Thursday, 3 April 2014

==>>FOOTPRINTING A WEBSITE<<==

what exactly is foot printing?? FOOT PRINTING OR INFORMATION GATHERING is just collecting some information about our target.So that we can use that information in the process of attacking.This foot printing is completely legal as we are using some third party sources to get information about our target.



1.WHO.IS:



This website provides a lot of information of our target.just go tohttp://www.who.is/



1.WHO.IS:


This website provides a lot of information of our target.just go tohttp://www.who.is/ .If your target is an ip-address give the ip address there else if your target is an website just give the name of the website there and click search.


Suppose you want information about blogger.com.Typehttp://www.blogger.com/ and search it.Lots of important details about blogger will be displayed


The following information is displayed:


Name MARKMONITOR INC.
Whois Server whois.markmonitor.com
Referral URL http://www.markmonitor.com/

Status clientDeleteProhibited, clientTransferProhibited, clientUpdateProhibited, serverDeleteProhibited, serverTransferProhibited, serverUpdateProhibited
Important Dates
Expires On June 22, 2014
Registered On June 22, 1999
Updated On June 22, 2012
Name Servers
ns1.google.com 216.239.32.10
ns2.google.com 216.239.34.10
ns3.google.com 216.239.36.10
ns4.google.com 216.239.38.10
Site Status
IP Address 64.233.171.191
Status active
Server Type GSE
Traffic Info
64
4
Alexa Trend/Rank One Month
60
10
Alexa Trend/Rank Three Month
10.3
1.34%
Page Views Per Visit One Month
9.9
76.9%
Page Views Per Visit Three Month
Raw Registrar Data


Domain Name: blogger.com
Registry Domain ID:
Registrar WHOIS Server: whois.markmonitor.com
Registrar URL: http://www.markmonitor.com/

Updated Date: 2013-12-06T08:17:22-0800
Creation Date: 2003-12-16T00:00:00-0800
Registrar Registration Expiration Date: 2014-06-22T10:43:51-0700
Registrar: MarkMonitor, Inc.
Registrar IANA ID: 292
Registrar Abuse Contact Email: Email Masking Image@markmonitor.com
Registrar Abuse Contact Phone: +1.2083895740
Domain Status: clientUpdateProhibited
Domain Status: clientTransferProhibited
Domain Status: clientDeleteProhibited
Registry Registrant ID:
Registrant Name: Dns Admin
Registrant Organization: Google Inc.
Registrant Street: Please contact Email Masking Image@google.com, 1600 Amphitheatre Parkway
Registrant City: Mountain View
Registrant State/Province: CA
Registrant Postal Code: 94043
Registrant Country: US
Registrant Phone: +1.6502530000
Registrant Phone Ext:
Registrant Fax: +1.6506188571
Registrant Fax Ext:
Registrant Email: Email Masking Image@google.com
Registry Admin ID:
Admin Name: DNS Admin
Admin Organization: Google Inc.
Admin Street: 1600 Amphitheatre Parkway
Admin City: Mountain View
Admin State/Province: CA
Admin Postal Code: 94043
Admin Country: US
Admin Phone: +1.6502530000
Admin Phone Ext:
Admin Fax: +1.6506188571
Admin Fax Ext:
Admin Email: Email Masking Image@google.com
Registry Tech ID:
Tech Name: DNS Admin
Tech Organization: Google Inc.
Tech Street: 1600 Amphitheatre Parkway
Tech City: Mountain View
Tech State/Province: CA
Tech Postal Code: 94043
Tech Country: US
Tech Phone: +1.6502530000
Tech Phone Ext:
Tech Fax: +1.6506188571
Tech Fax Ext:
Tech Email: Email Masking Image@google.com
Name Server: ns3.google.com
Name Server: ns2.google.com
Name Server: ns4.google.com
Name Server: ns1.google.c om
URL of the ICANN WHOIS Data Problem Reporting System:http://wdprs.internic.net/







THIS INFORMATION IS VERY MUCH USEFULL AND VALUABLE RIGHT NOW LETS GO TO THE NEXT STEP


2:WAPPALYZER: WAPPALYZER is a pluggin available for mozilla fire fox and Google chrome.Just install the plugin restart firefox and go to your targets website.After going there you will see the pic of wappalyser next to the url bar.Just click it.It gives information about on what programming language is the website developed and what script is used






For example just go to http://www.blogger.com/ and click wappalyzer icon there it gave the following information






It is developped on the java programming language and and a webframe work..






3. WAYBACK MACHINE: Ever imagined that you can seehttp://www.google.com/ in the same way it is on the year 2000 and use it??well,yes it is possible that concept is known as a wayback machine.For this also we are going to use a third party source which is known as http://www.archive.org/ .Just go the website type the website which you want to view select the year and the month of the particular website and u can go to the past. Nice isnt it 











4. Website hosting: Hosting is of two types shared hosting and deicated hosting.In the case of shared hosting multiple websites are in a single webserver to manage the cost as each and every website cannot afford to go for a server.In case of dedicated hosting the particular website will have their own webserver.Examples of a dedicated server are facebook, gmail, flipkart etc..Attack can happen easily if share hosting is used because once the server is attacked we can easily attack all the websites that are present in the particluar server even though a particular site is secured in the sharedserver it can be attacked easily.


Now how are we going to find out whether a website is hosted on dedicated server or a shared server.For this also we are going to use a third party source called you get signal (reverse ip look up).Go there and give the name of the site if its a dedicated server it shows urls related to that particular website only.If its a shared server it will give u all the details of the websites that are hosted in a single server. 





5.PING & TRACERT: Just ping the website using the command prompt it gives you the ip address of the websites server


example: ping http://www.blogger.com/




Tracert: It shows the route of the connection


example: tacert http://www.blogger.com/

 .It will give u some ip addresses.trace them using visual trace route you will get a geographical map of the route from the server to the client.










5.SOCIAL NETWORKING SITES & TRUE CALLER:


Last but not the least you are going to use them.Know the name of the website administrator and search for him in true caller and social networking sites like facebook you may find some details about him. 







Thats it about information gathering.I hope you learnt some thing by reading this.Please post your comments and follow me..Thank u for reading my Article this is Akhil signing off.. :)Please Share Dis.
Folow the admin more info.
www.facebook.com/akhil.manikanth.3/


0 comments:

Post a Comment