NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer...

11
NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba Czech Republic Google hacking

Transcript of NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer...

Page 1: NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba.

NAVY Research GroupDepartment of Computer Science

Faculty of Electrical Engineering and Computer Science VŠB-TUO17. listopadu 15

708 33 Ostrava-Poruba Czech Republic

Google hacking

Page 2: NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba.

navy.cs.vsb.cz2

GH – official statement

Google hacking is the term used when a hacker tries to find exploitable targets and sensitive data by using search engines. The Google Hacking Database (GHDB) is a database of queries that identify sensitive data.

GHDB http://www.hackersforcharity.org/ghdb/

Page 3: NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba.

navy.cs.vsb.cz3

GHDB - example

Page 4: NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba.

navy.cs.vsb.cz4

Introduction

• Google advanced operators help refine searches.

• They are included as part of a standard Google query.

• Advanced operators use a syntax such as the following: operator:search_term

• There’s no space between the operator, the colon, and the search term!

Page 5: NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba.

navy.cs.vsb.cz5

Special characters

• ( + ) force inclusion of something common • ( - ) exclude a search term • ( “ ) use quotes around search phrases • ( . ) a single-character wildcard • ( * ) any word • ( | ) boolean ‘OR’ • Parenthesis group queries (“master card” |

mastercard)

Page 6: NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba.

navy.cs.vsb.cz6

Advanced operators

Page 7: NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba.

navy.cs.vsb.cz7

Advanced operators

• Link to useful cheatsheethttps://www.sans.org/security-resources/GoogleCheatSheet.pdf

Page 10: NAVY Research Group Department of Computer Science Faculty of Electrical Engineering and Computer Science VŠB-TUO 17. listopadu 15 708 33 Ostrava-Poruba.

navy.cs.vsb.cz10

For fun

• http://193.138.213.169/CgiStart?page=Single&Mode=Motion&Language=9