Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Security & Privacy
Weekly Brief
Windows Vista
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: GoogleHackersInternet

Hackers Turn Google Into Password Hunter

Matthew Broersma, Techworld

Friday, February 22, 2008 2:00 PM PST
Recommend this story?

The hacking group Cult of the Dead Cow (CDC) this week released a tool that turns Google into an automated vulnerability scanner, scouring websites for sensitive information such as passwords or server vulnerabilities.

CDC first achieved notoriety ten years ago with its backdoor Back Orifice, which demonstrated in a highly public way just how easy it was to take unauthorized control of a Windows PC.

The new tool, called Goolag Scan, is equally provocative, making it easy for unskilled users to track down vulnerabilities and sensitive information on specific websites or broad web domains.

This capability should serve as a wake-up call for system administrators to run the tool on their own sites before attackers get around to it, according to CDC.

"It's no big secret that the Web is the platform, and this platform pretty much sucks from a security perspective," said CDC spokesperson Oxblood Ruffin, in a statement. "We've seen some pretty scary holes through random tests with the scanner in North America, Europe, and the Middle East. If I were a government, a large corporation, or anyone with a large website, I'd be downloading this beast and aiming it at my site yesterday."

The tool is a stand-alone Windows .Net application, licensed under the open source GNU General Public License, that provides about 1,500 customized searches under categories such as "vulnerable servers," "sensitive online shopping information" and "files containing juicy information."

The results are displayed as a list of links that can be opened directly in a browser. Example results include tell-tale error messages and Java applets for the remote control of surveillance cameras, according to CDC.

Goolag Scan is based on "Google hacking," the practice of exposing vulnerabilities via Google, which CDC says has been pioneered by a hacker going by the handle "Johnny I Hack Stuff."

Goolag Scan is, however, the first time such vulnerability searches have been built into a simple tool, according to CDC.


Recommend this story?
Related Searches: google hacker password server goolag scan

Comments
HP Ink Center
Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
CDW Solution Center
Deliver speed and scalability in your storage systems. Find out how at the CDW Solution Center.
Asus Notebook Center
Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more at the Asus Resource Center.
Intel Processor Technology
Which Intel Processor is Right for You?Centrino, Core 2 Duo, Core 2 Quad, Core 2 Extreme? Check out the Intel Technology Center for more info...
Are you a gamer?Visit the Intel's Gaming section for the latest downloads, hottest gaming events and to learn about Intel & Gaming.
See what Intel can do for Vista...Discover how Windows Vista technology work in the benchmarks with Intel Centrino processor technology.
VoIP Web Demo
Join Altigen for a Live Web Demo and learn how VoIP technology can improve your business communications.
The Future Sales Force - A Consultative Approach
This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ.
Latest News
Computer Sciences (CSC) has agreed to pay US $1.37 million to settle allegations that it received kickbacks on technology... 13-May-2008
HBO will begin selling some of its most popular television series on Apple's iTunes Store, the companies announced on Tuesday... 13-May-2008
A variety of malware already infects millions of PCs in an accelerated attack, security expert warns. 13-May-2008
The European Commission confirmed it has received a complaint about Microsoft's business practices from a British government... 13-May-2008
On Tuesday, Microsoft released Service Pack 1 (SP1) for Office 2008 for Mac, designed to add stability, security, and... 13-May-2008
HP's acquisition of another top-tier IT company brings benefits but huge challenges, analysts agree. 13-May-2008
Some episodes could cost $1.99 and up, in a pricing switch, sources say. 13-May-2008
Mozilla has wrapped its changes to RC1 of Firefox 3.0 and expects to release it in late May. 13-May-2008
One in four respondents to a new US corporate IT spending survey by ChangeWave Research said their company will spend less on... 13-May-2008
Engineers testing a recently launched Japanese data communications satellite have succeeded in establishing a two-way Internet... 13-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)