Web SecurityWeb Security · Lesson 03
Reconnaissance & Mapping
Fingerprinting, subdomains, directories and reading the front end.
Video tutorialTrack course · freeCodeCamp
Speed
Transcript & captions
9/9
Recon is the largest part of real testing: enumerate everything the target exposes before sending a single payload. The wider the map, the more likely you find the forgotten staging box.
- Passive: DNS records, certificate transparency logs, public repos, search operators, archived pages.
- Active: subdomain discovery, directory brute forcing, port scanning - in scope only.
- Fingerprinting: response headers, cookie names, error pages, framework artefacts.
- Read the JavaScript bundles - endpoints, feature flags and sometimes keys live there.
- Always check /robots.txt, /sitemap.xml, /.well-known/ and leftover source maps.
Client-side fingerprint
Knowledge check
0/2 answeredWhy read a site's JavaScript bundles?
Certificate transparency logs help you find...