Secondo recenti studi:
- Il 76% degli attacchi inizia con la fase di reconnaissance (Verizon DBIR 2023)
- Il 68% delle organizzazioni ha subito attacchi basati su OSINT nel 2023
- In media, gli attaccanti spendono 247 giorni in attività di reconnaissance prima di sferrare un attacco
- Il 92% delle password aziendali trovate nel dark web proviene da leak di terze parti
Metodologie di Information Gathering
1. OSINT (Open Source Intelligence)
- Fonti Pubbliche
- Social Media
- Registri pubblici
- WHOIS database
- Motori di ricerca specializzati
- Tecniche Avanzate
- Google Dorks
- Metadata Analysis
- Email Pattern Recognition
- Certificate Transparency Logs
2. Passive Information Gathering
Tools e Tecniche
# DNS Enumeration
dig +short target.com
whois target.com
host -t ns target.com
# SSL/TLS Analysis
sslscan target.com
testssl.sh target.com
# Subdomain Enumeration
subfinder -d target.com
amass enum -passive -d target.com
3. Active Information Gathering
Network Scanning
# Basic Network Scan
nmap -sS -sV -p- target.com
# Service Detection
nmap -sC -sV --script vuln target.com
# Web Application Scanning
nikto -h target.com
gobuster dir -u target.com -w wordlist.txt
Tool Essenziali
1. Reconnaissance Framework
- Maltego
- Visualizzazione dati
- Integrazione API
- Transform Hub
- SpiderFoot
- Automazione OSINT
- 200+ moduli integrati
- Reporting avanzato
2. DNS Analysis
- DNSRecon
dnsrecon -d target.com -t std
dnsrecon -d target.com -t axfr
- Sublist3r
sublist3r -d target.com -e google,yahoo,bing
3. Web Intelligence
- TheHarvester
theHarvester -d target.com -b all
- WayBackMachine
- Analisi storica
- File dimenticati
- Configurazioni esposte
Scenari di Attacco
1. Social Engineering
# Script esempio per email harvesting
import re
from bs4 import BeautifulSoup
import requests
def extract_emails(domain):
emails = set()
search_urls = [
f"https://www.google.com/search?q=@{domain}",
f"https://www.bing.com/search?q=@{domain}"
]
email_pattern = re.compile(f'[a-zA-Z0-9._%+-]+@{domain}')
for url in search_urls:
try:
response = requests.get(url)
soup = BeautifulSoup(response.text, 'html.parser')
found_emails = email_pattern.findall(soup.text)
emails.update(found_emails)
except Exception as e:
print(f"Error: {e}")
return emails
2. Infrastructure Mapping
# Network topology discovery
nmap -sn 192.168.1.0/24
masscan -p1-65535 192.168.1.0/24 --rate=1000
# Service enumeration
nmap -sV -sC -p- -T4 192.168.1.0/24
3. Data Leakage Detection
# Script per cercate secrets in repository Git
import re
from git import Repo
def scan_repo(repo_path):
repo = Repo(repo_path)
commits = list(repo.iter_commits('master'))
patterns = {
'aws_key': r'AKIA[0-9A-Z]{16}',
'password': r'password.*=.*',
'api_key': r'api[_-]key.*=.*'
}
for commit in commits:
for diff in commit.diff(commit.parents[0]):
for pattern_name, pattern in patterns.items():
matches = re.finditer(pattern, diff.diff.decode())
for match in matches:
print(f"Found {pattern_name} in commit {commit.hexsha}")
Misure di Difesa
1. Digital Footprint Reduction
# Nginx configuration per nascondere informazioni sensibili
server_tokens off;
proxy_hide_header X-Powered-By;
proxy_hide_header Server;
2. Content Security Policy
Content-Security-Policy: default-src 'self';
X-Frame-Options: DENY;
X-Content-Type-Options: nosniff;
Referrer-Policy: no-referrer;
3. DNS Security
# DNSSEC configuration
dnssec-keygen -a RSASHA256 -b 2048 -n ZONE domain.com
dnssec-signzone -A -3 $(head -c 1000 /dev/random | sha1sum | cut -b 1-16) -N INCREMENT -o domain.com -t domain.com.signed
Best Practices di Protezione
- Monitoring e Detection
- Implementare SIEM
- Network traffic analysis
- Behavioral analytics
- Policy e Procedure
- Information classification
- Data handling guidelines
- Security awareness training
- Technical Controls
- WAF implementation
- IDS/IPS deployment
- DLP solutions
Risorse Utili
Training
- OSINT Framework
- SANS SEC487
- TCM Security OSINT Course
Tools
Documentation
Come Proteggersi
- Asset Management
- Inventario completo
- Classification scheme
- Access control
- Surface Reduction
- Remove unnecessary services
- Regular vulnerability scanning
- Security headers implementation
- Monitoring
- Log analysis
- Network monitoring
- Threat intelligence
Conclusione
L’Information Gathering è fondamentale sia per gli attaccanti che per i difensori. La chiave è:
- Mantenere un programma di security proattivo
- Monitorare costantemente l’exposure
- Implementare controlli stratificati




