Footprinting Flashcards

(33 cards)

1
Q

What is footprinting?

A

An effort to map out, at a high level, what the landscape looks like.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the two types of footprinting?

A

Passive and active

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What’s passive footprinting?

A

Collecting information from publicly available sources without any touch-points on the target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What’s active footprinting?

A

Required the attacker to touch the device, network or resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What’s anonymous footprinting?

A

An attempt to hide yourself or conceal your actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What’s pseudonymous footprinting?

A

An attempt to misdirect your actions onto someone else

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Name the 4 key benefits of footprinting.

A

Know the security posture, reduce the focus area, identify vulnerabilities, draw a network map

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What’s competitive intelligence?

A

Information gathered by a business entity about its competitors’ customers, products and marketing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the logical flow of footprinting?

A

Investigtae web resources, map out network ranges, mine whois and DNS, finish with social engineering, email tracking and Google hacking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Name some example of passive footprinting.

A

Dumpster diving, Google search, company’s public website, DNS/WHOis lookup, Physical drive-by, Social media/LinkedIn

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Name some examples of active footprinting.

A

Social engineering, visit the building physically, network sniffing, ping/tracert, banner grabbing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Name some ways you can use search engines to footprint a target.

A

Mapping & location-specific information eg Google Maps, employee personal information from LinkedIn, job listings & boards, social networking sites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Name some ways you can use Google hacking to footprint a target.

A

Google search string operators, metadata in documents, Metagoofil, SiteDigger

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Name some useful Google search string operators.

A

intitle, inurl, site, filetype

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Name some ways you can use website and email footprinting.

A

Grab headers and cookies, analyse software in use, learn connection status, content type & web server information, web mirroring, website history, email headers, email tracking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Black Widow used for?

A

Web mirroring

17
Q

What is Archive.org used for?

A

Cached webpages back to 1996

18
Q

What is Google Cache used for?

A

Only the most recent crawl of a website - may only be a few days old

19
Q

What is EmailTrackerPro used for?

A

See where an email travels and how it gets there

20
Q

What are some useful information you can get from an email header?

A

Source IP address, physical location, anti-virus, SPF allowed IPs

21
Q

What is WebRipper used for?

A

Web mirroring

22
Q

What is Website Watcher used for?

A

Checks web pages for changes and automatically notifies you when there’s an update

23
Q

What is Metagoofil used for?

A

Scraping metadata from documents

24
Q

Name some ways you can carry out DNS footprinting.

A

Whois records (registrant, registrar, DNS server names), Nslookup to query DNS servers for information, Zone transfer

25
What is the UNIX version of Nslookup?
Dig
26
What is OSRFramework?
OSINT research framework for Kali Linux that profiles individuals
27
What is a web spider?
An application that crawls through a website
28
What is Maltego?
An open source itnelligence and forensics application designed to demonsrate social engineering weaknesses for your environment
29
What is SEF?
Social Engineering Framework - tools which can automate things such as extracrting email addresses out of websites
30
Name some tools which could mirror a website.
BlackWidow, WebRipper, Backstreet Browser, GNU Wget
31
Name some tools that could grab a websites' history.
Google Cache, Archive.org, WayBack Machine, Website Watcher
32
Name some email tracking tools.
Emailtrackerpro, mailtracking
33
Name some tools for visually building a network map.
NeoTrace, Trout, VisualRoute