Information Gathering: La Base di Ogni Assessment di Sicurezza

sentinelcore-dognettechnologies

Secondo recenti studi:

  • Il 76% degli attacchi inizia con la fase di reconnaissance (Verizon DBIR 2023)
  • Il 68% delle organizzazioni ha subito attacchi basati su OSINT nel 2023
  • In media, gli attaccanti spendono 247 giorni in attività di reconnaissance prima di sferrare un attacco
  • Il 92% delle password aziendali trovate nel dark web proviene da leak di terze parti

Metodologie di Information Gathering

1. OSINT (Open Source Intelligence)

  • Fonti Pubbliche
  • Social Media
  • Registri pubblici
  • WHOIS database
  • Motori di ricerca specializzati
  • Tecniche Avanzate
  • Google Dorks
  • Metadata Analysis
  • Email Pattern Recognition
  • Certificate Transparency Logs

2. Passive Information Gathering

Tools e Tecniche

# DNS Enumeration
dig +short target.com
whois target.com
host -t ns target.com

# SSL/TLS Analysis
sslscan target.com
testssl.sh target.com

# Subdomain Enumeration
subfinder -d target.com
amass enum -passive -d target.com

3. Active Information Gathering

Network Scanning

# Basic Network Scan
nmap -sS -sV -p- target.com

# Service Detection
nmap -sC -sV --script vuln target.com

# Web Application Scanning
nikto -h target.com
gobuster dir -u target.com -w wordlist.txt

Tool Essenziali

1. Reconnaissance Framework

  • Maltego
  • Visualizzazione dati
  • Integrazione API
  • Transform Hub
  • SpiderFoot
  • Automazione OSINT
  • 200+ moduli integrati
  • Reporting avanzato

2. DNS Analysis

  • DNSRecon
dnsrecon -d target.com -t std
dnsrecon -d target.com -t axfr
  • Sublist3r
sublist3r -d target.com -e google,yahoo,bing

3. Web Intelligence

  • TheHarvester
theHarvester -d target.com -b all
  • WayBackMachine
  • Analisi storica
  • File dimenticati
  • Configurazioni esposte

Scenari di Attacco

1. Social Engineering

# Script esempio per email harvesting
import re
from bs4 import BeautifulSoup
import requests

def extract_emails(domain):
    emails = set()
    search_urls = [
        f"https://www.google.com/search?q=@{domain}",
        f"https://www.bing.com/search?q=@{domain}"
    ]

    email_pattern = re.compile(f'[a-zA-Z0-9._%+-]+@{domain}')

    for url in search_urls:
        try:
            response = requests.get(url)
            soup = BeautifulSoup(response.text, 'html.parser')
            found_emails = email_pattern.findall(soup.text)
            emails.update(found_emails)
        except Exception as e:
            print(f"Error: {e}")

    return emails

2. Infrastructure Mapping

# Network topology discovery
nmap -sn 192.168.1.0/24
masscan -p1-65535 192.168.1.0/24 --rate=1000

# Service enumeration
nmap -sV -sC -p- -T4 192.168.1.0/24

3. Data Leakage Detection

# Script per cercate secrets in repository Git
import re
from git import Repo

def scan_repo(repo_path):
    repo = Repo(repo_path)
    commits = list(repo.iter_commits('master'))

    patterns = {
        'aws_key': r'AKIA[0-9A-Z]{16}',
        'password': r'password.*=.*',
        'api_key': r'api[_-]key.*=.*'
    }

    for commit in commits:
        for diff in commit.diff(commit.parents[0]):
            for pattern_name, pattern in patterns.items():
                matches = re.finditer(pattern, diff.diff.decode())
                for match in matches:
                    print(f"Found {pattern_name} in commit {commit.hexsha}")

Misure di Difesa

1. Digital Footprint Reduction

# Nginx configuration per nascondere informazioni sensibili
server_tokens off;
proxy_hide_header X-Powered-By;
proxy_hide_header Server;

2. Content Security Policy

Content-Security-Policy: default-src 'self';
X-Frame-Options: DENY;
X-Content-Type-Options: nosniff;
Referrer-Policy: no-referrer;

3. DNS Security

# DNSSEC configuration
dnssec-keygen -a RSASHA256 -b 2048 -n ZONE domain.com
dnssec-signzone -A -3 $(head -c 1000 /dev/random | sha1sum | cut -b 1-16) -N INCREMENT -o domain.com -t domain.com.signed

Best Practices di Protezione

  1. Monitoring e Detection
  • Implementare SIEM
  • Network traffic analysis
  • Behavioral analytics
  1. Policy e Procedure
  • Information classification
  • Data handling guidelines
  • Security awareness training
  1. Technical Controls
  • WAF implementation
  • IDS/IPS deployment
  • DLP solutions

Risorse Utili

Training

Tools

Documentation

Come Proteggersi

  1. Asset Management
  • Inventario completo
  • Classification scheme
  • Access control
  1. Surface Reduction
  • Remove unnecessary services
  • Regular vulnerability scanning
  • Security headers implementation
  1. Monitoring
  • Log analysis
  • Network monitoring
  • Threat intelligence

Conclusione

L’Information Gathering è fondamentale sia per gli attaccanti che per i difensori. La chiave è:

  • Mantenere un programma di security proattivo
  • Monitorare costantemente l’exposure
  • Implementare controlli stratificati

Potrebbe interessarti anche

ItalianoitItalianoItaliano