00:00/00:00

An overview of external reconnaissance techniques using tools like Shodan and ZoomEye, understanding network protocols, and conducting internal cloud security checks for AWS infrastructure using API keys and templates.

Introduction to Reconnaissance and Cloud Security Auditing

12:12Study Material
This lesson explores external reconnaissance methods to gather information about target systems using scanning tools like Shodan, ZoomEye, and Census. It covers the basics of network protocols, comparing unencrypted HTTP traffic to encrypted HTTPS sessions, and looks at how SSL certificates can occasionally expose internal subdomains. Users will learn about different networking technologies, understanding how Nginx is used as a proxy to handle large amounts of traffic in contrast to Apache and IIS. Additionally, the lesson transitions into internal cloud security auditing, outlining the process of auditing AWS infrastructure. It demonstrates how to use the free tool Scout Cloud in conjunction with AWS API keys to scan for misconfigured hosting features. The content emphasizes ensuring sensitive deployments, like S3 buckets, are not accidentally exposed to the public internet, and contrasts these internal audits with the external checks typically conducted by penetration testers.
Watch until the end to complete this lesson
0% watched
Back to Course

Tags

ShodanZoomEyeCensusSSL certificateNginxHTTPSTelnetWHOISScout CloudAWSS3 bucketReconnaissance