Footprinting and Reconnaissance
Types of Footprinting
There are two types of footprinting. Active methods may include hacking or social engineering, while passive methods focus on publicly available data. Both types are based on how information is gathered:
Passive Footprinting
In this type of footprinting, the attacker collects information about the target without directly interacting. It is useful for gathering undetected information. The attacker utilises publicly accessible data from online sources and analyses the target organisation’s website. Valuable information can be obtained about customers, employees, history, and more.
Passive footprinting methods offer additional options, including:
- Browsing the target’s website
Exploring the website to gather insights and potential vulnerabilities.
- Target monitoring using alert services
Using monitoring tools to receive updates on changes or activities related to the target.
- Examining an employee’s social media accounts
Extracting information from publicly available profiles of individuals associated with the target.
- Obtaining location information using web services
Obtaining geographical information about the target through various online services.
- Finding the website using WHOIS
Acquiring domain registration and contact information.
- Using search engines
Conducting targeted searches to gather information about the target.
- Social networking site social engineering
Employing manipulation techniques to extract information from individuals on social media platforms.
- Obtaining information about infrastructure from employment sites
Collecting information about the target’s infrastructure through job postings or descriptions.
- Financial services used to obtain monetary information
Extracting relevant financial data about the target organisation.
Active Footprinting
In active footprinting, the attacker directly interacts with the target to gather information. This approach increases the likelihood of the target detecting the activity. Methods used in active footprinting include human interaction, searching for digital files, email tracking, social engineering, performing WHOIS lookups, traceroutes, and more.
Active footprinting techniques can be applied in various ways, such as:
- Traceroute analysis
Tracing the network path to identify routers and potential vulnerabilities.
- Email tracking
Gathering information by tracking email interactions and analysing metadata.
- Whois lookup
Retrieving domain registration information to gather details about the target.
- Extracting DNS information
Gathering data related to the target’s domain names and associated IP addresses.
Methodology of Footprinting
Footprinting follows a systematic approach consisting of four main steps:
- Assess goals
Before starting the footprinting process, it is crucial to define the objectives or goals of the assessment. This helps in focusing efforts and determining the purpose of the information to be gathered.
- Gather information
Once the goals are established, the next step is to collect relevant information about the target. This includes obtaining details such as the company’s name, website, contact information, and any publicly available information on social media platforms. It also involves investigating the target’s security measures and infrastructure to gain insights into potential vulnerabilities.
- Analyse information
After gathering the necessary data, it needs to be analysed and evaluated. This involves assessing the potential threats and weaknesses that the collected information reveals. By identifying vulnerabilities and potential attack vectors, it becomes possible to understand the target’s security posture and the risks it faces.
- Report findings
The final step is to document and report the findings of the footprinting process. A detailed report is created, outlining the conclusions drawn from the analysis and providing recommendations to enhance the target’s security posture. This report serves as a valuable resource for the target organisation, enabling them to be aware of cybersecurity threats and take appropriate measures to mitigate risks.
