Passive information gathering
What passive information?
IP addresses, DNS, domain names and domain ownership
Email addresses, social media profiles
Web technologies, subdomains
TOOLS TO GATHER INFORMATION PASSIVELY:-
host command:- host <HOST>
robots.txt
sitemap.xml
whatweb :- whatweb <HOST> Display the technologies used in the website
whois :- whois <HOST> Display all the inforamtion about the target domain like Date of registration ,owner,owner email address,etc
Netcraft website :- Displays the follwoing information in an readble format
Background
Network: domain IP address, Nameserver, Domain registrar, IP delegation
SSL/TLS Certificate: Issuer, Validity, Transparency, vulnerabilities
Hosting History
Web Trackers
Site Technology: Server-Side, Client-Side, Frameworks, etc
wafw00f :- Displays the target is behind a firewall or not
sublist3r :- subdomain enumeration command :-sublist3r -d <domain name>
Last updated