WHOIS

One of the first things we will want to do is to determine where our target site is hosted and who owns the IP space we are testing.

This is done by using the command syntax: ~# whois target_site .

Now is a good time to go back and look over your scope. Depending on the NetRange you get back, these ranges may be in scope for a future DNS reverse lookups. Sometimes you might get large CDN’s returned like Akamai, CloudFlare, or SoftLayer. Here we have uncovered school email addresses as well as job titles as well as additional name servers. We will learn how to find out more information from then. Keep track of this information!