CEHv13-Module 02 Footprinting and Reconnaissance

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/96

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:53 PM on 3/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

97 Terms

1
New cards

Reconnaissance

The preparatory phase where an attacker gathers as much information as possible about a target

2
New cards

Footprinting

The process of collection information about a target network and its environment

3
New cards

Blueprint

The unique system profile of the target organization acquired by footprinting

4
New cards

Passive Footprinting

Gathering information about a target without direct interaction

5
New cards

Active Footprinting

Gathering information about a target with direct interaction

6
New cards

Information Obtained During Footprinting

1. Organizational Information

2. Network Information

3. System Information

7
New cards

Threats Made Possible Through Footprinting

1. Social Engineering

2. System and Network Attacks

3. Information Leakage

4. Privacy Loss

5. Corporate Espionage

6. Business Loss

8
New cards

Footprinting Methodolgy

A procedure for collection information about a target from all available sources

9
New cards

Types of Passive Footprinting

1. Through Search Engines

2. Through Internet Research Services

3. Through Social Networking Sites

4. Whois Footprinting

10
New cards

Types of Active Footprinting

1. DNS

2. Network and Email

3. Social Engineering

4. Footprinting Tasks Using Advnaced Tools and AI

11
New cards

Google Hacking

Refers to using advanced Google Search Operators for creating complex search queries to extract sensitive or hidden information

12
New cards

Google Hacking/Dork Operators

1. site

2. allinurl, inurl

3. allinanchor, inanchor

4. intext

5. allintitle, intitle

6. cache

7. link

8. related

9. info

10. location

11. filetype

12. source

13. before, after

13
New cards

Google Hacking Database (GHDB)

A subset of exploit-db that focuses on using Google Hacking Techniques

14
New cards

Google Hacking Database (GHDB) Categories

1. Footholds

2. Files Containing Usernames

3. Sensitive Directories

4. Web Server Detection

5.Vulnerable Files

6. Vulnerable Servers

7. Error Message

8. Files Containing Juicy Info

9. Files Containing Passwords

10. Sensitive Online Shopping Info

11. Network or Vulnerability Data

12. Pages Containing Login Portals

13. Various Online Devices

14. Advisories and Vulnerabilities

15
New cards

Shodan

A search engine used to detect devices and networks

16
New cards

Reverse Image Search

Allows you to use a photograph as the query

17
New cards

Meta Search Engine

Uses other search engines to produce their own results

18
New cards

File Transfer Protocol (FTP) Search Engine

Searches for files on an FTP Server

19
New cards

Internet of Things (IoT) Serach Engine

Crawls internet for publicly accessible IoT devices

20
New cards

Methods of Footprinting Using Search Engines

1. Google Hacking

2. Google Advanced Search, Image Search, and Reverse Image Search

3. Shodan

4. Video Search Engines

5. Meta Search Engines

6. File Transfer Protocol (FTP) Search Engines

7. Internet of Things (IoT) Search Engines

21
New cards

DNSdumpster

Domain research tool that can be used by attackers to discover hosts related to a domain

22
New cards

Pentest-Tools Find Subdomains

An online tool used for discovering subdomains and their IP addresses

23
New cards

Tools for Finding Subdomains

1. Netcraft

2. DNSdumpster

3. Pentest-Tools Find Subdomains

24
New cards

Wayback Machine

Allows target to get information removed from target's website

25
New cards

Photon

Attackers can use Photon to retrieve archived URLs of the target website from Wayback Machine

26
New cards

Spokeo

Attackers can use Spokeo to search for people belonging to the target organization

27
New cards

Tor Browser

Acts as a browser that allows users to connect to the dark web

28
New cards

Netcraft

Identifies sites associated with the target and finds the OS running on each site

29
New cards

Competitive Intelligence Gathering

Process of identifying, gathering, analyzing, verifying, and using information about your competitors

30
New cards

Indirect Competitive Intelligence Gathering

Involves gathering information from online resources

31
New cards

Electronic Data Gathering Analysis and Retrieval System (EDGAR) Database

Performs automated collection, validation, indexing, acceptance, and forwarding of submissions by companies and others who are required by law to file with the U.S. Security Exchange Commission (SEC)

32
New cards

D&B Hoovers

Leverages a commercial database of 120 million business records and analytics to deliver an intelligence solution that enables sales and marketing professionals to focus on the right prospects

33
New cards

LexisNexis

Provides content-enabled workflow solutions designed specifically for professionals in the legal, risk management, corporate, government, law enforcement, accounting, and academic markets

34
New cards

Business Wire

Focus on press release distribution and regulatory disclosure

35
New cards

Factiva

A global news database and licensed content provider

36
New cards

MarketWatch

Track the pulse of markets for engaged investors

37
New cards

Wall Street Transcript

A website as well as a paid subscription-based publication that publishes industry reports

38
New cards

Euromonitor

Provides strategy resource capabilities for consumer markets. It publishes reports on industries, consumers, and demographics

39
New cards

Experian

Provides insight on competitor's search, affiliate, display, and social marketing strategies

40
New cards

The Search Monitor

Provides competitive intelligence to monitor brand and trademark use, affiliate compliance, and competitive advertisers on paid search, organic search, local search, social media, mobile, and shopping engines worldwide

41
New cards

United States Patent and Trademark Office (USPTO)

Provides Information about Patent and Trademarks

42
New cards

SEMrush

A competitive keyword research tool

43
New cards

ABI/INFORM Global

Offers the latest business and financial information for researchers

44
New cards

SimilarWeb

Aggregates data from multiple sources to estimate traffic, geography, and referral data for a company's websites and mobile apps. It also provides a panel through a browser extension that allows refining other data sources by anonymously tracking browser activity across millions of browsers worldwide.

45
New cards

SERanking

An online competitor analysis tool that provides a complete view of the target organization's website traffic dynamics

46
New cards

Social Networking Sites

Online services, platforms, or sites that focus on facilitating the building of social networks or social relations among people

47
New cards

LinkedIn

A social networking site for professionals

48
New cards

theHarvester

A tool used for OSINT gathering that performs enumeration on websites

49
New cards

BuzzSumo

Finds most shared topics content for a topic, author, or domain

50
New cards

Sherlock

Used to search social media sites for a username

51
New cards

Social Searcher

Allows attacker to search for content on social media in real time and provides analytics data

52
New cards

Whois

A query and response protocol used for querying databases that store the registered users or assignees of an internet resource

53
New cards

Whois Port

Port 43 (TCP)

54
New cards

Thick Whois (Distributed Model)

Stores complete WHOIS information from all the registrars for a particular set of data

55
New cards

Thin Whois (Centralized Model)

Stores only the name of the Whois server of the registrar of the domain, which in turn holds complete details of the data being looked

56
New cards

Decentralized Whois

Stores complete Whois information and has multiple independent entities to manage the Whois database

57
New cards

IP2Location

Used to identify a visitor's geographic location

58
New cards

DNS A Record

Points to an IP address

59
New cards

DNS AAAA Record

Points to an IPv6 address

60
New cards

DNS MX Record

Points to the domain's mail server

61
New cards

DNS NS Record

Points to the host's name server

62
New cards

DNS CNAME Record

Canonical naming allows aliases to host

63
New cards

DNS SOA Record

Indicates authority for a domain

64
New cards

DNS SRV Record

Service record

65
New cards

DNS PTR Record

Maps IP address to hostname

66
New cards

DNS RP Record

Responsible person

67
New cards

DNS HINFO Record

Host information record

68
New cards

DNS TXT Record

Unstructured text record

69
New cards

SecurityTrails

An advanced DNS enumeration tool capable of creating a DNS map of the target domain network. It can enumerate current or past records. It also enumerates subdomains.

70
New cards

Fierce

A DNS tool used for scanning and collecting crucial information about the target domain. Can enumerate subdomains and non-contiguous IP addresses

71
New cards

DNS Lookup

Used to find the IP address for a hostname

72
New cards

Reverse DNS Lookup

Used to find the hostname for a given IP address

73
New cards

DNSRecon

Used to perform a reverse DNS lookup

74
New cards

Reverse Lookup

Used to perform a reverse DNS lookup

75
New cards

ARIN Website

A networking footprinting tool that allows you to find the target network range of a target

76
New cards

Traceroute Utility

A networking footprinting tool that traces the path or route through which the target host packets travel in the network

77
New cards

Layer 4 Traceroute

Many devices block ICMP Traceroute so attackers can use TCP or UDP Traceroute instead

78
New cards

PingPlotter

A networking footprinting Traceroute tool

79
New cards

NetScanTools Pro

A networking footprinting Traceroute tool

80
New cards

eMailTrackerPro

An email footprinting tool that analyzes email headers and allows the attacker to save past traces

81
New cards

IP2LOCATION's Email Header Tracer

An email footprinting tool that allows attackers to analyze and trace email paths using email headers

82
New cards

Social Engineering

The art of exploiting human behavior to extract confidential information

83
New cards

Eavesdropping

A social engineering attack that involves intercepting communication without the consent of the communicating parties

84
New cards

Shoulder Surfing

A social engineering attack that involves standing behind the victim to observe the victim's computer activities

85
New cards

Dumpster Diving

A social engineering attack that involves rummaging for information in garbage bins

86
New cards

Impersonation

A social engineering attacker where attacker pretends to be a legitimate or authorized person

87
New cards

Maltego

An automated footprinting tool that can be used to determine the relationships between real word links between people, groups, organizations, websites, and internet infrastructure

88
New cards

Recon-ng

A web reconnaissance framework with independent modules for database interaction that provides an environment which open-source web-based reconnaissance can be conducted

89
New cards

Fingerprinting Organizations with Collected Archives (FOCA)

A footprinting tool mainly used to find metadata and hidden information in documents

90
New cards

Subfinder

A footprinting subdomain discovery tool that helps attackers find valid subdomains for websites using passive online sources

91
New cards

OSINT Framework

An open source intelligence gathering framework that helps in performing automated footprinting and reconnaissance

92
New cards

Recon-Dog

A footprinting tool that uses APIs to collect information from the target system

93
New cards

BillChipher

A footprinting tool for websites or IP addresses

94
New cards

Use Cases of AI in OSINT

1. Web Scraping

2. Pattern Recognition

3. Content Summarization

4. Sentiment Analysis

5. Image Recognition: Face Recognition, Metadata Analysis, Reverse Image Search

6. AI Detection

95
New cards

Taranis AI

An AI-powered OSINT tool

96
New cards

OSS Insight

An AI-powered OSINT Tool for GitHub

97
New cards

Still learning (14)

You've begun learning these terms. Keep up the good work!