All language subtitles for 002 Information Gathering (OBJ 2.1)

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranî)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese Download
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

Instructor: The first step in the second phase

of the penetration testing methodology

is to conduct information gathering,

also known as reconnaissance.

This is when we learn all about the organization

in a systematic attempt to locate, gather, identify

and record information about our various targets

including things like hosts, servers, systems

and even employees of the organization.

Information gathering is also known

as footprinting the organization

and it includes figuring out exactly

what types of systems the organization is gonna be using

so we're able to attack them

in the third phase of our assessment,

which is the attacks and exploits phase.

Now, reconnaissance and footprinting

involves the identification, discovery

and obtaining of information

through a wide variety of tasks, goals, and outcomes.

For example, we can gather information

by using the internet,

open source research by looking at press releases,

job postings, resumes, social media sites,

as well as using Google to search around the internet.

These methods are considered passive reconnaissance

since we can attempt to gain information

about targeted computers and networks

without actively engaging with those systems.

We can also perform social engineering

which is where we attempt to trick a user

into giving us the information we need.

This can be through email attempts like phishing,

voice calls like vishing or even in-person

using deception techniques

or we may choose to go dumpster diving

where we're gonna go to the organization's physical location

and start going through their trash.

Once something is thrown to the trash

and is outside of the office,

it becomes open for anybody to access,

and we may be able to find things like usernames, phonelist,

organizational charts and other useful information

that we can use during our engagement.

Finally, we can conduct email harvesting

by collecting as many emails as we can

by crafting specialized search queries inside of Google too.

The point here is that all these techniques

are technically considered passive reconnaissance

because we're not directly engaging

with the organization's workstations or servers

like we do in our active reconnaissance phase

when we perform enumeration and fingerprinting

of their systems.

Now, during passive reconnaissance,

we're gonna be looking for specific information

at this point,

things like phone numbers, contact names,

organizational positions, email addresses,

security related information,

the type of information systems they're using,

whether they're running Windows or Linux,

or if they're using Apache or internet information services

or whatever type of web server they are using.

Most of this information is already out there

openly available online,

we just have to go and search for it.

Now, when you're working as part

of a penetration testing team, it's also important to gather

and catalog all the information you're finding

during your reconnaissance efforts

so that other members of your team can also review

what you found

and then use it during their collection efforts

or their exploitation efforts later on.

Some teams will use an internal wiki

and others will use a spreadsheet in order to list

all of the major findings that they've found.

Now, if you use a spreadsheet,

you can list each finding in its own row

and have columns going across the sheet

with additional details you collect.

For example, if I'm conducting reconnaissance

against a company

and I find that one of their former employees resumes

was posted online,

I might be able to gather some good details

about the organization's technical architecture

by looking at that resume.

For example, here's an old sample resume

that I use to make this point.

Notice that in this person's current job position

at ABC Energy,

they're listed as a Linux administration systems analyst.

As you look at their qualifications for that position,

you see that they're maintaining over 200 Linux servers

that are running Red Hat and SUSE Linux.

This is being done across three data centers.

They also tell us that they perform backup support

for VMware's ESXi servers, and this tells me

that this organization is also using virtualization

for a lot of their servers.

Now, I could continue to dissect each line of their resume

for when they worked at that company, and in this case,

it states they still work at that company currently

so the things they're listing should be fairly close

to the current infrastructure.

Now, this is just an example resume

that I like to use in my courses, so you're gonna notice

that it's pretty out of date when it talks about technology.

For example, it's saying Red Hat 4 and Windows 2003

but the point here is that you can gather

this type of information

simply by finding employee resumes online

or job postings by the organization themself.

So now that we have this resume

and we have some data from it,

we can add that to our spreadsheet.

For example, I might list the technique used

to find this information such as LinkedIn resume

and then I can add the type of assets

that I can identify from this resume,

such as the types of servers they're using

in that organization.

Next, I can add a column for the type of tool

that I'm gonna use if I wanna gather more information

and move into the enumeration phase.

For example, I might conduct an Nmap scan

of the company's public IP space and look for services

that are commonly associated with Linux servers

to see if we can find some of those 200 Red Hat servers

that are actually placed in a public facing screen subnet.

Once we do our enumeration,

we can add a column for our findings and results.

For example, I might find that there's a Red Hat server

located at 66.55.44.33

and it has ports 80, 443, and 22 open.

The next column might have the next step or test

that we're gonna want to conduct

such as a banner grabbing exercise or a vulnerability scan

or whatever it's gonna be.

By gathering the information and documenting it

in a shared spreadsheet or internal wiki,

data can then flow from one team member to another

during our penetration tests.

With larger penetration testing teams,

they're often gonna have different roles assigned

to different members of the team.

For example, you may become an information gathering ninja

so that's gonna be all you do.

Then you turn that information over to another team member

who's only focused on enumeration

and vulnerability scanning.

In turn, they take their results

and give them to one of the senior testers

who might create a custom exploit

based on the open ports and protocols

that they found during enumeration and scanning.

This allows each team member to become more specialized

in their portion of the assessment

and this can help increase the efficiency and effectiveness

of your overall penetration testing team.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.