Footprinting and Reconnaissance Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/99

flashcard set

Earn XP

Description and Tags

100 vocabulary flashcards covering footprinting concepts, OSINT tools, Google hacking, Whois, DNS, website/email footprinting, and countermeasures.

Last updated 7:47 AM on 9/7/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

100 Terms

1
New cards

Footprinting

The first step in reconnaissance where an attacker collects as much information as possible to trace target activity on the Internet and gain knowledge of its overall security posture.

2
New cards

Passive Footprinting

Gathering information on a target using publicly available sources (OSINT) without directly engaging or interacting with the target.

3
New cards

Active Footprinting

Interacting directly with a target's systems using normal expected actions (such as DNS queries, traceroutes, or website spidering) to collect details while trying to avoid suspicion.

4
New cards

Value of Footprinting

Helps create a bird's eye view of the target, including physical facility vulnerabilities, high-level network maps, potential target areas to attack, and potential human targets.

5
New cards

General Company Information

Information sought during footprinting that includes company mission, products, services, activities, location, and contact information.

6
New cards

Internet Presence Information

Technical details sought during footprinting such as domain names, website content, online services offered, IP addresses, and network reachability.

7
New cards

Information Sources for Footprinting

Resources used to gather target data, including company websites, Whois, search engines, people searches, job boards, social networking, news articles, press releases, and OSINT tools.

8
New cards

Open Source Intelligence (OSINT)

The practice of using the Internet and publicly available sources to gather information on a target without direct engagement.

9
New cards

Eavesdropping

A subtle human-based information gathering technique used to collect names, job titles, or sensitive details by secretly listening to conversations.

10
New cards

Shoulder Surfing

A physical gathering technique where an attacker secretively observes a target's screen or keyboard to capture credentials or confidential information.

11
New cards

Dumpster Diving

Searching through a target's discarded trash or recycling for sensitive printed documents, hardware details, or organizational charts.

12
New cards

Website Change Alerts

Automated notifications sent via email or SMS (such as Google Alerts or Twitter Alerts) to notify a user when a monitored website's content is updated.

13
New cards

Target Analysis

Evaluating gathered footprinting data to determine IP addresses to scan, servers/services to vulnerability scan, IoT devices to compromise, and targets for phishing or social engineering.

14
New cards

OSINT Framework

A web-based cybersecurity framework and search engine that organizes links to publicly available sources for usernames, domain names, IP addresses, breach data, and more.

15
New cards

OSINT Framework URL

The official web address for accessing the OSINT Framework (https://osintframework.com/).

16
New cards

Spyse

A cyberspace search engine and online platform/API that combines multiple data gathering tools into a full-service platform for Internet asset discovery.

17
New cards

Maltego

An open-source intelligence and forensics application used to mine, gather, and visualize data and relationships between people, groups, infrastructure, and files.

18
New cards

Maltego COVID-19 Application

The deployment of Maltego during the COVID-19 crisis to study virus spread scientifically and trace tourist/visitor movements from coronavirus hotspots.

19
New cards

Shodan.io

A search engine for Internet-connected devices that helps locate exposed routers, baby monitors, security cameras, satellites, water treatment systems, and power plants.

20
New cards

Censys.io

An online platform similar to Shodan that continually discovers Internet-facing assets and IoT devices, featuring a cloud-based dashboard.

21
New cards

theHarvester

A Python-based OSINT tool designed to collect emails, subdomains, hosts, employee names, open ports, and banners from search engines, PGP key servers, and SHODAN.

22
New cards

Sublist3r

A Python tool created by Ahmed Aboul-Ela (@aboul3la) that uses OSINT and multiple search engines to enumerate website subdomains and perform port scanning.

23
New cards

Subdomain Targeting Advantage

Why attackers target subdomains: they are often managed by smaller child organizations, have fewer security controls/resources, and are less secure than the parent domain.

24
New cards

Recon-ng

A full-featured web reconnaissance framework written in Python containing modular functions for OSINT, requiring target API keys for full functionality.

25
New cards

InSpy

A Python tool installed in Kali Linux (apt install inspy) used to perform job title and technology searches against LinkedIn profiles.

26
New cards

InSpy --empspy Option

A flag used with InSpy to search LinkedIn for company employees matching a specified wordlist of job titles.

27
New cards

InSpy --techspy Option

A flag used with InSpy to search Google for specific technologies used at a target organization using a list of technology terms.

28
New cards

Android InSpy

A mobile application used to track a target user's Instagram likes and comments.

29
New cards

SpiderFoot

A Python-based OSINT automation tool used for target monitoring and intelligence gathering, which also offers a cloud-hosted version named SpiderFoot HX.

30
New cards

SpiderFoot HX

The cloud-hosted version of SpiderFoot providing subscription-level target monitoring and OSINT automation.

31
New cards

OSRFramework

A set of libraries and applications for performing OSINT tasks such as username checking, DNS lookups, information leaks research, and deep web searching.

32
New cards

OSRFramework Creators

OSRFramework version 0.18.8 was created by Felix Brezo and Yaiza Rubio (i3visio).

33
New cards

Document Metadata Harvesting

The process of extracting hidden information (such as author names, software versions, and printer paths) from PDF and Office files to use in social engineering.

34
New cards

Metagoofil

A metadata extraction tool that uses Google hacks to locate public document files (pdf, doc, xls, ppt, docx, pptx, xlsx) belonging to a target and extract user and server details.

35
New cards

Christian Martorella

The creator of Metagoofil (Edge-Security.com).

36
New cards

FOCA

A tool used to extract metadata and hidden information from analyzed documents, revealing network paths, printers, servers, usernames, and operating systems.

37
New cards

Google Hacking / Dorking

The practice of using specialized Google search strings and advanced search operators to uncover sensitive data, hidden portals, log files, and vulnerabilities.

38
New cards

Google Guide

An online interactive tutorial and reference site (https://www.googleguide.com/category/overview/index.html) providing guidance on advanced Google search techniques.

39
New cards

Operator intitle:

A Google search operator used to restrict results to pages containing specific string text within their title tag (e.g., intitle:"Your Text").

40
New cards

Operator allintext:

A Google search operator that forces all specified terms to appear in the body text of returned search pages (e.g., allintext:"Contact").

41
New cards

Operator inurl:

A Google search operator that restricts results to URLs containing specified text strings (e.g., inurl:"news.php?id=").

42
New cards

Operator site:

A Google search operator that limits search results to a specific domain name or website (e.g., site:yeahhub.com "Keyword").

43
New cards

Operator filetype:

A Google search operator used to search for specific file extensions such as PDF, DOC, or MP3 (e.g., filetype:pdf "Cryptography").

44
New cards

Operator link:

A Google search operator that finds web pages linking back to a specified URL or domain (e.g., link:"example.com").

45
New cards

Operator cache:

A Google search operator that displays Google's cached version of a webpage (e.g., cache:yeahhub.com).

46
New cards

Operator info:

A Google search operator that displays summary information regarding a specific web page (e.g., info:www.example.com).

47
New cards

Operator OR

A Google boolean operator that instructs the search engine to match at least one of the specified keywords.

48
New cards

Operator AND

A Google boolean operator that requires all specified keywords to be present in the search results.

49
New cards

Operator Quotation Marks ("")

Google search operator syntax used to search for an exact phrase match of the enclosed words.

50
New cards

Operator Minus Sign (-)

A Google search operator placed directly before a keyword or operator to exclude it from search results (e.g., Linux -site:Wikipedia.org).

51
New cards

Operator Asterisk (*)

A Google search operator that serves as a wildcard representing one or more missing words in a phrase.

52
New cards

Operator Parentheses ()

Google search operators used to group keywords and boolean operators together (e.g., "google (dorks OR dorking)").

53
New cards

Live Camera Feed Dork

A specific Google dork search string such as intitle:"Live View / - AXIS" | inurl:/mjpg/video.mjpg?timestamp used to discover live network cameras.

54
New cards

Excel Email List Dork

The Google search query filetype:xls inurl:"email.xls" used to locate spreadsheets containing email addresses.

55
New cards

Password Log File Dork

The Google search string filetype:log intext:password intext:(@gmail.com | @yahoo.com | @hotmail.com) used to discover leaked credential log files.

56
New cards

Open FTP Server Dork

The Google search syntax intext:"index of" inurl:ftp used to locate accessible FTP servers with directory listings.

57
New cards

SQL Injection Vulnerability Dork

The Google dork string inurl:".php?id=" intext:(error AND sql) used to find PHP pages exposing SQL database errors.

58
New cards

Scanner Report Dork

The Google search string intitle:report (nessus | qualys) filetype:pdf used to discover exposed vulnerability scan PDF files.

59
New cards

SQL Database Dump Dork

The Google dork string intitle:"index of" "dump.sql" used to locate public directories containing SQL database backups.

60
New cards

Google Hacking Database (GHDB)

A publicly accessible repository hosted on Exploit Database (https://www.exploit-db.com/google-hacking-database/) containing community-submitted Google dorks.

61
New cards

ICANN

The Internet Corporation for Assigned Names and Numbers, a non-profit corporation that keeps the Internet secure and stable by managing DNS names and Autonomous System numbers.

62
New cards

IANA

The Internet Assigned Numbers Authority, a department within ICANN responsible for maintaining central Internet standards and distributing Internet numbers to regional registries.

63
New cards

IETF

The Internet Engineering Task Force, an open standards organization that develops and promotes voluntary Internet standards, particularly those related to IP.

64
New cards

Autonomous System (AS) Number

A unique identifying numerical value assigned to every major network that forms part of the global Internet routing infrastructure.

65
New cards

Regional Internet Registries (RIRs)

Governing bodies responsible for controlling and allocating IP addresses and domain registration records within specific operating regions.

66
New cards

ARIN

The Regional Internet Registry serving the United States, Canada, Antarctica, and parts of the Caribbean region.

67
New cards

APNIC

The Regional Internet Registry serving Asia, Australia, New Zealand, and surrounding regions.

68
New cards

AfriNIC

The Regional Internet Registry serving Africa and the Indian Ocean region.

69
New cards

RIPE NCC

The Regional Internet Registry serving Europe, Russia, Central Asia, and the Middle East.

70
New cards

LACNIC

The Regional Internet Registry serving Latin America and parts of the Caribbean region.

71
New cards

Whois Protocol

A widely-used query and response protocol used to search databases for registered users, assignees, domain names, IP blocks, and AS numbers.

72
New cards

Domain Registrar

An ICANN-accredited company certified to sell domain names to the public and manage records for their resellers.

73
New cards

Domain Registry

An organization responsible for maintaining the master database records for a specific top-level domain (TLD) such as .com or .org.

74
New cards

Whois Query Details

Information returned by a Whois lookup, including domain owner contact info, DNS servers, network blocks, AS numbers, creation date, and expiration date.

75
New cards

DNS Record A

A DNS record type that maps a domain or hostname to an IPv4 host address.

76
New cards

DNS Record AAAA

A DNS record type that maps a domain or hostname to an IPv6 host address.

77
New cards

DNS Record MX

A DNS record type that specifies the mail server responsible for receiving email on behalf of a domain.

78
New cards

DNS Record NS

A DNS record type that identifies the authoritative name servers for a domain.

79
New cards

DNS Record CNAME

A Canonical Name record in DNS that acts as an alias mapping one domain name to another domain name.

80
New cards

DNS Record SOA

Start of Authority record in DNS that indicates authoritative information about a domain zone, including primary name server and administrative contact.

81
New cards

DNS Record SRV

Service record in DNS that defines the location (hostname and port number) of servers for specific services.

82
New cards

DNS Record PTR

Pointer record in DNS used for reverse lookups to map an IP address to a hostname.

83
New cards

DNS Record RP

Responsible Person record in DNS that specifies the contact email/person responsible for a domain host.

84
New cards

DNS Record HINFO

Host Information record in DNS that specifies the CPU type and operating system of a host.

85
New cards

DNS Record TXT

An unstructured text record in DNS used to hold arbitrary human or machine-readable text for validation and security policies.

86
New cards

Nslookup

A command-line administration tool available on most OS platforms used to query DNS servers for domain name or IP address mapping records.

87
New cards

dig

Domain Information Groper, a flexible command-line tool used to query DNS name servers for detailed record information.

88
New cards

dig axfr Command

A specific dig command query syntax used to request a full DNS zone transfer from a target name server (e.g., dig axfr zonetransfer.me @nsztm1.digi.ninja.).

89
New cards

Physical Reconnaissance Tools

Mapping and satellite tools (such as Google Maps, Google Earth, Wikimapia, and Bing Maps) used to inspect a target's physical facility and grounds remotely.

90
New cards

Web Spiders

Automated tools (such as SpiderFoot, Scrapy, or Screaming Frog) that crawl target websites to gather emails, employee names, titles, phone numbers, and meta tags.

91
New cards

DIRB

A command-line web content scanner that launches dictionary-based attacks against web servers to locate existing and hidden subdirectories.

92
New cards

DirBuster

An OWASP GUI-based Java application used to brute-force directories and file names on web application servers using custom wordlists.

93
New cards

Website Mirroring

Downloading an exact copy of a target website to a local drive (using tools like HTTrack or Wget) to analyze files offline without triggering live intrusion alarms.

94
New cards

HTTrack Web Site Copier

An offline browser utility that allows users to download a website from the Internet to a local directory for offline analysis.

95
New cards

Archive.org / Wayback Machine

A non-profit digital library offering access to billions of archived snapshots of web pages over time, allowing attackers to view deleted website content.

96
New cards

Website Update Monitoring Tools

Software utilities (such as Website Watcher or Visual Ping) that monitor target web pages for content changes and automatically alert users via email or SMS.

97
New cards

Email Source Header

Raw email header text containing sender address details, originating IP, mail server path, timestamp, and authentication details to verify message origin.

98
New cards

Email Tracking Tools

Software services (such as EmailTrackerPro, PoliteMail, or Yesware) used to capture recipient IP addresses, geolocation, read times, device types, and proxy status.

99
New cards

Network Range Mapping

Identifying a target organization's IP address range and network boundaries by querying RIR databases or online services like CentralOps and NetworksDB.io.

100
New cards

Traceroute

A network diagnostic tool that sends ICMP or UDP packets with increasing TTL values to identify routers, firewalls, and path hops leading to a target host.