Information Gathering: The Base of Every Security Assessment

sentinelcore-dognettechnologies

According to recent studies:

  • 76% of the attacks begin with the reconnaissance phase (Verizon DBIR 2023)
  • 68% of organizations suffered OSINT-based attacks in 2023
  • On average, attackers spend 247 days in reconnaissance activities before venting an attack
  • 92% of business passwords found in the dark web comes from third-party leaks

Information Gathering Methodologies

1. OSINT (Open Source Intelligence)

  • Public sources
  • Social Media
  • Public registers
  • WHOIS database
  • Specialist search engines
  • Advanced Techniques
  • Google Dorks
  • Metadata Analysis
  • Email Pattern Recognition
  • Certificate Transparency Logs

2. Passive Information Gathering

Tools and Techniques

# DNS Enumeration
dig +short target.com
whois target.com
host -t ns target.com

# SSL/TLS Analysis
sslscan target.com
testssl.sh target.com

# Subdomain Enumeration
subfinder -d target.com
amass enum -passive -d target.com

3. Active Information Gathering

Network Scanning

# Basic Network Scan
nmap -sS -sV -p- target.com

# Service Detection
nmap -sC -sV --script vuln target.com

# Web Application Scanning
nikto -h target.com
gobuster dir -u target.com -w wordlist.txt

Essential tools

1. Reconnaissance Framework

  • Maltego
  • Data display
  • API integration
  • Transform Hub
  • SpiderFoot
  • OSINT automation
  • 200+ integrated modules
  • Advanced Reporting

2. DNS Analysis

  • DNSRecon
dnsrecon -d target.com -t std
dnsrecon -d target.com -t axfr
  • ♪
sublist3r -d target.com -e google,yahoo,bing

3. Web intelligence

  • The Harvester
theHarvester -d target.com -b all
  • WayBackMachine
  • Historical analysis
  • Forgotten files
  • Exposed configurations

Attack scenarios

1. Social Engineering

# Script esempio per email harvesting
import re
from bs4 import BeautifulSoup
import requests

def extract_emails(domain):
    emails = set()
    search_urls = [
        f"https://www.google.com/search?q=@{domain}",
        f"https://www.bing.com/search?q=@{domain}"
    ]

    email_pattern = re.compile(f'[a-zA-Z0-9._%+-]+@{domain}')

    for url in search_urls:
        try:
            response = requests.get(url)
            soup = BeautifulSoup(response.text, 'html.parser')
            found_emails = email_pattern.findall(soup.text)
            emails.update(found_emails)
        except Exception as e:
            print(f"Error: {e}")

    return emails

2. Infrastructure Mapping

# Network topology discovery
nmap -sn 192.168.1.0/24
masscan -p1-65535 192.168.1.0/24 --rate=1000

# Service enumeration
nmap -sV -sC -p- -T4 192.168.1.0/24

3. Data Leakage Detection

# Script per cercate secrets in repository Git
import re
from git import Repo

def scan_repo(repo_path):
    repo = Repo(repo_path)
    commits = list(repo.iter_commits('master'))

    patterns = {
        'aws_key': r'AKIA[0-9A-Z]{16}',
        'password': r'password.*=.*',
        'api_key': r'api[_-]key.*=.*'
    }

    for commit in commits:
        for diff in commit.diff(commit.parents[0]):
            for pattern_name, pattern in patterns.items():
                matches = re.finditer(pattern, diff.diff.decode())
                for match in matches:
                    print(f"Found {pattern_name} in commit {commit.hexsha}")

Defence measures

1. Digital Footprint Reduction

# Nginx configuration per nascondere informazioni sensibili
server_tokens off;
proxy_hide_header X-Powered-By;
proxy_hide_header Server;

2. Content Security Policy

Content-Security-Policy: default-src 'self';
X-Frame-Options: DENY;
X-Content-Type-Options: nosniff;
Referrer-Policy: no-referrer;

3. DNS Security

# DNSSEC configuration
dnssec-keygen -a RSASHA256 -b 2048 -n ZONE domain.com
dnssec-signzone -A -3 $(head -c 1000 /dev/random | sha1sum | cut -b 1-16) -N INCREMENT -o domain.com -t domain.com.signed

Best Practices of Protection

  1. Monitoring and Detection
  • Implementing SIEM
  • Network traffic analysis
  • Behavioral analytics
  1. Policy and Procedures
  • Information
  • Data handling guidelines
  • Security awareness training
  1. Technical Controls
  • WAF implementation
  • IDS/IPS deployment
  • DLP solutions

Resources

Training

Tools

Documentation

How to Protect

  1. Asset Management
  • Complete inventory
  • Classification
  • Access control
  1. Surface Reduction
  • Remove unnecessary services
  • Regular vulnerability scanning
  • Security headers implementation
  1. Monitoring
  • Log analysis
  • Network monitoring
  • Threat intelligence

Conclusion

Information Gathering is fundamental for both attackers and defenders. The key is:

  • Maintain a proactive security program
  • Monitoring Exposures constantly
  • Implementing laminated controls

It might also interest you

EnglishenEnglishEnglish