Chapter 2 - Reconaissance Flashcards

1
Q

Footprinting

A

Mapping out on a high level what the landscape of the target looks like. Part of reconaissance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Footprinting vs Reconaissance

A

Recon - Basic gathering of information. Footprinting - Maps out on a high level what the landscape looks like.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Anonymous vs Pseudonymous Footprinting

A

Anonymous - Information gathering without revealinbg anything about yourself. Pseudonymous - Making someone else take the blame for your actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 4 main focuses and benefits of footprinting

A
  1. Know the security posture (footprinting helps) 2. Reduce thefocus area (network range, number of targets, etc.) 3. Identify vulnerabilities 4. Draw a network map
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Active Footprinting vs. Passive Footprinting

A

Active - Requires attacker to touch the device or network (social engineering or any other interactions with target) Passive - Measures to collect information from publicly available sources. (Website, DNS, Database)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Competitive Intelligence

A

Information gathered by business about competitors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

NetCraft

A

Search Engine tool that provides information about websites and possibly OS info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

filetype:type

A

Google search that searches only for files of a specific type.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

“intitle:index of” passwd

A

show pages that show directory listings containing a certain word (passswd)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

info:string

A

Displays information Google stores about the page itself. Ex: info:www.anycomp.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

intitle:string

A

Search forpages that contain the string in the title

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Inurl:striing

A

Display pages with the string in the URL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

link:string

A

Displays linked pages based on search terms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

related:webpagename

A

Shows web pages similar to webpagename

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

site:domain or web page string

A

Display pages for a specific website or domain holding the search term.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

DNS Record Type: SRV

A

Service - This record defines the hostname and port number of servers providing specific services, such as Directory Services server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

DNS Record Type: SOA

A

Start of Authority - This record identifies the primary name server for the zone. The SOA record contains the hostname of the server responsible for all DNS records within the namespace, as well as the basic properties of the domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

DNS Record Type: PTR

A

Pointer - This maps an IP address to a hostname (providing for reverse DNS lookups). You don’t absolutely need a PTR record for every entry in your DNS namepsace but these are usually associated with email server records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

DNS Record Type: NS

A

Name Server - This record defines the name servers within your namespace. These servers are the ones that respond to your clients’ requests for name resolution

20
Q

DNS Record Type: MX

A

Mail Exchange - This record identifies your email servers within your domain

21
Q

DNS Record Type: CNAME

A

Canonical Name - This record provides for domain name aliases within your zone. For example, you may have an FTP service and a web service running on the same IP address. CNAME records could be used to list both within DNS for you.

22
Q

DNS Record Type: A

A

Address - This record maps an IP address to a hostname and is used most often for DNS lookups

23
Q

DNS Poisoning

A

Changing the cache on a local name server to point to a bogus server instead of the real address

24
Q

SOA Record Fields

A

Source Host - Hostname of primary DNS. Contact Email - email for the person responsible for the zone file. Serial Number - Revision number that increments with each change. Refresh Time - Time in which an update should occur. Retry Time - time that a NS should wait on a failure. Expire Time - time in which a zone transfer is allowed to complete. TTL - Minimum TTL for records within zone

25
Q

IP Address Management: ARIN

A

North America

26
Q

IP Address Management: APNIC

A

Asia Pacific

27
Q

IP Address Management: RIPE

A

Europe, Middle East

28
Q

IP Address Management: LACNIC

A

Latin America

29
Q

IP Address Management: AfriNIC

A

Africa

30
Q

Web Mirroring

A

Allows for discrete testing offline

31
Q

HTTrack

A

Web Mirroring Tool

32
Q

Wget

A

Web Mirroring Tool

33
Q

Black Widow

A

Web Mirroring Tool

34
Q

WebRipper

A

Web Mirroring Tool

35
Q

Teleport Pro

A

Web Mirroring Tool

36
Q

Backstreet Browser

A

Web Mirroring Tool

37
Q

Archive.org

A

Provides cached websites from various dates which possibly have sensitive information that has been now removed.

38
Q

Whois

A

obtains registration information for the domain

39
Q

What are two ways to lookup IP Address ranges on a target?

A

Use regional registrar to obtain info (www.arin.net), or use Tracert (Windows)/ Traceroute (linux)

40
Q

Tracert

A

windows command used to route paths and transit times. USES ECHO packets

41
Q

Traceroute

A

Linux command used to route paths and transit times. USES UDP

42
Q

OSRFramework

A

Uses OSINT to get information about target. Basically a Metasploit for OSINT

43
Q

Web Spiders

A

Tool that crawls websites to Obtain information from the website such as pages, etc.

44
Q

Maltego

A

OSINT and forensics application designed explicitly to demonstrate social engineering

45
Q

Shodan

A

Search engine that shows devices connected to the internet

46
Q

What tool would you use to footprint restricted URLs and OS information from a target?

A

Netcraft

47
Q

Computer Security Incident Response Team (CSIRT)

A

Point of contact for all incident response services for associates.