19. Information Gathering and Scanning
Chala mitrano, kontyahi hallyacha pahila tappa mhanje mahiti gola karne – recon. Chor ghar phodnyaadhi aadhi ghar pahato: darvaje kiti, khidkya kuthe, kutra aahe ka. Attacker pan tech karto: domain konacha, subdomains kiti, kontya machines chalu aahet, konte ports ughde aahet, tyavar konti service aani konta version aahe. Aaj aapan he sagla defender chya najrene shiku – karan jo recon samjto, toch to logs madhe olkhu shakto. Ek goshta punha sangto, lakshat theva: pratyek lab fakt tumchya host-only lab madhe (Kali 192.168.56.10, Metasploitable 2 192.168.56.20). Baherchya konatyahi domain kiwa IP var he tools chalvaycha nahi. Ghabru naka, ekdum simple aahe – chala suru karuya!
What you will learn in this chapter
- Passive vs active reconnaissance (टेहळणी), and why the difference matters legally and for detection
- whois and dig: registration data, DNS records and zone transfers, tested on the lab's own BIND server
- theHarvester and Recon-ng (overview) and a Maltego introduction – used only on lab data
- Netdiscover for finding live hosts on your lab network
- Nmap in depth: host discovery, port states, scan types, service/OS detection, NSE, timing and output files
- Masscan for very fast port scanning – and when it is (and is not) the right tool
- How defenders detect and block scanning: IDS alerts, firewall rules, rate limiting and closing unused ports
Lab scope for this whole chapter
Every lab below targets only your host-only network 192.168.56.0/24 (Metasploitable 2 at 192.168.56.20) and a private lab domain lab.local that you create yourself on Metasploitable 2. Do not run these tools against real domains, your institute or office network, public IPs or cloud ranges – even "passive" OSINT on a real organisation needs written permission in a professional engagement.
One-time lab setup: a lab DNS zone on Metasploitable 2. Metasploitable 2 already runs BIND (a DNS server) on port 53. We give it a small fake domain lab.local so that the dig, theHarvester, Recon-ng and Maltego labs all have a safe target. Log in to Metasploitable 2 (msfadmin / msfadmin):
# on Metasploitable 2 (very old Ubuntu – it uses /etc/init.d scripts, not 'service')
sudo nano /etc/bind/named.conf.local
# zone "lab.local" { type master; file "/etc/bind/db.lab.local"; allow-transfer { any; }; };
sudo nano /etc/bind/db.lab.local
$TTL 300
@ IN SOA ns1.lab.local. admin.lab.local. ( 1 3600 600 86400 300 )
@ IN NS ns1.lab.local.
@ IN MX 10 mail.lab.local.
@ IN TXT "v=spf1 mx -all"
ns1 IN A 192.168.56.20
www IN A 192.168.56.20
mail IN A 192.168.56.20
dev IN A 192.168.56.20
vpn IN A 192.168.56.20
sudo named-checkzone lab.local /etc/bind/db.lab.local # test the zone before restarting
sudo /etc/init.d/bind9 restart
The allow-transfer { any; } line is a deliberate misconfiguration so you can watch a zone transfer succeed in 19.2 – and then fix it.
Concepts in this chapter
- 19.1Passive vs Active Recon
- 19.2whois and dig
- 19.3theHarvester and Recon-ng (Overview)
- 19.4Maltego Introduction
- 19.5Netdiscover: Finding Lab Hosts
- 19.6Nmap Basics: Host Discovery, Port States and Scan Types
- 19.7Service Versions, OS Detection and NSE Scripts
- 19.8Timing, Output Formats and Scan Hygiene
- 19.9Masscan: Very Fast Port Scanning
- 19.10How Defenders Detect Scanning
- 19.11Red vs Blue, Project and Real Incidents
The chapter recap is at the end of the last concept page.