$ ping ptt.cc -t 5 PING ptt.cc (140.112.172.11): 56 data bytes 64 bytes from 140.112.172.11: icmp_seq=0 ttl=53 time=29.484 ms 64 bytes from 140.112.172.11: icmp_seq=1 ttl=53 time=28.149 ms 64 bytes from 140.112.172.11: icmp_seq=2 ttl=53 time=40.087 ms 64 bytes from 140.112.172.11: icmp_seq=3 ttl=53 time=40.083 ms 64 bytes from 140.112.172.11: icmp_seq=4 ttl=53 time=27.993 ms
--- ptt.cc ping statistics --- 5 packets transmitted, 5 packets received, 0.0% packet loss round-trip min/avg/max/stddev = 27.993/33.159/40.087/5.679 ms
$ traceroute ptt.cc traceroute: Warning: ptt.cc has multiple addresses; using 140.112.172.11 traceroute to ptt.cc (140.112.172.11), 64 hops max, 52 byte packets 1 h254.s98.ts.hinet.net (168.95.98.254) 18.052 ms 17.399 ms 22.979 ms 2 nkn1-3311.hinet.net (168.95.220.222) 14.384 ms 18.350 ms 18.664 ms 3 tne1-3011.hinet.net (220.128.26.54) 27.039 ms tne1-3011.hinet.net (220.128.26.58) 24.878 ms tne1-3011.hinet.net (220.128.26.50) 20.979 ms 4 220-128-26-62.hinet-ip.hinet.net (220.128.26.62) 20.432 ms 220-128-24-10.hinet-ip.hinet.net (220.128.24.10) 34.886 ms 220-128-26-62.hinet-ip.hinet.net (220.128.26.62) 20.343 ms 5 tpdt-3011.hinet.net (220.128.24.181) 19.962 ms tpdt-3011.hinet.net (220.128.13.89) 22.678 ms skc1-3316.hinet.net (220.128.24.89) 20.093 ms 6 tpdt-3301.hinet.net (220.128.1.97) 24.488 ms 23.240 ms 20.475 ms 7 211-22-226-201.hinet-ip.hinet.net (211.22.226.201) 25.781 ms 24.216 ms 20.356 ms 8 140.112.0.194 (140.112.0.194) 29.741 ms 21.139 ms 36.160 ms 9 140.112.0.189 (140.112.0.189) 28.453 ms 21.221 ms 31.266 ms 10 140.112.0.173 (140.112.0.173) 20.645 ms 20.324 ms 20.998 ms 11 ptt.cc (140.112.172.11) 22.423 ms 20.953 ms 20.944 ms
nslookup
nslookup 可以讓我們查詢 domain 指向的的 ip 位置
我們用下面的指令來查詢 ptt.cc 的 ip 位置 可以看到他透過 8.8.8.8 的 DNS server 查詢,得到了 6 台主機的 ip 位置。
Starting Nmap 7.60 ( https://nmap.org ) at 2018-03-20 15:14 CST Nmap scan report for ptt.cc (140.112.172.5) Host is up (0.023s latency). Other addresses for ptt.cc (not scanned): 140.112.172.3 140.112.172.4 140.112.172.2 140.112.172.11 140.112.172.1 rDNS record for 140.112.172.5: e.ptt.cc Not shown: 981 closed ports PORT STATE SERVICE 22/tcp open ssh 23/tcp open telnet 80/tcp open http 135/tcp filtered msrpc 139/tcp filtered netbios-ssn 443/tcp open https 445/tcp filtered microsoft-ds 3000/tcp open ppp 3001/tcp open nessus 3003/tcp open cgms 3005/tcp open deslogin 3006/tcp open deslogind 3007/tcp open lotusmtap 5959/tcp filtered unknown 5960/tcp filtered unknown 5961/tcp filtered unknown 5962/tcp filtered unknown 8888/tcp open sun-answerbook 9111/tcp open DragonIDSConsole
Nmap done: 1 IP address (1 host up) scanned in 1.91 seconds
我們可以看到 ptt 不只是開放我們經常使用的 http 80, https 443, telnet 23, ssh 22 服務而已 還開放了不同的 port 提供其他服務,我們就可以再利用其他工具測試這些 port 開放出來做什麼的進而找尋有機可趁的機會。