Footprinting Flashcards

1
Q

What is footprinting?

A

An effort to map out, at a high level, what the landscape looks like.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the two types of footprinting?

A

Passive and active

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What’s passive footprinting?

A

Collecting information from publicly available sources without any touch-points on the target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What’s active footprinting?

A

Required the attacker to touch the device, network or resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What’s anonymous footprinting?

A

An attempt to hide yourself or conceal your actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What’s pseudonymous footprinting?

A

An attempt to misdirect your actions onto someone else

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Name the 4 key benefits of footprinting.

A

Know the security posture, reduce the focus area, identify vulnerabilities, draw a network map

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What’s competitive intelligence?

A

Information gathered by a business entity about its competitors’ customers, products and marketing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the logical flow of footprinting?

A

Investigtae web resources, map out network ranges, mine whois and DNS, finish with social engineering, email tracking and Google hacking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Name some example of passive footprinting.

A

Dumpster diving, Google search, company’s public website, DNS/WHOis lookup, Physical drive-by, Social media/LinkedIn

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Name some examples of active footprinting.

A

Social engineering, visit the building physically, network sniffing, ping/tracert, banner grabbing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Name some ways you can use search engines to footprint a target.

A

Mapping & location-specific information eg Google Maps, employee personal information from LinkedIn, job listings & boards, social networking sites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Name some ways you can use Google hacking to footprint a target.

A

Google search string operators, metadata in documents, Metagoofil, SiteDigger

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Name some useful Google search string operators.

A

intitle, inurl, site, filetype

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Name some ways you can use website and email footprinting.

A

Grab headers and cookies, analyse software in use, learn connection status, content type & web server information, web mirroring, website history, email headers, email tracking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Black Widow used for?

A

Web mirroring

17
Q

What is Archive.org used for?

A

Cached webpages back to 1996

18
Q

What is Google Cache used for?

A

Only the most recent crawl of a website - may only be a few days old

19
Q

What is EmailTrackerPro used for?

A

See where an email travels and how it gets there

20
Q

What are some useful information you can get from an email header?

A

Source IP address, physical location, anti-virus, SPF allowed IPs

21
Q

What is WebRipper used for?

A

Web mirroring

22
Q

What is Website Watcher used for?

A

Checks web pages for changes and automatically notifies you when there’s an update

23
Q

What is Metagoofil used for?

A

Scraping metadata from documents

24
Q

Name some ways you can carry out DNS footprinting.

A

Whois records (registrant, registrar, DNS server names), Nslookup to query DNS servers for information, Zone transfer

25
Q

What is the UNIX version of Nslookup?

A

Dig

26
Q

What is OSRFramework?

A

OSINT research framework for Kali Linux that profiles individuals

27
Q

What is a web spider?

A

An application that crawls through a website

28
Q

What is Maltego?

A

An open source itnelligence and forensics application designed to demonsrate social engineering weaknesses for your environment

29
Q

What is SEF?

A

Social Engineering Framework - tools which can automate things such as extracrting email addresses out of websites

30
Q

Name some tools which could mirror a website.

A

BlackWidow, WebRipper, Backstreet Browser, GNU Wget

31
Q

Name some tools that could grab a websites’ history.

A

Google Cache, Archive.org, WayBack Machine, Website Watcher

32
Q

Name some email tracking tools.

A

Emailtrackerpro, mailtracking

33
Q

Name some tools for visually building a network map.

A

NeoTrace, Trout, VisualRoute