SlideShare a Scribd company logo
INFORMATION GATHERING
IN A PENTEST
By : Syarif
@fl3xu5
Cybercrime Investigation Center Mabes Polri
Jakarta, 28 Januari 2012
Agenda
About Pentest ( Penetration Testing )
Pentest Phase
How Important do Information Gathering
Passive & Active Information Gathering
Google Hack
Netcraft
Whois
host
dig
About Pentest ( Penetration Testing )
A method to evaluate the security of computer system / network
Practice ( attacking ) an IT System like a ‘hacker’ do
Find a security holes ( systemic weaknesses )
By pass security mechanism
compromise an Organization’s IT System Security
Must have a permission from IT System owner
~ The Person is called a Pentester ~
Pentest Phase
Information Gathering
Vulnerability Analysis
Exploitation
Post Exploitation
Reporting
How Important do Information Gath.
Information Gath. Chance of Successful attack~
Passive & Active Information Gathering
Passive Information Gathering Active Information Gathering
Google Hacking
Netcraft
Whois
Nslookup
Port Scanning
Service Scanning
Nmap
Metasploit
Google Hack
was introduced by Johnny Long
based on google basic usage information :http://
www.google.com/help/basics.html!
More : http://www.google.com/help/
operators.html
Google Hack ( cont’d )
Google basic search help
Google Hack ( cont’d )
Operators and More Search help
Google Hack ( cont’d )
Examples :
Google Hack ( cont’d )
Examples :
Google Hack ( cont’d )
Examples :
Google Hack ( cont’d )
Other Examples :
Google Hack ( cont’d )
Other Examples :
Google Hack ( cont’d )
More Examples :
Netcraft
an Internet monitoring company based on England
Uptimes
OS detection
web server
Netcraft ( cont’d )
Whois
host
dig
REFERENCES
http://www.pentest-standard.org/index.php/
PTES_Technical_Guidelines
http://www.metasploit.com/about/penetration-
testing-basics/
Metasploit The Penetration Tester’s Guide : David
Kennedy , Jim O’Gorman, Devon Kearns, Mati
Aharoni
GHDB , http://johnny.ihackstuff.com/ghdb/

More Related Content

PDF
iCrOSS 2013_Pentest
PDF
Pentesting with Metasploit
PPTX
Introduction To Exploitation & Metasploit
PPTX
Metasploit
ODP
Multi-Agent System for APT Detection
PPTX
CSE-Ethical-Hacking-ppt.pptx
PPTX
How to Use Crowd-Sourced Threat Intelligence to Stop Malware in its Tracks
PPTX
Metasploit
iCrOSS 2013_Pentest
Pentesting with Metasploit
Introduction To Exploitation & Metasploit
Metasploit
Multi-Agent System for APT Detection
CSE-Ethical-Hacking-ppt.pptx
How to Use Crowd-Sourced Threat Intelligence to Stop Malware in its Tracks
Metasploit

What's hot (20)

PDF
THOR Apt Scanner
PPTX
Eliz seminar
PPT
Setup Your Personal Malware Lab
PDF
Understanding CryptoLocker (Ransomware) with a Case Study
PPTX
Investigating Malware using Memory Forensics
PPTX
Malware analysis
PPTX
Lannguyen-Detecting Cyber Attacks
PDF
Understanding The Known: OWASP A9 Using Components With Known Vulnerabilities
PDF
Real life hacking101
PDF
Black Hat Europe 2016 Survey Report (FFRI Monthly Research Dec 2016)
PDF
Malware Analysis Using Free Software
PPTX
Reversing malware analysis training part10 exploit development basics
PPTX
Pentesting with linux
PPTX
Humla workshop on Android Security Testing - null Singapore
PPTX
Introduction to Metasploit
 
PPTX
Introduction to metasploit
 
PPTX
Metasploit
PPTX
Hunting Ghost RAT Using Memory Forensics
PDF
Michelle K Webster: Malware - Cryptolocker Research Final
PPT
Malware forensics
THOR Apt Scanner
Eliz seminar
Setup Your Personal Malware Lab
Understanding CryptoLocker (Ransomware) with a Case Study
Investigating Malware using Memory Forensics
Malware analysis
Lannguyen-Detecting Cyber Attacks
Understanding The Known: OWASP A9 Using Components With Known Vulnerabilities
Real life hacking101
Black Hat Europe 2016 Survey Report (FFRI Monthly Research Dec 2016)
Malware Analysis Using Free Software
Reversing malware analysis training part10 exploit development basics
Pentesting with linux
Humla workshop on Android Security Testing - null Singapore
Introduction to Metasploit
 
Introduction to metasploit
 
Metasploit
Hunting Ghost RAT Using Memory Forensics
Michelle K Webster: Malware - Cryptolocker Research Final
Malware forensics
Ad

Viewers also liked (6)

PDF
My pwk & oscp journey
PDF
Prepare Yourself to Become Infosec Professional
PDF
Pentest with Metasploit
PDF
Wireless LAN Security-Bimtek Kominfo
PDF
Social Network Security & Backdooring email
My pwk & oscp journey
Prepare Yourself to Become Infosec Professional
Pentest with Metasploit
Wireless LAN Security-Bimtek Kominfo
Social Network Security & Backdooring email
Ad

Similar to Information gath (20)

PPTX
Penetration testing overview
PDF
technical-information-gathering-slides.pdf
PPTX
Penetration testing reporting and methodology
PDF
How to Conduct Penetration Testing for Websites.pptx.pdf
PDF
Penetrating Networks for CompTIA Pentest+
DOCX
Vulnerability Assessment and Penetration Testing Framework by Falgun Rathod
PPTX
Physical-Penetration-Presentation-Tina-Ellis.pptx
PDF
Vulnerability Assessment and Penetration Testing using Webkill
DOCX
Syed Ubaid Ali Jafri - Black Box Penetration testing for Associates
PDF
Complete Guide to Pentesting Network for Beginners.pdf
PPTX
NETWORK PENETRATION TESTING
PDF
What is Penetration & Penetration test ?
PDF
Penetration Testing Service in India Senselearner .pdf
PPTX
Phases of penetration testing
PPTX
PPT
Penetration testing, What’s this?
PPTX
Ceh intro
PDF
DTS Solution - Penetration Testing Services v1.0
PDF
Itis pentest slides hyd
PDF
Ethical hacking
Penetration testing overview
technical-information-gathering-slides.pdf
Penetration testing reporting and methodology
How to Conduct Penetration Testing for Websites.pptx.pdf
Penetrating Networks for CompTIA Pentest+
Vulnerability Assessment and Penetration Testing Framework by Falgun Rathod
Physical-Penetration-Presentation-Tina-Ellis.pptx
Vulnerability Assessment and Penetration Testing using Webkill
Syed Ubaid Ali Jafri - Black Box Penetration testing for Associates
Complete Guide to Pentesting Network for Beginners.pdf
NETWORK PENETRATION TESTING
What is Penetration & Penetration test ?
Penetration Testing Service in India Senselearner .pdf
Phases of penetration testing
Penetration testing, What’s this?
Ceh intro
DTS Solution - Penetration Testing Services v1.0
Itis pentest slides hyd
Ethical hacking

Recently uploaded (20)

PPTX
Unit 4 Skeletal System.ppt.pptxopresentatiom
PDF
Complications of Minimal Access Surgery at WLH
PPTX
Radiologic_Anatomy_of_the_Brachial_plexus [final].pptx
PDF
Chinmaya Tiranga quiz Grand Finale.pdf
PDF
GENETICS IN BIOLOGY IN SECONDARY LEVEL FORM 3
PDF
A GUIDE TO GENETICS FOR UNDERGRADUATE MEDICAL STUDENTS
PPTX
History, Philosophy and sociology of education (1).pptx
PDF
ChatGPT for Dummies - Pam Baker Ccesa007.pdf
PPTX
UV-Visible spectroscopy..pptx UV-Visible Spectroscopy – Electronic Transition...
PDF
Practical Manual AGRO-233 Principles and Practices of Natural Farming
PPTX
Onco Emergencies - Spinal cord compression Superior vena cava syndrome Febr...
PDF
Classroom Observation Tools for Teachers
PDF
A systematic review of self-coping strategies used by university students to ...
PPTX
Tissue processing ( HISTOPATHOLOGICAL TECHNIQUE
PDF
Paper A Mock Exam 9_ Attempt review.pdf.
PDF
LDMMIA Reiki Yoga Finals Review Spring Summer
PDF
Weekly quiz Compilation Jan -July 25.pdf
PDF
Black Hat USA 2025 - Micro ICS Summit - ICS/OT Threat Landscape
PPTX
Final Presentation General Medicine 03-08-2024.pptx
DOC
Soft-furnishing-By-Architect-A.F.M.Mohiuddin-Akhand.doc
Unit 4 Skeletal System.ppt.pptxopresentatiom
Complications of Minimal Access Surgery at WLH
Radiologic_Anatomy_of_the_Brachial_plexus [final].pptx
Chinmaya Tiranga quiz Grand Finale.pdf
GENETICS IN BIOLOGY IN SECONDARY LEVEL FORM 3
A GUIDE TO GENETICS FOR UNDERGRADUATE MEDICAL STUDENTS
History, Philosophy and sociology of education (1).pptx
ChatGPT for Dummies - Pam Baker Ccesa007.pdf
UV-Visible spectroscopy..pptx UV-Visible Spectroscopy – Electronic Transition...
Practical Manual AGRO-233 Principles and Practices of Natural Farming
Onco Emergencies - Spinal cord compression Superior vena cava syndrome Febr...
Classroom Observation Tools for Teachers
A systematic review of self-coping strategies used by university students to ...
Tissue processing ( HISTOPATHOLOGICAL TECHNIQUE
Paper A Mock Exam 9_ Attempt review.pdf.
LDMMIA Reiki Yoga Finals Review Spring Summer
Weekly quiz Compilation Jan -July 25.pdf
Black Hat USA 2025 - Micro ICS Summit - ICS/OT Threat Landscape
Final Presentation General Medicine 03-08-2024.pptx
Soft-furnishing-By-Architect-A.F.M.Mohiuddin-Akhand.doc

Information gath