Re: New google's top query?

From: Alex Keller (alkeller_at_sfsu.edu)
Date: 08/24/04

  • Next message: Serkan Akpolat: "Re: Hafiye-1.0 Terminal Escape Sequence Injection Vulnerability"
    Date: Mon, 23 Aug 2004 21:54:06 -0700
    To: bugtraq@securityfocus.com
    
    

    Re: New google's top query?

    this "hack" (really a numrange search) was covered at DEFCON12
    (http://www.defcon.org/html/defcon-12/dc-12-index.html) and widely known
    before it was publicized by Johnny Long (http://johnny.ihackstuff.com/)
    during his talk at the conference (to his credit, he did NOT release the
    exact syntax BTW). following that search now will yield little sensitive
    info, as most of the affected sites have removed the pages that
    demonstrated this security breach. Google is well aware of the malicious
    activity that can be aided with their search engine....but they are in a
    bit of a predicament between notions of security and freedom; a common
    juxtaposition in politics, social order, and network security.

    this forum at Johnny's site has plenty more search "hacks":
    http://johnny.ihackstuff.com/index.php?module=prodreviews

    for further investigation and vulnerability testing, check out
    Foundstone's SiteDigger:
    http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/s3i_tools.htm

    Athena is another powerful Google digging tool that can expose search
    vulnerabilities; although i can't seem to find a working download site
    right now. you can grab the entire DEFCON12 iso (457MB) at:
    http://130.212.20.4/admin/defcon/defcon12.iso
    Athena can be found in the directory "Long".

    happy Google hunting...oh yeah, don't be an idiot and use this info for
    evil.

    -alex

    other
    Jérôme ATHIAS wrote:

    >
    > Hi,
    >
    >
    >
    > i don't remember to have seen this info here...
    >
    >
    >
    > If information is knowledge and knowledge is power, then Google must be all powerful. I say this because of the thing you can find on Google if you know how to look for them. A new Google hack has come to my attention that brings back some information that is a bit troubling. I must say that it is also good for the more you know about something the better you are to act upon it. The hack is this:
    >
    >
    >
    > http://www.google.com/search?q=visa+4356000000000000..4356999999999999
    >
    >
    >
    > When this query is put into the Google search, an idea of the brut strength of Google becomes apparent. You can find things like this, which may worry you if you found your name on it.
    >
    >
    >
    > I’m not really sure if Google knows what it can do, but they take an interesting stance toward their provision of data.
    >
    >
    >
    > Regards,
    >
    > Jérôme
    >
    >


  • Next message: Serkan Akpolat: "Re: Hafiye-1.0 Terminal Escape Sequence Injection Vulnerability"

    Relevant Pages

    • Re: How would the God of Standard Sql - Celko do server side paging?
      ... I think that first my query is checked against other previously ... A lot of people Google "<movie star ... Then using the same model as a report server, ... If I ask a truly original query of Google, ...
      (microsoft.public.sqlserver.programming)
    • Re: command-line search engine query
      ... But I'll assume Jens is right and you meant to query for, let's say, ... "saturn," and see where NASA came up in the results. ... luckily we /know/ what platform you use: Linux. ... This fetches the Google results page for a query on "saturn". ...
      (comp.programming)
    • Re: Google Architecture
      ... I'm always amazed when Google ... reformulate the query. ... Contrast this model to a traditional business enterprise I once worked at. ... If a report listed erroneous matches, ...
      (bit.listserv.ibm-main)
    • Re: That first goal
      ... Not really our fault that nobody discusses Everton but Everton fans on the internet. ... I guess someone needs to explain how Google works for you, then you might understand what I was saying. ... terms in that exact order. ... You were using a 3rd party system to query Google. ...
      (uk.sport.football.clubs.liverpool)
    • Re: How to get around "filter too long" run-time error?
      ... I cannot see them getting longer than 5 characters. ... > Instead of using the wherecondition argument, ... After all Google doesn't require that much effort, ... > How do I save a query from the form with the selected list items? ...
      (microsoft.public.access.formscoding)