Wednesday, April 7, 2010

bing-ip2hosts - Enumerating All Hostnames/Domains Associated with an IP

While I'm still a Google fan, Andrew Horton/urbanadventurer of MorningStar Security (http://www.morningstarsecurity.com/research/bing-ip2hosts) has written a script to use Bing to enumerate all of the hostnames associated with a particular IP address.

Of course, I love integrating new tools with my Backtrack 4 installation, so I use the following commands to do so:

mkdir /pentest/enumeration/bing
cd /pentest/enumeration/bing
wget http://www.morningstarsecurity.com/downloads/bing-ip2hosts-0.2.tar.gz
tar -zxvf bing-ip2hosts-0.2.tar.gz
cd bing-ip2hosts-0.2


Once "installed", I use the script to search for all domains and hostnames associated with nbc.com as a test ('./bing-ip2hosts nbc.com'). As you can see, the script enumerates quite a number of domains and hostnames, especially of interest for a TV show geek like myself.

A few personal favorites:

chuckmeout.com - For great shows I hope that don't get canceled
votepetrelli.com - For once great shows that I hope get canceled
whoframedcharlie.com - For a great show that did get canceled
princessunicorndoll.com & sensualsexuality.com - All of this from The Office (and links are SFW)
estradaornada.com - The name alone...
greendalecommunitycollege.com - From my favorite new comedy

Of course, one does start to see the pen testing advantages by using a tool like bing-ip2hosts to find additional targets for testing, not just finding geeky TV show sites to play with - though these are good too.

No comments:

Post a Comment