1. Footprinting
1.1. Footprinting (also known as reconnaissance) is the technique used for gathering information about computer systems and the entities they belong to. To get this information, a hacker might use various tools and technologies. This information is very useful to a hacker who is trying to crack a whole system.
2. Footprinting Terminologies
2.1. - Open Source or Passive Information Gathering: Collect information about a target from the publicly accessible source
2.2. - Active Information Gathering: Gather information through social engineering on-site visits, interviews, and questionnaires
2.3. - Anonymous Footprinting: Gather information from sources where the author of the information cannot be identified or traced
2.4. - Pseudonymous Footprinting: Collect information that might be published under a different name in an attempt to preserve privacy
2.5. - Organizational or Private Footprinting: Collect information from an organization´s web-based calendar and email services
2.6. - Internet Footprinting: Collect information about a target from the Internet
3. Objectives of Footprinting
3.1. Collect Network Information
3.1.1. The network information can be gathered by performing a Whois database analysis, trace routing, etc. includes: • Domain name • Internal domain names • Network blocks • IP addresses of the reachable systems • Rogue websites/private websites • TCP and UDP services running • Access control mechanisms and ACLs • Networking protocols • VPN points • ACLs • IDSes running • Analog/digital telephone numbers • Authentication mechanisms • System enumeration
3.2. Collect System Information
3.2.1. • User and group names • System banners • Routing tables • SNMP information • System architecture • Remote system type • System names • Passwords
3.3. Collect Organization’s Information
3.3.1. • Employee details • Organization's website • Company directory • Location details • Address and phone numbers • Comments in HTML source code • Security policies implemented • Web server links relevant to the organization • Background of the organization • News articles/press releases