Language Selection

English French German Italian Portuguese Spanish

Google now a hacker's tool

Filed under
Security

Somewhere out on the Internet, an Electric Bong may be in danger. The threat: a well-crafted Google query that could allow a hacker to use Google's massive database as a resource for intrusion.

"Electric Bong" was one of a number of household devices that security researcher Johnny Long came across when he found an unprotected Web interface to someone's household electrical network. To the right of each item were two control buttons, one labelled "on," the other, "off."

Long, a researcher with Computer Sciences Corp. and author of the book, "Google Hacking for Penetration Testers," was able to find the Electric Bong simply because Google contains a lot of information that wasn't intended to lie unexposed on the Web. The problem, he said at the Black Hat USA conference in Las Vegas last week, lies not with Google itself but with the fact that users often do not realize what Google's powerful search engine has been able to dig up.

In addition to power systems, Long and other researchers were able to find unsecured Web interfaces that gave them control over a wide variety of devices, including printer networks, PBX (private branch exchange) enterprise phone systems, routers, Web cameras, and of course Web sites themselves. All can be uncovered using Google, Long said.

But the effectiveness of Google as a hacking tool does not end there. It can also be used as a kind of proxy service for hackers, Long said.

Although security software can identify when an attacker is performing reconnaissance work on a company's network, attackers can find network topology information on Google instead of snooping for it on the network they're studying, he said. This makes it harder for the network's administrators to block the attacker. "The target does not see us crawling their sites and getting information," he said.

Often, this kind of information comes in the form of apparently nonsensical information -- something that Long calls "Google Turds." For example, because there is no such thing as a Web site with the URL (Uniform Resource Locator) "nasa," a Google search for the query "site:nasa" should turn up zero results. instead, it turns up what appears to be a list of servers, offering an insight into the structure of Nasa's (the U.S. National Aeronautics and Space Administration's) internal network, Long said.

Combining well-structured Google queries with text processing tools can yield things like SQL (Structured Query Language) passwords and even SQL error information. This could then be used to structure what is known as a SQL injection attack, which can be used to run unauthorized commands on a SQL database. "This is where it becomes Google hacking," he said. "You can do a SQL injection, or you can do a Google query and find the same thing."

Although Google traditionally has not concerned itself with the security implications of its massive data store, the fact that it has been an unwitting participant in some worm attacks has the search engine now rejecting some queries for security reasons, Long said. "Recently, they've stepped into the game."

Source.

More in Tux Machines

Automotive Grade Linux wants to help open source your next car

There are times I wonder how the auto industry has managed to fall so far behind in the realm of technology. Only within the past year or so have we seen the rise of commercially available wireless options in mass production vehicles. Take a look at the standard options for mobile displays within car dashboards and you will see nothing to truly impress you. Consider that a low-spec smartphone is more impressive (and offers far more features and services) than does that console of a high-end automobile. Recently I rented a Jeep Cherokee Limited edition, that included a touch-screen console with what was supposed to have all the bells and whistles. That touch screen wound up to be less-than user-friendly, not even remotely yielding to what I what I wanted it to do, and served little purpose other than to navigate my wife and I through Miami, Florida, listen to music, and view the rear-facing camera for backing up. The in-console display had serious issues connecting to any smartphone we had, so music was limited to satellite. Read more

Red Hat rides the IoT wave with open-source

In the past, only companies with the deepest pockets were able to benefit from gathering data from distributed devices to drive better decision making and realize additional revenue. Today, the economics of the IoT architecture--the hardware, the ubiquitous nature of connectivity, big data and analysis, and customer expectations are dramatically expanding the scope of IoT and making it possible for every enterprise--and not just consumers--to benefit. Read more

More .NET Openwashing

GeckoLinux 421.160623.0 Rolling Editions Out Based on Latest openSUSE Tumbleweed

This past weekend, the developers behind the openSUSE-based GeckoLinux computer operating system have announced the release of updated Rolling Editions, version 421.160623.0. Being the first time we write here about GeckoLinux, we would like to inform our readers that it's a versatile GNU/Linux distributions distributed in many flavors that are split into two main editions, Rolling Editions, based on openSUSE Tumbleweed and Static Editions, based on openSUSE Leap. Read more