Wednesday, March 14, 2012

Google Hacking, be careful with your web site!

(Now you can access to the Spanish version of this post | Puede acceder a la versión en Español de este post)

Hi there!
Long time ago from last post, I was very busy last months.
We're back again to talk about a old-classic way of hacking: "Google hacking".
This hacking is very simple a it doesn't require any advanced tool or software, it can be done just by using a 56k modem connection to the internet  (I really hope your connection is a bit faster than this  :D   )
All of us know about the advanced search algorithms and powerful data pickup of Google, I think Google is the most technologically advanced search engine in the world right now (in the last 5 - 10 years).
Google is much than a text box and a "Search" button; even much higher than a "I'm feeling lucky" button  :)
We should know Google has able to pickup data from other files than classic html web pages, every day Google is detecting a huge amount of pdf, doc,... files. Google has many filter and advanced search options, like search by filetype, by some text in a web address (url), by file extension...
This mechanism is simple as:
- Searching Doc. Watson logs from a machine
- Searching important information about personal data
- Searching files with users accounts
- Searching files with user and passwords!!!!
Yeah, absolutely, all of this info is there, we have free access at many files just using Google.
You can access to google help in order to learn about Google "commands" to perform some advanced searches.
Recently, this easy simple hacking type was used against many important security organisms from the U.S. and West-Europe.

This method can be considered "Social Engineering"

We are legion.
Next post: "Reaver and WPS attack"

No comments:

Post a Comment

Popular Posts