SlideShare a Scribd company logo
1 of 17
n|u Bangalore Meet
Recon-ng
Who am i?
Nutan Kumar Panda
@theosintguy
An Infosec Professional
An Osint Enthusiast
Game Of Thrones Fan 
Disclaimer
इस डेमो का ि कसी भी साइट या
संगठन को आहत करने का इरादा नह ं
है। प्रस्तोता आपत्तिजनक सामग्री के
ि कसी भी प्रकार के उपयोग ना करने
के लिए अपने स्तर पर पूर कोलिि की
है। अगर ि कसी को भी कु छ आक्रामक
िगताहैतो हम लसर्फ संयोग के रूप में
िेंगे।
Agenda
• OSINT
• Recon-ng
• Modules
• Test cases
• Demo
Open-source intelligence (OSINT) is
intelligence collected from publicly
available sources.
Define: Osint
Why Osint?
• Freely available data
• Open data
• Part of passive
reconnaissance
• Powerful as dragon
• Way to hidden treasure
You may get almost everything
Share less and Search more
Keep calm and use OSINT
Recon-ng
• This is an open source tool
written in python majorly by
Tim Tomes(@Lanmaster53).
• This project was one of its
kind in terms of complete
OSINT framework.
• Using this you can do
wonders.
The tool : https://bitbucket.org/LaNMaSteR53/recon-ng
The user guide: https://bitbucket.org/LaNMaSteR53/recon-ng/wiki/Usage%20Guide
The development guide: https://bitbucket.org/LaNMaSteR53/recon-ng/wiki/Development%20Guide
1. Discovery
2. Exploitation
3. Import
4. Recon
5. Reporting
Modules
Test Case
• Gather email id
• Find whether email is
hacked or not
• Physical tracking
• Vulnerability hunt
• Port scanning
• Exploitation
Brace yourself for the Demo
https://www.youtube.com/watch?v=vkmNTNl6urw
Special Mention
Greets to @lanmaster53
Rally the realm and spread the word
Greets to Sudhanshu Chauhan
Last Words???
Until The Next Meet: valar dohaeris

More Related Content

More from Nutan Kumar Panda

More from Nutan Kumar Panda (11)

Backtrack Manual Part10
Backtrack Manual Part10Backtrack Manual Part10
Backtrack Manual Part10
 
Backtrack Manual Part9
Backtrack Manual Part9Backtrack Manual Part9
Backtrack Manual Part9
 
Backtrack Manual Part8
Backtrack Manual Part8Backtrack Manual Part8
Backtrack Manual Part8
 
Backtrack Manual Part7
Backtrack Manual Part7Backtrack Manual Part7
Backtrack Manual Part7
 
Backtrack Manual Part6
Backtrack Manual Part6Backtrack Manual Part6
Backtrack Manual Part6
 
Backtrack Manual Part5
Backtrack Manual Part5Backtrack Manual Part5
Backtrack Manual Part5
 
Backtrack Manual Part4
Backtrack Manual Part4Backtrack Manual Part4
Backtrack Manual Part4
 
Backtrack Manual Part3
Backtrack Manual Part3Backtrack Manual Part3
Backtrack Manual Part3
 
Backtrack Manual Part2
Backtrack Manual Part2Backtrack Manual Part2
Backtrack Manual Part2
 
Backtrack manual Part1
Backtrack manual Part1Backtrack manual Part1
Backtrack manual Part1
 
Google Hack
Google HackGoogle Hack
Google Hack
 

Recently uploaded

2006_GasProcessing_HB (1).pdf HYDROCARBON PROCESSING
2006_GasProcessing_HB (1).pdf HYDROCARBON PROCESSING2006_GasProcessing_HB (1).pdf HYDROCARBON PROCESSING
2006_GasProcessing_HB (1).pdf HYDROCARBON PROCESSINGmarianagonzalez07
 
NLP Project PPT: Flipkart Product Reviews through NLP Data Science.pptx
NLP Project PPT: Flipkart Product Reviews through NLP Data Science.pptxNLP Project PPT: Flipkart Product Reviews through NLP Data Science.pptx
NLP Project PPT: Flipkart Product Reviews through NLP Data Science.pptxBoston Institute of Analytics
 
NO1 Certified Black Magic Specialist Expert Amil baba in Lahore Islamabad Raw...
NO1 Certified Black Magic Specialist Expert Amil baba in Lahore Islamabad Raw...NO1 Certified Black Magic Specialist Expert Amil baba in Lahore Islamabad Raw...
NO1 Certified Black Magic Specialist Expert Amil baba in Lahore Islamabad Raw...Amil Baba Dawood bangali
 
Semantic Shed - Squashing and Squeezing.pptx
Semantic Shed - Squashing and Squeezing.pptxSemantic Shed - Squashing and Squeezing.pptx
Semantic Shed - Squashing and Squeezing.pptxMike Bennett
 
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...Jack DiGiovanna
 
How we prevented account sharing with MFA
How we prevented account sharing with MFAHow we prevented account sharing with MFA
How we prevented account sharing with MFAAndrei Kaleshka
 
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一F sss
 
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort servicejennyeacort
 
RadioAdProWritingCinderellabyButleri.pdf
RadioAdProWritingCinderellabyButleri.pdfRadioAdProWritingCinderellabyButleri.pdf
RadioAdProWritingCinderellabyButleri.pdfgstagge
 
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024thyngster
 
PKS-TGC-1084-630 - Stage 1 Proposal.pptx
PKS-TGC-1084-630 - Stage 1 Proposal.pptxPKS-TGC-1084-630 - Stage 1 Proposal.pptx
PKS-TGC-1084-630 - Stage 1 Proposal.pptxPramod Kumar Srivastava
 
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...dajasot375
 
Machine learning classification ppt.ppt
Machine learning classification  ppt.pptMachine learning classification  ppt.ppt
Machine learning classification ppt.pptamreenkhanum0307
 
Advanced Machine Learning for Business Professionals
Advanced Machine Learning for Business ProfessionalsAdvanced Machine Learning for Business Professionals
Advanced Machine Learning for Business ProfessionalsVICTOR MAESTRE RAMIREZ
 
While-For-loop in python used in college
While-For-loop in python used in collegeWhile-For-loop in python used in college
While-For-loop in python used in collegessuser7a7cd61
 
ASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel CanterASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel Cantervoginip
 
Multiple time frame trading analysis -brianshannon.pdf
Multiple time frame trading analysis -brianshannon.pdfMultiple time frame trading analysis -brianshannon.pdf
Multiple time frame trading analysis -brianshannon.pdfchwongval
 
From idea to production in a day – Leveraging Azure ML and Streamlit to build...
From idea to production in a day – Leveraging Azure ML and Streamlit to build...From idea to production in a day – Leveraging Azure ML and Streamlit to build...
From idea to production in a day – Leveraging Azure ML and Streamlit to build...Florian Roscheck
 
Data Factory in Microsoft Fabric (MsBIP #82)
Data Factory in Microsoft Fabric (MsBIP #82)Data Factory in Microsoft Fabric (MsBIP #82)
Data Factory in Microsoft Fabric (MsBIP #82)Cathrine Wilhelmsen
 
Biometric Authentication: The Evolution, Applications, Benefits and Challenge...
Biometric Authentication: The Evolution, Applications, Benefits and Challenge...Biometric Authentication: The Evolution, Applications, Benefits and Challenge...
Biometric Authentication: The Evolution, Applications, Benefits and Challenge...GQ Research
 

Recently uploaded (20)

2006_GasProcessing_HB (1).pdf HYDROCARBON PROCESSING
2006_GasProcessing_HB (1).pdf HYDROCARBON PROCESSING2006_GasProcessing_HB (1).pdf HYDROCARBON PROCESSING
2006_GasProcessing_HB (1).pdf HYDROCARBON PROCESSING
 
NLP Project PPT: Flipkart Product Reviews through NLP Data Science.pptx
NLP Project PPT: Flipkart Product Reviews through NLP Data Science.pptxNLP Project PPT: Flipkart Product Reviews through NLP Data Science.pptx
NLP Project PPT: Flipkart Product Reviews through NLP Data Science.pptx
 
NO1 Certified Black Magic Specialist Expert Amil baba in Lahore Islamabad Raw...
NO1 Certified Black Magic Specialist Expert Amil baba in Lahore Islamabad Raw...NO1 Certified Black Magic Specialist Expert Amil baba in Lahore Islamabad Raw...
NO1 Certified Black Magic Specialist Expert Amil baba in Lahore Islamabad Raw...
 
Semantic Shed - Squashing and Squeezing.pptx
Semantic Shed - Squashing and Squeezing.pptxSemantic Shed - Squashing and Squeezing.pptx
Semantic Shed - Squashing and Squeezing.pptx
 
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...
Building on a FAIRly Strong Foundation to Connect Academic Research to Transl...
 
How we prevented account sharing with MFA
How we prevented account sharing with MFAHow we prevented account sharing with MFA
How we prevented account sharing with MFA
 
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
 
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service
9711147426✨Call In girls Gurgaon Sector 31. SCO 25 escort service
 
RadioAdProWritingCinderellabyButleri.pdf
RadioAdProWritingCinderellabyButleri.pdfRadioAdProWritingCinderellabyButleri.pdf
RadioAdProWritingCinderellabyButleri.pdf
 
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024
 
PKS-TGC-1084-630 - Stage 1 Proposal.pptx
PKS-TGC-1084-630 - Stage 1 Proposal.pptxPKS-TGC-1084-630 - Stage 1 Proposal.pptx
PKS-TGC-1084-630 - Stage 1 Proposal.pptx
 
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...
 
Machine learning classification ppt.ppt
Machine learning classification  ppt.pptMachine learning classification  ppt.ppt
Machine learning classification ppt.ppt
 
Advanced Machine Learning for Business Professionals
Advanced Machine Learning for Business ProfessionalsAdvanced Machine Learning for Business Professionals
Advanced Machine Learning for Business Professionals
 
While-For-loop in python used in college
While-For-loop in python used in collegeWhile-For-loop in python used in college
While-For-loop in python used in college
 
ASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel CanterASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel Canter
 
Multiple time frame trading analysis -brianshannon.pdf
Multiple time frame trading analysis -brianshannon.pdfMultiple time frame trading analysis -brianshannon.pdf
Multiple time frame trading analysis -brianshannon.pdf
 
From idea to production in a day – Leveraging Azure ML and Streamlit to build...
From idea to production in a day – Leveraging Azure ML and Streamlit to build...From idea to production in a day – Leveraging Azure ML and Streamlit to build...
From idea to production in a day – Leveraging Azure ML and Streamlit to build...
 
Data Factory in Microsoft Fabric (MsBIP #82)
Data Factory in Microsoft Fabric (MsBIP #82)Data Factory in Microsoft Fabric (MsBIP #82)
Data Factory in Microsoft Fabric (MsBIP #82)
 
Biometric Authentication: The Evolution, Applications, Benefits and Challenge...
Biometric Authentication: The Evolution, Applications, Benefits and Challenge...Biometric Authentication: The Evolution, Applications, Benefits and Challenge...
Biometric Authentication: The Evolution, Applications, Benefits and Challenge...
 

Recon-ng

  • 2. Who am i? Nutan Kumar Panda @theosintguy An Infosec Professional An Osint Enthusiast Game Of Thrones Fan 
  • 3. Disclaimer इस डेमो का ि कसी भी साइट या संगठन को आहत करने का इरादा नह ं है। प्रस्तोता आपत्तिजनक सामग्री के ि कसी भी प्रकार के उपयोग ना करने के लिए अपने स्तर पर पूर कोलिि की है। अगर ि कसी को भी कु छ आक्रामक िगताहैतो हम लसर्फ संयोग के रूप में िेंगे।
  • 4. Agenda • OSINT • Recon-ng • Modules • Test cases • Demo
  • 5. Open-source intelligence (OSINT) is intelligence collected from publicly available sources. Define: Osint
  • 6. Why Osint? • Freely available data • Open data • Part of passive reconnaissance • Powerful as dragon • Way to hidden treasure
  • 7. You may get almost everything
  • 8. Share less and Search more
  • 9. Keep calm and use OSINT
  • 10. Recon-ng • This is an open source tool written in python majorly by Tim Tomes(@Lanmaster53). • This project was one of its kind in terms of complete OSINT framework. • Using this you can do wonders. The tool : https://bitbucket.org/LaNMaSteR53/recon-ng The user guide: https://bitbucket.org/LaNMaSteR53/recon-ng/wiki/Usage%20Guide The development guide: https://bitbucket.org/LaNMaSteR53/recon-ng/wiki/Development%20Guide
  • 11. 1. Discovery 2. Exploitation 3. Import 4. Recon 5. Reporting Modules
  • 12. Test Case • Gather email id • Find whether email is hacked or not • Physical tracking • Vulnerability hunt • Port scanning • Exploitation
  • 13. Brace yourself for the Demo https://www.youtube.com/watch?v=vkmNTNl6urw
  • 15. Rally the realm and spread the word Greets to Sudhanshu Chauhan
  • 17. Until The Next Meet: valar dohaeris

Editor's Notes

  1. I tried my level best not to offend anyone 
  2. We use it in our day to day pentest or bug bounty Google site: Github dork Bing ip2host Test creditcards Fake addresses Email id harvest
  3. Maltego harvester
  4. Default credentials Admin consoles paths Many payloads
  5. Its better to know the enemy and it helps us to win over
  6. Our demo ll prove it
  7. Interactive Quite same as MSF Modular Scriptable Well documented and well maintained
  8. Discovery (Active recon with sending packet) Exploitation (Using payload) Import (to add list or prev projs) Recon (passive recon) Report (xml or html)
  9. DerbyCon Look Ma No Exploits The Recon Ng Framework Tim Lanmaster53 Tomes help Workspaces Workspaces list to get the lists Workspaces add osint Keys list to see which keys has been added https://bitbucket.org/LaNMaSteR53/recon-ng/wiki/Usage%20Guide#!acquiring-api-keys Add bing key fVGoRoqI5ZHSle5ZM0B3o0LSAsINFZ+l9AkA2gFiF4s Show Modules (Take a domain and dig deeper) recon/domains-hosts/bing_domain_api(to get whole bunch of hosts from domain) Show info set SOURCE fbi.gov Run recon/domains-hosts/bing_domain_web use recon/domains-hosts/netcraft (to get more hosts) http://toolbar.netcraft.com/site_report Show dashboard to see what we did so far Show hosts host table Lets fill the table with ips first use recon/hosts-hosts/resolve use recon/hosts-hosts/bing_ip Lets look for some technology information bug bounty $$$ Use recon/domains-hosts/builtwith to get technology idea recon/domains-vulnerabilities/punkspider to get free bugs Show in site http://punkspider.hyperiongray.com/ race360 Lets get some contact details Use recon/domains-contacts/whois_pocs Show contacts use recon/domains-contacts/pgp_search Harvest info from a perticular place about our target Use recon/profiles-profiles/namechk makash :P Get credentials use recon/contacts-credentials/hibp_paste for google@gmail.com Check for the downloaded files for more info :P Will get password and hashes Now save proj use reporting/html
  10. Last night also he did some update
  11. Shameless promotions 1may labor day release
  12. Any queries???
  13. tada