Re: How does Google get confidential URL-strings?



Hey Joe,

I see two possibilities. One, someone must be using Google desktop &
the search results got published. Once they get published it will also
get cached. Secondly, disgruntled or former employees as pointed out
by Jeffery. If there is Google toolbar then also this could be
possible.

cheers
TAS

--
http://www.niiconsulting.com/products/auditpro.html


2009/5/29 Joe <bitshield@xxxxxxxxx>

Hello guys

I was recently confronted with the problem, where using Google-Hacking
techniques I was able to find entries that point to my employer’s
website while having confidential username and password parameters in
the URL. Using this URL listed as Google’s search result everyone
could access personalized accounts on this website.

I see two kinds of problems here.

First, the web application should not put confidential parameters into
the URL. This is the GET/POST discussion which is clear to me.

Second, even if a web application puts these parameters into the URL I
wonder how his URL gets indexed by Google. Does anyone have a clue how
this can happen?

Interestingly Google lists only three user accounts while the website
has about 10’000 registered users. I was thinking about two
possibilities:
- The web applicaiton somehow leaks this URL to the Google search spider
- The affected users somehow publish their browser history on the web
(probably though malware?)

It would be interested if someone has Ideas on how the second problem
can be explained.

By the way, the Google query, that lead to the problematic entries
looked as follows: site:mydomain.com inurl:password inurl:user.

Any ideas?

Regards
Joe

------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Need to pass the CISSP? InfoSec Institute's CISSP Boot Camp in both Instructor-Led and Online formats is the most concentrated exam prep available. Comprehensive course materials and an expert instructor means you pass the exam. Gain a laser like insight into what is covered on the exam, with zero fluff!

http://www.infosecinstitute.com/courses/cissp_bootcamp_training.html
------------------------------------------------------------------------


------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Need to pass the CISSP? InfoSec Institute's CISSP Boot Camp in both Instructor-Led and Online formats is the most concentrated exam prep available. Comprehensive course materials and an expert instructor means you pass the exam. Gain a laser like insight into what is covered on the exam, with zero fluff!

http://www.infosecinstitute.com/courses/cissp_bootcamp_training.html
------------------------------------------------------------------------



Relevant Pages

  • Re: HTML-page clicked in Google dont get me to the website
    ... clicks a link to one of your pages from one of your pages or from Google. ... Catharinus van der Werf ... I have build a website with approximately 30 html-pages. ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: HTML-page clicked in Google dont get me to the website
    ... clicks a link to one of your pages from one of your pages or from Google. ... Catharinus van der Werf ... I have build a website with approximately 30 html-pages. ...
    (microsoft.public.dotnet.framework.webservices)
  • web solutions for global presence
    ... Are you a online sales and marketing personality? ... Do you have connection with lots of yahoo and google groups and huge ... Do you already own a website but want to revolutionize its design and ...
    (comp.lang.php)
  • Re: open source .NET search engine?
    ... pulling a napoleon- like google does-- and try to enter EVERY MARKET at ... open source .NET search engine try ... As for spidering, there are many website copiers out there, try HTTrack ... I want to spider Home Depot websites and sell it to Lowes. ...
    (microsoft.public.dotnet.languages.vb)
  • RE: Penetration test of 1 IP address
    ... Google the site name, IP address, and any of the contact details. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Hackers are concentrating their efforts on attacking applications on your ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
    (Pen-Test)