0xspade icon

Domain Reverse IP Look Up

0xspade | PRO | 08/25/16 05:54:55 AM UTC | 0 ⭐ | 699 👁️ | Never ⏰ | []
Python |

1.95 KB

|

None

|

0 👍

/

0 👎

<script src="//my.hellobar.com/d47b5e9fed3fd1926808aefff5134faac871bb04.js" type="text/javascript" charset="utf-8" async="async"></script>#!/usr/local/bin/python2.7
 
# The objective of this script is to generate an output file with all the URLs found on shared hosting ('DSQLiReverseLookUp.txt' by default)
# Shamelessly copied from http://hack-addict.blogspot.co.nz/2011/09/finding-domains-on-targeted-host.html.
# Thanks and credit to the author
 
import httplib, urllib, socket, sys
from xml.dom.minidom import parse, parseString
 
#reverseLookUp = 'DSQLiReverseLookUp.txt'
 
def generate_reverse_lookup(domainURL, filename, verbose):
    print "\t[*] Performing Reverse IP Lookup to collect all domains hosted on same server....."
    if domainURL[:7] == "http://": 
            domainURL = domainURL[7:]
    
#   print "\n inside generate_reverse_lookup function with args: ", domainURL
    AppId = '1734E2C92CA63FAA596335295B09CF1D0B5C6161'
    sites = [domainURL]
    ip = socket.gethostbyname(domainURL)
    offset = 50
    
    while offset < 300:
        uri = "/xml.aspx?AppId=%s&Query=ip:%s&Sources=Web&Version=2.0&Market=en-us&Adult=Moderate&Options=EnableHighlighting&Web.Count=50&Web.Offset=%s&Web.Options=DisableQueryAlterations"%(AppId, ip, offset)
        conn = httplib.HTTPConnection("api.bing.net")
        conn.request("GET", uri)
        res = conn.getresponse()
        data = res.read()
        conn.close()
        xmldoc = parseString(data)
        nameEls = xmldoc.getElementsByTagName('web:DisplayUrl')
    
        for el in nameEls:
            temp = el.childNodes[0].nodeValue
            temp = temp.split("/")[0]
        
            if temp.find('www.') == -1:
                if temp not in sites:
                    sites.append(temp)
        offset += 50
    
    print "\n\t[-] Reverse IP Look Up successful" 
#   print "\n\t[-] Number of domain(s) found: %d\n" % len(sites)
    
    try:
        fd_reverseLookUp = open(filename, 'w+')
        for site in sites:
            fd_reverseLookUp.write(site + '\n')
            if verbose == 1:
                print "\t\t", site
        
        print "\n\t[-] Number of domain(s) found: %d\n"

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎