Saturday 8 September 2012

Website Information Gathering

After we learn about Information Gathering, then we are given the task to gathering information on two websites.
is2c-dojo.com and spentera.com


Let's try..

First, I tried to gather information about is2c-dojo.com
root@bt:~# nslookup is2c-dojo.com
Server:        8.8.8.8
Address:    8.8.8.8#53

Non-authoritative answer:
Name:    is2c-dojo.com
Address: 108.162.199.180
Name:    is2c-dojo.com
Address: 108.162.199.80
Then i tried to use whois command.
root@bt:~# whois is2c-dojo.com
Spoiler:
 root@bt:~# whois is2c-dojo.com

Whois Server Version 2.0

Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to http://www.internic.net
for detailed information.

   Domain Name: IS2C-DOJO.COM
   Registrar: CV. JOGJACAMP
   Whois Server: whois.resellercamp.com
   Referral URL: http://www.resellercamp.com
   Name Server: IVAN.NS.CLOUDFLARE.COM
   Name Server: RITA.NS.CLOUDFLARE.COM
   Status: clientTransferProhibited
   Updated Date: 01-jun-2012
   Creation Date: 14-jan-2012
   Expiration Date: 14-jan-2013

>>> Last update of whois database: Fri, 07 Sep 2012 20:06:34 UTC <<<

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar.  Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services' ("VeriSign") Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability.  VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.
Domain Name: IS2C-DOJO.COM    
                                 
 Registrant:                     
     PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676   
                                 
 Creation Date: 14-Jan-2012
 Expiration Date: 14-Jan-2013
                                 
 Domain servers in listed order: 
     ivan.ns.cloudflare.com
    rita.ns.cloudflare.com
                 
                                 
 Administrative Contact:         
     PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676
                                 
 Technical Contact:              
     PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676    
                                 
 Billing Contact:                
     PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676      
                                 
 Status:LOCKED
    Note: This Domain Name is currently Locked. In this status the domain
    name cannot be transferred, hijacked, or modified. The Owner of this
    domain name can easily change this status from their control panel.
    This feature is provided as a security measure against fraudulent domain name hijacking.
                  
 PRIVACYPROTECT.ORG is providing privacy protection services to this domain name to
protect the owner from spam and phishing attacks. PrivacyProtect.org is not
responsible for any of the activities associated with this domain name. If you wish
to report any abuse concerning the usage of this domain name, you may do so at
http://privacyprotect.org/contact. We have a stringent abuse policy and any
complaint will be actioned within a short period of time.

The data in this whois database is provided to you for information purposes only,
that is, to assist you in obtaining information about or related
to a domain name registration record. We make this information available "as is",
and do not guarantee its accuracy. By submitting a whois query, you agree that you will
use this data only for lawful purposes and that, under no circumstances will you use this data to:
(1) enable high volume, automated, electronic processes that stress
or load this whois database system providing you this information; or
(2) allow, enable, or otherwise support the transmission of mass unsolicited,
commercial advertising or solicitations via direct mail, electronic mail, or by telephone.
The compilation, repackaging, dissemination or other use of this data is expressly prohibited without
prior written consent from us. The Registrar of record is CV. Jogjacamp.
We reserve the right to modify these terms at any time.
By submitting this query, you agree to abide by these terms.
From the result we know that the registrar of is2c-dojo.com is a CV.JOGJACAMP. And then i searched on google CV.JOGJACAMP, from google i know that the is2c-dojo.com using services of idwebhost.com. And is2c-dojo.com has nameserver, IVAN.NS.CLOUDFLARE.COM and RITA.NS.CLOUDFLARE.COM.
 


I also try to use http://whois.domaintools.com to check information about is2c-dojo.com. And from that some information i got. The server type cloudflare-nginx and the location is California - San Francisco - Cloudflare Inc.

Second, I tried to gather information about spentera.com

Same as before, i do nslookup to spentera.com 


root@bt:~# nslookup spentera.com
Server:        8.8.8.8
Address:    8.8.8.8#53

Non-authoritative answer:
Name:    spentera.com
Address: 108.162.195.184
Name:    spentera.com
Address: 108.162.195.84
 Then i tried to use whois command.

root@bt:~# whois spentera.com
Spoiler:
 root@bt:~# whois spentera.com

Whois Server Version 2.0

Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to http://www.internic.net
for detailed information.

   Domain Name: SPENTERA.COM
   Registrar: ENOM, INC.
   Whois Server: whois.enom.com
   Referral URL: http://www.enom.com
   Name Server: ART.NS.CLOUDFLARE.COM
   Name Server: DINA.NS.CLOUDFLARE.COM
   Status: ok
   Updated Date: 17-may-2012
   Creation Date: 15-feb-2011
   Expiration Date: 15-feb-2013

>>> Last update of whois database: Fri, 07 Sep 2012 20:52:48 UTC <<<

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar.  Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services' ("VeriSign") Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability.  VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.
=-=-=-=

Registration Service Provided By: Namecheap.com
Contact: support@namecheap.com
Visit: http://namecheap.com
   
Domain name: spentera.com

Registrant Contact:
   WhoisGuard
   WhoisGuard Protected ()
  
   Fax:
   11400 W. Olympic Blvd. Suite 200
   Los Angeles, CA 90064
   US

Administrative Contact:
   WhoisGuard
   WhoisGuard Protected (2289eab88851476688242cf0144287f4.protect@whoisguard.com)
   +1.6613102107
   Fax: +1.6613102107
   11400 W. Olympic Blvd. Suite 200
   Los Angeles, CA 90064
   US

Technical Contact:
   WhoisGuard
   WhoisGuard Protected (2289eab88851476688242cf0144287f4.protect@whoisguard.com)
   +1.6613102107
   Fax: +1.6613102107
   11400 W. Olympic Blvd. Suite 200
   Los Angeles, CA 90064
   US

Status: Active

Name Servers:
   art.ns.cloudflare.com
   dina.ns.cloudflare.com
  
Creation date: 15 Feb 2011 13:04:00
Expiration date: 15 Feb 2013 08:04:00


  

=-=-=-=
The data in this whois database is provided to you for information
purposes only, that is, to assist you in obtaining information about or
related to a domain name registration record. We make this information
available "as is," and do not guarantee its accuracy. By submitting a
whois query, you agree that you will use this data only for lawful
purposes and that, under no circumstances will you use this data to: (1)
enable high volume, automated, electronic processes that stress or load
this whois database system providing you this information; or (2) allow,
enable, or otherwise support the transmission of mass unsolicited,
commercial advertising or solicitations via direct mail, electronic
mail, or by telephone. The compilation, repackaging, dissemination or
other use of this data is expressly prohibited without prior written
consent from us. 

We reserve the right to modify these terms at any time. By submitting
this query, you agree to abide by these terms.
Version 6.3 4/3/2
From the result we know that the registrar of spentera.com is a ENOM, INC. spentera.com has name server ART.NS.CLOUDFLARE.COM and DINA.NS.CLOUDFLARE.COM. The server type is cloudflare-nginx and the location California - San Francisco - Cloudflare Inc.

And then i tried to view page source of spentera.com. I found that the spentera.com using wordpress with NovaTheme_v2.0 theme, and also using plugin All in One SEO Pack 1.6.15. From backtrack tools, i found Web Application Analysis for CMS Identification, i use wpscan. Later I searched on google how to use wpscan, and find a way to use a command like below.

Spoiler:
root@bt:/pentest/web/wpscan# ruby wpscan.rb --url www.spentera.com
____________________________________________________
 __          _______   _____                 
 \ \        / /  __ \ / ____|                
  \ \  /\  / /| |__) | (___   ___  __ _ _ __ 
   \ \/  \/ / |  ___/ \___ \ / __|/ _` | '_ \
    \  /\  /  | |     ____) | (__| (_| | | | |
     \/  \/   |_|    |_____/ \___|\__,_|_| |_| v1.1r425

    WordPress Security Scanner by the WPScan Team
 Sponsored by the RandomStorm Open Source Initiative
_____________________________________________________

[WARNING] The SVN repository is DEPRECATED, use the GIT one - http://github.com/wpscanteam/wpscan

| URL: http://www.spentera.com
| Started on Sat Sep  8 04:20:37 2012

[!] The WordPress theme in use is NovaTheme_v2.0 v2.0
[!] WordPress version 3.4.1 identified from advanced fingerprinting

[+] Enumerating plugins from passive detection ... 5 found :

 | Name: codeguard
 | Location: http://www.spentera.com/$wp-plugins$/codeguard/

 | Name: jetpack
 | Location: http://www.spentera.com/$wp-plugins$/jetpack/
 |
 | [!] jetpack plugin SQL Injection Vulnerability
 | * Reference: http://www.exploit-db.com/exploits/18126/

 | Name: lightbox-2
 | Location: http://www.spentera.com/$wp-plugins$/lightbox-2/

 | Name: easy-google-syntax-highlighter
 | Location: http://www.spentera.com/$wp-plugins$/easy-google-syntax-highlighter/

 | Name: google-syntax-highlighter
 | Location: http://www.spentera.com/$wp-plugins$/google-syntax-highlighter/

[+] Finished at Sat Sep  8 04:21:03 2012
 


We found some information, beside the theme, we know that spentera.com using wordpress version 3.4.1 and some plugins like codeguard, jetpack, lightbox-2, easy-google-syntax-highlighter, and google-syntax-highlighter.

In wordpress, the login page address is http://yoursite.com/wp-admin, and i try it to spentera.com, then web redirect to address http://www.spentera.com/wp-login.php?redirect_to=http%3A%2F%2Fwww.spentera.com%2Fwp-admin%2F&reauth=1, but it still bring up to the login page.



0 comments:

Post a Comment

Comment in here...