wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

Reconnaissance

profile
Jermin Shaikh
Aug 30, 2022
0 Likes
0 Discussions
180 Reads

Reconnaissance is the best practice for discovering and collecting information about a system. Reconnaissance derives from military language, which refers to a mission to obtain information from enemy territory.

HOW DOES RECONNAISSANCE WORK;

Reconnaissance generally follows seven steps:

  1. Collect initial information
  2. Determine the network range
  3. Identify active machines
  4. Find access points and open ports 
  5. Fingerprint the operating system
  6. Discover services on ports
  7. Map the network

Using these steps, an attacker will aim to gain the following information about a network:

  • File permissions
  • Running network services
  • OS platform
  • Trust relationships
  • User account information 

One of the most common techniques involved with reconnaissance is port scanning, which sends data to various TCP and UDP (user datagram protocol) ports on a device and evaluates the response. 

THE TWO PHASES OF RECONNAISSANCE IN ETHICAL HACKING ARE AS FOLLOWS;

  • Active reconnaissance
  • Passive reconnaissance

1. Active reconnaissance:-

Dynamic reconnaissance is the kind of reconnaissance where you assemble data about the framework/application by straightforwardly connecting with the framework. At the point when you utilize Active reconnaissance, there is a high possibility that some data like your IP address is known by the framework you are attempting to accumulate the data about. 

2. Passive reconnaissance:-

On account of Passive reconnaissance, you assemble data without interfacing with the framework/application you are attempting to think about. You accumulate data through web indexes or freely available reports. At the point when you utilize Passive reconnaissance, it is highly unlikely that the framework would know your IP address.

HOW TO PREVENT RECONNAISSANCE?

Organizations can use penetration testing to determine what their network would reveal in the event of a reconnaissance attack. Organizations can outsource the work by hiring security testing professionals to carry out penetration testing, vulnerability assessment, compliance testing, etc.

During testing, organizations can deploy port scanning tools (which scan large networks and determine which hosts are up) and vulnerability scanners (which find known vulnerabilities in the network).

SIEM solutions can also detect source IPs that are running a port scanning tool in your network.

Steps followed in reconnaissance –

  • Accumulate inceptive data 
  • Decide the range of the network 
  • Recognize all active machines 
  • Get hold of the OS being used 
  • Uniquely mark the working framework 
  • Reveal services used on ports 
  • Understand the network map

An example used in Reconnaissance:-

Reconnaissance is mainly used for gaining information by visual observation or other detection methods, about the activities and resources of an enemy or potential enemy, or about the meteorologic, hydrographic, or geographic characteristics of a particular area.

 


Comments ()


Sign in

Read Next

Tiranga - Abbas Haveliwala

Blog banner

Krishna Rao SAP ID--53003230076

Blog banner

Raid and levels of raid.

Blog banner

Rain bow

Blog banner

Virtual memory in windows

Blog banner

Memory Hierarchy

Blog banner

Not anti-social, but pro-solitude

Blog banner

Save Girl Child

Blog banner

Top 3 Places To Stay In Vienna

Blog banner

Booting Process In Operating System

Blog banner

Networking 101: How to Build Meaningful Connections in College

Blog banner

Linux Memory Management

Blog banner

Modern operating systems (OS)

Blog banner

The Five Steps of Data Science

Blog banner

Concurrency:Deadlock and Starvation

Blog banner

Different memory allocation strategies

Blog banner

Threads in OS

Blog banner

Memory management and virtual memory

Blog banner

Chicken Dum Biryani

Blog banner

Memory Management

Blog banner

Real-Time Operating Systems (RTOS) Deep Explanation

Blog banner

Operating system

Blog banner

Blockchain technology: security risk and prevention

Blog banner

operating system

Blog banner

FIREWALL

Blog banner

Environmental Management using GIS

Blog banner

Predictive Analytics: How Data Science Predicts Trends(Weather ,Stock Market,Sales Forecasting ).

Blog banner

Simple STEM Activities for Toddlers That Spark Curiosity

Blog banner

CRISP-DM Methodology

Blog banner

Power of words

Blog banner

VIRTUAL MACHINES

Blog banner

ProofHub

Blog banner

TRELLO

Blog banner

Hash password! Is it really secured?

Blog banner

Mumbaicha Dabbawalla

Blog banner

Search Marketing In 2026: From Keywords To Credibility And User Intent

Blog banner

Brain wash of social media

Blog banner

Memory Management

Blog banner

Diwali

Blog banner

Objectives and functions of Operating System...

Blog banner

Domain Name System

Blog banner

MYNTRA

Blog banner