Presentation is loading. Please wait.

Presentation is loading. Please wait.

NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba.

Similar presentations


Presentation on theme: "NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba."— Presentation transcript:

1 NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba Czech Republic Google hacking

2 navy.cs.vsb.cz 2 GH – official statement Google hacking is the term used when a hacker tries to find exploitable targets and sensitive data by using search engines. The Google Hacking Database (GHDB) is a database of queries that identify sensitive data. GHDB http://www.hackersforcharity.org/ghdb/http://www.hackersforcharity.org/ghdb/

3 navy.cs.vsb.cz 3 GHDB - example

4 navy.cs.vsb.cz 4 Introduction Google advanced operators help refine searches. They are included as part of a standard Google query. Advanced operators use a syntax such as the following: operator:search_term There’s no space between the operator, the colon, and the search term!

5 navy.cs.vsb.cz 5 Special characters ( + ) force inclusion of something common ( - ) exclude a search term ( “ ) use quotes around search phrases (. ) a single-character wildcard ( * ) any word ( | ) boolean ‘OR’ Parenthesis group queries (“master card” | mastercard)

6 navy.cs.vsb.cz 6 Advanced operators

7 navy.cs.vsb.cz 7 Advanced operators Link to useful cheatsheet https://www.sans.org/security- resources/GoogleCheatSheet.pdf

8 navy.cs.vsb.cz 8 Interesting Links Find all admin pages http://www.google.com/search?q=inurl:admin. php&start=10 Find email addresses https://www.google.cz/webhp?sourceid=chrom e-instant&ion=1&espv=2&ie=UTF- 8#q=inurl%3A%22email.xls%22

9 navy.cs.vsb.cz 9 Interesting links 2 Find printer interface https://www.google.cz/webhp?sourceid=chrome- instant&ion=1&espv=2&ie=UTF- 8#q=%22display+printer+status%22+intitle:%22Ho me%22 Find security cameras https://www.google.cz/?gfe_rd=cr&ei=WqAsVd6hH Omk8wfm6YCgBw&gws_rd=ssl#q=inurl:%22viewerf rame%3Fmode%3Dmotion%22

10 navy.cs.vsb.cz 10 For fun http://193.138.213.169/CgiStart?page=Single &Mode=Motion&Language=9

11 navy.cs.vsb.cz 11 Where to learn more? http://www.lukasnovak.net/skolni-prace/kib- google-hacking/ http://www.lukasnovak.net/skolni-prace/kib- google-hacking/ https://www.blackhat.com/presentations/bh- europe-05/BH_EU_05-Long.pdf https://www.blackhat.com/presentations/bh- europe-05/BH_EU_05-Long.pdf http://www.hackersforcharity.org/ghdb/


Download ppt "NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba."

Similar presentations


Ads by Google