Open-source information gathering
In this recipe, we will look at how to make of tools meant for online information gathering. We will cover tools that serve the purpose of gathering information with respect to Whois, domain tools, and MX mail servers. Shodan is a powerful search engine that locates drives for us over the Internet. With the help of various filters, we can find information about our targets. Among hackers, it is also called the world's most dangerous search engine.
Getting ready
We will make use of tools such as DNsenum for the purpose of Whois enumeration, find out all the IP addresses involved in a domain, and also how Shodan provides us with open-port information of the target searched.
How to do it...
The steps are as follows:
- For DNS scan, we will a tool called DNsenum. Let us start by typing the following in terminal:
dnsenum <domainname>
The output will be as shown in the following screenshot:
- We can also use the available to search for more subdomains via...