By Chris Maxcer LinuxInsider Part of the ECT News Network
02/25/08 2:26 PM PT
Google hacking -- attempting to find vulnerabilities in Web sites using specially crafted and complex Google searches -- was once the sport of advanced hackers. With Goolag Scanner, a group of hackers known as "The Cult of the Dead Cow" have made the technique more accessible to the masses, for better or for worse.
Crystal Reports - Discover the Latest Innovations. Download a free trial, view real-time 'behind the scenes' functionality, and learn about new Crystal Reports Server trade in options! Learn more.
The Cult of the Dead Cow (cDc) hacker group -- which claims to be the world's most attractive hacker group -- has released Goolag Scanner, an open source tool that uses Google's (Nasdaq: GOOG) search engines to look for vulnerabilities in Web sites.
Goolag Scanner is either a Web auditing tool that can be used by security professionals to help make their Web sites stronger -- or a hacking tool that provides wicked-easy access to a wealth of information "keys" unwittingly left lying around on Web site servers.
Hacks Galore
Goolag Scanner is based on a technique known as "Google hacking." It's a form of vulnerability research developed by a hacker who goes by the name "Johnny I Hack Stuff" and who's published a database of vulnerabilities and how to scan for them using specially crafted advanced Google searches.
Using individual searches to find flaws works -- it just takes a lot of time. Goolag Scanner is basically an application that rapidly runs lots of flaw-finding searches and quickly returns results more friendly to novices, friend or foe.
"It's no big secret that the Web is the platform, and this platform pretty much sucks from a security perspective," noted Oxblood Ruffin, who described himself as a cDc "spokesmodel."
"Goolag Scanner provides one more tool for Web site owners to patch up their online properties. We've seen some pretty scary holes through random tests with the scanner in North America, Europe and the Middle East. If I were a government, a large corporation, or anyone with a large Web site, I'd be downloading this beast and aiming it at my site yesterday. The vulnerabilities are that serious," he added.
Common Vulnerabilities
"It's difficult to refer to vulnerabilities as common other than from a structural perspective," Ruffin told LinuxInsider. "But having said that, most vulnerabilities that we've seen on the .gov/mil side have involved programming sloppiness. If you're asking how could a black hat exploit a Web site using Goolag Scanner, then I'd say that it would be on the 'point of entry' vector. You find a scab, you pick at it, and sooner or later you'll get blood," Ruffin explained.
Google hacking techniques aren't particularly new, and as cDc's online fact sheet notes, Goolag Scanner has been "bouncing around cDc internally for the past three years." It raises the question: Why release it to the public now?
"In our view, the public is ready to start thinking about Web security now. All kinds of services and conveniences are dragging people out of their homes/offices and onto the Web," Ruffin said.
"Who needs a hard drive when you can store data for free 'out there'? That's how people are beginning to think," Ruffin explained. "So we're just trying to create a moment of pause. Is it really such a good idea?"
Goolag Scanner will be released open source under the GNU Affero General Public license. It is a standalone windows GUI-based (graphical user interface) application that uses one XML-based (extensible markup language) configuration file for its settings.
Mozilla Dispatches Firefox Bug Zapper February 08, 2008
Mozilla rolled out a series of patches for the Firefox browser. "[Vulnerability MFSA 2008-08] is an interesting one," said analyst Chris Rodriguez. "It's rated moderate, and you might think of it by itself as just an annoyance. But it would allow a hacker to pop up something right before you click. Imagine you want to click 'no,' but it pops up right before you click and it says 'yes I want to download this executable.'"
Related Stories
Facebook Puts a Face on Defendants in Hacker Suit December 18, 2007
Facebook has named names in a federal lawsuit alleging that hackers illegally intruded on its networks in an effort to steal personal information on the social networking site's users. The effort is not nearly enough to address the weak security on Facebook -- and on social networking sites in general, said Paul Henry, vice president at Secure Computing.
Whippersnapper Hacker Springs Touch From Apple Slammer October 15, 2007
Apple's latest iPod, the touch, looks like an iPhone, works like an iPhone and now has been hacked like an iPhone. A hacker known as "AriX," who says he's 13 years old, has written an application that allows the Web-enabled touch to use third-party applications. However, "At the end of the day, once you hack the device you have to realize there is the potential for things going awry," said analyst Josh Martin.
Related News Alerts
More by Chris Maxcer
Let's Give the iPhone Hackers a Big Round of Applause November 06, 2009
It's safe to say most Apple customers are satisfied living in the walled-off ecosystem that the company has created for products like the iPhone. Still, it's good to know that it is possible -- and relatively easy, even -- to bust through those walls if one should ever want to. The work of iPhone hackers is appreciated even by those who've never felt the jailbreak itch.
What the iPhone Needs to Keep the Android Hordes at Bay October 30, 2009
The Android platform is growing fast, and Verizon is readying what may be the best Android phone yet. Consumers are getting more Android options on more networks. Meanwhile, Apple is sticking to a consistent device design on a single network. The iPhone doesn't need to branch off into multiple sizes and styles to be the dominant platform, but its single-U.S.-carrier situation is another story.
Apple Is Saving the Best for Last October 23, 2009
Sifting through the language used in Apple's quarterly results conference calls can sometimes yield clues to the highly secretive company's next moves. Apple's latest phone chat with analysts included a few comments about December shipping costs and a mystery "product." Here's why we might see an Apple tablet before the new year.