- Jaimin Gohel
What is Reconnaissance?
Passive reconnaissance
DNS information
Sniffing through regular traffic
WHOIS database
Active reconnaissance
Recon through search engines (Shodan.io)
Recon through search engines (Shodan.io)
DNS footprinting (http://ping.eu/nslookup/)
WHOIS lookup
WHOIS lookup (https://who.is)
WHOIS lookup (https://who.is) cont.
Through social networking sites/ people search services
Social site (https://pipl.com)
Find services used by target host
Namp example
Website recon
Web data extractors(httrack)
Wayback machine(https://archive.org)
Subdomain scanning (Sublist3r)