CPT 03 Recon
CPT 03 Recon
Reconnaissance
NetsBook
Penetration Testing
Reconnaissance
● Footprinting
● Scanning
● Enumerating
Active Footprinting
Passive Footprinting
Pseudonymous Footprinting
➢ Collect information from the sources that have been published on the
internet but is not directly linked to the author’s name.The information may be
published under a different name / pen name
Internet Footprinting
➢ Company policy may forbid access to certain web sites, but some
employees try creative techniques to view them anyway.
➢ Use trial and error method or Use any service which can fetch
information from web sites (www.netcraft.com)
NetsBook
Footprinting Methodology
❏ dnsmap certifiedhacker.com
❏ https://searchdns.netcraft.com
NetsBook
Footprinting Methodology
❏ urlcrazy -p microsoft.com
❏ Google Earth
❏ Google MAP
❏ Bing MAP
NetsBook
Footprinting Methodology
People Search Online Services
❏ https://www.privateeye.com
❏ https://www.peoplesearchnow.com
NetsBook
Footprinting Methodology
Gather Information through Financial Services
❏ www.google.com/finance
❏ www.finance.yahoo.com
NetsBook
Footprinting Methodology
Footprinting through Job Sites
❏ www.linkedin.com
❏ www.naukri.com
❏ https://www.google.com/alerts
NetsBook
Footprinting Methodology
NetsBook
Footprinting Methodology
NetsBook
Footprinting Methodology
Information Gathering through Groups, Forums and Blogs
NetsBook
Footprinting Methodology
Information Gathering through Groups, Forums and Blogs
NetsBook
Footprinting Methodology
Web Search Using Basic Operators
OR logical OR
NetsBook
Footprinting Methodology
Web Search Using Advanced Operators
https://www.google.com/advanced_search
NetsBook
Footprinting Methodology
Web Search Using Advanced Operators
https://www.google.com/advanced_search
NetsBook
Footprinting Methodology
Web Search Using Advanced Operators
❏ site:microsoft.com filetype:pdf
❏ related:pdfdrive.com
❏ cache:pdfdrive.com
❏ link:www.linkedin.com
❏ allintext:books download
❏ intext:books
❏ allintitle:books download
NetsBook
Footprinting Methodology
Google hacking or Google dorking
Examples:-
NetsBook
Footprinting Methodology
Shodan
❏ Shodan is a search engine lets the user find specific types of devices
(webcams, routers, servers, etc.) connected to the internet using a
variety of filters.
Website footprinting
❏ https://www.netcraft.com
NetsBook
Footprinting Methodology
Web Spiders or Web Crawlers
❏ A Web crawler or spider, systematically browses the web sites, for Web
indexing and extract details.
NetsBook
Example http://www.webinvestigatorservice.com/investigate/
Footprinting Methodology
www.Archive.org/web
https://builtwith.com
NetsBook
Footprinting Methodology
Email Header
NetsBook
Footprinting Methodology
❏ Yesware(http://mm.yesware. corn)
❏ DidTheyReadlt(http://www.didtheyreadit. corn)
❏ WhoReadN1 e (http://whoreadme.com)
NetsBook
Footprinting Methodology
Competitive Intelligence
❏ Official websites
❏ Job Advertisements
❏ Press release
❏ Annual reports
❏ Product catalogs
❏ Analysis report
❏ Regulatory report
NetsBook
Footprinting Methodology
Competitive Intelligence
❏ EDGAR https://www.sec.gov/edgar.shtml
❏ Business Wire https://www.businesswire.com/portal/site/home
NetsBook
Footprinting Methodology
❏ Monitis https://www.monitis.com
❏ Web-start https://www.web-stat.com
❏ Alexa https://www.alexa.com
Rankur https://rankur.com
Social mention http://www.socialmention.com
NetsBook
Footprinting Methodology
WHOIS Footprinting
https://www.whois.com
https://whois.domaintools.com
smartwhois tool
NetsBook
Footprinting Methodology
WHOIS Footprinting
# whois evil.com
❏ http://wq.apnic.net/static/search.html
❏ https://www.ultratools.com/tools/ipWhoisLookup
# nslookup
# set type=ns
# microsoft.com
NetsBook
Footprinting Methodology
DNS Footprinting
❏ https://tools.dnsstuff.com
❏ https://centralops.net/co/DomainDossier.aspx
❏ https://network-tools.com
# dnsrecon -d www.evil.com
# dnsenum --enum evil.com
# dig google.com -t soa
# whois google.com
NetsBook
Footprinting Methodology
DNS Footprinting
❏ https://www.ultratools.com/tools/dnsLookup
❏ https://www.yougetsignal.com/tools/web-sites-on-web-server/
# dig ns certifiedhacker.com
# dig @ns1.bluehost.com certifiedhacker.com axfr
# nslookup -type=any certifiedhacker.com
# dnsrecon -t axfr -d certifiedhacker.com
NetsBook
Footprinting Methodology
Network footprinting
❏ Ping
❏ Traceroute / tracert
❏ Nslookup
❏ Visualroute
NetsBook
Social Engineering (SE)
NetsBook
Footprinting Methodology
NetsBook
Social Engineering (SE)
Common target of SE pen Test
NetsBook
Social Engineering (SE)
SE Penetration Testing Steps
NetsBook
Footprinting Methodology
❏ Recon-ng
❏ FOCA
NetsBook