2.1 Open Source Intelligence (OSINT) & Information Gathering

Key Takeaways

  • Passive reconnaissance gathers critical intelligence regarding target domain infrastructure, email formatting, employee identities, and technology stacks without sending direct packets to target systems.

  • DNS zone transfers (AXFR) over TCP port 53 replicate the full zone file; misconfigured authoritative nameservers expose the complete internal and external DNS infrastructure.

  • Advanced Google Dorking operators (such as site:, filetype:, and intitle:) discover indexed configuration files, database backups, and unauthenticated directory listings.

  • Public aggregators including Certificate Transparency logs (crt.sh), theHarvester, WHOIS databases, and Shodan reveal subdomains, IP ranges, and perimeter services without alerting target defensive controls.

Last updated: October 2026

Foundations of Passive Reconnaissance

In professional penetration testing methodologies—such as the Penetration Testing Execution Standard (PTES)—reconnaissance serves as the primary intelligence-gathering phase. Before a penetration tester transmits a single network packet directly toward target infrastructure, they perform comprehensive passive reconnaissance. Passive information gathering relies entirely on publicly accessible sources, third-party data aggregators, search engine caches, and registrar databases.

Because passive reconnaissance queries intermediary repositories rather than the target's own network interfaces, it leaves zero footprint in the target organization's Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Next-Generation Firewalls (NGFW), or Security Information and Event Management (SIEM) telemetry logs. The primary objective is to build a detailed target profile, including:

  • Registered domain names, subdomains, and associated IP address blocks
  • Authoritative Domain Name System (DNS) servers and mail routing infrastructure
  • Employee identities, organizational hierarchy, and email naming conventions
  • Leaked credentials, source code repositories, and misconfigured public cloud storage
  • Exposed infrastructure technologies, software versions, and perimeter security implementations

Mastering passive reconnaissance allows penetration testers to identify high-value targets, hidden administrative portals, and forgotten development staging environments before launching active port scans.


DNS Architecture & Record Enumeration

The Domain Name System (DNS) translates human-readable hostnames into machine-routable IP addresses. For an ethical hacker, DNS represents an invaluable directory of an organization's public and internal network topography. When an organization provisions new servers, services, or internal subnets, corresponding DNS records are configured on their authoritative nameservers.

Essential DNS Record Types

Penetration testers inspect several fundamental DNS record types during intelligence gathering:

  • A (Address): Maps a fully qualified domain name (FQDN) to a 32-bit IPv4 address.
  • AAAA (IPv6 Address): Maps a hostname to a 128-bit IPv6 address, frequently uncovering IPv6 infrastructure that lacks the strict firewall rules applied to IPv4.
  • MX (Mail Exchange): Identifies the mail servers responsible for accepting incoming email for the domain, along with priority preferences. This reveals third-party filtering appliances (such as Proofpoint or Mimecast) or self-hosted mail daemons.
  • NS (Name Server): Specifies the authoritative nameservers responsible for the domain zone. Nameservers are primary targets for zone transfer attempts.
  • TXT (Text): Holds arbitrary human or machine-readable text. TXT records frequently contain Sender Policy Framework (SPF) rules, DomainKeys Identified Mail (DKIM) public keys, and third-party domain verification strings (such as Google Workspace, Microsoft 365, or Atlassian tokens) that expose internal SaaS adoption.
  • SOA (Start of Authority): Contains core administrative data regarding the DNS zone, including the primary master nameserver, the administrator's email address (with the first dot replacing an @), the zone serial number, and zone refresh timers.
  • CNAME (Canonical Name): Creates an alias pointing one hostname to another canonical domain name, often revealing external cloud resources, CDN buckets (such as Amazon CloudFront or S3), or SaaS hosts.
  • PTR (Pointer): Maps an IP address back to a canonical hostname in reverse lookup zones (in-addr.arpa), useful during active subnet sweeps.

Manual DNS Queries with dig, host, and nslookup

Linux environments provide powerful command-line utilities to query DNS servers directly. The most versatile tool is dig (Domain Information Grok):

# Query all standard records for a target domain
dig target.com ANY

# Query specific record types (e.g., Mail Exchangers or Nameservers)
dig target.com MX +noall +answer
dig target.com NS +noall +answer

# Query a specific public DNS resolver (e.g., Cloudflare 1.1.1.1 or Google 8.8.8.8)
dig @1.1.1.1 target.com A +noall +answer

# Extract TXT records to evaluate SPF and domain verification strings
dig target.com TXT +short

The host utility provides a streamlined alternative for fast lookups:

# Discover IP addresses and mail servers
host target.com

# Discover nameservers
host -t ns target.com

# Perform reverse lookup on an IP address
host 198.51.100.25
Record TypeInspection CommandPrimary Pentest Intelligence Utility
A / AAAAdig target.com A +shortMaps external IPv4 and IPv6 perimeter server addresses
MXdig target.com MX +shortIdentifies mail security gateways, cloud mail hosts, and MX priorities
NSdig target.com NS +shortIdentifies authoritative nameservers targeted for zone transfers
TXTdig target.com TXT +shortExposes SPF authorization blocks, third-party SaaS validations, and subnets
SOAdig target.com SOA +noall +answerExposes administrator contact email and zone update serial numbers
CNAMEhost -t cname sub.target.comUncovers dangling DNS aliases susceptible to subdomain takeover

DNS Zone Transfers (AXFR) and Subdomain Discovery

The Asynchronous Transfer Full Range (AXFR) Mechanism

Authoritative DNS architecture typically features a primary (master) nameserver and one or more secondary (slave) nameservers to maintain high availability and geographic redundancy. To synchronize the zone database across nameservers, the DNS protocol defines the AXFR (Asynchronous Transfer Full Range) replication protocol under RFC 5936.

While standard DNS lookups occur over UDP port 53 using single-packet request/response pairs, a DNS zone transfer requires the reliable, stream-oriented delivery of TCP port 53 to transmit the complete zone file. When an administrator improperly configures an authoritative nameserver to answer AXFR requests from arbitrary external clients rather than restricting transfers strictly to trusted secondary nameserver IP addresses, an unauthenticated penetration tester can download the entire DNS database in seconds.

Executing Zone Transfer Tests

To test for an unauthenticated zone transfer:

  1. Enumerate the target domain's authoritative nameservers:
dig target.com NS +short
# Output:
# ns1.target.com.
# ns2.target.com.
  1. Issue an AXFR query directly against each authoritative nameserver:
dig axfr @ns1.target.com target.com

Using the host command, the syntax is equally direct:

host -l target.com ns1.target.com

If the zone transfer succeeds, the server returns every record in the zone, revealing internal hostnames, development servers (dev-app.target.com), intranet endpoints (corp-vpn.target.com), database clusters, and stage environments. If the nameserver responds with Transfer failed or REFUSED, zone transfers are properly restricted.

Automated Subdomain Enumeration with fierce

When zone transfers are disabled, penetration testers employ automated wordlist enumeration to discover subdomains. The tool fierce automates this methodology by first checking for misconfigured zone transfers, and if refused, executing targeted dictionary attacks against the target domain:

# Run fierce against a target domain
fierce --domain target.com

# Run fierce specifying a custom wordlist and custom DNS resolver
fierce --domain target.com --sub-domains /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt --dns-servers 1.1.1.1

Advanced Google Dorking for Information Disclosure

Search engines continuously crawl and index public web servers. Google Dorking (also known as Google Hacking) leverages advanced search operators to uncover sensitive data, hidden administrative portals, leaked credentials, and unprotected configuration files accidentally indexed by search crawlers.

Core Google Dorking Operators

  • site:: Restricts search results strictly to a specific domain or top-level domain (e.g., site:target.com or site:gov).
  • inurl:: Filters for pages containing a specified string inside the URL path (e.g., inurl:admin).
  • intitle:: Restricts results to documents with the specified string in the HTML <title> tag (e.g., intitle:"Dashboard").
  • filetype: / ext:: Filters results strictly to specific file extensions (e.g., filetype:pdf, filetype:sql, filetype:env).
  • cache:: Displays Google's cached snapshot of a webpage, bypassing active website modifications.

Index Traversal & Directory Browsing

When an Apache, Nginx, or IIS web server lacks a default index document (such as index.html or index.php) and directory browsing is enabled, the web server generates a standardized HTML directory listing. Attackers target this using title matching:

intitle:"index of /" site:target.com
intitle:"index of /" "parent directory" site:target.com
intitle:"index of /backup" site:target.com

This reveals exposed directories containing unencrypted database dumps, compressed archives, and source code.

High-Value Dorking Patterns for Penetration Testers

Target AssetGoogle Dork SyntaxIntelligence Discovered
Environment Filessite:target.com filetype:env "DB_PASSWORD"Exposes plaintext database credentials, API tokens, and secret keys
SQL Database Dumpssite:target.com filetype:sql "INSERT INTO"Exposes complete relational database tables, password hashes, and user data
PHP Configurationsite:target.com filetype:php intitle:"phpinfo()"Discloses PHP version, server paths, enabled modules, and environment variables
Administrative Portalssite:target.com inurl:admin OR inurl:login intitle:adminIdentifies unlinked administrative login interfaces and control panels
Private Keys & Certssite:target.com filetype:pem OR filetype:key "BEGIN PRIVATE KEY"Leaks SSH private keys, TLS private certificates, and client tokens
Log & Debug Filessite:target.com filetype:log "error" OR "password"Reveals internal system errors, application exceptions, and logged credentials

OSINT Tools & Public Data Sources

Beyond DNS lookups and search engine dorks, penetration testers leverage specialized OSINT tools and public repositories to assemble comprehensive profiles.

theHarvester

theHarvester is a Python-based OSINT framework designed to gather corporate email addresses, employee names, virtual hosts, open ports, and subdomains from diverse public data sources (including Google, Bing, DuckDuckGo, PGP key servers, and LinkedIn):

# Gather emails, subdomains, and hostnames using Google, Bing, and crt.sh
theHarvester -d target.com -b google,bing,crtsh -l 500

Identifying employee email formats (such as first.last@target.com or flast@target.com) enables targeted username generation for subsequent authentication auditing, password spraying, and social engineering assessments.

WHOIS Lookups

The WHOIS protocol queries databases maintained by Regional Internet Registries (such as ARIN in North America, RIPE NCC in Europe, and APNIC in Asia-Pacific). WHOIS records expose:

  • The organization's registered name, physical address, and technical contact details
  • Authoritative domain registrars and domain registration/expiration dates
  • Assigned Autonomous System Numbers (ASNs) and IP network ranges (CIDR blocks)
whois target.com
whois 198.51.100.0

Certificate Transparency (crt.sh)

Certificate Transparency (CT) is an open cryptographic auditing framework (RFC 6962) designed to detect mistakenly or maliciously issued SSL/TLS certificates. Public Certificate Authorities (CAs) are mandated to publish every issued digital certificate into publicly auditable, append-only logs.

Penetration testers query CT aggregators like crt.sh using wildcard domain queries (%.target.com) to extract every historical and current subdomain that ever requested a TLS certificate. Because organizations frequently issue certificates for internal staging servers, VPN portals, and development environments before exposing them publicly, CT logs provide an unmatched source of passive subdomain discovery.

Internet-Wide Scanners: Shodan & Censys

Search engines such as Shodan and Censys continuously scan the global IPv4 and IPv6 address space, banner-grabbing open services, indexing SSL/TLS certificates, and mapping industrial control systems. Rather than actively scanning a target, a tester searches Shodan's indexed database:

  • hostname:target.com: Discovers all indexed devices associated with the domain
  • ssl.cert.subject.CN:"target.com": Locates servers hosting certificates for the target organization, even on unlinked external hosting providers
  • org:"Target Corporation" port:22,3389: Identifies all remote administrative endpoints (SSH and RDP) registered to the organization's ASN

By leveraging passive intelligence, the penetration tester enters the active scanning phase with a verified list of IP addresses, valid subdomains, and technology baselines.

Test Your Knowledge

What network transport protocol and mechanism does a DNS zone transfer (AXFR) rely upon to synchronize records between nameservers?

A

UDP port 53 using connectionless datagram queries to avoid handshake overhead

B

TCP port 80 utilizing HTTP REST endpoints to export XML database dumps

C

TCP port 53 establishing a reliable stream connection to replicate the complete zone database

D

UDP port 67 broadcast packets distributing record updates across the broadcast domain

Test Your Knowledge

Which search engine dork query is specifically crafted to locate exposed environmental configuration files containing database passwords and API tokens on publicly indexed web servers?

A

filetype:env "DB_PASSWORD" site:example.com

B

inurl:login.php "admin panel" site:example.com

C

intitle:"index of /" filetype:html

D

link:example.com/config.php -site:example.com

Test Your Knowledge

Why are Certificate Transparency (CT) search engines like crt.sh particularly valuable during passive subdomain enumeration?

A

They execute direct TCP SYN port scans across all IP addresses owned by the target domain

B

They decrypt HTTPS traffic in real time to capture active user session cookies

C

They force target DNS authoritative nameservers to release internal PTR reverse records

D

They maintain public append-only logs of every TLS certificate issued by public Certificate Authorities

Sections you finish are checked off in the contents.