Google ‘makes hacking easier'

old news really, If you're familiar with the search engine industry (which is what i do) these things have been known for months (if not years). There's even a book about google 'hacks'. It's not a secret, everybody can do it if you bother to read up about it. it's just that webmasters have no clue about what gets indexed by google (and other search engines). You can look for databases, passwords, admin information, yaddah yaddah yaddah if you know how to use google thorougly. Yes it's shocking what you can find, and ppl should 'protect' their sites better, but it's not rocket science to use a search engine to it's full extent. google shouldn't get the blame for it. webmasters should...
 
i wouldn't even call it hacking as that information is in the public domain (unlike real hacking). and if you don't want your site indexed, modify your robot.txt
 
google might get sued, but the complainants don't have a case. Like i said, if you don't want a part of your site to get indexed in a search engine, it's very simple to block the search engines from spidering certain sections by modifying your robot.txt file. If you don't do that, common sense is that your WHOLE site will get indexed, even the sensiteve parts.

and if you know what to look for (e.g. inurl:admin or inurl:.mdb) people will be able to retrieve that information.

The main argument of the complainants tends to be : it's not b/c my site is on the internet that i want it to be indexed (or publicly available). Which imho is a load of cr*p, b/c how else are ppl going to find your site?

so it's good that the issue is raised, to make ppl aware of it. But please don't blow it out of proportion.
 
the only point of contention is really that Google caches sites (and thus information) it doesn't actually own. That's really where the privacy issue comes in. Because it means information can still be available although the owner has taken it offline.
 
As the article states, rename any scripts you are using to something unusual and also, remove version numbers, for instance :- "Powered by: vBulletin Version 3.0.5"

Just kidding rpm ! :D
 
Top
Sign up to the MyBroadband newsletter
X