
One expert says so...
By Robert Lemos
Published: 30 July 2004 08:55 BST
Google, the world's most popular search engine, is one of the handiest tools for hackers, according to one security expert.
Google's ability to record internet sites' content can be used to pinpoint those with weak security, Johnny Long, a security researcher and computer scientist for Computer Security Corp. told attendees at the Black Hat Security Briefings. Though the technique is not new, well-crafted searches turned up so many sites with vulnerabilities that even jaded researchers laughed during the session.
"It is an old dog with new tricks," Long said. "It never ceases to amaze people, all the vulnerabilities out there."
By searching for default server page titles, for example, an attacker can find easily exploitable servers. Applications left in default modes can also be found by searching for error pages generated by the software. And searching for specific file names can pinpoint vulnerable servers connected to the internet.
"It is the first step to finding vulnerable targets," Long said.
A simple search for the log-in page of Microsoft's web server software, the internet Information Server, turned up 11,300 sites on the internet that exposed the page to the public. Gathering log-in information for poorly configured databases is also easy, he said.
The exploitation of Google's in-depth searching capabilities underscores how software with no malicious motive can be used to help online intruders. The recent MyDoom.O virus hammered Google and other search engines with searches from infected PCs for additional email addresses to which the program could send itself. Security researchers have also theorised that Google and other search engines could be used as a carrier of malicious code.
"I only use Google to find vulnerable servers," said Tim Mullin, security specialist for accounting-software maker Anchor IS. Mullin said other search engines don't have the advanced search option available on Google and don't cache old versions of Web sites. "Not only can I see what exists now, but I can see what the website looked like before."
A Google representative could not immediately comment, citing Securities and Exchange Commission regulations regarding the quiet period before a public offering.
For most, the depth of Google searches is just one more potential threat to worry about.
"It's not revolutionising anything that people are doing now," Long said. "It is just adding another attack vector."
Robert Lemos writes for News.com
Here we have a group of guys who developed somthin...
Anonymous
Its a good thing if Google highlights these securi...
I hate Dell
I have to admit, we have used Google to track down...
Jon
Google is NOBODYs friend. It tracks and monitors y...
Aenox
yes, thats like blaming the writer of "ping" for a...
Mayuresh Kadu
Software Engineer - Equities Pricing - C++, C, UNIX, SDLC, multi-threading - London, South East The Real-Time Pricing Engine team is responsible for ...
A leading manufacturer within the heavy engineering industry based in the East Midlands has an immediate requirement for a development engineer on an ...
One of the world's leading international investment banks is currently looking to hire a Senior C# Developer to work in its industry leading ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...