Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 65 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow Information / Intelligence Gathering
EH-Net
May 25, 2012, 08:22:52 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Information / Intelligence Gathering  (Read 7695 times)
0 Members and 4 Guests are viewing this topic.
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« on: March 16, 2010, 01:02:37 PM »

Information / Intelligence Gathering.

This post is going to be about information gathering. Its one of the important things. You want to know what you are going up against.

Information about location, building, and etc...
   Google Maps and Google streets.(1)
   Local government office might have building blueprints.

Network(IP, AP, Servers, Software, OS's, and etc...) Information
   WiGLE//great resource, has map of wireless AP's(2)
   Network-Tools.com//ping, traceroute, and other stuff.(3)
   Geobytes IP Locatior//shows location, and other things about the location(4)
   DNSStuff//just what it sounds line(5)
   Geektools//hotspot list(not good as WiGLE), Traceroute, Whois(6)
   Robtex//Lots of tools on there(7)
   Traceroute.org//you can traceroute from different places.(Cool
   NetCraft//Finds information about the server(9)
   SamSpade//whois(10)
   dnssy.com//dns stuff..(11)
   centralops.net//lots of tool on there.(12)
   serversniff.de//lots of tools on here too(13)
   web-sniffer.net//gets information about webserver(header, etc..)(14)
   yougetsignal.com//great things here too.(15)
   Maltego//can be used too.(16)
   Shodan//good stuff.(26)
   Shodan Queries//(28)
   FOCA//it searches webz for files(pdfs,docs, etc..) tells you usernames,          software names, and other things.(34) Backtrack also has tools included       similar to this.

   Tools
   Nmap, Hping..just download backtrack open menu, go to backtrack > Network          Mapping > All. Wink (17)
   

// You can also use tor with nmap http://pauldotcom.com/2009/08/scanning-through-a-tor-network.html

Individual(Names, Emails, Social Networks, Phone Numbers, and etc...) Information
   White Pages(18) / Yellow Book(19)//
   Google(20)
   Pipl.com(21)
   123People.com(22)
   Maltego(16)
   tracksomebody.com(23)
   Snoopstation.com//free background checks(35)

Information about a company
   Google Maps.//It sometimes gives you phone numbers, websites, names, with          map.(1)
   Job websites.//they want to hire people so they will put some information          there, it might be useful when social engineering.
   Google.//use your Google-fu(google hacks).(24-25)
   Maltego//
   Snoopstation.com//free background checks(35)
   TheHarvestor//its in backtrack, it gets lots of emails by searching google          and other places.
   abika//network stuff, and phone and email stuff.
   

Going to another level
   Drive-by//Get kismet or netstumbler running and drive by their building see          whats in the air.
   Email//Email them, when you get reply check the headers for internal IP.
   Parked car in front of the building, and using their wireless//now you can          gather information about internal network.
   Fake ID(32)//very useful.
   Social Engineering(33)//also very useful and good to know.

Organizing
   Onenote(27)//Microsoft product, not free.
   Evernote(29)//Similar to Onenote, but free and works on everything but Linux
   Leo(30-31)//Small program for making outlines.
   
Links
   1, maps.google.com
   2, wigle.net
   3, Network-Tools.com
   4, http://www.geobytes.com/iplocator.htm
   5, www.dnsstuff.com
   6, www.geektools.com
   7, www.robtex.com
   8, Traceroute.org
   9, www.netcraft.com
   10, www.samspade.org
   11, dnssy.com
   12, centralops.net
   13, serversniff.de
   14, web-sniffer.net
   15, yougetsignal.com
   16, www.paterva.com/web4/index.php/maltego
   17, backtrack-linux.org
   18, www.whitepages.com
   19, www.yellowpages.com
   20, www.google.com
   21, pipl.com
   22, 123people.com
   23, tracksomebody.com
   24, http://www.hackersforcharity.org/ghdb/
   25, http://pentestit.com/google-dorks/
   26, http://www.shodanhq.com/
   27, http://office.microsoft.com/en-us/products/FX010562591033.aspx
   28, http://pentestit.com/shodan-queries/
   29, www.evernote.com
   30, http://sourceforge.net/projects/leo/
   31, http://www.offensive-security.com/videos/leo-basic-usage/leo-basic-usage_controller.swf
   32, http://www.fakenamegenerator.com/
   33, http://www.social-engineer.org/
   34, http://www.informatica64.com/DownloadFOCA/
   35, Snoopstation.com
   
If i have mistakes correct me, I am human.
Please add more.

EDIT: https://addons.mozilla.org/en-US/firefox/addon/13308  good addon.
« Last Edit: March 16, 2010, 01:27:57 PM by pizza1337 » Logged

Knowledge Resource is Power.
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #1 on: March 16, 2010, 01:18:57 PM »

Pizza - This is a good list, there a few I didn't know about in there.

I have a full mindmap of my OSINT process, would you guys like see?
Logged

pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #2 on: March 16, 2010, 01:22:57 PM »

Pizza - This is a good list, there a few I didn't know about in there.

I have a full mindmap of my OSINT process, would you guys like see?

Yep
Logged

Knowledge Resource is Power.
aweSEC
Hero Member
*****
Offline Offline

Posts: 1100


View Profile
« Reply #3 on: March 16, 2010, 01:28:29 PM »

Nice list, pizza1337.

Pizza - This is a good list, there a few I didn't know about in there.

I have a full mindmap of my OSINT process, would you guys like see?

Sure, much appreciated. Smiley
Logged
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #4 on: March 16, 2010, 02:00:47 PM »

When i get home ill put it up and we can all trade notes =)
Logged

j0rDy
Hero Member
*****
Offline Offline

Posts: 578


View Profile
« Reply #5 on: March 17, 2010, 05:07:19 AM »

good list pizza!

i see some things i recognize from the http://www.vulnerabilityassessment.co.uk/ framework.

another one is the http://www.isecom.org/osstmm/ Open Source Security Testing Methodology Manual.

i'd love to exchange notes, but all i have are some notes from the CEH training, but nothing in there worth of sharing Wink
Logged

ISC2 Associate, CEH, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #6 on: March 17, 2010, 08:29:29 AM »

good list pizza!

i see some things i recognize from the http://www.vulnerabilityassessment.co.uk/ framework.

another one is the http://www.isecom.org/osstmm/ Open Source Security Testing Methodology Manual.

i'd love to exchange notes, but all i have are some notes from the CEH training, but nothing in there worth of sharing Wink

Share it anyway, i have no training, ill learn something from it.

btw, very nice link, i never knew about them.
Logged

Knowledge Resource is Power.
j0rDy
Hero Member
*****
Offline Offline

Posts: 578


View Profile
« Reply #7 on: March 18, 2010, 03:23:49 AM »

i'd have to digitalize them first. there all on paper. some things i remember that are on there are the most common ip ports, ip ports of common rootkits (deep throat, masters paradise, netbuster etc.) and some wireshark command options. ill see if i can make a nice selection and post them here...
Logged

ISC2 Associate, CEH, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
hackertarget
Newbie
*
Offline Offline

Posts: 2


View Profile WWW
« Reply #8 on: February 07, 2011, 06:59:45 PM »

We have a new intelligence gathering project up and running.

http://www.dnsdumpster.com - dumpster dive a domain and get a bunch of information.

Hope someone finds it useful. The aim is to provide a quick and easy technical overview of a domain and related systems. Uses various methods to collect the information.
Logged

HackerTarget.com
Online Security Tools
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.192 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.