当前位置:网站首页>Penetration test information collection - basic enterprise information

Penetration test information collection - basic enterprise information

2022-07-06 18:35:00 Aspirin. two thousand and two

Basic information of the enterprise

1. Basic information of the enterprise .
2. Employee information ( Phone number 、 mailbox 、 Name, etc ), Organizational framework 、 Enterprise legal person 、 Enterprise comprehensive information, etc .
3. Among them, employee information collection is an important work in information collection , Employee information includes : Employee name 、 Employee job number 、 Employee family and communication information 、 Internet habits, etc .( social engineering )
4. Employee identity information : Employee resume , Employee ID card , cell-phone number , Birthday , hometown , Address and other personal information .
5、 Employee social account information :QQ Number ,QQ Group , Microblogging , WeChat , Alipay , Employee email account number, etc .

Things used :

https://www.tianyancha.com Check the inner eye
https://www.qichacha.com/ Companies check
https://aiqicha.baidu.com/ I love checking

 View the enterprise framework , Personal information of enterprise executives 、 Other industries , One recruit among all employees of the enterprise is likely to win all 

https://www.reg007.com/ Which websites have you registered
https://www.email-format.com/i/search/ Check the email related to this domain name online
Maltego(kali Tools ) information gathering —— visualization

Various recruitment networks

https://www.aies.cn/pinyin.htm Online Chinese character to Pinyin —— Make a dictionary
https://github.com/shack2/SNETCracker/releases Super weak password tool
https://anonymousemail.me/ Anonymous email

JS information gathering

adopt JS collect ,url, Directory and parameters

Js As an important part of our information collection, many people will ignore ,Js It may contain a lot of sensitive information , Make up a dictionary fuzz The effect is very good .

Many people will ignore the festival ,Js It may contain a lot of sensitive information , Make up a dictionary fuzz The effect is very good .

The script used :https://github.com/Threezh1/JSFinder

原网站

版权声明
本文为[Aspirin. two thousand and two]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/02/202202131300352615.html