Wednesday 25 January 2012

Information Gathering

this article about informtion gathering from website www.is2c-dojo.net, www.is2c-dojo.com, www.spentera.com

1. information gathering from www.is2c-dojo.net

A. passive information gathering from www.is2c-dojo.net
     Gathering information From www.is2c-dojo.net using who.is website
     the following result :

IS2C-DOJO.NET SITE INFORMATION

IP: 72.14.204.121
IP Location: Mountain View, United States
Website Status: active
Server Type: GSE



 for complete information as below :



IS2C-DOJO.NET WHOIS

Updated: 4 hours ago
Registration Service Provided By: PARTNER IT
Contact: +62.2749570974

Domain Name: IS2C-DOJO.NET

Registrant:
    PrivacyProtect.org
    Domain Admin        (@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

Creation Date: 22-Dec-2011
Expiration Date: 22-Dec-2012

Domain servers in listed order:
    partnerit1.earth.orderbox-dns.com
    partnerit1.mars.orderbox-dns.com
    partnerit1.mercury.orderbox-dns.com
    partnerit1.venus.orderbox-dns.com


Administrative Contact:
    PrivacyProtect.org
    Domain Admin        (@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

Technical Contact:
    PrivacyProtect.org
    Domain Admin        (@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

Billing Contact:
    PrivacyProtect.org
    Domain Admin        (@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676



B .active information gathering from www.is2c-dojo.net

to active information gathering from www.is2c-dojo.net i used tools nmap.
first, run nmap and type the command :

root@bt:~# nmap -v -A is2c-dojo.net

this command will have result as below :





root@bt:~# nmap -v -A is2c-dojo.net

Starting Nmap 5.61TEST4 ( http://nmap.org ) at 2012-01-26 11:46 BNT
NSE: Loaded 87 scripts for scanning.
NSE: Script Pre-scanning.
Initiating Ping Scan at 11:46
Scanning is2c-dojo.net (216.239.32.21) [4 ports]
Completed Ping Scan at 11:46, 0.14s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 11:46
Completed Parallel DNS resolution of 1 host. at 11:46, 0.03s elapsed
Initiating SYN Stealth Scan at 11:46
Scanning is2c-dojo.net (216.239.32.21) [1000 ports]
Discovered open port 80/tcp on 216.239.32.21
Completed SYN Stealth Scan at 11:46, 11.79s elapsed (1000 total ports)
Initiating Service scan at 11:46
Scanning 1 service on is2c-dojo.net (216.239.32.21)
Completed Service scan at 11:46, 6.84s elapsed (1 service on 1 host)
Initiating OS detection (try #1) against is2c-dojo.net (216.239.32.21)
Retrying OS detection (try #2) against is2c-dojo.net (216.239.32.21)
Initiating Traceroute at 11:46
Completed Traceroute at 11:46, 0.09s elapsed
Initiating Parallel DNS resolution of 11 hosts. at 11:46
Completed Parallel DNS resolution of 11 hosts. at 11:46, 0.12s elapsed
NSE: Script scanning 216.239.32.21.
Initiating NSE at 11:46
Completed NSE at 11:46, 1.46s elapsed
Nmap scan report for is2c-dojo.net (216.239.32.21)
Host is up (0.071s latency).
Other addresses for is2c-dojo.net (not scanned): 216.239.34.21 216.239.36.21 216.239.38.21
rDNS record for 216.239.32.21: any-in-2015.1e100.net
Not shown: 998 filtered ports
PORT    STATE  SERVICE VERSION
80/tcp  open   http    Google httpd 2.0 (GFE)
|_http-methods: No Allow or Public header in OPTIONS response (status code 301)
| http-title: 301 Moved
|_Did not follow redirect to http://www.is2c-dojo.net/
113/tcp closed ident
Device type: general purpose
Running (JUST GUESSING): IBM OS/2 4.X (86%)
OS CPE: cpe:/o:ibm:os2:4
Aggressive OS guesses: IBM OS/2 Warp 2.0 (86%)
No exact OS matches for host (test conditions non-ideal).
Uptime guess: 0.000 days (since Thu Jan 26 11:46:55 2012)
Network Distance: 11 hops
TCP Sequence Prediction: Difficulty=259 (Good luck!)
IP ID Sequence Generation: Randomized
Service Info: OS: Linux; CPE: cpe:/o:linux:kernel

TRACEROUTE (using port 113/tcp)
HOP RTT      ADDRESS
1   22.06 ms 192.168.1.1
2   42.44 ms 1.subnet110-136-160.speedy.telkom.net.id (110.136.160.1)
3   40.46 ms 181.subnet125-160-15.infra.telkom.net.id (125.160.15.181)
4   70.88 ms 17.subnet118-98-57.astinet.telkom.net.id (118.98.57.17)
5   70.19 ms 118.98.15.29
6   63.44 ms 181.subnet118-98-57.astinet.telkom.net.id (118.98.57.181)
7   60.98 ms 37.subnet118-98-56.astinet.telkom.net.id (118.98.56.37)
8   58.61 ms 6.subnet118-98-59.astinet.telkom.net.id (118.98.59.6)
9   53.54 ms 42.subnet118-98-59.astinet.telkom.net.id (118.98.59.42)
10  52.19 ms 180.240.190.13
11  53.99 ms any-in-2015.1e100.net (216.239.32.21)

NSE: Script Post-scanning.
Read data files from: /usr/local/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 27.46 seconds
           Raw packets sent: 2079 (95.304KB) | Rcvd: 47 (2.728KB)





2. information gathering from www.is2c-dojo.com
 
    A.  Gathering information From www.is2c-dojo.com using who.is website
          the following result :

IP: 67.222.154.106
Website Status: active
Server Type: Apache/2.2.21 (Unix) mod_ssl/2.2.21 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_antiloris/0.4


  

 for complete information as below :

Registration Service Provided By: PARTNER IT
Contact: +62.2749570974

Domain Name: IS2C-DOJO.COM

Registrant:
    n/a
    Mada Rambu Perdhana        (@gmail.com)
    Jl. MT Haryono No.25A rt.36 Kelurahan Damaii
    Balikpapan
    Balikpapan,12345
    ID
    Tel. +62.087838463816

Creation Date: 14-Jan-2012
Expiration Date: 14-Jan-2013

Domain servers in listed order:
    ns1.partnerit.us
    ns2.partnerit.us


Administrative Contact:
    n/a
    Mada Rambu Perdhana        (@gmail.com)
    Jl. MT Haryono No.25A rt.36 Kelurahan Damaii
    Balikpapan
    Balikpapan,12345
    ID
    Tel. +62.087838463816

Technical Contact:
    n/a
    Mada Rambu Perdhana        (@gmail.com)
    Jl. MT Haryono No.25A rt.36 Kelurahan Damaii
    Balikpapan
    Balikpapan,12345
    ID
    Tel. +62.087838463816

Billing Contact:
    n/a
    Mada Rambu Perdhana        (@gmail.com)
    Jl. MT Haryono No.25A rt.36 Kelurahan Damaii
    Balikpapan
    Balikpapan,12345
    ID
    Tel. +62.087838463816



B .active information gathering from www.is2c-dojo.com

to active information gathering from www.is2c-dojo.com  i used tools nmap.
first, run nmap and type the command :

root@bt:~# nmap -v -A is2c-dojo.com

this command will have result as below :
root@bt:~# nmap -v -A is2c-dojo.com

Starting Nmap 5.61TEST4 ( http://nmap.org ) at 2012-01-26 11:52 BNT
NSE: Loaded 87 scripts for scanning.
NSE: Script Pre-scanning.
Initiating Ping Scan at 11:52
Scanning is2c-dojo.com (67.222.154.106) [4 ports]
Completed Ping Scan at 11:52, 3.06s elapsed (1 total hosts)
Nmap scan report for is2c-dojo.com (67.222.154.106) [host down]
NSE: Script Post-scanning.
Read data files from: /usr/local/bin/../share/nmap
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 4.09 seconds
           Raw packets sent: 8 (304B) | Rcvd: 0 (0B)



1. information gathering from www.spentera.com

A. passive information gathering from www.spentera.com
     Gathering information From www.ispentera.com using who.is website
     the following result :

      IP: 74.81.66.104
      IP Location: Atlanta, United States
      Website Status: active
      Server Type: Apache


  

 For complete  information as below :


Registration Service Provided By: Namecheap.com
Contact: @namecheap.com
Visit: http://namecheap.com

Domain name: spentera.com

Registrant Contact:
   WhoisGuard
   WhoisGuard Protected ()
  
   Fax:
   11400 W. Olympic Blvd. Suite 200
   Los Angeles, CA 90064
   US

Administrative Contact:
   WhoisGuard
   WhoisGuard Protected (@whoisguard.com)
   +1.6613102107
   Fax: +1.6613102107
   11400 W. Olympic Blvd. Suite 200
   Los Angeles, CA 90064
   US

Technical Contact:
   WhoisGuard
   WhoisGuard Protected (@whoisguard.com)
   +1.6613102107
   Fax: +1.6613102107
   11400 W. Olympic Blvd. Suite 200
   Los Angeles, CA 90064
   US

Status: Active

Name Servers:
   dns1.namecheaphosting.com
   dns2.namecheaphosting.com
  
Creation date: 15 Feb 2011 13:04:00
Expiration date: 15 Feb 2012 08:04:00 









B .active information gathering from www.spentera.com

to active information gathering from www.spentera.com  i used tools nmap.
first, run nmap and type the command :

root@bt:~# nmap -v -A spentera.com

this command will have result as below :
root@bt:~# nmap -v -A spentera.com
Starting Nmap 5.61TEST4 ( http://nmap.org ) at 2012-01-26 12:01 BNT
NSE: Loaded 87 scripts for scanning.
NSE: Script Pre-scanning.
Initiating Ping Scan at 12:01
Scanning spentera.com (74.81.66.104) [4 ports]
Completed Ping Scan at 12:01, 0.71s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 12:01
Completed Parallel DNS resolution of 1 host. at 12:02, 0.40s elapsed
Initiating SYN Stealth Scan at 12:02
Scanning spentera.com (74.81.66.104) [1000 ports]
Discovered open port 53/tcp on 74.81.66.104
Discovered open port 80/tcp on 74.81.66.104
Discovered open port 21/tcp on 74.81.66.104
Discovered open port 443/tcp on 74.81.66.104
Discovered open port 25/tcp on 74.81.66.104
Discovered open port 143/tcp on 74.81.66.104
Discovered open port 995/tcp on 74.81.66.104
Discovered open port 993/tcp on 74.81.66.104
Discovered open port 110/tcp on 74.81.66.104
SYN Stealth Scan Timing: About 8.77% done; ETC: 12:07 (0:05:23 remaining)
SYN Stealth Scan Timing: About 9.63% done; ETC: 12:12 (0:09:32 remaining)
SYN Stealth Scan Timing: About 10.50% done; ETC: 12:16 (0:12:56 remaining)
Increasing send delay for 74.81.66.104 from 0 to 5 due to 11 out of 25 dropped probes since last increase.

SYN Stealth Scan Timing: About 11.37% done; ETC: 12:19 (0:15:44 remaining)
SYN Stealth Scan Timing: About 12.23% done; ETC: 12:22 (0:18:03 remaining)
SYN Stealth Scan Timing: About 13.10% done; ETC: 12:25 (0:20:01 remaining)
SYN Stealth Scan Timing: About 13.97% done; ETC: 12:27 (0:21:40 remaining)
Increasing send delay for 74.81.66.104 from 5 to 10 due to 11 out of 11 dropped probes since last increase.
SYN Stealth Scan Timing: About 14.83% done; ETC: 12:29 (0:23:04 remaining)
SYN Stealth Scan Timing: About 15.87% done; ETC: 12:31 (0:24:29 remaining)
SYN Stealth Scan Timing: About 17.30% done; ETC: 12:33 (0:25:58 remaining)
Increasing send delay for 74.81.66.104 from 10 to 20 due to 11 out of 11 dropped probes since last increase.






  


No comments:

Post a Comment