Footprinting and Reconnaissance

 Footprinting and Reconnaissance



Types of Footprinting

There are two types of footprinting. Active methods may include hacking or social engineering, while passive methods focus on publicly available data. Both types are based on how information is gathered:

Passive Footprinting

In this type of footprinting, the attacker collects information about the target without directly interacting. It is useful for gathering undetected information. The attacker utilises publicly accessible data from online sources and analyses the target organisation’s website. Valuable information can be obtained about customers, employees, history, and more.

Passive footprinting methods offer additional options, including:

  • Browsing the target’s website
 

Exploring the website to gather insights and potential vulnerabilities.

  • Target monitoring using alert services
 

Using monitoring tools to receive updates on changes or activities related to the target.

  • Examining an employee’s social media accounts
 

Extracting information from publicly available profiles of individuals associated with the target.

  • Obtaining location information using web services
 

Obtaining geographical information about the target through various online services.

  • Finding the website using WHOIS
 

Acquiring domain registration and contact information.

  • Using search engines
 

Conducting targeted searches to gather information about the target.

  • Social networking site social engineering
 

Employing manipulation techniques to extract information from individuals on social media platforms.

  • Obtaining information about infrastructure from employment sites
 

Collecting information about the target’s infrastructure through job postings or descriptions.

  • Financial services used to obtain monetary information
 

Extracting relevant financial data about the target organisation.


Active Footprinting

In active footprinting, the attacker directly interacts with the target to gather information. This approach increases the likelihood of the target detecting the activity. Methods used in active footprinting include human interaction, searching for digital files, email tracking, social engineering, performing WHOIS lookups, traceroutes, and more.

Active footprinting techniques can be applied in various ways, such as:

  • Traceroute analysis
 

Tracing the network path to identify routers and potential vulnerabilities.

  • Email tracking
 

Gathering information by tracking email interactions and analysing metadata.

  • Whois lookup
 

Retrieving domain registration information to gather details about the target.

  • Extracting DNS information
 

Gathering data related to the target’s domain names and associated IP addresses.

Methodology of Footprinting

Footprinting follows a systematic approach consisting of four main steps:

  • Assess goals
 

Before starting the footprinting process, it is crucial to define the objectives or goals of the assessment. This helps in focusing efforts and determining the purpose of the information to be gathered.

  • Gather information
 

Once the goals are established, the next step is to collect relevant information about the target. This includes obtaining details such as the company’s name, website, contact information, and any publicly available information on social media platforms. It also involves investigating the target’s security measures and infrastructure to gain insights into potential vulnerabilities.

  • Analyse information
 

After gathering the necessary data, it needs to be analysed and evaluated. This involves assessing the potential threats and weaknesses that the collected information reveals. By identifying vulnerabilities and potential attack vectors, it becomes possible to understand the target’s security posture and the risks it faces.

  • Report findings
 

The final step is to document and report the findings of the footprinting process. A detailed report is created, outlining the conclusions drawn from the analysis and providing recommendations to enhance the target’s security posture. This report serves as a valuable resource for the target organisation, enabling them to be aware of cybersecurity threats and take appropriate measures to mitigate risks.