How Hackers Actually Find Vulnerabilities: Reconnaissance & Scanning

Software engineering learner documenting my journey across Java, backend development, DSA, and cybersecurity. I write beginner-friendly explanations, practical notes, and lessons learned while building and analyzing real-world systems.
In Part 1, I followed a packet from my browser to a server.
In Part 2, I understood where networks become vulnerable.
Everything started making sense.
But one question kept bothering me:
How do attackers even find these vulnerabilities in the first place?
They don’t randomly guess.
They don’t magically “hack” into systems.
They observe, collect, and analyze.
That process is called reconnaissance.
Reconnaissance – Where Every Attack Begins
Before any real attack happens, there’s a quiet phase.
No alerts.
No warnings.
No visible damage.
Just information gathering.
At first, I thought hacking starts with exploitation.
But I was wrong.
It actually starts with understanding the target better than the target understands itself.
There are two types:
1. Passive Recon
No direct interaction with the target
Uses publicly available data
Examples:
Company websites
Social media
Public documents
2. Active Recon
Direct interaction with the target system
Leaves traces
Examples:
Scanning ports
Sending requests
Probing services
And honestly, this realization surprised me:
It felt less like hacking… and more like digital stalking.
OSINT – When Information Is Already Public
One of the most eye-opening things I learned was about OSINT (Open Source Intelligence).
This is information that is already available — legally and publicly.
No hacking required.
Examples include:
Domain details (WHOIS)
DNS records
Employee LinkedIn profiles
GitHub repositories
Job postings (revealing tech stacks)
At first, this felt harmless.
But then I realized something uncomfortable:
Sometimes, organizations expose more information themselves
than attackers need to steal.
A simple job post like:
“We are hiring a backend developer with experience in Node.js and MongoDB”
Already tells an attacker:
What tech stack is used
What kind of vulnerabilities might exist
And suddenly, recon becomes targeted.
Scanning – Knocking on Every Door
After gathering information, the next step is scanning.
This is where attackers start interacting with the system.
Think of it like this:
If a system is a house,
scanning is checking which doors and windows are open.
Each “door” is a port.
Examples:
Port 22 → SSH
Port 80 → HTTP
Port 443 → HTTPS
If a port is open, it means:
➡️ A service is running
➡️ And it’s waiting for connections
That doesn’t mean it’s vulnerable.
But it can be.
And the more open ports there are, the larger the attack surface becomes.
Enumeration – Looking Inside the Doors
Scanning tells you what is open.
Enumeration tells you what exactly is running.
This step goes deeper.
Attackers try to extract:
Usernames
Service versions
Shared resources
System details
In simple words:
If scanning finds the door,
enumeration tries to peek inside.
This is where things start becoming dangerous.
Because now, the attacker is no longer guessing.
They are building a clear map of the system.
The Tools That Made This Real for Me
Until this point, everything felt theoretical.
Recon, scanning, enumeration — it all made sense.
But it didn’t feel real.
That changed when I started using some basic tools.
1. DNS & Domain Information
I came across tools like:
nslookupwhois
With just a domain name, I could find:
IP addresses
DNS records
Domain details
It was surprising how much information is publicly accessible.
I didn’t need to hack anything.
I just needed to ask the right questions.
2. Port Scanning with Nmap
Then I tried Nmap.
This was the moment things clicked.
With a single command, I could see:
Open ports
Running services
Sometimes even service versions
It felt like:
I was no longer guessing —
I was seeing the system from the outside.
3. Watching Traffic with Wireshark
Then came Wireshark.
Instead of just knowing that packets exist,
I could actually see them moving.
Requests
Responses
Protocol details
Everything was visible.
Networking stopped being invisible.
It became something I could observe in real time.
What I Realized
These tools didn’t “hack” anything.
They simply helped me:
Understand systems better
See what is exposed
Think like an attacker
And that’s when I understood:
The difference between a normal user and an attacker
is often just awareness and observation.
Why This Stage Is More Dangerous Than It Looks
At this point, something important clicked for me:
👉 No vulnerability has been exploited yet
👉 No system has been “hacked”
And still…
This is one of the most critical phases.
Why?
Because by the time an attacker reaches exploitation:
They already know which ports are open
They already know which services are running
They already know where the weak points are
It’s no longer random.
It’s precise.
The real danger is not just in exploitation…
It’s in how accurately the target is understood before the attack.
Connecting This to What I Learned Earlier
In Part 2, I explored vulnerabilities like:
ARP spoofing
DHCP attacks
Open ports
Misconfigurations
At that time, it felt like:
“These are possible risks.”
But now I see it differently:
These vulnerabilities don’t stay hidden.
They are actively searched for.
Attackers don’t wait for mistakes.
They look for them.
What Changed in My Thinking
Earlier, I used to see systems as:
Applications
Features
Functionalities
Now, I see them as:
Attack surfaces
Information exposure points
Potential entry paths
When I see:
Open ports → I think which services are exposed?
Public data → I think what can be used for recon?
Running services → I think are they outdated or misconfigured?
This shift in thinking changed everything for me.
Final Thought
Security doesn’t start when an attack happens.
It starts much earlier.
It starts when someone begins observing you.
Quietly.
Carefully.
Systematically.
And that’s what makes reconnaissance so powerful.
This blog is part of my Cybersecurity Learning Journey:
Part 1: What Really Happens When You “Just Open a Website”?
Part 2: Where Networks Become Vulnerable
Part 3: How Hackers Actually Find Vulnerabilities (this blog)
If you’re learning cybersecurity like me,
this stage is where everything starts to feel real.
Because now, you don’t just see systems.
You see how they can be understood — and eventually, attacked. 🔐


