0% found this document useful (0 votes)
13 views17 pages

Recon Methodology for Penetration Testing

Uploaded by

turkeyisbiard
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views17 pages

Recon Methodology for Penetration Testing

Uploaded by

turkeyisbiard
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CAT RELOADED

DIFFERENT METHODOLOGY
TO RECON TARGETS

~$Eslam Akl
2020
$~:whoami
eslam3kl

Penetration tester
CAT Reloaded Cyber Security member
Python script lover, Technical blogger and Vuln
machine attacker
$~:Agenda
Hunting & Penetration testing Steps.
Recon Types.
Before & After Recon.
Recon based on SCOPE.
Small Scope required information
Medium Scope required information
Large Scope required information
Recommended options.
Simple Methodology
Automation framework 3klcon v1.0
Practice on real target.
Juicy links and resources.
Hunting & Penetration testing Steps:

Recon / Information Gathering


Scanning
Vuln. Assessment
Post-Exploitation
Reporting
Recon Types:

1. Passive Recon
Collecting information about the target without any type
of interaction with it.
> Scan web application itself ! We don’t do that here D:

2. Active Recon
Scan the web application domain, subdomains,
acquisitions, servers, etc
> Actually, we do that here :)
Before Recon After Recon
Company name Subdomains
Available scope ASN&Acquisitions
User credentials Service info
to login (more Database info
Backend technology
than account)
used
Overview about the
Information
company business,
Exposure
works and logic
Interesting
Information from directories&
program page Endpoints
related to Juicy links which
security purposes may be vulnerable
More and more
Recon based SCOPE

Small Scope Target > domain or subdomain


Ex. [Link] / [Link] / [Link]

Medium Scope Target > list of subdomains


Ex. *.[Link]

Large Scope Target > All website related to the


company is in scope
Small Scope required information
! All processes here will be performed on specific subdomain

Directory enum. Waybackurls enum.


GitHub Dorking Parameter discovery
Server enum. Automation vulnerability
Database enum. scanning
Google dorking for JS file analysis
sensitive files Backend enum.
Extract juicy WAF detection
vulnerable links by GitHub search links
GF-Patterns Port scan
Medium Scope required information
! All processes here will be performed on all subdomains

List of subdomains Waybackurls enum.


Subdomains takeover Parameter discovery
Misconfiguration in Automation vulnerability
Storage vuln (S3 scanning
buckets) JS file analysis
Directory enum. Backend enum.
GitHub Dorking Search Engine
GitHub search links discovery(Shodan, Spyse,
Server enum. Censys, etc)
Google dorking for Port scan
sensitive files WAF detection
Database enum.
Large Scope required information
! All processes here will be performed on all targets

Seeds/Roots Waybackurls enum.


ASN to get IP ranges Parameter discovery
Acquisitions Automation vulnerability
DNS & SSL enum. scanning
List of subdomains JS file analysis
Subdomains takeover Backend enum.
Misconfiguration in Search Engine discovery
Storage vuln (S3 (Shodan, Spyse, Censys, etc)
buckets) Port scan
Directory enum. WAF detection
GitHub Dorking Database enum.
GitHub search links Server enum.
sensitive files Google dorking for
Simple Methodology
Recommended options

Don’t perform all this steps MANUALLY!


Automate it <3

Let your remote machine discover


vulnerabilities while sleeping. VPS machines
via Amazon or Google

Stay in touch with new tools and technologies


to update your framework! Update it every week
<3

Use bash or python to script any process which


may take much time like using regex to extract
special pattern of data
3klcon v2.0 Automation Recon framework

Link: [Link]
That’s enough !

Let’s
PRACTICE !!
Juicy references and resources.

GitHub Dorking
[Link]
sensitive-data-exposure/

Js analysis
[Link]
javascript-for-pen-testers-and-bug-bounty-hunters-f1cb1a5d5288

Just another recon methodology from jhaddix


Just another Recon Guide for Pentesters and Bug Bounty Hunters |
Offensity

Bug bounty hunting methodology v4.0 from jhaddix (Recommended)


[Link]

Active recon by using Nmap, Metasploit, etc


[Link]
recon-active-information-gathering-and-vulnerability-search/
Don’t forget !
Google
Is your friend <3
Thank you <3

Stay in Touch !

Medium Blog | GitHub | Twitter

You might also like