- Mastering Kali Linux for Advanced Penetration Testing
- Robert W. Beggs
- 214字
- 2021-07-16 11:33:22
Chapter 3. Active Reconnaissance and Vulnerability Scanning
The objective of the reconnaissance phase is to gather as much information about the target as possible in order to facilitate the exploitation phase of the kill chain.
We have seen how passive reconnaissance, which is almost undetectable, can yield a significant amount of information about the target organization and its users.
Active reconnaissance builds on the results of open-source intelligence and passive reconnaissance, and focuses on using probes to identify the path to the target and the exposed attack surface of the target. In general, complex systems have a greater attack surface, and each surface may be exploited and then leveraged to support additional attacks.
Although active reconnaissance produces more information, and more useful information, interactions with the target system may be logged, triggering alarms by protective devices, such as firewalls and intrusion detection systems. As the usefulness of the data to the attacker increases, so does the risk of detection; this is shown in the following diagram:

To improve the effectiveness of active reconnaissance in providing detailed information, our focus will be on using stealthy, or difficult to detect, techniques.
In this chapter, you will learn:
- Stealth scanning strategies
- Network infrastructure, host discovery, and enumeration
- Comprehensive reconnaissance applications, especially
recon-ng
- Targeted vulnerability scanning
- 計(jì)算機(jī)網(wǎng)絡(luò)安全技術(shù)(第6版·慕課版)
- 零信任網(wǎng)絡(luò):在不可信網(wǎng)絡(luò)中構(gòu)建安全系統(tǒng)
- 黑客攻防技巧
- 數(shù)據(jù)安全實(shí)踐指南
- Applied Network Security
- 物聯(lián)網(wǎng)安全滲透測(cè)試技術(shù)
- 信息安全導(dǎo)論(第2版)
- 先進(jìn)云安全研究與實(shí)踐
- 電腦安全與攻防入門很輕松(實(shí)戰(zhàn)超值版)
- 構(gòu)建新型網(wǎng)絡(luò)形態(tài)下的網(wǎng)絡(luò)空間安全體系
- 網(wǎng)絡(luò)空間安全:拒絕服務(wù)攻擊檢測(cè)與防御
- Web代碼安全漏洞深度剖析
- Practical Internet of Things Security
- Kali Linux無(wú)線網(wǎng)絡(luò)滲透測(cè)試詳解
- ATT&CK與威脅獵殺實(shí)戰(zhàn)