|
-
March 21st, 2008, 08:34 PM
#1
Goolag - Automated Google hacking
From the SearchSecurity.com (TechTarget) March 21 Newsletter:
Those clever folks at Cult of the Dead Cow (cDc), previously most infamous for creating the Windows hacking tool "Back Orifice," have once again raised a rallying cry with their new tool, Goolag. Goolag allows security personnel and ruffians alike to make automated queries that test websites for hundreds of common security flaws.
Using a technique popularized by security researcher Johnny Long, the Google search engine is used to send specially crafted queries to websites, which often oblige by returning information that most security administrators would prefer remain hidden or fixed.
A typical example of such "Google hacking" would be to search for a particular PHP script used during development, but not removed from an operational system: inputting the phrase filetype hp inurl:"viewfile" -"index.php" -"idfil into Google unsurprisingly reveals a fair number of websites that fail to prevent such files from being viewed. This is but one of literally hundreds of security gaffes that Google can be used to uncover.
However, running hundreds of search queries one-by-one in order to "Google hack" a website can lead to carpel tunnel, which may be why cDc decided to automate the process by creating Goolag. The Goolag scanner is a standalone Windows application with a simple GUI. It uses a single XML-based configuration file for its settings. All the Google hacking queries (affectionately known as "dorks" within the
industry) come with the distribution of the scanner and reside in a single file.
For those who have misgivings about installing software created by clever hackers, the cDc has published the full source code of Goolag; for the brave, simply download the executable and you can be Google hacking in mere minutes.
Running Goolag is simplicity itself, so resist the temptation to examine anything for which you don't have direct security responsibility. Then take the output of Goolag and get your Web developers busy fixing the flaws you will most likely find.
Scott Sidel is an ISSO with Lockheed Martin.
www.goolag.org... This is just too easy...
Similar Threads
-
By Egaladeist in forum General Computer Discussions
Replies: 1
Last Post: October 28th, 2005, 04:49 AM
-
By ch4r in forum Other Tutorials Forum
Replies: 2
Last Post: January 21st, 2005, 02:53 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|