Ravindra BagaleCourses & study guides

19. Information Gathering and Scanning

Chala mitrano, kontyahi hallyacha pahila tappa mhanje mahiti gola karne – recon. Chor ghar phodnyaadhi aadhi ghar pahato: darvaje kiti, khidkya kuthe, kutra aahe ka. Attacker pan tech karto: domain konacha, subdomains kiti, kontya machines chalu aahet, konte ports ughde aahet, tyavar konti service aani konta version aahe. Aaj aapan he sagla defender chya najrene shiku – karan jo recon samjto, toch to logs madhe olkhu shakto. Ek goshta punha sangto, lakshat theva: pratyek lab fakt tumchya host-only lab madhe (Kali 192.168.56.10, Metasploitable 2 192.168.56.20). Baherchya konatyahi domain kiwa IP var he tools chalvaycha nahi. Ghabru naka, ekdum simple aahe – chala suru karuya!

What you will learn in this chapter

  • Passive vs active reconnaissance (टेहळणी), and why the difference matters legally and for detection
  • whois and dig: registration data, DNS records and zone transfers, tested on the lab's own BIND server
  • theHarvester and Recon-ng (overview) and a Maltego introduction – used only on lab data
  • Netdiscover for finding live hosts on your lab network
  • Nmap in depth: host discovery, port states, scan types, service/OS detection, NSE, timing and output files
  • Masscan for very fast port scanning – and when it is (and is not) the right tool
  • How defenders detect and block scanning: IDS alerts, firewall rules, rate limiting and closing unused ports

Lab scope for this whole chapter

Every lab below targets only your host-only network 192.168.56.0/24 (Metasploitable 2 at 192.168.56.20) and a private lab domain lab.local that you create yourself on Metasploitable 2. Do not run these tools against real domains, your institute or office network, public IPs or cloud ranges – even "passive" OSINT on a real organisation needs written permission in a professional engagement.

One-time lab setup: a lab DNS zone on Metasploitable 2. Metasploitable 2 already runs BIND (a DNS server) on port 53. We give it a small fake domain lab.local so that the dig, theHarvester, Recon-ng and Maltego labs all have a safe target. Log in to Metasploitable 2 (msfadmin / msfadmin):

# on Metasploitable 2 (very old Ubuntu – it uses /etc/init.d scripts, not 'service')
sudo nano /etc/bind/named.conf.local
#   zone "lab.local" { type master; file "/etc/bind/db.lab.local"; allow-transfer { any; }; };
sudo nano /etc/bind/db.lab.local
$TTL 300
@       IN SOA  ns1.lab.local. admin.lab.local. ( 1 3600 600 86400 300 )
@       IN NS   ns1.lab.local.
@       IN MX   10 mail.lab.local.
@       IN TXT  "v=spf1 mx -all"
ns1     IN A    192.168.56.20
www     IN A    192.168.56.20
mail    IN A    192.168.56.20
dev     IN A    192.168.56.20
vpn     IN A    192.168.56.20
sudo named-checkzone lab.local /etc/bind/db.lab.local   # test the zone before restarting
sudo /etc/init.d/bind9 restart

The allow-transfer { any; } line is a deliberate misconfiguration so you can watch a zone transfer succeed in 19.2 – and then fix it.

Concepts in this chapter

  1. 19.1Passive vs Active Recon
  2. 19.2whois and dig
  3. 19.3theHarvester and Recon-ng (Overview)
  4. 19.4Maltego Introduction
  5. 19.5Netdiscover: Finding Lab Hosts
  6. 19.6Nmap Basics: Host Discovery, Port States and Scan Types
  7. 19.7Service Versions, OS Detection and NSE Scripts
  8. 19.8Timing, Output Formats and Scan Hygiene
  9. 19.9Masscan: Very Fast Port Scanning
  10. 19.10How Defenders Detect Scanning
  11. 19.11Red vs Blue, Project and Real Incidents

The chapter recap is at the end of the last concept page.