Footprinting and Reconnaissance Flashcards
What is Sherlock? (Software)
Sherlock is a tool to search a vast number of social networking sites for a target username. This tool helps the attacker to locate the target user on various social networking sites along with the complete URL
What is BeRoot? (Software)
BeRoot is a post-exploitation tool to check for common misconfigurations which can allow an attacker to escalate their privileges.
What is OpUtils? (Software)
SNMP enumeration protocol that helps to monitor, diagnose and troubleshoot IT resources.
What is Passive Footprinting
Passive footprinting involves gathering information about the target without direct interaction. It is mainly useful when the information gathering activities are not to be detected by the target. Performing passive footprinting is technically difficult, as active traffic is not sent to the target organization from a host or anonymous hosts or services
What is Active Footprinting?
Active footprinting involves gathering information about the target with direct interaction. In active footprinting, the target may recognize the ongoing information gathering process, as we overtly interact with the target network. Active footprinting requires more preparation than passive footprinting, as it may leave traces that may alert the target organization.
What is Intelius? (Software)
Attackers can use the Intelius people search online service to search for people belonging to the target organization.
What is TinEye? (Software)
A reverse image search service.
What is Mention? (Software)
Mention is an online reputation tracking tool that helps attackers in monitoring the web, social media, forums, and blogs to learn more about the target brand and industry
Which Google query can be used to find Cisco VPN client passwords?
“[main]” “enc_GroupPwd=” ext:txt
Which Google query can be used to find configuration pages for online VoIP devices?
intitle:”Sipura.SPA.Configuration” -.pdf
What is Professional Toolset? (Software)
Professional Toolset (https://tools.dnsstuff.com) and DNS Records (https://network-tools.com) are DNS footprinting tools
What is Infoga? (Software)
Infoga is a tool used for gathering email account information from different public sources and it checks if an email was leaked using the haveibeenpwned.com API
What is Octoparse? (Software)
Octoparse offers automatic data extraction, as it quickly scrapes web data without coding and turns web pages into structured data
What is Metagoofil? (Software)
Metagoofil extracts metadata of public documents (pdf, doc, xls, ppt, docx, pptx, and xlsx) belonging to a target company
What is an advanced Google search query that returns a list of FTP servers by IP address, which are mostly Windows NT servers with guest login capabilities?
inurl:~/ftp://193 filetype:(php | txt | html | asp | xml | cnf | sh) ~’/html’