Login

Username:

Password:

 
Lost Password?
Register now!


Did you know?
Why choose SafeInput?



Random FAQ
What is Keyboard Input Disguise?

Vulnerabilities & Exploits : Hackers develop Google-based scanning tool
Posted by glm on 2008/12/22 18:05:38 (23 reads)





By :Clement James


Feb 28, 2008 9:29 AM




The group claims that the Goolag Scanner enables anyone to audit their own website via Google.

The scanner technology is based on 'Google hacking', a form of vulnerability research developed by a cDc member known as 'Johnny I Hack Stuff'.

Available as a downloadable application, Goolag makes use of 'dorks', or detailed search patterns that show untapped results for sites previously indexed by Google.

Dorks find results that might show information relevant to security issues and/or confidential data, and are not limited to Google's search engine, according to cDc.

However, the Goolag Scanner is focused on usability. It simplifies the use of myriad numbers of dorks to a few mouse clicks, and does not require cryptic command line options or knowledge of 'Google hacking'.

Goolag Scanner comes with its own dorks database, but it is not limited to this, essentially lowering the bar for would be hackers using dorks to scan sites for vulnerabilities.

"It is no big secret that the web is the platform, and this platform pretty much sucks from a security perspective," said cDc spokesman 'Oxblood Ruffin'.

"Goolag Scanner provides one more tool for site owners to patch their online properties. We've seen some pretty scary holes through random tests with the scanner in North America, Europe, and the Middle East.

"If I were a government, a large corporation, or anyone with a large website, I'd be downloading this beast and aiming it at my site yesterday. The vulnerabilities are that serious."

With Goolag, cDc appears to be repeating history by putting easy-to-use hacking tools into the hands of novices.

The group shot to notoriety during the 1990s with the release of the BackOrifice tools which allowed low-level users to hijack and take control of Windows PCs.





Source from:Copyright © 2008 vnunet.com







Other articles
2009/2/4 23:20:16 - Cloud computing is a storage spot for malware
2009/2/4 23:20:15 - Microsoft responds to Windows 7 security gripe
2009/2/4 23:20:12 - Web identity hijacking on the rise
2009/2/4 23:20:12 - Google glitch puts surfers in a quandary
2009/2/4 23:20:11 - Facebook plays down privacy concerns
2009/2/4 23:20:10 - Australian Computer Society to use Sophos security solution
2009/2/4 23:20:09 - Google working on fix for clickjacking vulnerability in Chrome
2009/2/4 23:20:08 - McAfee: Malware will use web and USB sticks to spread in 2009
2009/2/4 23:20:07 - With economy in tailspin, Monster discloses major breach
2009/2/4 23:20:06 - OS X 'pirate' trojan resurfaces
2009/2/4 23:20:05 - IE 8 approaching on formal release
2009/2/4 23:20:04 - Companies warned over use of Netbooks
2009/2/4 23:20:03 - Trend Micro signs up with BigFix
2009/2/4 23:17:08 - Banks urged to change security policies
2009/2/4 23:17:08 - Heartland incident provides opportunity to standardise data breach notification laws

The comments are owned by the poster. We aren't responsible for their content.

Articles