It is used by millions of people on the Internet every day. Now, it is also used with increasing frequency by hackers seeking sensitive data like Social Security numbers: a Google search.. A recent data breach at Yale University marks the latest example of a security flaw exposed by "Google hacking," which involves querying the popular search engine for website vulnerabilities. For 10 months, names and Social Security numbers belonging to 43,000 people affiliated with Yale were visible through a Google search, the Yale Daily News reported last week. On Monday, the security firm Identity Finder said it found 300,000 names and Social Security numbers of California residents who applied for workers' compensation benefits by searching Google for common keywords. And in June, an Australian security consultant said the customer database of Groupon's India subsidiary was also visible through a Google search. . A recent data breach at Yale University marks the latest example of a security flaw exposed by 'Goog. millions, people, internet, every, increasing. . LinuxSecurity.com Team
Interesting perspective, for sure could prove handy on a nation-wide scale. The concept of googling for private keys has been around for quite a while, and here's an informative paper emphasising on how Google can Reveal Cryptographic Secrets taking the topic even further : . "Google hacking is a term to describe the search queries that find out security and privacy flaws. Finding vulnerable servers and web applications, server fingerprinting, accessing to admin and user login pages and revealing username-passwords are all possible in Google with a single click. Google can also reveal secrets of cryptography applications, i.e., clear text and hashed passwords, secret and private keys, encrypted messages, signed messages etc. In this paper, advanced search techniques in Google and the search queries that reveal cryptographic secrets are explained with examples in details." The link for this article located at Dancho Danchev is no longer available. . Investigate the ways in which Google hacking uncovers hidden cryptographic vulnerabilities and exposes potential security weaknesses using sophisticated search methodologies.. Google Hacking,Cryptographic Secrets,Privacy Vulnerabilities,Security Flaws,Information Disclosure. . LinuxSecurity.com Team
Although security software can identify when an attacker is performing reconnaissance work on a company's network, attackers can find network topology information on Google instead of snooping for it on the network they're studying, he said. This makes it harder for the network's administrators to block the attacker. "The target does not see us crawling their sites and getting information," he said. . Often, this kind of information comes in the form of apparently nonsensical information -- something that Long calls "Google Turds." For example, because there is no such thing as a Web site with the URL (Uniform Resource Locator) "nasa," a Google search for the query "site:nasa" should turn up zero results. instead, it turns up what appears to be a list of servers, offering an insight into the structure of Nasa's (the U.S. National Aeronautics and Space Administration's) internal network, Long said. Combining well-structured Google queries with text processing tools can yield things like SQL (Structured Query Language) passwords and even SQL error information. This could then be used to structure what is known as a SQL injection attack, which can be used to run unauthorized commands on a SQL database. "This is where it becomes Google hacking," he said. "You can do a SQL injection, or you can do a Google query and find the same thing." Although Google traditionally has not concerned itself with the security implications of its massive data store, the fact that it has been an unwitting participant in some worm attacks has the search engine now rejecting some queries for security reasons, Long said. "Recently, they've stepped into the game." The link for this article located at InfoWorld is no longer available. . Discover how Google can be exploited for intelligence gathering, revealing weaknesses in networks and facilitating breaches such as cross-site scripting.. Google Hacking,Cybersecurity Strategies,Network Exploitation,SQL Injection. . Brittany Day
Why bother pounding at a website in search of obscure holes when you can simply waltz in through the front door? Hackers have recently done just that, turning to Google to help simplify the task of honing in on their . . . . Why bother pounding at a website in search of obscure holes when you can simply waltz in through the front door? Hackers have recently done just that, turning to Google to help simplify the task of honing in on their targets. "Google, properly leveraged, has more intrusion potential than any hacking tool," said hacker Adrian Lamo, who recently sounded the alarm. The hacks are made possible by Web-enabled databases. Because database-management tools use canned templates to present data on the Web, typing specific phrases into Internet search tools often leads a user directly to those templated pages. For example, typing the phrase "Select a database to view" -- a common phrase in the FileMaker Pro database interface -- into Google recently yielded about 200 links, almost all of which lead to FileMaker databases accessible online. The link for this article located at wired.com is no longer available. . Cyber intruders manipulate Google tools to uncover weak web databases, disclosing potential vulnerabilities and threats in digital platforms.. Database Security, Google Hacking, Online Vulnerabilities. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.