OSINT

Google Dorking

Summary: How crawlers work & how to google dork

Room: https://tryhackme.com/r/room/googledorkingarrow-up-right

  • crawler indexes websites, note the keywords, search for insite urls, then crawl that url recursively

  • crawlers first check for robots.txt

  • you might want to hide all .ini file with /*.ini$

  • in UNIX system, hide all .conf files

  • sitemap.xml provides the websute structure, helps with SEO

  • https://pagespeed.web.dev/arrow-up-right -> google site analyzer, check speed performance

Web OSINT

Summary: there are so many ways we can do to uncover the owner of a website & unveil connections between websites

Room: https://tryhackme.com/r/room/webosintarrow-up-right

Geolocating Images

Summary: how to know location from image

Room: https://tryhackme.com/r/room/geolocatingimagesarrow-up-right

  • Best reverse image search: Yandex > Bing > Google

    • Yandex uses AI, it tries to get what's really in the picture

    • Google finds exact match

    • TinEye looks for exact duplicate

  • increase the image resolution, 200x200 and below is no hope

  • try mirrorring, cropping, rotating the photo

  • blurring outarrow-up-right the photo subject can let the search engine focus on finding the background

Geolocating

  • rough estimate

    • get text, landmarks, road layouts

    • what is likely to be on the country/region

      • climate

      • popular brand of cars

      • driving side

      • etc

    • IP/ASN number

    • metadata/EXIF, social media geotagging

  • pinpointing

Last updated