The YouGetSignal (http://www.yougetsignal.com/) is a website that provides a reverse IP lookup feature. In layman's terms, the website will try to obtain the IP address for every hostname entered and then it will do a reverse IP lookup on it, so it will discover other hostnames that are associated with that particular IP. A classic situation is when the website is hosted on a shared server. If we had the task of penetrating a website, then we could do a reverse lookup for the website hostname on YouGetSignal and then attempt to break into other sites (if in scope). Then we could escalate privileges to get into the target website hosted on the same server.
For demonstration purposes, I'll do a reverse IP lookup through YouGetSignal on www.packtpub.com
.
The YouGetSignal gave us a list of possible domains that are hosted on the same server.