Footprinting is the first phase of ethical hacking — gathering information about a target before launching an attack. This module covers passive and active techniques, OSINT tools, WHOIS lookups, DNS interrogation, Google hacking with dorks, and online intelligence services.
The CEHStudy app carries 26 flashcards for Module 2 across 8 sections — open the Module 2 deck and drill the DNS record types until they are automatic.
Key Topics Covered
Passive vs active footprinting techniques
OSINT (Open Source Intelligence) collection and analysis
WHOIS protocol and Regional Internet Registries (RIRs)
DNS interrogation, reverse DNS lookups, MX records
Google hacking with dorks: site:, filetype:, inurl:, intitle:, cache:
Internet asset discovery: Shodan, Censys, Netcraft
Footprinting countermeasures and defensive strategies
Important Terms & Concepts
OSINT: Open-source intelligence — collection and analysis of information from public/open sources. Not related to open-source software.
Passive footprinting: Gathering info without direct contact with the target (e.g., news, WHOIS databases, social media).
Active footprinting: Direct interaction with the target (e.g., nmap scanning, port scanning, DNS queries).
Google Dorks: Advanced Google search operators: site:, filetype:, inurl:, intitle:, intext:, cache:
WHOIS guard: A proxy between domain owners and WHOIS accessers. Emails are usually still redirected, allowing phishing attempts.
MX records: Mail exchange records that expose which email service a target uses — smallest preference number = highest priority.
Maltego: Proprietary OSINT tool that provides graphical links for investigative tasks — visualizing relationships between data.
Shodan: Search engine that finds IoT devices connected to the internet (webcams, routers, servers) with filtering by open ports.
Google Dork Examples
site:example.com — limits results to a specified domain
filetype:pdf site:example.com — PDF files on a domain
intitle:"index of" — finds directory listings
inurl:admin — pages with admin in the URL
How to Study This Module
Practice using Google dorks on real websites to understand how information leaks
Memorize the difference between passive and active footprinting with examples
Know each reconnaissance tool (Maltego, Recon-ng, FOCA, DMITRY) and its primary function
Understand WHOIS thick vs thin databases and the role of RIRs
Frequently Asked Questions
Why is footprinting important? It is the first phase of hacking — the quality of information gathered determines how effective subsequent scanning and attacks will be.
What are the four types of RIRs? ARIN (Americas), AFRINIC (Africa), APNIC (Asia-Pacific), RIPE (Europe), and LACNIC (Latin America/Caribbean).
What is Footprinting & Reconnaissance in Ethical Hacking?
Footprinting and Reconnaissance is the first technical domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers passive and active information gathering, OSINT (Open Source Intelligence), WHOIS and DNS enumeration, Google hacking with advanced search operators, and reconnaissance platforms like Shodan, Censys, and Maltego. Module 2 accounts for about 8% of CEH v13 exam questions.
Key Concepts in Footprinting & Reconnaissance
Passive vs Active Footprinting: Passive footprinting gathers information without touching the target (WHOIS databases, news archives, social media, certificate transparency logs); active sends direct traffic to target systems (DNS queries, port scans, banner grabbing). Know which category a technique falls into.
DNS Record Types & Interrogation: A, AAAA, MX, NS, TXT, SOA, CNAME, and SRV queries map an organization's infrastructure. Reverse lookups (PTR) expose hostnames that reveal server roles; an AXFR zone-transfer vulnerability exposes the entire zone.
OSINT Framework: Systematic collection of publicly available data — from corporate filings and job postings to geotagged images and dark web forums. Maltego (relationship mapping), Recon-ng (recon framework), FOCA (metadata extraction), and DMITRY (multi-source scanner) automate the workflow.
Shodan & Censys Internet Mapping: Shodan and Censys index internet-connected devices by open ports and banners (not webpages, like Google), revealing exposed IoT devices, misconfigured routers, and unpatched servers.
Common Exam Mistakes in Module 2
Classifying WHOIS lookups as active footprinting: WHOIS queries, search engines, social media, news archives, and public records never touch the target — they are passive. Traffic to the target's own infrastructure (a dig AXFR zone transfer, port scan, or ping sweep) makes a technique active and detectable.
Reversing thick and thin WHOIS: Thick WHOIS stores complete registration data in one searchable database; thin WHOIS stores only the domain name and points to the registrar's whois server for the rest. The exam swaps these definitions.
Guessing at RIR regions: ARIN covers the Americas, APNIC the Asia-Pacific, RIPE NCC Europe/Middle East/Central Asia, AFRINIC Africa, and LACNIC Latin America and the Caribbean. When a question names a region it wants the registry — and vice versa.
Tools Used in Footprinting & Reconnaissance
The recon toolkit the exam sorts into passive vs active:
theHarvester: aggregates email addresses, subdomains, and hostnames from public sources (search engines, SSL data, virtual hosts)
FOCA: extracts metadata from Office documents and PDFs — author names, company fields, timestamps, tracked changes, embedded network paths
Maltego: graph-based link analysis across people, domains, IPs, URLs, and social accounts
Shodan: search engine over internet-facing devices and service banners — the go-to for exposed IoT/SCADA gear; Censys and ZoomEye do the same job
dig: the workhorse DNS query tool: A/MX/NS lookups and the axfr test for misconfigured zone transfers
whois: queries RIR and registrar databases for registration data — owner contacts, creation dates, nameservers
Recon-ng: open-source, modular recon framework bundling the sources above into one web interface
DNSRecon: enumerates DNS hosts and subdomains and flags misconfigurations such as transferable zones; Fierce does similar subdomain discovery
Worked Example: A Passive Footprint Pass on an Authorized Domain
You are authorized to footprint your own company's domain. Start with sources that never touch it: whois reveals the registrar, both nameservers, and the creation date; dig A / dig MX map the web and mail infrastructure; a dig axfr request tests whether the zone transfers — a properly configured server's refusal is itself a finding.
What each step proves: Shodan, queried by IP block, shows which company devices answer with open ports and banners — no company cooperation needed. FOCA over a published PDF can surface embedded author names, internal hostnames, and network paths. Nothing here sent traffic to the target — detection risk stays minimal, the defining property of passive footprinting.
How to Study Footprinting & Reconnaissance for the CEH v13 Exam
To study Module 2:
Review the key terms, focusing on the passive/active distinction — a frequent exam question type
Practice with the flashcards above, paying attention to DNS record types and their security implications
Perform passive footprinting on your own domain using only WHOIS lookups, dig queries, certificate transparency logs (crt.sh), and Google dorks — document everything without a single active connection
Frequently Asked Questions About Footprinting & Reconnaissance
What is the difference between passive and active footprinting on the CEH exam?
Passive footprinting collects information from third-party sources without touching the target — WHOIS lookups, social media scraping, news archives, Shodan/Censys searches. Active footprinting sends packets directly to the target — DNS zone transfers, port scanning, banner grabbing, traceroute. Expect to classify a technique by category; passive ones are harder to detect.
Why is Google dorking considered such an effective reconnaissance technique?
Google dorking uses advanced search operators to surface information organizations have inadvertently exposed. A query like site:target.com filetype:pdf intext:confidential can reveal internal documents; inurl:admin finds misconfigured admin interfaces. The data is already indexed by Google's crawler, so dorking is entirely passive — the target gets no notification and detection risk is minimal.