Google_Hacking_without_faces.pdf

(903 KB) Pobierz
Google Hacking
Information Security Summit
Cleveland, Ohio
Pete Garvin
pgarvin@protectus.com
October 2005
Google Hacking Overview
A few words about Google
What is Google Hacking?
Why it’s relevant
How-to
Defenses
References
Google Hacking - October 2005
2
Google Overview
Googlebot
Web Server
Web Server
Web Server
Web Servers
Web Server
(robots.txt)
(meta-tags)
Google
Database
Google Hacking - October 2005
3
Did Google get hacked?
No it didn’t, it just has
lots of options.
Select Preferences
from the main page.
Google Hacking - October 2005
4
What is Google Hacking?
• The technique of using search engines to:
– Find vulnerable targets
• Misconfigured servers
• Web based admin interfaces
• Servers running a particular version of software
– Find sensitive data
• “Unpublished” web pages
• Directory listings
• Databases
Google Hacking - October 2005
5
Zgłoś jeśli naruszono regulamin