When it comes to active footprinting, per
EC-Council, we’re really talking about social engineering,
human interaction, and anything that requires the hacker to interact
with the organization. In short, whereas passive measures take advantage
of publicly available information that won’t (usually) ring any alarm
bells, active footprinting involves exposing your information
gathering to discovery. For example, you can scrub through DNS usually
without anyone noticing a thing, but if you were to walk up to
an employee and start asking them questions about the organization’s
infrastructure, somebody is going to notice.
Social engineering has all sorts of definitions, but it
basically comes down to convincing people to reveal sensitive information,
sometimes without even realizing they’re doing it. There are millions of
methods for doing this, and it can sometimes get really confusing. From the
standpoint of active footprinting, the social engineering methods you should be
concerned about involve human interaction. If you’re calling an employee or
meeting an employee face to face for a conversation, you’re practicing active
footprinting.
This may seem easy to understand, but it can get confusing
in a hurry. For example, I just finished telling you social media is a great
way to uncover information passively, but surely you’re aware you can use some
of these social sites in an active manner. What if you openly use Facebook
connections to query for information? Or what if you tweet a question to
someone? Both of those examples could be considered active in nature, so be
forewarned.