While footprinting a target organization you have identified a publicly reachable host at 203.0.113.27. Before launching any active scans, you want to learn which other IP addresses are likely owned by the same company so you can plan a focused engagement. Which approach will most reliably reveal the entire CIDR netblock that has been allocated to this host without generating traffic toward additional target systems?
Perform a Whois query against the appropriate Regional Internet Registry to obtain the NetRange or CIDR information for 203.0.113.27.
Request the target domain's MX records from its authoritative DNS server to enumerate associated IP ranges.
Send an oversized ICMP timestamp request to the host and use the returned TTL values to calculate the size of the organization's subnet.
Run a UDP scan against port 7 (Echo) on the host to capture replies that disclose the subnet mask and network size.
Querying a Regional Internet Registry (RIR) Whois service such as ARIN, RIPE NCC, APNIC, LACNIC, or AFRINIC for the IP address returns registration records that include the NetRange/CIDR field. This information lists the starting and ending addresses (or prefix length) of the block assigned to the registrant, allowing an attacker to determine all potential in-scope hosts passively. MX record lookups disclose only mail exchangers, not full address blocks. A UDP port 7 scan and ICMP timestamp probing are active techniques that touch the target network and do not provide authoritative allocation details.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Regional Internet Registry (RIR)?
Open an interactive chat with Bash
What is CIDR and how does it work?
Open an interactive chat with Bash
Why is Whois used in footprinting?
Open an interactive chat with Bash
What is a CIDR netblock?
Open an interactive chat with Bash
What are Regional Internet Registries (RIRs)?
Open an interactive chat with Bash
What is a Whois query and how does it work?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
Reconnaissance Techniques
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .