Google Hacking (MoreNET).pdf

(3688 KB) Pobierz
Google Hacking
Beth Young
Kris Trower
MOREnet Security
security@more.net
www.more.net | University of Missouri
Copyright ©2009 MOREnet and The Curators of the University of Missouri
Agenda
Google Hacking introduction
Automating searches
Building queries
What to expect from your results
Controlling how your content is indexed
References
www.more.net | University of Missouri
Copyright ©2009 MOREnet and The Curators of the University of Missouri
What is Google Hacking?
Google hacking is an advanced search
technique that could allow someone to
find sensitive data or vulnerabilities on
any site indexed by a search engine.
www.more.net | University of Missouri
Copyright ©2009 MOREnet and The Curators of the University of Missouri
What benefit does it provide?
An attacker
Anonymous profiling of your network/organization through
publically accessible information
Documents and data on your website
Configuration and network information that you may have
posted on a mail list or forum
Device and software information that you may have posted
in job openings
Information about your employees, students and patrons
that could be used in a social engineering attack
Misconfigurations and vulnerabilities on your server
www.more.net | University of Missouri
Copyright ©2009 MOREnet and The Curators of the University of Missouri
What benefit does it provide?
You
The ability to find potential exposures and vulnerabilities
and correct them!
www.more.net | University of Missouri
Copyright ©2009 MOREnet and The Curators of the University of Missouri
Zgłoś jeśli naruszono regulamin