Information Gathering

Passive Information Gathering

##Whois Enumeration
whois megacorpone.com 
whois megacorpone.com -h 192.168.50.251    #Here -h parameter is the whois server database which can provide details
#we can do reverse lookups as well
whois 38.100.193.70
whois 38.100.193.70 -h 192.168.50.251 

##Google Hacking
site:megacorpone.com
site:megacorpone.com filetype:txt
site:megacorpone.com -filetype:html
intitle:“index of” “parent directory”
#This website has lot of docks as well: https://www.exploit-db.com/google-hacking-database

##Netcraft
#We can use netcraft website as well for information gathering: https://searchdns.netcraft.com/

##Open-Source Code
#git hub is great source to find open-source code
#some usefull searches in github: https://github.com/megacorpone
filename:users
user:megacorpone filename:users
#We can use automated tools like Gitrob and Gitleaks as well

##Shodan
hostname:megacorpone.com
hostname:megacorpone.com port:"22"

##Security Headers and SSL/TLS
#https://securityheaders.com/
#https://www.ssllabs.com/ssltest/

Active Information Gathering

Last updated