Footprinting Flashcards
What is footprinting?
An effort to map out, at a high level, what the landscape looks like.
What are the two types of footprinting?
Passive and active
What’s passive footprinting?
Collecting information from publicly available sources without any touch-points on the target
What’s active footprinting?
Required the attacker to touch the device, network or resource
What’s anonymous footprinting?
An attempt to hide yourself or conceal your actions
What’s pseudonymous footprinting?
An attempt to misdirect your actions onto someone else
Name the 4 key benefits of footprinting.
Know the security posture, reduce the focus area, identify vulnerabilities, draw a network map
What’s competitive intelligence?
Information gathered by a business entity about its competitors’ customers, products and marketing
What is the logical flow of footprinting?
Investigtae web resources, map out network ranges, mine whois and DNS, finish with social engineering, email tracking and Google hacking
Name some example of passive footprinting.
Dumpster diving, Google search, company’s public website, DNS/WHOis lookup, Physical drive-by, Social media/LinkedIn
Name some examples of active footprinting.
Social engineering, visit the building physically, network sniffing, ping/tracert, banner grabbing
Name some ways you can use search engines to footprint a target.
Mapping & location-specific information eg Google Maps, employee personal information from LinkedIn, job listings & boards, social networking sites
Name some ways you can use Google hacking to footprint a target.
Google search string operators, metadata in documents, Metagoofil, SiteDigger
Name some useful Google search string operators.
intitle, inurl, site, filetype
Name some ways you can use website and email footprinting.
Grab headers and cookies, analyse software in use, learn connection status, content type & web server information, web mirroring, website history, email headers, email tracking