Showing posts with label Footprinting. Show all posts
Showing posts with label Footprinting. Show all posts
Footprinting - Attack Methods
0
comments
vic
-
Attack Methods
The attacker may choose to source the information from:
* A web page (save it offline, e.g. using offline browser such as Teleport pro
* Yahoo or other directories. (Tifny is a comprehensive search tool for USENET newsgroups.
* Multiple search engines (All-in-One, Dogpile), groups.google.com is a great resource for searching large numbers of news group archives without having to use a tool.
* Using advanced search (e.g. AltaVista),
* Search on publicly trade companies (e.g. EDGAR).
* Dumpster diving (To retrieve documents that have been carelessly disposed)
* Physical access (False ID, temporary/contract employees, unauthorized access etc)
There are four RIRs, each maintaining a whois database holding details of IP address registrations in their regions. The RIR whois databases are located at:
*
ARIN (North America and sub-Saharan Africa)
*
APNIC (Asia Pacific region)
*
LACNIC (Southern and Central America and Caribbean)
*
RIPE NCC (Europe and northern Africa)
Tools
There are tools available to aid a whois lookup. Some of them are Sam Spade (downloadable from www.samspade.org). Smart Whois (downloadable fromwww.tamos.com). Netscan (downloadable from www.netscantools.com) and GTWhois (Windows XP compatible) (www.geektools.com) etc.
The attacker may choose to source the information from:
* A web page (save it offline, e.g. using offline browser such as Teleport pro
* Yahoo or other directories. (Tifny is a comprehensive search tool for USENET newsgroups.
* Multiple search engines (All-in-One, Dogpile), groups.google.com is a great resource for searching large numbers of news group archives without having to use a tool.
* Using advanced search (e.g. AltaVista),
* Search on publicly trade companies (e.g. EDGAR).
* Dumpster diving (To retrieve documents that have been carelessly disposed)
* Physical access (False ID, temporary/contract employees, unauthorized access etc)
There are four RIRs, each maintaining a whois database holding details of IP address registrations in their regions. The RIR whois databases are located at:
*
ARIN (North America and sub-Saharan Africa)
*
APNIC (Asia Pacific region)
*
LACNIC (Southern and Central America and Caribbean)
*
RIPE NCC (Europe and northern Africa)
Tools
There are tools available to aid a whois lookup. Some of them are Sam Spade (downloadable from www.samspade.org). Smart Whois (downloadable fromwww.tamos.com). Netscan (downloadable from www.netscantools.com) and GTWhois (Windows XP compatible) (www.geektools.com) etc.
Footprinting - Attack Methods
Attack Methods
The attacker may choose to source the information from:
* A web page (save it offline, e.g. using offline browser such as Teleport pro
* Yahoo or other directories. (Tifny is a comprehensive search tool for USENET newsgroups.
* Multiple search engines (All-in-One, Dogpile), groups.google.com is a great resource for searching large numbers of news group archives without having to use a tool.
* Using advanced search (e.g. AltaVista),
* Search on publicly trade companies (e.g. EDGAR).
* Dumpster diving (To retrieve documents that have been carelessly disposed)
* Physical access (False ID, temporary/contract employees, unauthorized access etc)
There are four RIRs, each maintaining a whois database holding details of IP address registrations in their regions. The RIR whois databases are located at:
*
ARIN (North America and sub-Saharan Africa)
*
APNIC (Asia Pacific region)
*
LACNIC (Southern and Central America and Caribbean)
*
RIPE NCC (Europe and northern Africa)
Tools
There are tools available to aid a whois lookup. Some of them are Sam Spade (downloadable from www.samspade.org). Smart Whois (downloadable fromwww.tamos.com). Netscan (downloadable from www.netscantools.com) and GTWhois (Windows XP compatible) (www.geektools.com) etc.
The attacker may choose to source the information from:
* A web page (save it offline, e.g. using offline browser such as Teleport pro
* Yahoo or other directories. (Tifny is a comprehensive search tool for USENET newsgroups.
* Multiple search engines (All-in-One, Dogpile), groups.google.com is a great resource for searching large numbers of news group archives without having to use a tool.
* Using advanced search (e.g. AltaVista),
* Search on publicly trade companies (e.g. EDGAR).
* Dumpster diving (To retrieve documents that have been carelessly disposed)
* Physical access (False ID, temporary/contract employees, unauthorized access etc)
There are four RIRs, each maintaining a whois database holding details of IP address registrations in their regions. The RIR whois databases are located at:
*
ARIN (North America and sub-Saharan Africa)
*
APNIC (Asia Pacific region)
*
LACNIC (Southern and Central America and Caribbean)
*
RIPE NCC (Europe and northern Africa)
Tools
There are tools available to aid a whois lookup. Some of them are Sam Spade (downloadable from www.samspade.org). Smart Whois (downloadable fromwww.tamos.com). Netscan (downloadable from www.netscantools.com) and GTWhois (Windows XP compatible) (www.geektools.com) etc.
What is Footprinting?
Defining Foot printing
*
Foot printing is the blueprinting of the security profile of an organization, undertaken in a methodological manner.
*
Foot printing is one of the three pre-attack phases. The others are scanning and enumeration.
*
Foot printing results in a unique organization profile with respect to networks (Internet / Intranet / Extra net / Wireless) and systems involved.
There is no single methodology for foot printing, as a hacker can choose several routes to trace the information. Foot printing therefore, needs to be carried out precisely and in an organized manner. The information unveiled at various network levels can include details of domain name, network blocks, network services and applications, system architecture, intrusion detection systems, specific IP addresses, access control mechanisms and related lists, phone numbers, contact addresses, authentication mechanisms and system enumeration.
The information gathering activity can be broadly divided into seven phases:
o The attacker would first unearth initial information (such as domain name),
o locate the network range of the target system (using tools such as Nslookup, whois etc),
o ascertain the active machines (for instance by pinging the machine),
o discover open ports or access points (using tools such as port scanners),
o detect operating systems (for instance querying with telnet),
o uncover services on ports and
o ultimately map the network.
This not only speeds up the real attack process, but also aids in helping the attacker prepare better for covering his tracks and thereby leave a smaller or minimal footprint.
Initial Information:
Commonly includes:
o
Domain name lookup
o
Locations
o
Contacts (Telephone / mail)
Information Sources:
o
Open source
o
Who is
o
Nslookup
Hacking Tool:
o
Sam Spade
Open Source Foot printing is the easiest and safest way to go about finding information about a company. Information that is available to the public, such as phone numbers, addresses, etc. Performing whois requests, searching through DNS tables are other forms of open source foot printing. Most of this information is fairly easy to get, and within legal limits. One easy way to check for sensitive information is to check the HTML source code of the website to look for links, comments, Meta tags etc
*
Foot printing is the blueprinting of the security profile of an organization, undertaken in a methodological manner.
*
Foot printing is one of the three pre-attack phases. The others are scanning and enumeration.
*
Foot printing results in a unique organization profile with respect to networks (Internet / Intranet / Extra net / Wireless) and systems involved.
There is no single methodology for foot printing, as a hacker can choose several routes to trace the information. Foot printing therefore, needs to be carried out precisely and in an organized manner. The information unveiled at various network levels can include details of domain name, network blocks, network services and applications, system architecture, intrusion detection systems, specific IP addresses, access control mechanisms and related lists, phone numbers, contact addresses, authentication mechanisms and system enumeration.
The information gathering activity can be broadly divided into seven phases:
o The attacker would first unearth initial information (such as domain name),
o locate the network range of the target system (using tools such as Nslookup, whois etc),
o ascertain the active machines (for instance by pinging the machine),
o discover open ports or access points (using tools such as port scanners),
o detect operating systems (for instance querying with telnet),
o uncover services on ports and
o ultimately map the network.
This not only speeds up the real attack process, but also aids in helping the attacker prepare better for covering his tracks and thereby leave a smaller or minimal footprint.
Initial Information:
Commonly includes:
o
Domain name lookup
o
Locations
o
Contacts (Telephone / mail)
Information Sources:
o
Open source
o
Who is
o
Nslookup
Hacking Tool:
o
Sam Spade
Open Source Foot printing is the easiest and safest way to go about finding information about a company. Information that is available to the public, such as phone numbers, addresses, etc. Performing whois requests, searching through DNS tables are other forms of open source foot printing. Most of this information is fairly easy to get, and within legal limits. One easy way to check for sensitive information is to check the HTML source code of the website to look for links, comments, Meta tags etc
Sponsor
Cyber Security, News & Support, and Technology. Follow Us, Stay Connected and Be Safe.
Share It With Friends
Blog Archive
About Me
Tag Cloud
Admin Tools
(16)
Adobe
(1)
Adsense
(12)
Airtel Hacks
(1)
Android
(9)
Anonymous Hackers
(2)
Apple
(14)
Applications
(3)
ATM Machine
(1)
Backtrack
(3)
Batch Files
(1)
Blackberry
(1)
Blogger
(17)
Browsers
(1)
Bugs
(2)
Business
(1)
C source code
(2)
Camera Hack
(1)
Chat
(1)
Chrome Os
(1)
computer_tricks
(122)
Computing
(4)
Corporate
(9)
Cracks
(5)
Crimes
(2)
Cyber Attacks
(12)
Cyber Crimes
(4)
Cyber Security
(51)
Cyber Threat
(19)
cyber_news
(30)
Database Hacking
(8)
Defaced
(2)
Dos
(1)
Dos Commands
(1)
Dos Tricks
(2)
Downloads
(7)
E_Books
(8)
Easy Applications
(6)
Email Security
(1)
Emails
(2)
Encryption Tools
(2)
Entrepreneur
(3)
Ethical Hacking Tools
(53)
Ethical Hacking Tutorial
(134)
Ethical Hacking Videos'
(12)
examples
(5)
Exploit
(19)
Facebook
(36)
Fakes
(1)
Featured
(19)
Footprinting
(3)
Gadgets
(20)
Gadgets_news
(14)
games
(3)
Gmail
(5)
Google
(32)
Google Dorks
(2)
Google+
(17)
Hacked
(3)
Hackers
(16)
Hacking
(74)
Hacking News
(4)
Hacking Softwares
(139)
Hacking Techniques
(112)
Hacking Tools
(144)
Hacking_news
(45)
Hacking_terms
(38)
Hackng with Mobile
(4)
Internet_Tricks
(3)
Java-Script Hacks
(1)
Keyloggers
(2)
Keys
(1)
Laptops
(1)
Latest Mobile Phones
(3)
Lecture
(1)
Linux
(6)
Loophole
(10)
Making Applications
(1)
Metasploit
(1)
Mobile
(11)
Mobile Applications
(3)
Mobile_tricks
(15)
Network Security
(6)
news
(50)
Nokia
(2)
Notepad Hacks
(1)
Operating Systems
(11)
Oracle
(1)
Password Cracking
(9)
Pendrive
(3)
penetration testing
(32)
phase_hacking
(9)
phishing
(6)
Photoshop
(11)
Programs
(1)
Protection Tools
(17)
Proxy
(2)
Scripting
(1)
Secure Computing
(38)
Security Bleach
(5)
Seminars_Work Shops_Demo
(5)
SEO
(15)
shell
(2)
shortcuts
(2)
Social Networking
(6)
Software
(70)
source
(4)
source code
(4)
SQL Injection
(9)
System security
(30)
Techie
(4)
Technology
(5)
The Pirate Bay
(1)
Torrent
(1)
Touch
(5)
Ubuntu
(3)
Updates
(2)
Video Tutorials
(4)
Virus
(20)
Vulnerability scanner
(9)
Vulnerable
(11)
Web Security
(13)
Web Traffic
(1)
Wifi Cracking
(2)
Windows
(7)
Windows Xp Tricks
(4)
Wireless hacking
(7)
workshop
(2)
Workshops and Seminars
(2)
worms
(1)
Xss Attack
(2)
Yahoo Messenger
(1)