Best practices
In this chapter, we focused on different reconnaissance attacks. When it comes to DNS, enumerating your domain on a public DNS server cannot be avoided. However, protecting against zone transfers is critical to keeping your domain secure. You can leverage further DNS protections such as DNSSEC for this, which requires domain name lookups to be authenticated. You can further protect your domain by separating your internal and external DNS servers. The internet is filled with DNS security articles that can help guide you.
In this chapter, you saw the power of Shodan. Many people consider Shodan an offensive tool. However, look at Shodan as a great tool that can discover publicly accessible assets within your organization. Rather than blocking Shodan, integrate it into your security hardening process. It will ensure that you protect your public-facing assets correctly.
Cloud assets can be difficult to control; however, major cloud providers provide security suites...