渗透测试之信息收集

1. 渗透测试之信息收集

1.1 收集域名信息

1.1.1 whois查询

$ whois starbucks.com

 Domain Name: STARBUCKS.COM
   Registry Domain ID: 993367_DOMAIN_COM-VRSN
   Registrar WHOIS Server: whois.corporatedomains.com
   Registrar URL: http://www.cscglobal.com/global/web/csc/digital-brand-services.html
   Updated Date: 2018-10-20T05:46:56Z
   Creation Date: 1993-10-25T04:00:00Z
   Registry Expiry Date: 2019-10-24T04:00:00Z
   Registrar: CSC Corporate Domains, Inc.
   Registrar IANA ID: 299
   Registrar Abuse Contact Email: domainabuse@cscglobal.com
   Registrar Abuse Contact Phone: 8887802723
   Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
   Domain Status: serverDeleteProhibited https://icann.org/epp#serverDeleteProhibited
   Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
   Domain Status: serverUpdateProhibited https://icann.org/epp#serverUpdateProhibited
   Name Server: A4.NSTLD.COM
   Name Server: F4.NSTLD.COM
   Name Server: G4.NSTLD.COM
   Name Server: H4.NSTLD.COM
   Name Server: J4.NSTLD.COM
   Name Server: L4.NSTLD.COM
   DNSSEC: unsigned
   URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of whois database: 2019-03-12T12:43:59Z <<<

For more information on Whois status codes, please visit https://icann.org/epp

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar.  Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services' ("VeriSign") Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability.  VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.

Domain Name: starbucks.com
Registry Domain ID: 993367_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.corporatedomains.com
Registrar URL: www.cscprotectsbrands.com
Updated Date: 2018-10-20T05:46:56Z
Creation Date: 1993-10-25T04:00:00Z
Registrar Registration Expiration Date: 2019-10-24T04:00:00Z
Registrar: CSC CORPORATE DOMAINS, INC.
Registrar IANA ID: 299
Registrar Abuse Contact Email: domainabuse@cscglobal.com
Registrar Abuse Contact Phone: +1.8887802723
Domain Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited
Domain Status: serverDeleteProhibited http://www.icann.org/epp#serverDeleteProhibited
Domain Status: serverTransferProhibited http://www.icann.org/epp#serverTransferProhibited
Domain Status: serverUpdateProhibited http://www.icann.org/epp#serverUpdateProhibited
Registry Registrant ID:
Registrant Name: Internet Hostmaster
Registrant Organization: Starbucks Coffee Company
Registrant Street: 2401 Utah Avenue S, #800
Registrant City: Seattle
Registrant State/Province: WA
Registrant Postal Code: 98134
Registrant Country: US
Registrant Phone: +1.2063181575
Registrant Phone Ext:
Registrant Fax: +1.2063182439
Registrant Fax Ext:
Registrant Email: inethost@starbucks.com
Registry Admin ID:
Admin Name: Internet Hostmaster
Admin Organization: Starbucks Coffee Company
Admin Street: 2401 Utah Avenue S, #800
Admin City: Seattle
Admin State/Province: WA
Admin Postal Code: 98134
Admin Country: US
Admin Phone: +1.2063181575
Admin Phone Ext:
Admin Fax: +1.2063182439
Admin Fax Ext:
Admin Email: inethost@starbucks.com
Registry Tech ID:
Tech Name: Internet Hostmaster
Tech Organization: Starbucks Coffee Company
Tech Street: 2401 Utah Avenue S, #800
Tech City: Seattle
Tech State/Province: WA
Tech Postal Code: 98134
Tech Country: US
Tech Phone: +1.2063181575
Tech Phone Ext:
Tech Fax: +1.2063182439
Tech Fax Ext:
Tech Email: inethost@starbucks.com
Name Server: g4.nstld.com
Name Server: a4.nstld.com
Name Server: j4.nstld.com
Name Server: h4.nstld.com
Name Server: f4.nstld.com
Name Server: l4.nstld.com
DNSSEC: unsigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: 2018-10-20T05:46:56Z <<<

For more information on Whois status codes, please visit https://icann.org/epp

Corporation Service Company(c) (CSC)  The Trusted Partner of More than 50% of the 100 Best Global Brands.

Contact us to learn more about our enterprise solutions for Global Domain Name Registration and Management, Trademark Research and Watching, Brand, Logo and Auction Monitoring, as well SSL Certificate Services and DNS Hosting.

NOTICE: You are not authorized to access or query our WHOIS database through the use of high-volume, automated, electronic processes or for the purpose or purposes of using the data in any manner that violates these terms of use. The Data in the CSC WHOIS database is provided by CSC for information purposes only, and to assist persons in obtaining information about or related to a domain name registration record. CSC does not guarantee its accuracy. By submitting a WHOIS query, you agree to abide by the following terms of use: you agree that you may use this Data only for lawful purposes and that under no circumstances will you use this Data to: (1) allow, enable, or otherwise support the transmission of mass unsolicited, commercial advertising or solicitations via direct mail, e-mail, telephone, or facsimile; or (2) enable high volume, automated, electronic processes that apply to CSC (or its computer systems). CSC reserves the right to terminate your access to the WHOIS database in its sole discretion for any violations by you of these terms of use. CSC reserves the right to modify these terms at any time.

Register your domain name at http://www.cscglobal.com


➜  ~ whois starbucks.com.cn
Domain Name: starbucks.com.cn
ROID: 20021209s10011s00064641-cn
Domain Status: clientTransferProhibited
Registrant ID: hc0758810115230
Registrant: 星巴克企业管理(中国)有限公司
Registrant Contact Email: inethost@starbucks.com
Sponsoring Registrar: 阿里云计算有限公司(万网)
Name Server: ns3.dnsv4.com
Name Server: ns4.dnsv4.com
Registration Time: 1998-09-23 00:00:00
Expiration Time: 2019-09-23 00:00:00
DNSSEC: unsigned

还可以在以下网站查询域名的信息

https://whois.aizhan.com/ 
http://whois.chinaz.com/ 
https://www.virustotal.com/#/home/url

1.1.2 备案信息

http://www.beianbeian.com

序号 单位名称 单位性质 网站备案/许可证号 网站名称 网站首页网址 审核时间
1 星巴克企业管理(中国)有限公司 企业 沪ICP备17003747号-1[反查] 星巴克中国官网 www.starbucks.com.cn 2018-07-09

天眼查查询企业信息

https://www.tianyancha.com/company/803257297

1.2 收集敏感信息

利用搜索引擎的语法

关键字 说明
site 指定域名
inurl url中存在关键字的网页
intext 网页正文中的关键字
filetype 指定文件类型
intitle 网页标题中的关键字
link link:baidu.com 即表示返回所有和baidu.com做了链接的URL
info 查找指定的一些基本信息
cache 搜索google里关于某些内容的缓存

1.3 收集子域名信息

https://github.com/aboul3la/Sublist3r
python sublist3r.py -d starbucks.com.cn


https://github.com/lijiejie/subDomainsBrute
python subDomainsBrute.py starbucks.com.cn

subDomainsBrute 从dns暴力枚举子域名,可以枚举到搜索引擎搜不到的域名

sublist3r 从搜索引擎查询子域名

https://dnsdumpster.com/

证书透明度公开日志枚举

查看https证书的日志

https://crt.sh/?q=starbucks.com.cn

https://censys.io/ipv4?q=starbucks.com.cn

1.4 收集常用端口信息

➜  ~ nmap -A 180.153.48.188
Starting Nmap 7.70 ( https://nmap.org ) at 2019-03-13 21:35 CST
Nmap scan report for 180.153.48.188
Host is up (0.030s latency).
Not shown: 980 closed ports
PORT     STATE    SERVICE        VERSION
42/tcp   filtered nameserver
80/tcp   open     http-proxy     HAProxy http proxy 1.3.1 or later
|_http-open-proxy: Proxy might be redirecting requests
|_http-title: Did not follow redirect to https://180.153.48.188/
88/tcp   open     http-proxy     HAProxy http proxy 1.3.1 or later
|_http-open-proxy: Proxy might be redirecting requests
|_http-title: Did not follow redirect to https://180.153.48.188:88/
135/tcp  filtered msrpc
139/tcp  filtered netbios-ssn
443/tcp  open     ssl/http       nginx
|_http-server-header: nginx
|_http-title: \xE6\x98\x9F\xE5\xB7\xB4\xE5\x85\x8B | \xE7\x94\xA8\xE6\xAF\x8F\xE4\xB8\x80\xE6\x9D\xAF\xE5\x92\x96\xE5\x95\xA1\xE4\xBC\xA0\xE9\x80\x92\xE6\x98\x9F\xE5\xB7\xB4\xE5\x85\x8B\xE7\x8B\xAC\xE7\x89\xB9\xE7\x9A\x84\xE5\x92\x96\xE5\x95\xA1\xE4\xBD...
| ssl-cert: Subject: commonName=www.starbucks.com.cn/organizationName=Starbucks Coffee Company/stateOrProvinceName=Washington/countryName=US
| Subject Alternative Name: DNS:www.starbucks.com.cn, DNS:achievement.starbucks.com.cn, DNS:api.starbucks.com.cn, DNS:auth.starbucks.com.cn, DNS:callcenter.starbucks.com.cn, DNS:cards.starbucks.com.cn, DNS:coupons.starbucks.com.cn, DNS:emsr.starbucks.com.cn, DNS:giftcard.starbucks.com.cn, DNS:old.giftcard.starbucks.com.cn, DNS:old.rewards.starbucks.com.cn, DNS:profile.starbucks.com.cn, DNS:rewards.starbucks.com.cn
| Not valid before: 2018-06-26T00:00:00
|_Not valid after:  2019-06-26T23:59:59
|_ssl-date: TLS randomness does not represent time
445/tcp  filtered microsoft-ds
593/tcp  filtered http-rpc-epmap
901/tcp  filtered samba-swat
1025/tcp filtered NFS-or-IIS
1068/tcp filtered instl_bootc
1434/tcp filtered ms-sql-m
3128/tcp filtered squid-http
3333/tcp filtered dec-notes
4444/tcp filtered krb524
5800/tcp filtered vnc-http
5900/tcp filtered vnc
6129/tcp filtered unknown
6667/tcp filtered irc
9999/tcp open     ssl/abyss?
| ssl-cert: Subject: commonName=www.starbucks.com.cn/organizationName=Starbucks Coffee Company/stateOrProvinceName=Washington/countryName=US
| Subject Alternative Name: DNS:www.starbucks.com.cn, DNS:achievement.starbucks.com.cn, DNS:api.starbucks.com.cn, DNS:auth.starbucks.com.cn, DNS:callcenter.starbucks.com.cn, DNS:cards.starbucks.com.cn, DNS:coupons.starbucks.com.cn, DNS:emsr.starbucks.com.cn, DNS:giftcard.starbucks.com.cn, DNS:old.giftcard.starbucks.com.cn, DNS:old.rewards.starbucks.com.cn, DNS:profile.starbucks.com.cn, DNS:rewards.starbucks.com.cn
| Not valid before: 2018-06-26T00:00:00
|_Not valid after:  2019-06-26T23:59:59
|_ssl-date: 2019-03-13T13:37:13+00:00; 0s from scanner time.
Device type: load balancer|PBX|specialized|firewall
Running (JUST GUESSING): F5 Networks TMOS 11.6.X|11.4.X (87%), Vodavi embedded (85%), AVtech embedded (85%), OSRAM embedded (85%)
OS CPE: cpe:/o:f5:tmos:11.6 cpe:/h:vodavi:xts-ip cpe:/h:osram:lightify cpe:/o:f5:tmos:11.4
Aggressive OS guesses: F5 BIG-IP Local Traffic Manager load balancer (TMOS 11.6) (87%), Vodavi XTS-IP PBX (85%), AVtech Room Alert 26W environmental monitor (85%), OSRAM Lightify ZigBee gateway (85%), F5 BIG-IP AFM firewall (85%), F5 BIG-IP load balancer (TMOS 11.4) (85%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 14 hops
Service Info: Device: load balancer

TRACEROUTE (using port 3389/tcp)
HOP RTT      ADDRESS
1   0.35 ms  XiaoQiang (192.168.31.1)
2   ... 3
4   3.12 ms  124.65.61.21
5   8.41 ms  123.126.0.125
6   31.16 ms 219.158.6.166
7   71.74 ms 219.158.8.230
8   76.11 ms 202.97.17.181
9   28.22 ms 202.97.46.25
10  ...
11  34.20 ms 101.95.207.6
12  32.55 ms 124.74.232.66
13  28.14 ms 124.74.184.77
14  28.57 ms 180.153.48.188

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 93.98 seconds

1.5 指纹识别

http://whatweb.bugscaner.com
http://www.yunsee.cn/
https://www.whatweb.net/

1.6 查找真实ip

目标服务器存在CDN

使用多地ping, 如果ip都是一样的,极有可能不存在CDN

https://ping.chinaz.com     可以使用国内的多地ping,还可以使用海外多地ping
https://www.17ce.com/

绕过CDN寻找真实IP

内部邮箱源
扫描网站测试文件
分站域名
国外访问  https://asm.ca.com/en/ping.php 可能会得到真实ip
查询域名的解析记录 https://www.netcraft.com/
如果有app, 尝试抓包
绕过CloudFlare CDN查找真实ip  "cloudflare watch"

如何验证真实ip
如果是web, 直接用ip访问,看是否和域名访问

1.7 收集敏感目录文件

DirBuster (kali自带该工具,由OWASP用Java开发的工具)
御剑后台扫描珍藏版
wwwscan
Spinder.py
Sensitivefilescan
Weakfilescan

1.8 社会工程学

收集信息的过程中,可以给收集到的电子邮箱,发送邮件,然后等到回复邮件,可以分析邮件头来收集真实ip以及内部电子邮件服务器的相关信息。
。。。
©著作权归作者所有,转载或内容合作请联系作者
  • 序言:七十年代末,一起剥皮案震惊了整个滨河市,随后出现的几起案子,更是在滨河造成了极大的恐慌,老刑警刘岩,带你破解...
    沈念sama阅读 200,392评论 5 470
  • 序言:滨河连续发生了三起死亡事件,死亡现场离奇诡异,居然都是意外死亡,警方通过查阅死者的电脑和手机,发现死者居然都...
    沈念sama阅读 84,258评论 2 377
  • 文/潘晓璐 我一进店门,熙熙楼的掌柜王于贵愁眉苦脸地迎上来,“玉大人,你说我怎么就摊上这事。” “怎么了?”我有些...
    开封第一讲书人阅读 147,417评论 0 332
  • 文/不坏的土叔 我叫张陵,是天一观的道长。 经常有香客问我,道长,这世上最难降的妖魔是什么? 我笑而不...
    开封第一讲书人阅读 53,992评论 1 272
  • 正文 为了忘掉前任,我火速办了婚礼,结果婚礼上,老公的妹妹穿的比我还像新娘。我一直安慰自己,他们只是感情好,可当我...
    茶点故事阅读 62,930评论 5 360
  • 文/花漫 我一把揭开白布。 她就那样静静地躺着,像睡着了一般。 火红的嫁衣衬着肌肤如雪。 梳的纹丝不乱的头发上,一...
    开封第一讲书人阅读 48,199评论 1 277
  • 那天,我揣着相机与录音,去河边找鬼。 笑死,一个胖子当着我的面吹牛,可吹牛的内容都是我干的。 我是一名探鬼主播,决...
    沈念sama阅读 37,652评论 3 390
  • 文/苍兰香墨 我猛地睁开眼,长吁一口气:“原来是场噩梦啊……” “哼!你这毒妇竟也来了?” 一声冷哼从身侧响起,我...
    开封第一讲书人阅读 36,327评论 0 254
  • 序言:老挝万荣一对情侣失踪,失踪者是张志新(化名)和其女友刘颖,没想到半个月后,有当地人在树林里发现了一具尸体,经...
    沈念sama阅读 40,463评论 1 294
  • 正文 独居荒郊野岭守林人离奇死亡,尸身上长有42处带血的脓包…… 初始之章·张勋 以下内容为张勋视角 年9月15日...
    茶点故事阅读 35,382评论 2 317
  • 正文 我和宋清朗相恋三年,在试婚纱的时候发现自己被绿了。 大学时的朋友给我发了我未婚夫和他白月光在一起吃饭的照片。...
    茶点故事阅读 37,432评论 1 329
  • 序言:一个原本活蹦乱跳的男人离奇死亡,死状恐怖,灵堂内的尸体忽然破棺而出,到底是诈尸还是另有隐情,我是刑警宁泽,带...
    沈念sama阅读 33,118评论 3 315
  • 正文 年R本政府宣布,位于F岛的核电站,受9级特大地震影响,放射性物质发生泄漏。R本人自食恶果不足惜,却给世界环境...
    茶点故事阅读 38,704评论 3 303
  • 文/蒙蒙 一、第九天 我趴在偏房一处隐蔽的房顶上张望。 院中可真热闹,春花似锦、人声如沸。这庄子的主人今日做“春日...
    开封第一讲书人阅读 29,787评论 0 19
  • 文/苍兰香墨 我抬头看了看天上的太阳。三九已至,却和暖如春,着一层夹袄步出监牢的瞬间,已是汗流浃背。 一阵脚步声响...
    开封第一讲书人阅读 30,999评论 1 255
  • 我被黑心中介骗来泰国打工, 没想到刚下飞机就差点儿被人妖公主榨干…… 1. 我叫王不留,地道东北人。 一个月前我还...
    沈念sama阅读 42,476评论 2 346
  • 正文 我出身青楼,却偏偏与公主长得像,于是被迫代替她去往敌国和亲。 传闻我的和亲对象是个残疾皇子,可洞房花烛夜当晚...
    茶点故事阅读 42,057评论 2 341

推荐阅读更多精彩内容