com : SERVFAIL                                                                                                                                 
----------------                                                                                                                                                                              
Wildcards test:                                                                                                                                                                              
----------------                                                                                                                                                                              
 good                                                                                                                                           
brute force file not specified, bay.
==========================================================
Using Whatweb
Result:

root@bt:/pentest/enumeration/web/whatweb# ./whatweb -vv is2c-dojo.com
#<Thread:0xa030f84> started for http://is2c-dojo.com                                                                                                                                           
http://is2c-dojo.com/ [200]                                                                                                                                                                    
http://is2c-dojo.com [200] HTTPServer[cloudflare-nginx], WooFramework[5.3.12], Title[IS2C | Information Security Shinobi Camp], JQuery[1.7.2,5180], WordPress, cloudflare, x-pingback[http://is2c-dojo.com/xmlrpc.php], IP[108.162.199.80], UncommonHeaders[x-pingback,link], MetaGenerator[Coffee Break 2.4.2,WooFramework 5.3.12], Country[UNITED STATES][US], Cookies[__cfduid,wfvt_1801216213], Frame                                                                                                                                                                                      
Identifying: http://is2c-dojo.com                                                                                                                                                              
HTTP-Status: 200                                                                                                                                                                               
[["HTTPServer",                                                                                                                                                                                
  [{:name=>"server string", :string=>"cloudflare-nginx", :certainty=>100}]],                                                                                                                   
 ["WooFramework",                                                                                                                                                                              
  [{:version=>["5.3.12"],                                                                                                                                                                      
    :regexp_compiled=>                                                                                                                                                                         
     /<meta name="generator" content="WooFramework ([\d\.]+)"/,                                                                                                                                
    :certainty=>100}]],                                                                                                                                                                        
 ["Title",                                                                                                                                                                                     
  [{:name=>"page title",                                                                                                                                                                       
    :string=>"IS2C | Information Security Shinobi Camp",                                                                                                                                       
    :certainty=>100}]],                                                                                                                                                                        
 ["JQuery",                                                                                                                                                                                    
  [{:regexp=>                                                                                                                                                                                  
     ["<script type='text/javascript' src='http://is2c-dojo.com/wp-content/themes/coffeebreak/includes/js/slides.min.jquery",                                                                  
      "<script type='text/javascript' src='http://is2c-dojo.com/wp-includes/js/jquery/jquery"],                                                                                                
    :regexp_compiled=>/<script [^>]*jquery/,                                                                                                                                                   
    :certainty=>100},                                                                                                                                                                          
   {:version=>["1.7.2", "5180"],                                                                                                                                                               
    :regexp_compiled=>/jquery.js\?ver=([0-9\.]+)['"]/,                                                                                                                                         
    :certainty=>100}]],                                                                                                                                                                        
 ["WordPress",                                                                                                                                                                                 
  [{:regexp=>                                                                                                                                                                                  
     ["\">\r\n\t\t<!--//--><![CDATA[//><!--\r\n\t\t\tjQuery(window).load(function(){\r\n\t\t\t\t\r\n\t\t\t\tif ( jQuery( '#slides .slide' ).length > 1 && jQuery( '#slides .slide' ).length > 0 ) {\t\t\r\n\t\t\t\t\tjQuery('#slides').slides({\r\n\t\t\t\t\t\tcontainer: 'slides_container',\r\n\t\t\t\t\t\tpreload: true,\r\n\t\t\t\t\t\tpreloadImage: 'http://is2c-dojo.com/wp-content/themes/coffeebreak/images/loading.png',\r\n\t\t\t\t\t\t\t\t\t\t\t\teffect: 'slide',\r\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\tplay: 4000,\r\n\t\t\t\t\t\t\t\t\t\r\n\t\t\t\t\t\tslideSpeed: 500,\r\n\t\t\t\t\t\tfadeSpeed: 500,\r\n\t\t\t\t\t\tcrossfade: false,\r\n\t\t\t\t\t\tgenerateNextPrev: false,\r\n\t\t\t\t\t\tgeneratePagination: false\r\n\t\t\t\t\t});\r\n\t\t\t\t} else {\r\n\t\t\t\t\tjQuery( '#slides .slides_container' ).fadeIn();\r\n\t\t\t\t}\r\n\t\t\t\t\r\n\t\t\t});\r\n\t\t//-->!]]>\r\n\t\t</script>\r\n\t\t\t\t\r\n\t<script type=\"",
      "\"http://is2c-dojo.com/wp-content/plugins/wordfence/visitor.php?hid=CCBF92932E0799BF6B9FCACA1879A42E\"",
      "\"http://is2c-dojo.com/wp-content/themes/coffeebreak/custom.css\"",
      "\"http://is2c-dojo.com/wp-content/themes/coffeebreak/functions/css/shortcodes.css\"",
      "\"http://is2c-dojo.com/wp-content/themes/coffeebreak/images/slider-arrow-left.png\"",
      "\"http://is2c-dojo.com/wp-content/themes/coffeebreak/images/slider-arrow-right.png\"",
      "\"http://is2c-dojo.com/wp-content/themes/coffeebreak/includes/js/menu.js\"",
      "\"http://is2c-dojo.com/wp-content/themes/coffeebreak/includes/js/pngfix.js\"",
      "\"http://is2c-dojo.com/wp-content/themes/coffeebreak/style.css\"",
      "\"http://is2c-dojo.com/wp-content/themes/coffeebreak/styles/chrome.css\"",
      "\"http://is2c-dojo.com/wp-content/uploads/2012/06/class.png\"",
      "\"http://is2c-dojo.com/wp-content/uploads/2012/06/favicon.ico\"",
      "\"http://is2c-dojo.com/wp-content/uploads/2012/06/logo-kiri2.png\"",
      "\"http://is2c-dojo.com/wp-content/uploads/2012/06/slide.png\"",
      "\"http://is2c-dojo.com/wp-content/uploads/2012/06/slide2.png\"",
      "\"http://is2c-dojo.com/wp-content/uploads/2012/06/slide3.png\"",
      "\"http://www.desktop-reporting.com/wp-content/uploads/2011/08/polaris_mini_icon.png\"",
      "\"http://www.trainingdigital.info/wp-content/uploads/polar/logos/achtung.gif\""],
    :name=>"wp-content",
    :certainty=>75,
    :regexp_compiled=>/"[^"]+\/wp-content\/[^"]+"/},
   {:name=>"Relative /wp-content/ link", :certainty=>100}]],
 ["cloudflare",
  [{:name=>"__cfduid cookie", :certainty=>100},
   {:name=>"server header", :certainty=>100}]],
 ["x-pingback",
  [{:string=>"http://is2c-dojo.com/xmlrpc.php", :certainty=>100}]],
 ["IP", [{:string=>"108.162.199.80", :certainty=>100}]],
 ["UncommonHeaders",
  [{:name=>"headers", :string=>"x-pingback,link", :certainty=>100}]],
 ["MetaGenerator",
  [{:string=>["Coffee Break 2.4.2", "WooFramework 5.3.12"],
    :regexp_compiled=>
     /<meta[^>^=]+name[\s]*=[\s]*["|']?generator["|']?[^>^=]+content[\s]*=[\s]*"([^"^'^>]+)"/i,
    :certainty=>100}]],
 ["Country", [{:string=>"UNITED STATES", :module=>"US", :certainty=>100}]],
 ["Cookies",
  [{:string=>"wfvt_1801216213", :certainty=>100},
   {:string=>"__cfduid", :certainty=>100}]],
 ["Frame",
  [{:regexp=>
     ["https://maps.google.com/maps?f=d&amp;source=s_d&amp;saddr=&amp;daddr=x+%40-7.7918707872440764,110.40991812944412&amp;hl=en&amp;geocode=&amp;sll=-7.791698,110.410202&amp;sspn=0.001549,0.002411&amp;t=h&amp;mra=mift&amp;ie=UTF8&amp;ll=-7.79203,110.410162&amp;spn=0.00372,0.00456&amp;z=17&amp;output=embed"],
    :regexp_compiled=>
     /<[\s]*[i]?frame[^>]+src[\s]*=[\s]*["|']?([^>^"^'^\s]+)/i,
    :certainty=>100}]]]

URL    : http://is2c-dojo.com
Status : 200
   Cookies --------------------------------------------------------------------
        Description: Display the names of cookies in the HTTP headers. The
                     values are not returned to save on space.
        String     : wfvt_1801216213
        {:certainty=>100, :string=>"wfvt_1801216213"}
        String     : __cfduid
        {:certainty=>100, :string=>"__cfduid"}

   Country --------------------------------------------------------------------
        Description: Shows the country the IPv4 address belongs to. This uses
                     the GeoIP IP2Country database from
                     http://software77.net/geo-ip/. Instructions on updating the
                     database are in the plugin comments.
        String     : UNITED STATES
        Module     : US
        {:certainty=>100, :string=>"UNITED STATES", :module=>"US"}

   Frame ----------------------------------------------------------------------
        Description: This plugin detects instances of frame and iframe HTML
                     elements.
        {:certainty=>100}

   HTTPServer -----------------------------------------------------------------
        Description: HTTP server header string. This plugin also attempts to
                     identify the operating system from the server header.
        String     : cloudflare-nginx (from server string)
        {:name=>"server string", :certainty=>100, :string=>"cloudflare-nginx"}

   IP -------------------------------------------------------------------------
        Description: IP address of the target, if available.
        String     : 108.162.199.80
        {:certainty=>100, :string=>"108.162.199.80"}

   JQuery ---------------------------------------------------------------------
        Description: Javascript library
        {:certainty=>100}
        Version    : 1.7.2,5180
        {:certainty=>100, :version=>["1.7.2", "5180"]}

   MetaGenerator --------------------------------------------------------------
        Description: This plugin identifies meta generator tags and extracts its
                     value.
        String     : Coffee Break 2.4.2,WooFramework 5.3.12
        {:certainty=>100, :string=>["Coffee Break 2.4.2", "WooFramework 5.3.12"]}

   Title ----------------------------------------------------------------------
        Description: The HTML page title
        String     : IS2C | Information Security Shinobi Camp (from page title)
        {:name=>"page title", :certainty=>100, :string=>"IS2C | Information Security Shinobi Camp"}

   UncommonHeaders ------------------------------------------------------------
        Description: Uncommon HTTP server headers. The blacklist includes all
                     the standard headers and many non standard but common ones.
                     Interesting but fairly common headers should have their own
                     plugins, eg. x-powered-by, server and x-aspnet-version.
                     Info about headers can be found at www.http-stats.com
        String     : x-pingback,link (from headers)
        {:name=>"headers", :certainty=>100, :string=>"x-pingback,link"}

   WooFramework ---------------------------------------------------------------
        Description: WooFramework - theme framework -
                     http://www.woothemes.com/wooframework/
        Version    : 5.3.12
        {:certainty=>100, :version=>["5.3.12"]}

   WordPress ------------------------------------------------------------------
        Description: WordPress is an opensource blogging system commonly used as
                     a CMS. Homepage: http://www.wordpress.org/
        {:name=>"wp-content", :certainty=>75}
        {:name=>"Relative /wp-content/ link", :certainty=>100}

   cloudflare -----------------------------------------------------------------
        Description: ClouldFlare - https://www.cloudflare.com/
        {:name=>"__cfduid cookie", :certainty=>100}
        {:name=>"server header", :certainty=>100}

   x-pingback -----------------------------------------------------------------
        Description: A pingback is one of three types of linkbacks, methods for
                     Web authors to request notification when somebody links to
                     one of their documents. This enables authors to keep track
                     of who is linking to, or referring to their articles. Some
                     weblog software, such as Movable Type, Serendipity,
                     WordPress and Telligent Community, support automatic
                     pingbacks
        String     : http://is2c-dojo.com/xmlrpc.php
        {:certainty=>100, :string=>"http://is2c-dojo.com/xmlrpc.php"}
==========================================================

PASSIVE IG
From www.robtex.com
 
Result of http://www.robtex.com/dns/spentera.com.html :

==========================================================================
==========================================================================

==========================================================================
==========================================================================

IIIIIIIIII SSSSSSSSSSSSSSS 222222222222222 CCCCCCCCCCCCC
I::::::::I SS:::::::::::::::S2:::::::::::::::22 CCC::::::::::::C
I::::::::IS:::::SSSSSS::::::S2::::::222222:::::2 CC:::::::::::::::C
II::::::IIS:::::S SSSSSSS2222222 2:::::2 C:::::CCCCCCCC::::C
I::::I S:::::S 2:::::2 C:::::C CCCCCC
I::::I S:::::S 2:::::2C:::::C
I::::I S::::SSSS 2222::::2 C:::::C
I::::I SS::::::SSSSS 22222::::::22 C:::::C
I::::I SSS::::::::SS 22::::::::222 C:::::C
I::::I SSSSSS::::S 2:::::22222 C:::::C
I::::I S:::::S2:::::2 C:::::C
I::::I S:::::S2:::::2 C:::::C CCCCCC
II::::::IISSSSSSS S:::::S2:::::2 222222 C:::::CCCCCCCC::::C
I::::::::IS::::::SSSSSS:::::S2::::::2222222:::::2 CC:::::::::::::::C
I::::::::IS:::::::::::::::SS 2::::::::::::::::::2 CCC::::::::::::C
IIIIIIIIII SSSSSSSSSSSSSSS 22222222222222222222 CCCCCCCCCCCCC

==========================================================================
==========================================================================

My Classmate


==========================================================================
( ) ) ( ( (
* ) )\ ) ( /( ( /( ( )\ ) )\ ) )\ )
` ) /((()/( )\()) )\()) )\ (()/((()/( ( (()/(
( )(_))/(_))((_)\ ((_)\((((_)( /(_))/(_)) )\ /(_))
(_(_())(_)) __ ((_) _((_))\ _ )\ (_)) (_))_ ((_) (_))
|_ _|| _ \\ \ / / | || |(_)_\(_)| _ \ | \ | __|| _ \
| | | / \ V / | __ | / _ \ | / | |) || _| | /
|_| |_|_\ |_| |_||_|/_/ \_\ |_|_\ |___/ |___||_|_\

==========================================================================