Chapter 4 Footprinting & Reconnaissance Flashcards
PHASE 1 of the ethical hacking process!!
Footprinting - PASSIVELY gaining info about target
i.e. want just enough data to plan next phase of scanning
includes IP address ranges, Namespaces, Employee info, phone #s, facility info, job info, OS
Phase 2
Scanning - ACTIVELY gaining info; footprinting helps identify targets but not all may be active, which is where scanning takes place
includes locating active hosts to target in later phase, pings, ping sweeps, port scans, tracert
Phase 3
Enumeration - systematic probing of target w/ goal of obtaining user lists, routing tables, & protocols from the system; shifting from outside to inside to gather data
includes shares, users, groups, applications, protocols, banners, usernames, group info, passwords, device info, NW layout, services
Phase 4
System Hacking - methodical approach including cracking passwords, escalating privileges, executing apps, hiding files, covering tracks, concealing evidence
Footprinting, or reconnaissance definition
method of observing & collecting info about potential target w/ the intention of finding a way to attack
Maltego
app that illustrates relationship between people, gruops, companies, etc (illustrates the dangers of social networking)
Financial Services Info Types
Company officers, financials, sites, known risks, competitive analysis
Job Site Info Type
Hardware/software details, org structure
WhoReadMe.com
allows you to track emails & provides info on OS, browster type, location, etc
Competitive Analysis
establishing what makes your product or service unique; looking at what competitors are doing to see how your target is moving
reports provide info such as project data, financial status, etc
Tools such as EDGAR (reports), LexisNexis (news), BusinessWire (status), CNBC (future plans)
Google Hacking “cache:”
shows page in google cache (not the actual website)
Whois
find domain name, IP info, etc
Archive.org
(aka The Wayback Machine) allows you to find archived copies of websites form which you can extract information
Netcraft
suite of tools used to obtain web server version, IP address, subnet data, OS info, subdomain info
Link Extractor
this tool locates & extracts the internal and external URLs for a given location