Google Hacking for Penetration Testers

1st Edition

Authors: Johnny Long Bill Gardner Justin Brown
Paperback ISBN: 9781597491761
eBook ISBN: 9780080484266
Imprint: Syngress
Published Date: 7th November 2007
Page Count: 560
30.99 + applicable tax
49.95 + applicable tax
38.95 + applicable tax
Unavailable
Compatible Not compatible
VitalSource PC, Mac, iPhone & iPad Amazon Kindle eReader
ePub & PDF Apple & PC desktop. Mobile devices (Apple & Android) Amazon Kindle eReader
Mobi Amazon Kindle eReader Anything else

Institutional Access


Description

This book helps people find sensitive information on the Web.

Google is one of the 5 most popular sites on the internet with more than 380 million unique users per month (Nielsen/NetRatings 8/05). But, Google’s search capabilities are so powerful, they sometimes discover content that no one ever intended to be publicly available on the Web including: social security numbers, credit card numbers, trade secrets, and federally classified documents. Google Hacking for Penetration Testers Volume 2 shows the art of manipulating Google used by security professionals and system administrators to find this sensitive information and “self-police” their own organizations.

Readers will learn how Google Maps and Google Earth provide pinpoint military accuracy, see how bad guys can manipulate Google to create super worms, and see how they can "mash up" Google with MySpace, LinkedIn, and more for passive reconaissance.

Key Features

• Learn Google Searching Basics Explore Google’s Web-based Interface, build Google queries, and work with Google URLs. • Use Advanced Operators to Perform Advanced Queries Combine advanced operators and learn about colliding operators and bad search-fu. • Learn the Ways of the Google Hacker See how to use caches for anonymity and review directory listings and traversal techniques. • Review Document Grinding and Database Digging See the ways to use Google to locate documents and then search within the documents to locate information. • Understand Google’s Part in an Information Collection Framework Learn the principles of automating searches and the applications of data mining. • Locate Exploits and Finding Targets Locate exploit code and then vulnerable targets. • See Ten Simple Security Searches Learn a few searches that give good results just about every time and are good for a security assessment. • Track Down Web Servers Locate and profile web servers, login portals, network hardware and utilities. • See How Bad Guys Troll for Data Find ways to search for usernames, passwords, credit card numbers, social security numbers, and other juicy information. • Hack Google Services Learn more about the AJAX Search API, Calendar, Blogger, Blog Search, and more.

Readership

Security professionals, system administrators, and power users using Google’s powerful, and at times complex, search features to find sensitive information that should NOT be publicly available on the Web.

Table of Contents

Instructions for online access

Acknowledgments

Lead Author

Contributing Authors

Chapter 1: Google Searching Basics

Introduction

Exploring Google’s Web-based Interface

Language Tools

Building Google Queries

Working With Google URLs

URL Syntax

Summary

Solutions Fast Track

Links to Sites

Frequently Asked Questions

Chapter 2: Advanced Operators

Introduction

Operator Syntax

Troubleshooting Your Syntax

Introducing Google’s Advanced Operators

Allintext: Locate a String Within the Text of a Page

Inurl and Allinurl: Finding Text in a URL

Site: Narrow Search to Specific Sites

Filetype: Search for Files of a Specific Type

Link: Search for Links to a Page

Inanchor: Locate Text Within Link Text

Cache: Show the Cached Version of a Page

Numrange: Search for a Number

Daterange: Search for Pages Published Within a Certain Date Range

Info: Show Google’s Summary Information

Related: Show Related Sites

Author: Search Groups for an Author of a Newsgroup Post

Group: Search Group Titles

Insubject: Search Google Groups Subject Lines

Msgid: Locate a Group Post by Message ID

Stocks: Search for Stock Information

Define: Show the Definition of a Term

Phonebook: Search Phone Listings

Colliding Operators and Bad Search-Fu

Summary

Solutions Fast Track

Links to Sites

Frequently Asked Questions

Chapter 3: Google Hacking Basics

Introduction

Anonymity with Caches

Directory Listings

Locating Dir

Details

No. of pages:
560
Language:
English
Copyright:
© Syngress 2007
Published:
Imprint:
Syngress
eBook ISBN:
9780080484266
Paperback ISBN:
9781597491761

About the Author

Johnny Long

Johnny Long is a Christian by grace, a professional hacker by trade, a pirate by blood, a ninja in training, a security researcher and author. He can be found lurking at his website (http://johnny.ihackstuff.com). He is the founder of Hackers For Charity(http://ihackcharities.org), an organization that provides hackers with job experience while leveraging their skills for charities that need those skills.

Affiliations and Expertise

A Christian by grace, a professional hacker by trade, a pirate by blood, a ninja in training, a security researcher and author who lurks at his website (http://johnny.ihackstuff.com) and is the founder of Hackers For Charity(http://ihackcharities.org), an organization that provides hackers with job experience while leveraging their skills for charities that need them

Bill Gardner

Bill Gardner is an Assistant Professor at Marshall University, where he teaches information security and foundational technology courses in the Department of Integrated Science and Technology. He is also President and Principal Security Consultant at BlackRock Consulting. In addition, Bill is Vice President and Information Security Chair at the Appalachian Institute of Digital Evidence. AIDE is a non-profit organization that provides research and training for digital evidence professionals including attorneys, judges, law enforcement officers and information security practitioners in the private sector. Prior to joining the faculty at Marshall, Bill co-founded the Hack3rCon convention, and co-founded 304blogs, and he continues to serve as Vice President of 304Geeks. In addition, Bill is a founding member of the Security Awareness Training Framework, which will be a prime target audience for this book.

Affiliations and Expertise

Bill Gardner OSCP, i-Net+, Security+, Asst. Prof. at Marshall University

Justin Brown

Justin Brown (@spridel11) is an Information Assurance Analyst at a large financial institution. Previously, Justin worked for as a consultant specializing in Open Source Intelligence. Through Google Hacking and dorks Justin has uncovered numerous troves of information leaks regarding his clients. Justin can usually be found at conferences volunteering with Hackers for Charity.

Affiliations and Expertise

Information Security Professional at One Worlds Lab