官术网_书友最值得收藏!

  • Learn Penetration Testing
  • Rishalin Pillay
  • 225字
  • 2021-06-24 14:09:15

Performing Information Gathering

The skill of gathering information about your target is an essential skill that any penetration tester should have.

There is a big difference between passive and active information gathering. Passive information gathering leverages publicly available information. Active information gathering involves direct interaction with the target system. Active information gathering crosses the line when it comes to laws in specific countries, as some countries deem it illegal to perform any type of penetration test without permission—this is where your "get out of jail free card" (as discussed in Chapter 1, Introduction to Penetration Testing) comes in. It's important to have the right authorizations before you perform any active information gathering.

The information you gather about your target will be used to plan your attack. In this phase, you will look for anything that can expose information about your target. For example, are their public facing servers exposing known vulnerable ports? Are there any documents or information (such as social media posts) that contain sensitive information that's available on the internet? As you build your repository of information, you can begin threat modeling and search for vulnerabilities that can be used in your attack plan.

As you progress through this chapter, you will learn about the following topics:

  • Passive information gathering
  • Active information gathering
  • Vulnerability scanning
  • Known vulnerable services
  • Capturing traffic
主站蜘蛛池模板: 登封市| 祁阳县| 同德县| 保亭| 乃东县| 罗山县| 沁水县| 嘉鱼县| 临洮县| 济宁市| 凌海市| 石门县| 恩平市| 曲麻莱县| 阳信县| 吉木萨尔县| 阜康市| 金溪县| 泾阳县| 深州市| 太湖县| 昌宁县| 长宁区| 岳普湖县| 安义县| 昆明市| 泸水县| 万源市| 贞丰县| 柳州市| 壤塘县| 靖州| 贵德县| 崇左市| 郧西县| 宁阳县| 北安市| 英吉沙县| 江阴市| 忻州市| 长治县|