The importance of favicons in website OSINT research
osintme.com
osintme.com
And here's a map of favicons that Shodan has seen across the Internet: https://faviconmap.shodan.io/
The first time I encountered it was in the context of civilians collecting actionable military intel in the Russia-Ukraine conflict by trolling social media. But now I see people talking about it like it's a career, and see what I would have standard IT security posted under it.
Do people just use it to refer to any sort of civilian information gathering these days? Has IT security just rebranded as OSINT?
This is opposed to acquiring data by other means, like breaking into protected systems, stealing classified materials, planting moles, extortion and blackmailing, etc.
I continue to believe that half (or more) of all security reports/warnings are false positives due to inaccuracies such as this.
https://blog.chromium.org/2021/07/m92-faster-and-more-effici...
- the site is a careless impostor
- the site is the real deal
- a hash collision
Case 3 must exist by the pigeonhole principle given that the hashes are smaller than most favicons. Otoh, if it does show up, you can exclude it by doing a full comparison.
So, just a waste of time for anyone hoping to see an exploit based on favicons.
Favicons are very useful for spotting phishing sites and finding forgotten servers.
OSINT is about exploiting public data for private benefit.
The article was meh, others are expressing similar opinions if you read. It is OK that you find it useful but for me was sincerely expecting something more from the title.