Skip to main content

Command Palette

Search for a command to run...

How Hackers Actually Find Vulnerabilities: Reconnaissance & Scanning

Updated
•6 min read•View as Markdown
How Hackers Actually Find Vulnerabilities: Reconnaissance & Scanning
S

Software engineering learner documenting my journey across Java, backend development, DSA, and cybersecurity. I write beginner-friendly explanations, practical notes, and lessons learned while building and analyzing real-world systems.

In Part 1, I followed a packet from my browser to a server.
In Part 2, I understood where networks become vulnerable.

Everything started making sense.

But one question kept bothering me:

How do attackers even find these vulnerabilities in the first place?

They don’t randomly guess.
They don’t magically “hack” into systems.

They observe, collect, and analyze.

That process is called reconnaissance.


Reconnaissance – Where Every Attack Begins

Before any real attack happens, there’s a quiet phase.

No alerts.
No warnings.
No visible damage.

Just information gathering.

At first, I thought hacking starts with exploitation.
But I was wrong.

It actually starts with understanding the target better than the target understands itself.

There are two types:

1. Passive Recon

  • No direct interaction with the target

  • Uses publicly available data

Examples:

  • Company websites

  • Social media

  • Public documents

2. Active Recon

  • Direct interaction with the target system

  • Leaves traces

Examples:

  • Scanning ports

  • Sending requests

  • Probing services

And honestly, this realization surprised me:

It felt less like hacking… and more like digital stalking.


OSINT – When Information Is Already Public

One of the most eye-opening things I learned was about OSINT (Open Source Intelligence).

This is information that is already available — legally and publicly.

No hacking required.

Examples include:

  • Domain details (WHOIS)

  • DNS records

  • Employee LinkedIn profiles

  • GitHub repositories

  • Job postings (revealing tech stacks)

At first, this felt harmless.

But then I realized something uncomfortable:

Sometimes, organizations expose more information themselves
than attackers need to steal.

A simple job post like:
“We are hiring a backend developer with experience in Node.js and MongoDB”

Already tells an attacker:

  • What tech stack is used

  • What kind of vulnerabilities might exist

And suddenly, recon becomes targeted.


Scanning – Knocking on Every Door

After gathering information, the next step is scanning.

This is where attackers start interacting with the system.

Think of it like this:

If a system is a house,
scanning is checking which doors and windows are open.

Each “door” is a port.

Examples:

  • Port 22 → SSH

  • Port 80 → HTTP

  • Port 443 → HTTPS

If a port is open, it means:
➡️ A service is running
➡️ And it’s waiting for connections

That doesn’t mean it’s vulnerable.

But it can be.

And the more open ports there are, the larger the attack surface becomes.


Enumeration – Looking Inside the Doors

Scanning tells you what is open.
Enumeration tells you what exactly is running.

This step goes deeper.

Attackers try to extract:

  • Usernames

  • Service versions

  • Shared resources

  • System details

In simple words:

If scanning finds the door,
enumeration tries to peek inside.

This is where things start becoming dangerous.

Because now, the attacker is no longer guessing.

They are building a clear map of the system.


The Tools That Made This Real for Me

Until this point, everything felt theoretical.

Recon, scanning, enumeration — it all made sense.

But it didn’t feel real.

That changed when I started using some basic tools.

1. DNS & Domain Information

I came across tools like:

  • nslookup

  • whois

With just a domain name, I could find:

  • IP addresses

  • DNS records

  • Domain details

It was surprising how much information is publicly accessible.

I didn’t need to hack anything.
I just needed to ask the right questions.

2. Port Scanning with Nmap

Then I tried Nmap.

This was the moment things clicked.

With a single command, I could see:

  • Open ports

  • Running services

  • Sometimes even service versions

It felt like:

I was no longer guessing —
I was seeing the system from the outside.

3. Watching Traffic with Wireshark

Then came Wireshark.

Instead of just knowing that packets exist,
I could actually see them moving.

  • Requests

  • Responses

  • Protocol details

Everything was visible.

Networking stopped being invisible.
It became something I could observe in real time.


What I Realized

These tools didn’t “hack” anything.

They simply helped me:

  • Understand systems better

  • See what is exposed

  • Think like an attacker

And that’s when I understood:

The difference between a normal user and an attacker
is often just awareness and observation.

Why This Stage Is More Dangerous Than It Looks

At this point, something important clicked for me:

👉 No vulnerability has been exploited yet
👉 No system has been “hacked”

And still…

This is one of the most critical phases.

Why?

Because by the time an attacker reaches exploitation:

  • They already know which ports are open

  • They already know which services are running

  • They already know where the weak points are

It’s no longer random.

It’s precise.

The real danger is not just in exploitation…
It’s in how accurately the target is understood before the attack.


Connecting This to What I Learned Earlier

In Part 2, I explored vulnerabilities like:

  • ARP spoofing

  • DHCP attacks

  • Open ports

  • Misconfigurations

At that time, it felt like:

“These are possible risks.”

But now I see it differently:

These vulnerabilities don’t stay hidden.
They are actively searched for.

Attackers don’t wait for mistakes.

They look for them.


What Changed in My Thinking

Earlier, I used to see systems as:

  • Applications

  • Features

  • Functionalities

Now, I see them as:

  • Attack surfaces

  • Information exposure points

  • Potential entry paths

When I see:

  • Open ports → I think which services are exposed?

  • Public data → I think what can be used for recon?

  • Running services → I think are they outdated or misconfigured?

This shift in thinking changed everything for me.


Final Thought

Security doesn’t start when an attack happens.

It starts much earlier.

It starts when someone begins observing you.

Quietly.
Carefully.
Systematically.

And that’s what makes reconnaissance so powerful.


This blog is part of my Cybersecurity Learning Journey:

Part 1: What Really Happens When You “Just Open a Website”?
Part 2: Where Networks Become Vulnerable
Part 3: How Hackers Actually Find Vulnerabilities (this blog)


If you’re learning cybersecurity like me,
this stage is where everything starts to feel real.

Because now, you don’t just see systems.

You see how they can be understood — and eventually, attacked. 🔐

Understanding Cybersecurity Step by Step

Part 3 of 8

This series is my journey into cybersecurity — breaking down how systems work, where they become vulnerable, and how attackers think. Written in a simple, practical way for anyone starting out.

Up next

What Happens After a Cyber Attack?

Inside a SOC Analyst's World Series: Understanding Cybersecurity Step by Step Part