ALL PASS, NO FAIL!

CEH v13 Module 2: Footprinting & Reconnaissance

Footprinting is the first phase of ethical hacking — gathering information about a target before launching an attack. This module covers passive and active techniques, OSINT tools, WHOIS lookups, DNS interrogation, Google hacking with dorks, and online intelligence services.

The CEHStudy app carries 26 flashcards for Module 2 across 8 sections — open the Module 2 deck and drill the DNS record types until they are automatic.

Key Topics Covered

Important Terms & Concepts

OSINT: Open-source intelligence — collection and analysis of information from public/open sources. Not related to open-source software.
Passive footprinting: Gathering info without direct contact with the target (e.g., news, WHOIS databases, social media).
Active footprinting: Direct interaction with the target (e.g., nmap scanning, port scanning, DNS queries).
Google Dorks: Advanced Google search operators: site:, filetype:, inurl:, intitle:, intext:, cache:
WHOIS guard: A proxy between domain owners and WHOIS accessers. Emails are usually still redirected, allowing phishing attempts.
MX records: Mail exchange records that expose which email service a target uses — smallest preference number = highest priority.
Maltego: Proprietary OSINT tool that provides graphical links for investigative tasks — visualizing relationships between data.
Shodan: Search engine that finds IoT devices connected to the internet (webcams, routers, servers) with filtering by open ports.

Google Dork Examples

How to Study This Module

Frequently Asked Questions

Why is footprinting important?
It is the first phase of hacking — the quality of information gathered determines how effective subsequent scanning and attacks will be.

What are the four types of RIRs?
ARIN (Americas), AFRINIC (Africa), APNIC (Asia-Pacific), RIPE (Europe), and LACNIC (Latin America/Caribbean).

Related Modules

What is Footprinting & Reconnaissance in Ethical Hacking?

Footprinting and Reconnaissance is the first technical domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers passive and active information gathering, OSINT (Open Source Intelligence), WHOIS and DNS enumeration, Google hacking with advanced search operators, and reconnaissance platforms like Shodan, Censys, and Maltego. Module 2 accounts for about 8% of CEH v13 exam questions.

Key Concepts in Footprinting & Reconnaissance

Common Exam Mistakes in Module 2

Classifying WHOIS lookups as active footprinting: WHOIS queries, search engines, social media, news archives, and public records never touch the target — they are passive. Traffic to the target's own infrastructure (a dig AXFR zone transfer, port scan, or ping sweep) makes a technique active and detectable.
Reversing thick and thin WHOIS: Thick WHOIS stores complete registration data in one searchable database; thin WHOIS stores only the domain name and points to the registrar's whois server for the rest. The exam swaps these definitions.
Guessing at RIR regions: ARIN covers the Americas, APNIC the Asia-Pacific, RIPE NCC Europe/Middle East/Central Asia, AFRINIC Africa, and LACNIC Latin America and the Caribbean. When a question names a region it wants the registry — and vice versa.

Tools Used in Footprinting & Reconnaissance

The recon toolkit the exam sorts into passive vs active:

Worked Example: A Passive Footprint Pass on an Authorized Domain

You are authorized to footprint your own company's domain. Start with sources that never touch it: whois reveals the registrar, both nameservers, and the creation date; dig A / dig MX map the web and mail infrastructure; a dig axfr request tests whether the zone transfers — a properly configured server's refusal is itself a finding.

What each step proves: Shodan, queried by IP block, shows which company devices answer with open ports and banners — no company cooperation needed. FOCA over a published PDF can surface embedded author names, internal hostnames, and network paths. Nothing here sent traffic to the target — detection risk stays minimal, the defining property of passive footprinting.

How to Study Footprinting & Reconnaissance for the CEH v13 Exam

To study Module 2:

  1. Review the key terms, focusing on the passive/active distinction — a frequent exam question type
  2. Practice with the flashcards above, paying attention to DNS record types and their security implications
  3. Perform passive footprinting on your own domain using only WHOIS lookups, dig queries, certificate transparency logs (crt.sh), and Google dorks — document everything without a single active connection
  4. Review Module 3 (Scanning Networks) for the active scanning that follows, and Module 4 (Enumeration) for protocol-level discovery

Frequently Asked Questions About Footprinting & Reconnaissance

What is the difference between passive and active footprinting on the CEH exam?

Passive footprinting collects information from third-party sources without touching the target — WHOIS lookups, social media scraping, news archives, Shodan/Censys searches. Active footprinting sends packets directly to the target — DNS zone transfers, port scanning, banner grabbing, traceroute. Expect to classify a technique by category; passive ones are harder to detect.

Why is Google dorking considered such an effective reconnaissance technique?

Google dorking uses advanced search operators to surface information organizations have inadvertently exposed. A query like site:target.com filetype:pdf intext:confidential can reveal internal documents; inurl:admin finds misconfigured admin interfaces. The data is already indexed by Google's crawler, so dorking is entirely passive — the target gets no notification and detection risk is minimal.

Related CEH v13 Modules

Related Glossary Terms