{"id":546501,"date":"2005-06-24T15:15:28","date_gmt":"2005-06-24T15:15:28","guid":{"rendered":"http:\/\/localhost:8888\/wordpress\/technology\/546501-google-makes-hacking-easier.html"},"modified":"2005-06-24T15:15:28","modified_gmt":"2005-06-24T15:15:28","slug":"google-makes-hacking-easier","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/technology\/546501-google-makes-hacking-easier.html","title":{"rendered":"Google \u2018makes hacking easier&#8217;"},"content":{"rendered":"<p><font face=\"verdana,arial,helvetica,sans-serif\" size=\"2\">According to Barry Cribb, MD of IS Digital Networks, a potential hacker can identify weaknesses in Web sites simply by building the correct queries in the advanced search criteria.<\/font> <\/p>\n<p><font face=\"Arial\" size=\"2\"><font face=\"verdana,arial,helvetica,sans-serif\">Obviously these criteria have been designed to help the average Net user refine their searches, but as they say in the classics, what can be used for good can also be used for evil,\u201d he says.<\/font> <\/font><\/p>\n<p \/>\n<p><font size=\"2\">\u201cThe real problem here is that the traffic is initially directed to the Google search engine cache, passing firewall or IDS detection mechanisms, so the victim is unaware a hacker has even discovered the vulnerability until it is too late.\u201d <\/font><\/p>\n<p><font size=\"2\"><\/font><\/p>\n<p><font size=\"2\">He says that by using specific commands combined with wild card characters, it is possible to build queries capable of searching for specific vulnerabilities of Internet-facing devices, thus providing hackers with more targets faster than ever before. <\/font><\/p>\n<p><font size=\"2\"><\/font><\/p>\n<p><font size=\"2\">\u201cThis is emerging more and more in the public domain, because as more people become aware of this, they are curious, so it may even be done by someone who is simply trying it simply to see how it works, rather than a dedicated hacker,\u201d says Cribb. <\/font><\/p>\n<p><font size=\"2\"><\/font><\/p>\n<p><font size=\"2\">Cribb says entering a certain string into the Google search window \u201cwill get a list of about 38\u00a0000 sites with admin login pages\u201d. <\/font><\/p>\n<p><font size=\"2\"><\/font><\/p>\n<p><font size=\"2\">\u201cThe recent Santy worm, as an example, used a flaw in the popular bulletin board phpBB to spread, as the worm simply searched Google for sites using the vulnerable version.\u201d <\/font><\/p>\n<p><font size=\"2\"><\/font><\/p>\n<p><font size=\"2\">He claims that standard login pages and welcome messages, as well as the standard error messages are examples of weaknesses that may be exploited by hackers. <\/font><\/p>\n<p><font size=\"2\"><\/font><\/p>\n<p><font size=\"2\">\u201cThe best way of protecting yourself from the possibility of Google hacking is to change your default welcome message; change default error messages; remove the site \u2013 or at least parts of it \u2013 from the Google list, using the robots.txt file; and remove sensitive information from the Web site. <\/font><\/p>\n<p><font size=\"2\"><\/font><\/p>\n<p><font size=\"2\">\u201cAnother way is to test the Google cache yourself by effectively hacking your own site, to see your site vulnerabilities from the point of view of an attacker,\u201d says Cribb. <\/font><\/p>\n<p><font size=\"2\"><\/font><\/p>\n<p><font size=\"2\">Google could not be reached for comment at the time of publication. <\/font><\/p>\n<p><font size=\"2\"><\/font><\/p>\n<p><font size=\"2\">IS Digital Networks will host the first of a number of presentations explaining how Google hacking works and how to prevent it on 28 July. For more information, go to <\/font><a href=\"http:\/\/www.isdigital.co.za\/google_hacking.html\" target=\"_blank\" rel=\"noopener\"><font size=\"2\">http:\/\/www.isdigital.co.za\/google_hacking.html<\/font> <\/a><\/p>\n<p \/>\n","protected":false},"excerpt":{"rendered":"<p>So-called \u201cGoogle hacking\u201d is making it easier for would-be hackers to find vulnerable Internet sites.<\/p>\n","protected":false},"author":23,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[17],"tags":[],"class_list":["post-546501","post","type-post","status-publish","format-standard","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/546501"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=546501"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/546501\/revisions"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=546501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=546501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=546501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}