MODULE 2: Footprinting & Reconnaissance Flashcards

1
Q

Which Google advanced search operator displays the web pages stored in the google cache?

A

[cache:]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which Google advanced search operator lists web pages that have links to the specified web page?

A

[link:]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which Google advanced search operator lists web pages that are similar to the specified web page?

A

[related:]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which Google advanced search operator presents some information that google has about a particular web page?

A

[info:]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which Google advanced search operator restricts the results to those websites in the given domain?

A

[site:]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which Google advanced search operator restricts the results to those websites containing all the search keywords in the title?

A

[allintitle:]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which Google advanced search operator restricts the results to documents containing the search keyword in the title?

A

[intitle:]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which Google advanced search operator restricts the results to those containing all the search keywords in the URL?

A

[allinurl:]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which Google advanced search operator restricts the results to documents containing the search keyword in the url?

A

[inurl:]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which Google advanced search operator finds results for a specific location?

A

[location:]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is an authoritative source for querying the google search engine, contains a dynamic list of google dorks that hackers may find useful?

A

The Google Hacking Database (GHDB)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What tool can be used to perform enumeration of LinkedIn?

A

theHarvester

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What tool can a hacker utilize to mirror an entire website for testing in an offline environment?

A

HTTrack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What website is referred to as a “Way-Back machine” that can be used to view old versions of websites as far back as 1996?

A

Archive.org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What tool allows hackers to compile word lists to use in brute force attacks from a target website?

A

CeWL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What type of databases are maintained by regional internet registries and contain personal information of domain owners?

A

Whois

17
Q

Which regional internet registry is used for north America?

A

ARIN

18
Q

What regional internet registry is used for France/Europe?

A

RIPE NCC

19
Q

What type of records provide important information about the location and type of servers/hosts in a target network?

A

DNS Records

20
Q

Match the DNS record type to its description:

  1. A Service Records
  2. MX Indicates authority for a domain
  3. NS Points to a host’s IP address
  4. CNAME Points to domain’s mail server
  5. SOA Responsible Person
  6. SRV Unstructured text records
  7. PTR Canonical naming allows aliases to a host
  8. RP Points to a hosts name server
  9. HINFO Maps IP address to a host name
  10. TXT Host information record, includes CPU and OS
A
  1. A 6. Service Records
  2. MX 5. Indicates authority for a domain
  3. NS 1. Points to a host’s IP address
  4. CNAME 2. Points to domain’s mail server
  5. SOA 8. Responsible Person
  6. SRV 10. Unstructured text records
  7. PTR 4. Canonical naming allows aliases to a host
  8. RP 3. Points to a hosts name server
  9. HINFO 7. Maps IP address to a host name
  10. TXT 9. Host information record, includes CPU and OS
21
Q

Between (A) and (AAAA) DNS records, which one maps to a 32 bit IPv4 address vs. a 128 bit IPv6 address?

A

A - IPv4

AAAA - IPv6

22
Q

What DNS record previously covered is also used to provide authentication of mail sent and received by the same email system?

A

TXT (SPF, DKIM)

23
Q

What tool works on the concept of the ICMP protocol and the use of the TTL field in the header of ICMP packets to discover the routers on the path to a target host?

A

traceroute(nix)/tracert(win)

24
Q

What tool can be used to determine the relationships and real world links between people, groups, organizations, websites, infrastructure, ect.?

A

Maltego

25
Q

What search engine tool provides a full view of every server and device exposed to the internet?

A

Censys