Information Gathering Lab
For this lab, my tasks were: find live hosts on the netblock 10.50.96.0/23 using ICMP packets and then other means (TCP half-open SYN scans for example); find DNS servers; locate name servers and mail exchange servers; find other hosts on the netblock and create a map of the network. I started by checking the network information using a python program I have written to help with such tasks. This was useful as it allowed me to see the entire scope of the engagement more easily. It became clear that there would be two networks involved: 10.50.96.0/24 and 10.50.97.0/24 I used an ip command to check this out further: My next job was to get started identifying live hosts. I began by using ICMP packets (ping and timestamp requests combined into -PEP). I used the -sn flag because I did not want nmap to do any kind of port scanning. This was quick and returned some results, but since ICMP traffic is often dropped by firewalls, I went on to try half-open SYN scans. I used the -F flag beca...