Passive & Active Recon


June, 2022

Days 21 -25
Passive & Active Recon
100 Days of Hacking

The next series of post are from the module Information Gathering – Web Edition, found within HTB’s Bug Bounty Job Role Path. Specifically, this post will cover Passive and Active Information Gathering.

When dealing with passive information gathering, I’ll use Whois and DNS to gather passive information on targets. Both with the objective of understanding and performing Passive Subdomain Enumeration along with Passive Infrastructure Indentification.

When doing Active Infomation Gathering, my focus will be on Active Infrastructure Identification and Active Subdomain Enumeration.

Day 21 –

Passive Information Gathering


Perform a WHOIS lookup against the domain. What is the registrant Internet Assigned Numbers Authority (IANA) ID number?

What is the admin email contact for the domain (also in-scope for the PayPal bug bounty program)?

flat screen computer monitor displaying white and black screen
flat screen computer monitor displaying white and black screen


Which IP address maps to

Which subdomain is returned when querying the PTR record for

What is the first mailserver returned when querying the MX records for

Day 22-

Active Information Gathering

Active Infrastructure Identification

What Apache version is running on app.inlanefreight.local? (Format: 0.0.0)

Which CMS is used on app.inlanefreight.local? (Format: word)

On which operating system is the dev.inlanefreight.local webserver running on? (Format: word)

Develop intuitive judgement and understanding for everything…Perceive those things which cannot be seen…Pay attention even to trifles.” – Miyamoto Musashi

Days 23-25

Active Sub-domain enumerationy

Submit the FQDN of the nameserver for the “inlanefreight.htb” domain as the answer.

Identify how many zones exist on the target nameserver. Submit the number of found zones as the answer.

Find and submit the contents of the TXT record as the answer.

What is the FQDN of the IP address

What FQDN is assigned to the IP address Submit the FQDN as the answer.

Which IP address is assigned to the “us.inlanefreight.htb” subdomain? Submit the IP address as the answer.

Submit the number of all “A” records from all zones as the answer.

1.1 37 votes
Article Rating
Would love your thoughts, please comment.x

Subscribe To Our Newsletter

Join our mailing list to receive the latest news and updates from our team.

You have Successfully Subscribed!

Share This