0% found this document useful (0 votes)
12 views3 pages

Reconnaissance and OSINT in Cybersecurity

Uploaded by

Demian De silva
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views3 pages

Reconnaissance and OSINT in Cybersecurity

Uploaded by

Demian De silva
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

1) What is Reconnaissance?

 The phase of gathering information about a target to identify vulnerabilities,


either actively or passively
2) What is Passive Reconnaissance?

 Gathering data without direct interaction, using public sources to avoid


detection.
3) Research on OSINT (Open-Source Intelligence) tools and list down the
important details you found-[Link]
intelligence/ (you can refer other resources as well)

 theHarvester: Collects emails, subdomains, and IPs from public sources.


 Shodan: Searches for internet-connected devices.
 Maltego: Maps relationships using data from multiple sources.

4) Surf LinkedIn to find out a vulnerable job description posted which may
reveal sensitive data in the company like the network devices and the
operating systems used in the infrastructure and list down the details you
found
About the job

About Gapstars

Gapstars is a Netherlands-based software development services provider that builds remote, agile teams in Sri
Lanka and Portugal for innovative tech companies. Today, we are home to 220+ TechStars and innovative minds,
turning scalable software into performance products that shape the future. Our partners are highly ambitious tech
companies that are looking to conquer their respective markets.

The Role

We are looking for an experienced Network Architect to help us build best-in-class, web hosting infrastructures
within Europe.

You will be building and operating the critical infrastructure behind hundreds of thousands of online services.
Together with an international team of like-minded professionals, you will be continuously striving for
improvements to our environment.

Together with your team, you will be responsible for:

We seek a proactive team member with excellent communication skills, an open-source mindset, and the ability to
thrive in a small, collaborative team, demonstrating a willingness to work in a less corporate, locally-focused
environment.

Designing and building a scalable network stack, closely integrated with the host (KVM, CloudStack, OpenStack)

The security, reliability, and performance of our network services

Advocating and adopting infrastructure as code best practices (or defining them).

Continuous improvement of our practices, processes, and technology stack.

Sharing success and learning from failure. We support a blameless culture.


Participating in on-call rotations for incident response.

Our main technology stack:

 Automation: GitLab CI/CD, Bash, Python, Ansible and Kubernetes

 Network: IPv6-first, EVPN, VXLAN, FRR, Cumulus Linux, Juniper

 Cloud infrastructure: CloudStack, KVM, Ceph , or OpenStack

Hard Skills

 8+ years of relevant work experience

 Expert-level knowledge of network administration at scale in a Linux environment

 Strong scripting and automation skills such as Python, Ansible, Puppet, etc.

 Familiarity with virtualization technology (KVM, Qemu, libvirt) is beneficial.

 Experience with network devices and network layers.

 Knowledge of, and experience with running a cloud computing platform (we use CloudStack or OpenStack)

"Gapstars is committed to a diverse and inclusive workplace. We are an equal-opportunity employer and do not
discriminate based on race, national origin, gender, disability, or age. Your personal information collected during
the application process is handled following our privacy policy and used exclusively for recruitment and hiring
purposes only"

Reveled info
Technology Stack: The posting lists specific technologies:

Automation: GitLab CI/CD, Bash, Python, Ansible, Kubernetes


Network Protocols and Devices: IPv6, EVPN, VXLAN, FRR, Cumulus Linux,
Juniper
Cloud Infrastructure: CloudStack, KVM, Ceph, OpenStack

5) Why is it important for companies to limit the amount of sensitive


information disclosed in public job descriptions, and what are some best
practices to avoid revealing too much?¨
WHY?
 Data Reduces Exposure to Attacks: Specific details (e.g., OS types, network
devices) can help attackers identify vulnerabilities to exploit.
 Prevents Targeted Social Engineering: Revealing internal structures aids
attackers in crafting phishing or impersonation attacks aimed at employees.
 Protects Company Infrastructure: Disclosing security tools or configurations
can allow attackers to plan attacks that bypass these defenses.
WHAT COULD BE DONE;
 Use General Descriptions: Instead of specific product names (e.g., Cisco ASA),
use generic terms like “network firewall.”
 Avoid Software Version Numbers: Only mention required skills without listing
exact software versions.
 Limit Detailed Infrastructure Info: Avoid references to specific internal
technologies; instead, focus on general technical competencies.

6) Practice the advance google searching methods given in the PDF in LMS
and try to find more commands

Common questions

Powered by AI

The essential skills include expert-level knowledge of network administration in a Linux environment, strong scripting capabilities with tools like Python and Ansible, and familiarity with virtualization technologies such as KVM and libvirt. Key technologies include GitLab CI/CD, Bash, Kubernetes, IPv6, EVPN, VXLAN, FRR, Cumulus Linux, Juniper, CloudStack, and OpenStack .

The role requires both advanced technical skills and a proactive, collaborative mindset. Technical expertise is mandatory for designing and building scalable, secure network infrastructures using advanced technologies. Simultaneously, collaboration skills are essential for working within an international team, promoting a blameless culture, and contributing to continuous improvements .

If sensitive information in a job posting leads to a cyber attack, the company may face data breaches, financial loss, and reputational damage. The exposure of confidential information can affect operations, while repairing the damage and implementing additional security measures can incur significant costs. Furthermore, the company's stakeholder trust may diminish due to perceived negligence in protecting sensitive information .

A 'blameless culture' encourages team members to share successes and learn from failures without fear of negative repercussions. This fosters open communication, where employees feel safe to experiment and innovate. It supports problem-solving through collaborative and transparent discussions, leveraging collective knowledge to improve strategies and technologies continuously .

Precautions include avoiding specifics that disclose network setups or security measures, using abstract language for technology requirements, and withholding any sensitive configurations or internal processes that could be exploited by competitors or bad actors conducting reconnaissance .

Disclosing detailed technological information in job postings poses several risks: it reduces exposure to attacks by identifying vulnerabilities, facilitates targeted social engineering by revealing internal structures, and jeopardizes the protection of company infrastructure by exposing security tools or configurations .

Implementing "infrastructure as code" best practices ensures consistency, reliability, and scalability in infrastructure management. It allows automated and repeatable infrastructure provisioning, thereby reducing human errors, improving efficiency through automation, and facilitating easier recovery and auditing processes .

Passive reconnaissance is advantageous as it allows attackers to gather data without direct interaction, minimizing the risk of detection. This minimizes the risk of defensive actions from the target and allows attackers to aggregate publicly available information to identify vulnerabilities clandestinely .

General descriptions prevent attackers from targeting known vulnerabilities. By using generic terms like “network firewall” instead of specific brands, companies reduce the risk of exposing specific technologies that attackers could exploit based on previously known weaknesses or vulnerabilities .

Organizations can utilize OSINT tools to gather intelligence proactively: theHarvester can collect potential exposure data such as emails and IPs, Shodan can be used to identify vulnerabilities in internet-connected devices, and Maltego can map relationships from multiple data sources to visualize potential threat vectors .

You might also like