You are on page 1of 1

SECGURU

Reconnaissance Cheat Sheet

Gathering information from Open Sources


Owner of IP-address range Technical Contact Public Server's Banner Information.
Address Range Business Partners DNS Servers
Domain Names Administrative Contacts WEB Servers
Computing Platforms Email Addresses SMTP Servers
Network Architecture Technology being used Zones & Sub-domains
User(name) Information Phone No's Locate Firewalls/Perimeter devices.
Physical Location Route to target's
Active Services Internet Accessible data

Techniques

Target's Website DNS SMTP


Mirror the web AXFR vrfy; email_enumeration
Use Grep or Similar Version Banner information
Scan for keywords Zones & Sub-domains Bounced Emails
Banner Information Nmap -sL Email Header
Applications DNSDig expn; email mapping
Cgi's Nslookup
Cookie style Dig commands Job Databases
Scripting language Host commands
Job requirements
Code-reading Active services
Employee profile
Weblogs info [e.g. MRTG]
Hardware information
Traceroute Software information
Search Engines (Google) ISP information
intitle: "index of /etc" Locate Firewalls Personal Website
inurl: "config.php.bak" Network Infrastructure
Employee job profile
site:"target.com" Tcptraceroute
Hardware information
filetype:".bak" Firewalk
Software information
Cross-Links
Search for group postings Finger
News Articles Ping
List of live systems
SamSpade RTT, delays
Whois N/W connectivity
Netcraft

© secguru.com

You might also like