Footprinting
Footprinting
Passive Footprinting
Active Footprinting
Apart from the mode of information collection, the classification also takes the risk
of detection in the account
Usually both modes of recon are important in order to gain as much information as
possible and to create a comprehensive test plan
Objectives of FootPrinting
https://en.wikipedia.org/wiki/
https://www.google.com/
https://www.bing.com/
https://duckduckgo.com/
Introduction to WHOIS Foot printing
Whois Databases are maintained by (RIR) Regional Internet Registries and contain the Personal
Information of domain owners
WebTools: https://www.netcraft.com
Finding Company’s Public and Restricted Details
Finding Company’s Public and Restricted Details
Determining the Operating System
Attackers use shodan search engine to get the information of specific computers, servers
routers which are in public
https://www.shodan.io
Determining the OS, Port & Services
Collect the Location Information
Attackers use to find the physical location of target by using many online tools available
Below are some of these most
popular online services are:
Google Map
Bing Map
Wikimapia
Yahoo Map
Other Map and Location services
People Search: Social Networking Sites
Social Networking sites are great source of personal and organizational information
Information about an individual persons can be found at various Social networking sites
The people search returns the following information about a person or organization
People Search: Social Networking Sites
Below are the some of the online websites to foot printing on individuals :
https://www.peekyou.com
https://www.truepeoplesearch.com
https://www.truthfinder.com
https://www.facebook.com
https://www.zabasearch.com
https://in.linkedin.com
https://www.google.com
https://suip.biz
https://pipl.com
Foot Printing Using Google Dorks
Some advanced options which can be used to search for a specific topic using Google
search engines. These Advance search operators will searching more appropriate and
focused on a particular topic ,advanced search operators by google :
Advanced Description
Search
operators For Google Advanced Search, You can also
site : search for the results in the given domain use the following URL:
related : search for similar web pages
cache : Display the web pages stored in Cache https://www.google.com/advanced_search
link : List the websites having a links to a specific web pages
allintext : Search for websites containing a specific keywords
intext : Search for documents containing a specific keyword
allintitle : Search for websites containing a specific keywords in the
title
intitle : Search for documents containing a specific keywords in the
title
allinurl : Search for websites containing a specific keywords in URL
In Job Sites, Company's offers the vacancies to people provide their organization's
information and portfolio also is job post. This information includes Company location,
Industry information, Contacts, number of employees in organization Job requirements,
hardware, and software information. Similarly, on these job sites, by a posting fake job,
personal information can be collected from a targeted individual. Some of the popular
job sites are:
www.linkedIn.com
www.monster.com
www.indeed.com
www.careerbuilder.com
www.naukri.com
Website FootPrinting using web spiders
Web Spiders perform automated search on target website to get the results of employee
Details, email address etc.
Tool : Web Data extractor
Mirroring Entire Website
Mirroring an entire website in to local system for attackers to browse the target
website offline and it also consist of directory structure along with valuable
information.
Website copier tools are allow you to download a website to local directory along
with HTML code, Video, images, flash, other config files from server to local system
Download tool from below link
https://www.httrack.com/
Website Mirroring Tools
Software Websites
PageNest http://www.pagenest.com
http://www.dnsstuff.com
http://network-tools.com
http://www.mydnstools.info
http://www.domaintools.com
http://www.dnsqueries.com
http://www.ultratools.com
Template FootPrinting Testing
Source : EC-Council
FootPrinting Countermeasures