官术网_书友最值得收藏!

Open Source Intelligence

One of the key terms often associated with information gathering is Open Source Intelligence (OSINT). Military and intelligence organizations divide their intelligence sources into a variety of types. True espionage, involving interaction between spies, is often referred to as Human Intelligence (HUMINT). The capturing of radio signals with the intent of cracking the encryption is called Signals Intelligence (SIGINT). While the penetration tester is not likely to interface with either of these, the information gathering stage is OSINT. OSINT is information derived from sources that have no security controls preventing their disclosure. They are often public records or information that target organizations share as part of their daily operations.

For this information to be of use to the penetration tester, they need specific knowledge and tools to find this information. The information gathering stage relies heavily on this information. In addition, simply showing an organization what OSINT they are leaking may give them an idea of areas in which to increase security. As we will see in this chapter, there is a great deal of information that is visible to those who know where to look.

主站蜘蛛池模板: 灌南县| 图们市| 无为县| 额济纳旗| 山东省| 调兵山市| 栾城县| 文山县| 宁南县| 丹江口市| 临安市| 台湾省| 孝感市| 桓仁| 平江县| 乌拉特中旗| 商都县| 永善县| 周至县| 淮北市| 临高县| 山东| 三门峡市| 楚雄市| 荃湾区| 呼伦贝尔市| 泰来县| 东辽县| 栖霞市| 鹤山市| 丰都县| 巫溪县| 宣城市| 蒲城县| 临武县| 万安县| 金乡县| 沁阳市| 盱眙县| 宁河县| 弥渡县|