Chapter 2 - Reconaissance Flashcards

1
Q

Footprinting

A

Mapping out on a high level what the landscape of the target looks like. Part of reconaissance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Footprinting vs Reconaissance

A

Recon - Basic gathering of information. Footprinting - Maps out on a high level what the landscape looks like.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Anonymous vs Pseudonymous Footprinting

A

Anonymous - Information gathering without revealinbg anything about yourself. Pseudonymous - Making someone else take the blame for your actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 4 main focuses and benefits of footprinting

A
  1. Know the security posture (footprinting helps) 2. Reduce thefocus area (network range, number of targets, etc.) 3. Identify vulnerabilities 4. Draw a network map
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Active Footprinting vs. Passive Footprinting

A

Active - Requires attacker to touch the device or network (social engineering or any other interactions with target) Passive - Measures to collect information from publicly available sources. (Website, DNS, Database)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Competitive Intelligence

A

Information gathered by business about competitors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

NetCraft

A

Search Engine tool that provides information about websites and possibly OS info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

filetype:type

A

Google search that searches only for files of a specific type.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

“intitle:index of” passwd

A

show pages that show directory listings containing a certain word (passswd)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

info:string

A

Displays information Google stores about the page itself. Ex: info:www.anycomp.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

intitle:string

A

Search forpages that contain the string in the title

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Inurl:striing

A

Display pages with the string in the URL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

link:string

A

Displays linked pages based on search terms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

related:webpagename

A

Shows web pages similar to webpagename

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

site:domain or web page string

A

Display pages for a specific website or domain holding the search term.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

DNS Record Type: SRV

A

Service - This record defines the hostname and port number of servers providing specific services, such as Directory Services server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

DNS Record Type: SOA

A

Start of Authority - This record identifies the primary name server for the zone. The SOA record contains the hostname of the server responsible for all DNS records within the namespace, as well as the basic properties of the domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

DNS Record Type: PTR

A

Pointer - This maps an IP address to a hostname (providing for reverse DNS lookups). You don’t absolutely need a PTR record for every entry in your DNS namepsace but these are usually associated with email server records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

DNS Record Type: NS

A

Name Server - This record defines the name servers within your namespace. These servers are the ones that respond to your clients’ requests for name resolution

20
Q

DNS Record Type: MX

A

Mail Exchange - This record identifies your email servers within your domain

21
Q

DNS Record Type: CNAME

A

Canonical Name - This record provides for domain name aliases within your zone. For example, you may have an FTP service and a web service running on the same IP address. CNAME records could be used to list both within DNS for you.

22
Q

DNS Record Type: A

A

Address - This record maps an IP address to a hostname and is used most often for DNS lookups

23
Q

DNS Poisoning

A

Changing the cache on a local name server to point to a bogus server instead of the real address

24
Q

SOA Record Fields

A

Source Host - Hostname of primary DNS. Contact Email - email for the person responsible for the zone file. Serial Number - Revision number that increments with each change. Refresh Time - Time in which an update should occur. Retry Time - time that a NS should wait on a failure. Expire Time - time in which a zone transfer is allowed to complete. TTL - Minimum TTL for records within zone

25
IP Address Management: ARIN
North America
26
IP Address Management: APNIC
Asia Pacific
27
IP Address Management: RIPE
Europe, Middle East
28
IP Address Management: LACNIC
Latin America
29
IP Address Management: AfriNIC
Africa
30
Web Mirroring
Allows for discrete testing offline
31
HTTrack
Web Mirroring Tool
32
Wget
Web Mirroring Tool
33
Black Widow
Web Mirroring Tool
34
WebRipper
Web Mirroring Tool
35
Teleport Pro
Web Mirroring Tool
36
Backstreet Browser
Web Mirroring Tool
37
Archive.org
Provides cached websites from various dates which possibly have sensitive information that has been now removed.
38
Whois
obtains registration information for the domain
39
What are two ways to lookup IP Address ranges on a target?
Use regional registrar to obtain info (www.arin.net), or use Tracert (Windows)/ Traceroute (linux)
40
Tracert
windows command used to route paths and transit times. USES ECHO packets
41
Traceroute
Linux command used to route paths and transit times. USES UDP
42
OSRFramework
Uses OSINT to get information about target. Basically a Metasploit for OSINT
43
Web Spiders
Tool that crawls websites to Obtain information from the website such as pages, etc.
44
Maltego
OSINT and forensics application designed explicitly to demonstrate social engineering
45
Shodan
Search engine that shows devices connected to the internet
46
What tool would you use to footprint restricted URLs and OS information from a target?
Netcraft
47
Computer Security Incident Response Team (CSIRT)
Point of contact for all incident response services for associates.