Hands-On Ethical Hacking and Network Defense, Third Edition 4-1
Chapter 04
Footprinting and Social Engineering
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Quick Quizzes
Hands-On Ethical Hacking and Network Defense, Third Edition 4-2
Lecture Notes
Overview
This chapter describes footprinting, a technique used to find network information. A list of
several free web tools that can be used for security testers, or attackers, for footprinting is
provided. Students will learn about competitive intelligence and why it is important for an
organization. Next, they will learn how to gather more information when footprinting a
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Use Web tools for footprinting
Conduct competitive intelligence
Teaching Tips
Using Web Tools for Footprinting
1. Footprinting is a technique used to find information about a company’s network. This
2. Use Table 4-1 to describe several Web tools available for footprinting.
Conducting Competitive Intelligence
1. Explain the purpose of competitive intelligence to your class. Many companies use this
technique to find out information about their competitors. With the advent of
2. Your students must be able to identify and report all mechanisms used by others to
Analyzing a Company’s Web Site
2. Zed Attack Proxy (ZAP) is a powerful tool for UNIX and Windows OSs and can be
3. Using Figure 4-1 through Figure 4-4, describe the process of analyzing a Web site using
ZAP.
Using Other Footprinting Tools
1. Explain the Whois command and how it can be used to gather IP address and domain
information. Use Figure 4-5 to demonstrate the use of this command.
Teaching
Tip
There are several online Whois tools. Visit
http://networking.ringofsaturn.com/Tools/whois.php to find out more. This Web
site also allows you to query whois databases.
Using E-mail Addresses
1. Explain how e-mail addresses can be used either by security testers or attackers to find
more information about a particular company. When analyzing an e-mail address, you
2. Activity 4-2 describes how to use groups.google.com to determine e-mail addresses for
Using HTTP Basics
1. Recall that HTTP is a protocol that operates on port 80. As a security tester, you can use
2. Use Table 4-2 to describe the most important HTTP client error codes.
Hands-On Ethical Hacking and Network Defense, Third Edition 4-4
3. Use Table 4-3 to describe the most important HTTP server error codes.
4. Use Table 4-4 to describe the most important HTTP methods.
Teaching
Tip
Check http://www.softwareqatest.com/qatweb1.html for links to Web site
security test tools.
Other Methods of Gathering Information
1. Describe the use of cookies by Web sites. Cookies are text files generated by a Web site
3. Explain the use of Web bugs. Web bugs are one-pixel by one-pixel image files
referenced in <IMG> tags on Web pages. Web bugs usually work with cookies to
Quick Quiz 1
1. In computer jargon, the process of finding information on a company’s network is
called which of the following?
A. zone transfer
B. competitive intelligence
C. footprinting
D. whois
2. True or False: Competitive intelligence is synonymous of information gathering.
3. On what port does HTTP work?
4. Which of the following is a text file generated by a Web server and stored on a user’s
browser?
A. cookie
B. tag
C. web bug
D. port
5. A one-pixel by one-pixel image file referenced in an <IMG> tag that usually works with
a cookie is known as which of the following?
A. port
B. http
C. web bug
D. whois
Using Domain Name Service (DNS) Zone Transfers
1. Begin discussion of this section by explaining the DNS service. Words are easier to
2. Zone transfers enable you to see all hosts on a network. In other words, it gives you an
organization’s network diagram. The main tools used when performing zone transfers
Introduction to Social Engineering
1. Introduce the art of social engineering. Social engineers target the human component of
2. Describe the main tactics used by social engineers when profiling a person, including:
A. Persuasion
3. Social engineers study human behavior. They try to recognize personality traits such as
4. Explain the main techniques used by social engineers, including:
A. Urgency
5. Mention to your class that the best defense against social engineers is education.
Security professionals should train their users not to reveal company’s information to
outsiders and to always verify the identity of a caller.
The Art of Shoulder Surfing
1. Describe how an attacker can gain confidential information by shoulder surfing. The
attacker observes what you type from a nearby location. They might be very close to the
victim and look over the victim’s shoulder, or they might use binocular or high-powered
telescopes to spy from a safe distance. Shoulder surfers try to obtain the following
information:
a. Logon names
2. Explain what techniques you can use to protect yourself from shoulder surfing. These
techniques must include:
a. Avoid typing when someone is nearby
Security
Tip
Security lens are recommended when traveling to prevent shoulder surfing.
Hands-On Ethical Hacking and Network Defense, Third Edition 4-7
The Art of Dumpster Diving
1. Describe how an attacker can gain information by dumpster diving. Many companies do
not pay attention to what they dispose as trash; an eager social engineer can use this
information getting a better picture about the company. This seemingly innocuous
information can be used by social engineers on more elaborated attacks. For example,
discarded phone directories can give attacker a list of all employees’ full names. Here
are some examples of what dumpster divers look for:
a. Financial reports
b. Interoffice memos
c. Discarded computer programs
d. Company organizational charts showing managers’ names
e. Resumes of employees
2. Explain what techniques you can use to protect yourself from dumpster diving,
including:
a. Educate your users about dumpster diving
b. Use proper trash disposal
c. Format disks before disposing them
The Art of Piggybacking
1. Explain the risks of piggybacking to your students. Piggybacking is a technique used by
attackers to gain access to restricted areas without alerting security personnel. The
2. As a security professional, you should educate your users about piggybacking and show
them effective techniques to prevent it from happening. These techniques include:
Phishing
1. Describe phishing to your students. A phishing e-mail message is usually framed as an
2. Explain that spear phishing attacks are directed to specific people. The e-mail message
may appear to come from someone the receiver knows and mention a topic of mutual
Quick Quiz 2
1. What can attacker use to see all the host computers on a company’s network?
A. zone transfer
B. phishing
C. shoulder surfing
D. piggybacking
2. True or False: Social engineering uses knowledge of human nature to get information
from people.
3. A person who is skilled at reading what users enter on their keyboards would be known
as which of the following?
A. piggybacker
B. dumpster diver
C. shoulder surfer
D. social engineer
4. The art of trailing closely behind an employee who has access to an area without the
person realizing it is known as which of the following?
A. Shoulder surfing
B. Piggybacking
C. Dumpster diving
D. Phishing
5. An attack that is carried out by e-mail that combines social engineering with exploiting
vulnerabilities is known as which of the following?
A. spear phishing
B. piggybacking
C. shoulder surfing
D. zone transfer
Class Discussion Topics
1. What is a reverse DNS lookup? Can it be used when attacking a network?
2. When disposing disks or hard drives, it is recommended to format them (writing binary
zeros) at least seven times. Why seven times?
Additional Projects
1. If you post messages on newsgroups using your e-mail address, chances are that an
2. Show students how to install Web bug detector software that works with Microsoft
Internet Explorer. Ask students to research on the Internet whether the detector software
Additional Resources
2. Wget command man pages:
4. How Domain Name Servers Work:
5. Social Engineering at SecurityFocus:
Key Terms
See Glossary for definitions of Key Terms.
competitive intelligence
cookie
dumpster diving
footprinting
phishing
Technical Notes for Activities
Activity 4-1: This activity requires a Web browser and an Internet connection.
Activity 4-2: This activity requires a Web browser and an Internet connection.