Ethical Hacking #03: Reconnaissance & OSINT (Profiling a Target)
Автор: Noah explains hacking
Загружено: 2026-06-21
Просмотров: 68
Описание:
In this episode of the Ethical Hacking series, we cover passive reconnaissance and OSINT — how penetration testers build a complete target profile before firing a single packet. Zero alerts. Zero logs. The target never knows you looked.
Learn Google Dorking to find exposed files and admin panels, WHOIS and DNS recon with dig and dnsenum, automated email and subdomain harvesting with theHarvester, internet-connected device discovery on Shodan, certificate transparency log mining, and visual link analysis with Maltego.
Everything in this episode is passive — no packets sent to the target. These techniques are legal on public sources and are used by professional pentesters on every authorized engagement.
TOOLS COVERED:
• Google Dorking — site:, filetype:, intitle:, inurl:, cache: operators + Google Hacking Database (exploit-db.com/ghdb)
• whois — domain registration records, registrar, name servers, registrant email
• dig + dnsenum — DNS record enumeration, zone transfer attempts, subdomain brute-force
• theHarvester — email addresses, subdomains, IP ranges from public sources (Kali pre-installed)
• crt.sh — Certificate Transparency log search for hidden subdomains
• Shodan (shodan.io) — internet-connected device search engine, banner grabbing, vuln filters
• Maltego Community Edition — visual link analysis and relationship graph
TIMESTAMPS:
0:00 - Hook: Hackers listen before they attack
0:45 - Why passive recon is the most valuable phase
1:30 - Legal framework for this episode
2:50 - Google Dorking — operators and pentest-ready dorks
4:00 - Power dorks: filetype:xls, index.of, ext:sql, filetype:log
5:00 - WHOIS records and what they reveal
6:00 - DNS recon with dig, nslookup, and dnsenum
7:10 - theHarvester — automated intel gathering from all sources
7:55 - Certificate Transparency logs — no hidden subdomain is safe
8:30 - Shodan — the most dangerous search engine on earth
9:15 - Practical Shodan searches for pentesters
9:55 - Maltego Community Edition — visual link analysis
10:30 - Building the complete intelligence profile
11:15 - Impact: 40-80 pages of findings from free tools
11:45 - The golden rule: intelligence vs authorization
SERIES:
Episode 01 — The 5 Phases Every Hacker Follows
Episode 02 — Build Your Own Hacking Lab (Kali + Vulnerable VMs)
Episode 03 — Reconnaissance and OSINT [THIS VIDEO]
Episode 04 — Network Scanning with Nmap (coming next)
For educational purposes only. Practice against your own domain, your own infrastructure, or bug bounty targets within their defined scope.
Music: "Hitman" by Kevin MacLeod (incompetech.com) — Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)
Footage credits (CC BY 4.0 — https://creativecommons.org/licenses/by/4....
• Google Dorking demo — "Google Dorking: Unraveling the Art of Ethical Hacking" by Korben Kirscht: • Google Dorking: Unraveling the Art of Ethi...
• DNS recon demo — "DNS Enumeration | Ethical hacking from Scratch" by Nilesh Kumar Jadav: • DNS Enumeration | Ethical hacking from Scr...
• theHarvester demo — "how hackers do footprinting using The Harvester tool" by RAMJEE TECH CHANNEL: • how hackers do footprinting using The Harv...
• Shodan demo — "Getting Started and Having Fun With The Shodan Search Engine" by Lawrence Systems: • Getting Started and Having Fun With The Sh...
HASHTAGS:
#ethicalhacking #cybersecurity #osint #reconnaissance #shodance #penetrationtesting #informationsecurity
TAGS:
ethical hacking, OSINT, reconnaissance, Google dorking, theHarvester, Shodan, Maltego, cybersecurity tutorial, passive reconnaissance, DNS enumeration, whois, dig, dnsenum, certificate transparency logs, crt.sh, penetration testing, information gathering, hacking tutorial, network security, ethical hacker, kali linux, pentest, bug bounty, infosec, cyber security, OSINT tools, subdomain enumeration, google hacking database, internet security, passive recon, target profiling, security research, shodan tutorial, maltego tutorial, theharvester kali, google dorking tutorial, cyber threat intelligence
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: