🔍 Footprinting & Recon

Footprinting & Reconnaissance In-Depth Guide

Complete guide to footprinting and reconnaissance — passive and active techniques, tools, and countermeasures.

Introduction to Footprinting

Footprinting (or reconnaissance) is the first phase of ethical hacking, where attackers gather information about a target before launching an attack. Ethical hackers use the same techniques to identify security weaknesses.

Objectives


Types of Footprinting

A. Passive Footprinting

B. Active Footprinting


Footprinting Techniques & Tools

A. Google Dorking (Advanced Search Queries)

B. WHOIS Lookup

C. DNS Enumeration

D. Social Media & OSINT (Open-Source Intelligence)

E. Network Scanning (Preliminary)


Advanced Reconnaissance Techniques

A. Email Harvesting

B. Subdomain Enumeration

C. Metadata Extraction

D. Website Mirroring (Offline Analysis)


Countermeasures Against Footprinting

✔ Restrict WHOIS data (Private domain registration)

✔ Disable directory listings on web servers

✔ Monitor logs for unusual scans

✔ Educate employees on social engineering risks


Hands-On Lab Exercise

Task: Perform Passive & Active Recon on a Target

  1. Google Dorking — Find exposed files (site:example.com filetype:pdf)
  2. WHOIS Lookup — Identify domain owner (whois example.com)
  3. DNS Enumeration — List all DNS records (dig example.com ANY)
  4. Subdomain Discovery — Use Sublist3r (sublist3r -d example.com)
  5. Email Harvesting — Use theHarvester (theHarvester -d example.com -b google)

Tools Checklist

Tool Purpose
Maltego Visual link analysis & OSINT
theHarvester Email, domain, and subdomain search
Nmap Network scanning & service detection
Sublist3r Subdomain enumeration
Metagoofil Metadata extraction from documents

Next Steps

💡 Would you like a deeper dive into any specific tool or technique (e.g., Nmap scanning, Maltego, or social engineering recon)?