RE: Blind penetration testing

From: Grab Raham (grabrahamat_private)
Date: Tue Oct 02 2001 - 19:01:06 PDT

  • Next message: Rosenau: "DENY x REJECT"

    I like to send an email to an internal address that is more than likely 
    going to bounce back at me. The mail headers in the bounceback often reveal 
    valuable information.
    
    G.
    
    
    >Im about to start work on a completely blind penetraton test for a >client. 
    >The only information i have been given is the company name. >From this i 
    >can get their corporate web site and from there do a DIG >for more company 
    >info and address ranges after which i can start my >reconnaissance. 
    >Question, can anyone out there offer any tips based on >this scenario?
    
    
    
    _________________________________________________________________
    Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Thu Oct 04 2001 - 11:31:59 PDT