Presentation is loading. Please wait.

Presentation is loading. Please wait.

Reconnaissance Steps. EC-Council Gathering information from Open Sources  Owner of IP-address range  Address Range  Domain Names  Computing Platforms.

Similar presentations


Presentation on theme: "Reconnaissance Steps. EC-Council Gathering information from Open Sources  Owner of IP-address range  Address Range  Domain Names  Computing Platforms."— Presentation transcript:

1 Reconnaissance Steps

2 EC-Council Gathering information from Open Sources  Owner of IP-address range  Address Range  Domain Names  Computing Platforms  Network Architecture  User(name) Information  Physical Location  Active Services

3 EC-Council Gathering information from Open Sources  Technical Contact  Business Partners  Administrative Contacts  Email Addresses  Technology being used  Phone No's  Route to target's  Internet Accessible data

4 EC-Council Gathering information from Open Sources  Public Server's Banner Information.  DNS Servers  WEB Servers  SMTP Servers  Zones & Sub-domains  Locate Firewalls/Perimeter devices.

5 EC-Council Target's Website  Mirror the web  Use Grep or Similar  Scan for keywords  Banner Information  Applications  Cgi's  Cookie style  Scripting language  Code-reading  Weblogs info

6 EC-Council DNS  AXFR  Version  Zones & Sub-domains  Nmap -sL  DNSDig  Nslookup  Dig commands  Host commands  Active services

7 EC-Council SMTP  Verfy; email enumeration  Banner information  Bounced Emails  Email Header  Email mapping

8 EC-Council Search Engines (Google)  intitle: "index of /etc"  inurl: "config.php.bak"  site:"target.com"  filetype:".bak"  Cross-Links  Search for group postings  News Articles

9 EC-Council Traceroute  ISP information  Locate Firewalls  Network Infrastructure  Tcptraceroute  Firewalk

10 EC-Council Job Databases  Job requirements  Employee profile  Hardware information  Software information

11 EC-Council Personal Website  Employee job profile  Hardware information  Software information

12 EC-Council Ping  List of live systems  RTT, delays  N/W connectivity


Download ppt "Reconnaissance Steps. EC-Council Gathering information from Open Sources  Owner of IP-address range  Address Range  Domain Names  Computing Platforms."

Similar presentations


Ads by Google