Web SecurityWeb Security · Lesson 03

Reconnaissance & Mapping

Fingerprinting, subdomains, directories and reading the front end.

Video tutorialTrack course · freeCodeCamp
Speed
Next lesson
Watch 00:00 · 2 checkpoints Watch on YouTube More on this topic
Transcript & captions
9/9

Recon is the largest part of real testing: enumerate everything the target exposes before sending a single payload. The wider the map, the more likely you find the forgotten staging box.

  • Passive: DNS records, certificate transparency logs, public repos, search operators, archived pages.
  • Active: subdomain discovery, directory brute forcing, port scanning - in scope only.
  • Fingerprinting: response headers, cookie names, error pages, framework artefacts.
  • Read the JavaScript bundles - endpoints, feature flags and sometimes keys live there.
  • Always check /robots.txt, /sitemap.xml, /.well-known/ and leftover source maps.
Client-side fingerprint

Knowledge check

0/2 answered

Why read a site's JavaScript bundles?

Certificate transparency logs help you find...