A Dark Intro To Google Hacking

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    A Dark Intro To Google Hacking - Presentation Transcript

    1. A Dark Intro To Google Hacking By d0ubl3_h3lix Mon Jan 07 2008
    2. Agenda
      • What to know First
      • What Google Hacking (GH)?
      • GH As a Hack Tool
      • Some GH Syntaxes
      • GH Formula
      • The Bad Guys’ Weapon
      • The Good Guys’ Defense
    3. What to Know First
      • Make sure to have well understanding of Google Advanced Search Operators and Exploit Strings you search
      • Simply browsing Google Hacking Database loses your time much
      • E.g., phpBB 3.0 hole is announced. Before you do GH, ask yourself ‘Do I know about that hole well?’
    4. What Google Hacking (GH)?
      • Effective Google Searching with the help of Google Advanced Search Operators
      • Results Highly Customizable
      • Goes Straight to only what we desire
      • Supposed to have initial popularity among underground hacker communities; then widely publicized because of Johnny ’s community
    5. GH As Hack Tool
      • Mainly used in Information Gathering and Recon States of HardC0re hacking
      • Eliminates former heavy use of Vulnerability Scanners
      • Lets you dig security vulnerabilities using clues of texts on pages that vulnerable products use
      • For example, intext:"Powered by InvisionBoard 1.x"
    6. Some GH Syntaxes
      • Most commonly used: - intitle: - intext: - inurl: - ext: - filetype: - cache: - link: - site:
    7. GH Formula
      • For one vulnerability, Vulnerability x Google Hacking = Possible Thousands of Victims
    8. The Bad Guys’ Weapon
      • Hunt for random vulnerable hosts using GH
      • Viruses, worms, …etc use GH to find next victims
      • Once they find victims, they auto-launch endless sequences of attacks with the aid of malwares
    9. The Good Guys’ Defense
      • While Bad Guys search random targets,
      • Good Guys protect a particular host that they’re responsible for using GH Methods
      • Test both blackbox & whitebox approaches. Use Goolge Honeypot if you wish
      inurl:<vulnerable strings here> + site:www.IProtectThisSite.com

    + Aung  KhantAung Khant, 2 years ago

    custom

    1358 views, 0 favs, 0 embeds more stats

    A little bit intro to google hacking

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 1358
      • 1358 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 46
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories

    Tags