Network enumeration
Identify domain names and networks
- registrar query. In Linux/UNIX issue whois “domain.”@whois.crsnic.net In Windows download CyberKit and perform the query. Then use the domain.xxx to find the registrar.
- organizational query. Use name organization name and query the respective registrar, as shown in this example.
- domain query. Given all possible domains start with one of them and query the registrar about the domain. Note phones, DNS, etc.
- network query. The ARIN database can provide information on IP blocks assigned to an organization. Query whois.arin.net.
- countermeasures: only administrative cleanup, because the information is required for registration.