- This topic has 8 replies, 6 voices, and was last updated 10 years, 3 months ago by
COm_BOY.
-
AuthorPosts
-
-
October 1, 2010 at 11:51 am #5640
Determ
ParticipantHello.
I haven’t noticed any course or book about only information gathering (infrastructure & personal data). Also there is some non-official classes of penetration expertises (like exploits development, social engineering, malware analysis, forensics, wireless, etc.). Why is not Information Gathering a class for itself?
-
October 1, 2010 at 1:52 pm #35501
dynamik
ParticipantDo a search for open source information gathering. There’s a ton of resources already available. Chris Gates has a good presentation that’s an overview of a lot of the tools that are out there. Google Hacking by Johnny Long is an excellent written resource. Most ethical hacking/penetration testing books contain recon chapters that adequately cover common tools and techniques.
-
October 1, 2010 at 1:57 pm #35502
dante
ParticipantInformation Gathering is a vital part of penetration testing and is covered in detail in good security books(Hacking exposed ?) and in good security courses(OSCP?).. I admit that I dont know a book dedicated to information gathering.. But if you are looking for advances in this area you should probably start with Chris Gates presentation on open source intelligence gathering at brucon…
Update
@dynamik damn you are fast … -
October 1, 2010 at 2:44 pm #35503
ziggy_567
ParticipantCheck out SANS 550 – Information Reconnaissance: Competitive Intelligence and Online Privacy. It is a one day class that talks about nothing but recon.
There’s even a review on EH-Net:
-
October 4, 2010 at 10:49 am #35504
Determ
ParticipantGoogling with “Open Source IG” has given me lots of results. It kept me busy for weekend. 8)
Before posting I was wondering how to go “beyond” information gathering, since I’m doing OSCP and already saw Chris Gates presentation.
So thanks for replies, they have given me more to work on.
-
October 4, 2010 at 2:09 pm #35505
MaXe
ParticipantThere’s a good chapter about Information Gathering in The Penetration Testers Open Source Toolkit vol. 2 (book).
Tactical Exploitation by Valsmith and HD Moore has a good part too:
http://blog.attackresearch.com/publications/hdmoore_valsmith_tactical_paper.pdfAnd of course: Information Gathering with MaXe – Part 1 (video):
http://www.youtube.com/watch?v=1nd6vAz4SOwThat’s just a few resources to get you started 😉
Best regards,
MaXe -
October 12, 2010 at 4:56 pm #35506
COm_BOY
Participantdo try Maltego v3 Community Edition …… its awsome
-
October 17, 2010 at 11:54 am #35507
Determ
ParticipantI have tried Maltego V3, great tool.
One questions: Is it possible to get a good book which will teach python from basic, but has to be focused more on python scripting for data, text and web mining?
-
October 17, 2010 at 8:26 pm #35508
COm_BOY
Participant@Determ wrote:
I have tried Maltego V3, great tool.
One questions: Is it possible to get a good book which will teach python from basic, but has to be focused more on python scripting for data, text and web mining?
Cant say much on that , check out amazon.com and check the comments of readers . Along with that do check out LinuxCBT Python Programing edition ( Video Training ) . I dont think its that expensive .
-
-
AuthorPosts
- You must be logged in to reply to this topic.