官术网_书友最值得收藏!

Reconnaissance

A huge portion of your penetration testing time will be spent in this first critical part of the test. While some break down this phase into active and passive, I prefer to clump them together as the data acquired would speak for itself.

Reconnaissance is the systematic approach where you attempt to locate and gather as much information on your target, this is otherwise known as foot-printing.

The techniques involved in foot-printing include but are not limited to the following:

  • Social engineering (this is great fun)
  • Internet research (Google, Bing, LinkedIn, and so on)
  • Dumpster-diving (getting your hands dirty)
  • Cold-calling

It's basically any way you can acquire any information on your target, so be creative. So, what are we looking for?

Well, every bit of info is useful, but it needs to be prioritized and keep in mind that something that you may not find useful at first just might come in handy somewhere else. But for starters the important things would be the following:

  • Contact names within the organization
  • Other locations of the organization (if any)
  • Email addresses (which we could later used for phishing, whaling, or spear-phishing)
  • Phone numbers of important figures within the company (these can be used for phishing)
  • Systems used within the company such as Windows or Linux
  • Job postings
  • Employee CVs (past/present)

While all of this might be self-explanatory, job postings seems a bit strange; however, let's say you come across one for a system admin, and based on the requirements that they are asking for the position it would provide, you with a lot of information about their internal systems. This can then be used to come up with attack vectors or to find exploits.

Employee CVs work in a similar manner; by knowing what their employees' skill sets are, you can determine what kind of systems they may or may not be running.

While this might seem tedious, keep in mind that the more information you have, the more capable you would be when making decisions later. I personally find myself coming back to this phase throughout the engagement. ?

主站蜘蛛池模板: 卢湾区| 太谷县| 安龙县| 河南省| 永顺县| 天柱县| 宁明县| 高碑店市| 小金县| 霍林郭勒市| 苏尼特左旗| 前郭尔| 马龙县| 大余县| 淄博市| 阳朔县| 珲春市| 承德县| 沙洋县| 高平市| 色达县| 集贤县| 永川市| 惠水县| 福泉市| 临汾市| 吴堡县| 许昌县| 淳化县| 宜州市| 大渡口区| 禹城市| 容城县| 鸡西市| 兴安盟| 监利县| 皋兰县| 紫云| 万安县| 乐亭县| 株洲市|