Matt Payne - Google hacking CSF-Jun2005.pdf
(
624 KB
)
Pobierz
Google Hacking 101
Google Hacking 101
Edited by Matt Payne, CISSP
15 June 2005
http://MattPayne.org/talks/gh
1
Outline
• Google Bombing
• Schneier in
Secrets and Lies
– Attack at a distance
–
Emergent behavior
– Automation
• Google as a mirror
• “Interesting Searches”
– Software versions
– Passwords, credit card numbers, ISOs
• CGI Scanning
– Vulnerable software
• Defense against Google Hacking
2
Google Bombing
!=
Google Hacking
• http://en.wikipedia.org/wiki/Google_bomb
• A
Google bomb
or
Google wash
is an
attempt to influence the ranking of a given
site in results returned by the Google
search engine. Due to the way that
Google's Page Rank algorithm works, a
website will be ranked higher if the sites that
link to that page all use consistent anchor
text.
3
So What Determines Page
Relevance and Rating?
• Exact Phrase: are your keywords found as
an exact phrase in any pages?
• Adjacency: how close are your keywords to
each other?
• Weighting: how many times do the
keywords appear in the page?
• PageRank/Links: How many links point to
the page? How many links are actually in
the page?
4
From: Google 201, Advanced Googology - Patrick Crispen, CSU
Equation: (Exact Phrase Hit)+(AdjacencyFactor)+(Weight) * (PageRank/Links)
Simply Put
• “Google allows for a great deal of target
reconnaissance that results in little or no
exposure for the attacker.” – Johnny Long
• Using Google as a “mirror” searches find:
– Google searches for Credit Card and SS #s
– Google searches for passwords
– CGI (active content) scanning
5
Plik z chomika:
wariatowaty
Inne pliki z tego folderu:
AVG 2013 + Key do 2018 roku!!.rar
(117099 KB)
avg.jpeg
(13 KB)
AVG PC TuneUp 2013 PL ,krack,klucz Polski Opis instalacji.rar
(54373 KB)
Podsluch GG i innych komunikatorow by ICEHOT.rar
(7319 KB)
Lamanie Hasel i Zaawansowane Opcje Systemu XP.rar
(1984 KB)
Inne foldery tego chomika:
Pliki dostępne do 01.06.2025
Camera
Dokumenty
Filmy
Galeria
Zgłoś jeśli
naruszono regulamin