2 hours 26 minutes

Video Transcription

Welcome back In the last video, we went over data licks and data breaches, and in this one will go through some of the posts and tools and techniques concerning systems which are exposed to the Internet.
Here you will learn what's technical knowledge would be mandatory prior to approaching these kind of Postant work, then about great search engine off Internet devices. And after that, what geolocation tool to use for eyepiece, what DNS tools to use, what other popular tools are there
and where to find the right tools for euros and investigations.
As I have mentioned, a prerequisite knowledge for this video would be that, you know, or are at least familiar with the technical I t concepts, which are pretty much involved in a system or a network admin job.
This is not to scare you away from watching this video just to better prepare you. What are we going to talk about? Also, I added python with a plus because learning Pathan is really beneficial. I have mentioned it in the prerequisites for this course, and honestly,
I also went on to learn python. Since I have been using all the tools of written in that language
and wanted to know how the tools worked and why some tools did the things the way they did them. Now I want to tell you about a great tool, cold shoulder. You can find it on their showed in that I owe address. This tool is also golden standard in search engines for devices.
But before I Seymour about showed and I would like to show you a quote from Mr Thomas Watson,
who was the chairman of IBM in the 19 forties, off the last century,
the quote goes,
I think there is a world market for maybe five computers. End quote.
Mr. Watson would be probably shocked if he saw just simple search rules out on showing that I owe
Children is a great Web tool for finding the finger brains of connected devices. Allow me to show you how it looks like
open up a browser and go to the he showed in that I owe address.
Basically, the search engine discovers devices they're connected to the Internet that includes Webcams, smart TV's refrigerators, power plants and so on.
Do is the search fielders. You have to create an account with your name and email address. I'm already logged in here, and we'll type
8.8 dot 8.8 in Search Box and click Search.
As you can see, this is a Google's DNS device with two ports open,
53 for DNS and 443 for https.
A great feature off shoulder is that it collects logging banners from all the devices, and you immediately get additional technical information about the target device. Now I will use a search fielder
all type
quotation H R
Quotation Spaceport
and enter
the results off this search filter are all the Internet devices in creation with an open RTP port? As you can see, the total result number usually I T professionals use showed in to see the exposure and the vulnerabilities off their systems. Andi, by that company's
another great tool. Similar to shoulder is a sense of that ill, which by some people is called an academic brother to show them because if it's more complicated, interface and filtering options, I would encourage you to check both of them in detail because this is like Internet device born for us. I t guys Next
I would like to mention a very important thing
that is sometimes overlooked. That's geo location,
like with exit data we mentioned in pictures. We also want to know where something is. If you have an I p off a target, you could easily find out in the targets eyepieces associated with. Let's say we'd be in service. Try to type in i p off your website and see where is it hosted.
You can try the tool i p location dot net.
When I say Dennis knows a lot, I mean that DNS has so much information in itself that it's potentially a great resource for any kind of investigation.
Besides domain names and their information, a great deal of information, for example, about a company's system can be included in the DNS records. I have listed two tools that are, I think, great. For starters,
they both have similar features, But there are also differences in Vienna's Dumpster. I like the feature off the graphic demand mapping with all the records and I P's included and Indiana Athletics. I like that it's included information like ranking in for about the domain and the Who is data. I will just briefly touch on a few more tools.
Well, Tegal, Spider Foot Recon and G. The Harvester and Sub Blister
Multi Ago is an awesome tool from Patera, which is included in the Cali Lennox operating system. This is a great tool that visualize is your findings. It has free version, which limits the utilization off its transform tools and size of the graph displayed.
But it should be large enough for researching small. Let's say companies
most able will query DNS Records who is record search engines, social networks, various online application programming interfaces or a P eyes and extract meta data that is used to find correlation ALS relationships between names,
email addresses, aliases, groups, companies, organization's websites, domains
or operating systems and so forth.
You should really buy the whole product if you are doing threat intelligence or a lot of infrastructure analysis.
Next, Spider Foot is a great reconnaissance tool that automatically queries over 100 public data sources Together Intelligence and I P addresses domain names, email addresses. It also has a useful graphic representation off findings and, of course, not only bait eyes found
but metadata, which could give you a great insight into a vulnerability off a target system.
Recon Angie is another useful tool to perform reconnaissance on the target, and it's also built in the cattle. Lennox
Ricard and G has various models in built, and it's usage somewhat resembles to that off metal split
lots of fits tools used a p I. So you won't be able to use Ricans features without them. A typical example would be to connect to Re Kon and showed in via AP I to use Ricans showed in modules. The next tool, called Harvester, is another Oh, since tool for reconnaissance that it's spring installed in the Cala Lennix.
It uses several sources off information together results and help us determine the company's perimeter.
The harvester gathers e mails, sub domains, I P's and you are else. Lastly, Sub Lister is a python tool designated to enumerates sub domains. So for website using ghosts, sub lister enumerates sub domains using many search engines such as Google, Yahoo, Bing and many more.
These tools are for the technical part of Postant investigations
to look at your company's infrastructure and they're exposed device perimeter. So, as I have mentioned and will have to mention it again, It's always good for you to be familiar with the technical and 90 concepts. Understand how the Internet works from the network's perspective.
How is BDP used? And it's a tournament system numbers
also to learn about routing website beck and stuff even. And maybe this is going to sound silly. Understand ocean cabling for inter continent connections.
Okay, this is maybe an overkill, but you understand what I'm trying to tell you now. I would like to show you a great homeland resource for all since tools that Mr Justin Nordine created.
It's called the Olsen Framework, and you can find it on the Olsen framework that can't. Let's see how it looks like
in your favorite ocean browser.
Go to the ocean framework. That common dress,
as you can see here when you click on any of the categories like such as user name,
email, address, domain name,
a lot of useful resource is will appear on the street in the form of a sub tree.
In my example, I'm interested in the whole discovery tools, so I will choose I p address
host slash Port Discovery,
and one of the tools listed is showed in which we discussed earlier searching for you. There's similar dresses I p addresses are social network details become super easy as you have all the tools available in one single interface.
It's just like a giant Olson bookmarks library.
Additionally, don't forget about get her dot com, which is a great online oh sent resource. This is why I put an emphasis on being familiar with the Python programming language.
In this lesson, we covered the basic open source intelligence tools that are used in the context off I T systems and their exposure on the Internet. In the next video, we will do a quick module summary, so see you there.

Up Next

Open Source Intelligence (OSINT) Fundamentals

In this Open Source Intelligence (OSINT) Fundamentals training course, you will gain fundamental knowledge about OSINT, who uses it, and the ethical implications of using it. Upon completion, students will have a solid understanding of OSINT.

Instructed By

Instructor Profile Image
Tino Sokic
CEO at DobarDan