PDA

View Full Version : Google Hacking For Penetration Testers


FluxGFX
July 14th, 2005, 09:31 AM
I'm rolling the ball at this one. Let me know what you think, that if you've read the book about it.

Some great information can be found in their and also this allowed me to actually uncover holes in a few popular websites :)

Regards,
fluxgfx.com

meneer
July 14th, 2005, 10:13 AM
There's this nice site (http://johnny.ihackstuff.com/) too.

It's indeed amazing the stuff you can find. Like opening pandora's box. I just don't take the time to (mis)use it.

Vikorr
July 14th, 2005, 06:38 PM
Hacker community donating to charity ?

FluxGFX
July 18th, 2005, 09:56 AM
meneer,

I know what you mean. I have the book and several other articles and it was amazing what you could find. Once simple example of that is a exchange server that allowed me to login and create my own email account on the server and then be able to check the emails out and view the Global Address List. One other instance is how I could manage to retreive an SQL database with information...

Scary... when you think about it.

akshay_k72
July 18th, 2005, 11:11 AM
Actually, Chip (http://www.chip-india.com/tmissue.php) magazine's latest issue in India has a similar cover story. Never knew about it untill I read the article. No doubt, its pretty scary.

Cheers

Akshay

FluxGFX
July 18th, 2005, 12:14 PM
Hi,

Yeah. More specificly some technics you can use to retreive sensitive information such as cc, records, receipts etc...

Mind you that google has been trying to fix some loopholes but still remains you can use other crafted search syntax to achieve the same goal.

I got sh*t scared when I understood the potential g**gle had.

Regards,
fluxgfx.com

iceni60
July 18th, 2005, 01:42 PM
i have some hacks that let find whatever you want and download music, films, ebooks etc i have only used it once to see if it worked and downloaded the Paris Hilton vid :D

FluxGFX
July 19th, 2005, 09:16 AM
Hi,

The search syntax are quite easy to find. They are all over the place. You can get in depth knowledge of this with the book called "Google Hacking for Penetration Testers"

Regards,
fluxgfx.com

tom772
July 28th, 2005, 09:14 PM
Google Hacking for Penetration Testers" - what does this mean, sorry to ask, but im interested

T;)

meneer
July 29th, 2005, 03:43 AM
Penetration testing is the action to try to enter a system by means of using vulnerabilities, holes, misconfigurations etc. Penetration testing is also known as white hat or ethical hacking, because usually this act is performed by security specialists and auditors, who are requested to perform a penetration test by the owner of a system. White hat hackers may also unrequested cech for vulnerabilities, but the claim to inform the owner of the system of their findings, without using them.

When the owner of a system doesn't ask for the test, it's just a plain old hack, also known as a black hat hack , or criminal activity if the hacker is trying to gain access to certain resources on the system.

Cracking (using avaliable scripts by script kiddies) is in another league. Just plain nuisance.

tom772
July 29th, 2005, 10:53 PM
-{ Quote: "Penetration testing is the action to try to enter a system by means of using vulnerabilities, holes, misconfigurations etc. Penetration testing is also known as white hat or ethical hacking, because usually this act is performed by security specialists and auditors, who are requested to perform a penetration test by the owner of a system. White hat hackers may also unrequested cech for vulnerabilities, but the claim to inform the owner of the system of their findings, without using them.

When the owner of a system doesn't ask for the test, it's just a plain old hack, also known as a black hat hack , or criminal activity if the hacker is trying to gain access to certain resources on the system.

Cracking (using avaliable scripts by script kiddies) is in another league. Just plain nuisance." }-I also thought that hackers were all the same not white or black. Thats for the info though, you learning something new each day,

cheers T