Open Source Intelligence
One of the key terms often associated with Information Gathering is Open Source Intelligence (OSINT). Military and intelligence organizations divide their intelligence sources into a variety of types. True espionage, involving interaction between spies, is often referred to as Human Intelligence (HUMINT). The capturing of radio signals with the intent of cracking the encryption is called Signals Intelligence (SIGINT). While the penetration tester is not likely to interface with either of these, the information gathering stage is OSINT. OSINT is information derived from sources that have no security controls preventing their disclosure. They are often public records or information that target organizations share as part of their daily operations.
For this information to be of use to the penetration tester, they need specific knowledge and tools to find this information. The Information Gathering stage relies heavily on this information. In addition, simply showing an organization what OSINT they are leaking may give them an idea of areas in which to increase security. As we will see in this chapter, there is a great deal of information that is visible to those who know where to look.
- Git高手之路
- 程序員考試案例梳理、真題透解與強化訓練
- INSTANT CakePHP Starter
- Python程序設計與算法基礎教程(第2版)(微課版)
- Koa與Node.js開發實戰
- Spring Web Services 2 Cookbook
- JavaScript Unit Testing
- Apache Kafka 1.0 Cookbook
- MySQL從入門到精通
- Swift 2 Blueprints
- MonoTouch應用開發實踐指南:使用C#和.NET開發iOS應用
- Unity與C++網絡游戲開發實戰:基于VR、AI與分布式架構
- Python程序設計
- R High Performance Programming
- Scratch編程入門與算法進階(第2版)