官术网_书友最值得收藏!

Open Source Intelligence and Passive Reconnaissance

"If something is not meant to be on the internet, probably it shouldn't be there in the first place."

Information gathering is the way to gather all the relevant information from publicly available sources, and is often referred as Open Source Intelligence (OSINT). Passive reconnaissance through OSINT occurs during the first step of the kill chain when conducting a penetration test or an attack against a network or server target. An attacker will typically dedicate up to 75% of the overall work effort for a penetration test to reconnaissance, as it is this phase that allows the target to be defined, mapped, and explored for the vulnerabilities that will eventually lead to exploitation.

There are two types of reconnaissance: passive reconnaissance (direct and indirect) and active reconnaissance.

Generally, passive reconnaissance is concerned with analyzing information that is openly available, usually from the target itself or public sources online. On accessing this information, the tester or attacker does not interact with the target in an unusual manner – requests and activities will not be logged, or will not be traced directly to the tester. Therefore, passive reconnaissance is conducted first to minimize the direct contact that may signal an impending attack or identify the attacker.

In this chapter, you will learn the principles and practices of passive reconnaissance, which include the following:

  • Basic principles of reconnaissance
  • OSINT
  • Online resources
  • Using scripts to automatically gather OSINT data
  • Obtaining user information
  • Profiling users for password lists
  • Using social media to extract words

Active reconnaissance, which involves direct interaction with the target, will be covered in Chapter 3, Active Reconnaissance of External and Internal Networks.

主站蜘蛛池模板: 青海省| 滕州市| 顺平县| 龙门县| 芦山县| 平潭县| 乌什县| 思茅市| 太仆寺旗| 堆龙德庆县| 噶尔县| 永善县| 通化县| 定远县| 中牟县| 上蔡县| 诸城市| 榆树市| 德惠市| 同江市| 景洪市| 婺源县| 克拉玛依市| 会理县| 荆州市| 静乐县| 神池县| 高要市| 高陵县| 镇巴县| 沂水县| 蒙山县| 韶关市| 衢州市| 根河市| 南川市| 吴旗县| 吉隆县| 乌鲁木齐市| 凌云县| 昆明市|