Versus71 Posted June 16, 2012 Share Posted June 16, 2012 This is the hidden content, please Sign In or Sign Up For a domain: Find Domain’s Name servers (NS Records) Find Domain’s Mail servers (MX Records) Find sub-domains using Google Search Find sub-domains using Brute force Find possible Clusters / Balancers (different IP, same Host) Find related domains Whois Domain details For Name servers: Check Name Servers for Zone-Tranfers Check Name Servers for Version Bind (Banner) For Mail servers: Check Mail Servers for User Enumeration (VRFY / EXPN) Check Mail Servers for Open Relay For IP Addresses: Find Host Names Find Virtual Hosts using Bing API 2.0 Whois IP details (Gets ISP / LIR details as well) Find more IP Ranges based on Net Name Find more IP Ranges based on Maintainer (mnt-by) For Ports (import Nmap xml file): Find Port banner Find Web (HTTP/HTTPS) Ports Find Same Web Sites running on different IP / Port Check Web Ports for OPTIONS, Server Banner, Internal IPs exposure Download: This is the hidden content, please Sign In or Sign Up Link to comment Share on other sites More sharing options...
Recommended Posts