Sponsor Advertisements help keep UGN Security Online.
Sponsor Advertisements help keep UGN Security Online.
Want to earn prizes for clicking online advertisements? Join Rewards1.com.
|
|
|
#1545 - 03/11/04 07:05 AM
Google is your friend.
|
UGN Super Poster
Registered: 09/18/02
Posts: 553
Loc: Cluj-Napoca, Romania
|
There was a very interesting article written in The Register today (you can find it here ). The article points out that while Google is a great search engine that can be used for good, it can also be used by evil individuals to find out vulnerabilities or discover passwords, etc. This is done by using the advanced search operators like site: intitle: inurl: (check out the complete list of Google Advance Search Operators here ) and combining them with the usual error messages. For example searching in Google for something like intitle:"Index of..etc" passwd will return about 190 sites where you can access the passwd file. From there it's just a matter of time while JTR does the rest of the work for you. Combine the above search with site:www.enter_site_here.com and google for something like : site:www.enter_site_here.com intitle:"Index of..etc" passwd and you'll be able to find out if you can access the passwd file of the site you are looking for. There is more to this than just passwd files. Googleing for stuff like mysql or php error messages can reveal a lot of stuff as well. I guess it depends of how creative you get. Of course you can use a robots.txt file to specify the paths of the folders/files you don't want google to list, but someone could allways look for the robots.txt file and find out what you are trying to hide. This reminds me of that post about the interesting stuff you can find using the right words in Kazaa. 
|
|
Top
|
|
|
|
Sponsor Advertisements help keep UGN Security Online.
Sponsor Advertisements help keep UGN Security Online.
|
|
#1546 - 03/11/04 07:17 AM
Re: Google is your friend.
|
Community Owner
   
Registered: 02/28/02
Posts: 7192
Loc: Portland, OR; USA
|
|
|
Top
|
|
|
|
#1547 - 03/11/04 12:07 PM
Re: Google is your friend.
|
Member
Registered: 06/05/02
Posts: 207
Loc: US
|
yeah, but just watch out. it's not to hard for a web admin to forge that stuff. and create false logins to sit there and watch you.//
_________________________
Unbodied unsouled unheard unseen Let the gift be grown in the time to call our own Truth is natural like a wind that blows Follow the direction no matter where it goes Let the truth blow like a hurricane through me
|
|
Top
|
|
|
|
#1548 - 03/11/04 01:55 PM
Re: Google is your friend.
|
UGN Super Poster
Registered: 09/18/02
Posts: 553
Loc: Cluj-Napoca, Romania
|
Yeah, as a matter of fact I have seen one such "honney pot" right here . But I'm quite sure they can't arrest me for searching "passwd" on Google, and entering their site. More info on this subject can be found here , in case anyone wants to see what else can be done.
|
|
Top
|
|
|
|
#1550 - 03/12/04 11:04 AM
Re: Google is your friend.
|
UGN Super Poster
Registered: 10/08/02
Posts: 955
Loc: Merrill, IA, USA
|
Yes, I wouldn't limit it to google as you said. About any search engine would work. People have to realize what they are opening up to the public. Check configurations atleast twice, regardless of a webserver, a P2P client/server, or a vanilla installation of windows. I tend to run anti-virus, adware, spyware, trojan, web exploits, port scanners, etc on myself. Better finding these things yourself than someone else doing it for you 
|
|
Top
|
|
|
|
#1551 - 03/12/04 04:20 PM
Re: Google is your friend.
|
UGN Dumbass 2003/04
Registered: 02/07/04
Posts: 74
Loc: A compfy place.
|
how I do love Google
_________________________
You know that when I hate you, it is because I love you to a point of passion that unhinges my soul. ~Julie De Lespinasse~
|
|
Top
|
|
|
|
#1552 - 03/13/04 10:28 AM
Re: Google is your friend.
|
UGN Super Poster
Registered: 10/29/02
Posts: 616
Loc: The Beach
|
Dood it's not just google, google is liek the word "hacker" right now, it's becoming annoyingly fuckin stupid. How about I eat muh brefas bacon, and cock slap the fucker that's keeping this google fad going. People don't realize until they actually look until the surface that google has internal boolean modifiers, you can mold the search options to search for VERY specific file info. Images, text, exploitage, cacheing. Hell I just translated a cache of a dead site for my lostcity stargate community. then the site came active again, and through the translation cache url it refreshed to take on the uppage in liek seconds. Yea that is html, but it's advanced stuff for a searcher. Then think about calculations, conversions, all kinds of shit google does, and then matches to a search. Liek I'm 203 centimeters if I make it centimeters, if I do liek 80in to cm I get to see what knowledge is out there on 6'8 converted to cm things that are 23 centi meter's long such..heh I just woke at 7 watching part 1 to 2 part stargate sg-1 season 7 end to season 8, and atlantis switch over. yar...google is elite, but ppl are lame about it, it always seems. But I do disliek ignorance, and liek stubborness to be ignorant...so...
_________________________
"Beware the Jabberwock, my son! The jaws that bite, the claws that catch! Beware the Jubjub bird, and shun The frumious Bandersnatch!"
|
|
Top
|
|
|
|
#1553 - 03/13/04 07:55 PM
Re: Google is your friend.
|
UGN Dumbass 2003/04
Registered: 02/07/04
Posts: 74
Loc: A compfy place.
|
weeve, that thing with the inches and centimeters I have a feeling I have heard that somewhere before. 
_________________________
You know that when I hate you, it is because I love you to a point of passion that unhinges my soul. ~Julie De Lespinasse~
|
|
Top
|
|
|
|
|
Registered: 03/01/02
Posts: 505
|
|
2198 Members
46 Forums
24927 Topics
60097 Posts
Max Online: 1567 @ 04/25/10 10:20 AM
|
|
|
1 registered (Gremelin),
308
Guests and
201
Spiders online. |
|
Key:
Admin,
Global Mod,
Mod
|
|
|