Ethical Hacking Lab Manual
ISBN 9788119221523

Highlights

Notes

  

Chapter 1: Use software tools/commands to perform foot printing/ information gathering and generate analysis report

Aim: Use software tools/commands to perform foot printing /information gathering and generate analysis report

Solution:

Phases of Ethical Hacking

Footprinting is a part of Reconnaissance

Types of Footprinting

    1) Passive

    2) Active

During footprinting, a hacker can collect the

    1) Domain Name

    2) IP Address

    3) Namespaces

    4) Employee Information

    5) Phone Numbers

    6) E-mails

    7) Job Information

Footprinting methods and tools

    1) Search Engines

    Google Earth

    Google Maps

    Bing Maps

    The above Search Engines provide Location Information

    Linkedin.com

    Piple.com

    These sites are used to view the Personal Information

    www.netcraft.com

    Performing footprinting using Google Hacking commands

    2) Google Hacking

    Google Hacking involves Manipulating a Search String with addition of specific Operators to search for vulnerabilities.

Basic Examples

table-wrap

This Search

Find Pages Containing…

Biking Italy

The words biking and Italy

Recycle steel OR iron

Information on recycling steel or recycling iron

“I have a dream”

The exact phrase I have a dream

Salsa -dance

The word Salsa but NOT the word dance

Louis “I” France

Information about Louis the First (I), weeding out other kings of

France

Castle ~glossary

Glossaries about Castles, as well as dictionaries, lists of terms, terminology, etc.

Fortune-telling

All forms of the term, whether spelled as a single word, a phrase, or hyphenated

define: imbroglio

Definitions of the word imbroglio from the Web

Calculator

table-wrap

Operators

Meaning

Type into Search Box (& Results)

+ - * /

Basic Arithmetic

12 + 34 – 56 * 7 / 8

% of

Percentage of

45% of 39

^ or **

Raise to a power

2 ^ 5 or 2 ** 5

Old units in new units

Convert units

300 Euros in USD, 130 lbs. in kg, or 31 in hex

Restrict Search

table-wrap

Operators

Meaning

Type into Search Box (& Results)

city1 city2

Book flights

SFO BOS (Book flights from San Francisco (SFO) to Boston (BOS))

site:

Search only one website or domain

Halloween site:www.census.gov

(Search for information on Halloween gathered by the US Census Bureau.)

[#]..[#]

Search within a range of numbers.

Dave Barry pirate 2002..2006

(Search for Dave Barry articles mentioning pirates written in these years.)

filetype: (or ext:)

Find documents of the specified type

Form 1098-T IRS filetype: pdf

(Find the US tax from 1098-T in PDF format.)

link:

Find linked pages, i.e., show pages that point to the URL

link:warriorlibrarian.com

(Find pages that link to Warrior Librarian’s website.)

Specialized Information Queries

table-wrap

Operators

Meaning

Type into Search Box (& Results)

book

(or books)

Search full-text of books

book Ender’s Game (Show book-related information Note: No colon needed after book.)

define, what is, what are

Show a definition for a word or phrase

Define monopsony, what is podcast

(Show a definition for the words monopsony and

podcast.)

define:

Provide definitions for words, phrases, any acronyms from the web.

define: kerning

(Find definitions for kerning from the Web.)

movie:

Find reviews and showtimes

movie: traffic

(Search for information about this movie, including reviews, showtimes, etc.)

stocks:

Given ticker symbols, show stock information

stocks:goog

(Find Google’s current stock price.)

weather

Given a location (US zip code or city) show the weather

weather Seattle WA, weather 81612

(Show the current weather and forecast.)

table-wrap

Operators

Syntax

Description

filetype

filetype: type

Searches only for files of a specific type (DOC, XLS, and so on). For example, the following will return all Microsoft Word Documents:

filetype: doc

index of

index of /string

Displays pages with directory browsing enabled, usually used with another operator. For example, the following will display pages that show directory listings containing password:

“intitle: index of” passwd

info

info: string

Displays information Google stores about the page itself:

info: www.anycomp.com

intitle

Intitle: string

Searches for the pages that contain the string in the title. For example, the following will return pages with the word login in the title:

intitle: login

inurl

inurl: string

Displays pages with the string in the URL. For example, the following display all pages with the word passwd in the URL:

inurl: passwd

related

related: webpage name

Show web pages similar to webpage name.

To find out the information about a website

http://whois.domaintools.com

www.archive.org

To trace any received email

http://www.emailtrackerpro.com/support/headertutorials/gmail.html

To fetch DNS information

(find the IP addresses and Aliases of the websites)

Command Prompt:

www.ping.eu

www.exploit-db.com/papers

www.hackersforcharity.org/ghdb

www.mcafee.com

www.ip2location.com