Domain 2: Information Gathering and Vulnerability Scanning Flashcards
Information Gathering and Vulnerability Scanning
What is Reconnaissance?
Learning abiut an organization in a systematic attmept to locate, gather, identify and record information about the target
aka Footprinting
What is passive reconaissance?
Investigating the target without activly engaging with the target organizations systems.
What is Open-Source Intelligence?
The collection and analysis of data gathered from publicly available sources to produce actionable inteliligence
What should you do with reconaissance findings?
Gather and catalog all findings for others to review and use
Useful for when workign as a team.
Examples of Open Source Inteligence
- Blogs
- Publications\
- Adverts
- Job Listings
- Metadata
- Website Information
Good key details to understand abouut the target organization?
- Roles of different employees
- Different teams and departments
- Contact Information
- Technical Aptitud\e and Security Training
- Employee and Managerial Mindset
A linux-based tool that can search the metadata associated with public documents located on a targets website
Security Tool
Obj 2.1
Metagoofil
What is Metadata?
The data about the data in the file
Used to find metadata and hidden information in collected documents from an organization.
Secuirty Tool
Obj 2.1
Fingerprint Organizations with Collected Archives (FOCA)
A program for gathering emails, subdomains, hosts, employee names, email addresses, PGP Key Entires, open ports ans service banner from servers.
Secuirty Tool
Obj 2.1
The Harvester
Uses a system of modules to add additional features and functions for your use
Security Tool
Obj 2.1
Recon-NG
A website search engine used for finding hosts and networks across the Internet with data abouit their configurations
Secuirty Tool
Obj 2.1
Censys
A piece of commercial software used for conducting open-source inteligence that visually helps connect those relationships
Security Tool
Obj 2.1
Maltego
A website search engine for web cameras, routers, servers and other devices that are considered part of the internet of things
Secuirty Tool
Obj 2.1
Shodan
What is the system that helps network clients find a website using human-readable hostnames instead of numeric IP addresses?
Obj 2.1
Domain Name System (DNS)
Links a hostname to an IPv4 address
DNS Record
Obj 2.1
Address (A) Record
Links a hostname to a IPv6 address
DNS Record
Obj 2.1
AAAA Record
Points a domain to another domain or subdomain
DNS Record
Obj 2.1
Canonical Name (CNAME) Record
Directs mail to a mail server
DNS Record
Obj 2.1
Mail Exchange (MX) Record
Stores important information about the domain or zone
DNS Record
Obj 2.1
Start of Authority (SOA) Record