Google Hacking Week : Grab juicy info with the right search query.

Feb 28

So we showed you how powerful a good Google search could be this week. Time to turn to the dark side and give you some examples of how hackers can use these skills to get to some pretty scary things. To create a dangerous situation where the wrong information can fall into the wrong hands, you need 2 ingredients. Somebody who is stupid enough to put it online, and somebody who is clever enough to find it. Below are some pretty creepy examples of how some Google dorks spill some information that was supposed to be private.

hackers_4996108_lrg

Some juicy searches.

Some people write down their domain registration information in a .doc file .. and then put it on the internet. Whoever can put two and two together .. can steal their domain.

  • filetype:docx Domain Registrar $user $pass

How about finding product licence files for the Avast antivirus program ? Some of them are just up for grabs.

  •  

    filetype:avastlic

How about we go searching for a randomly published list of phonenumbers.

  • allinurl:phonenumbers filetype:xls

Search for random resume’s that candidates (or their employees) put online.

  • inurl:Curriculum Vitae filetype:pdf

How about some “Confidential Salary” documents that people put online. (we stood in awe at the first hit )

  • ext:(doc | pdf | xls | txt | ps | rtf | odt | sxw | psw | ppt | pps | xml) (intext:confidential salary | intext:”budget approved”) inurl:confidential

Or take a peek at people’s random downloaded hotmail emails. 

  • inurl:getmsg.html intitle:hotmail

Its a little bit of history .. but how about a random netscape browser history file. (we giggled at THIS one)

  • inurl:netscape.hst

And when combining this generic search query for root directories of certain FTP servers with a certain domain .. you can find out a lot. If you use it as listed below .. its just an interesting way to browse random file directories.

  • intitle:”FTP root at”

Msn messenger does not exist anymore, but there are plenty of contact lists well stocked with juicy email addresses up for grabs.

  • filetype:ctt “msn”

And the list goes on and on and on. Now, standing by themselves the Google searches above are quite harmless. They are too generic to do any harm and are only good for a chuckle. The dangerous part begins when these queries are targeted at a certain person, site our domain. Armed with ONLY their browser and an internet connection, the wrong people can find out all the right things they need to know to make you / your company / your website have a really bad day. Knowledge is power and it is also ambivalent. It can be used for good and for evil… So are you SURE that there is not digital flotsam with your username/passwords floating around on the internet ? Because once Google indexes it .. anybody with the right skills can find it.

Related Posts

Leave a Reply

Your email address will not be published. Required fields are marked *