Billionwaves technologies provides Cyber security as the application of technologies,

Is information gathering the first step towards website hacking?

It is, not only for site hacking but any kind of hacking in general.

Major steps in hacking:-

  • Reconnaissance(info gathering)
  • Scanning
  • Exploiting
  • Maintaining access
  • Cleanup

So, for any procedural attack, information gathering is essential. If you want someone in jail, you won't directly go and arrest them. You need to collect evidence or proof against them. Similarly to attack a target, you need to collect as much information as you can, related to them.

In the case of website hacking, crucial information can be backend tech stack, sub-domain enumeration, sensitive information leakage, attack surface identification, etc.

