Lesson 3- Footprinting and Gathering Intelligence Flashcards
What OSINT tool is useful for finding known vulnerabilities, default passwords especially on iOT devices
Shodan
Name a common DNS Tool that can be used for Windows and Linux
Nslookup
Dig is the Linux tool only and good for reverse lookups
What tool can I use for getting details on a company’s domain name such as address, contact numbers, etc.
WhoIS
What are some tools for image searches and why are these important
TinEye
Google
Yandex
Bing
compromised images of target organization
According to OWASP enumeration is also referred to as
Predictable Resource Location
File or Directory Enumeration
What is used to identify unlinked URL’s or IP’s from a website to gain access to unprotected resources
Forced Browsing
typically a manual process
Field in a digital signature allowing a host to be identified by multiple host names/subdomains
Subject Alternate Name
(SAN)
Where can I find logs of Public Certificate Authorities (CA)
Certificate Transparency (CT) Framework
What is the current model of validating a Digital Certificate
Using the Online Certificate Status Protocol (OCSP)
What is a process where the web server must validate a certificate called
Stapling the Certificate
What is the Linux tool that is great for discovering Metadata and Fingerprinting an organizations and what type of scripting does it use
Metagoofil and Python
flags
-d website - scan for docs
-t PDF - scan for pdf docs
-l 75 - search for 75 docs
-n 25 - download 25 docs
-o dirname - save downloads to dirname directory
What is the Graphical OSINT tool (Windows only) that specializes in working with documents that have been downloaded
FOCA
requires a local SQL Server to store data
________ in an intuitive tool that can search a company’s visible threat landscape and uses multiple methods such as Google Comodo Social media and banner Grabbing functionality using Shodan
theHarvester
theharvester -d website -b LinkedIn
What tool is similar to theHarvester but more robust and uses dozens of different modules
Recon-ng
Modules Inlcude
Whois
PGP key search
Social Medial profiles associations
File crawler
DNS Record enumerator
also used Have | Been Pwnded database
What is the CLI Tool that helps users visualize gathered OSINT Data and uses an extensive library. In addition what are these libraries called that automate the querying of public databases
Maltego and Transforms