Google
Hackers claim that Goolag Scanner enables anyone to audit websites via Google
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Hackers develop Google-based scanning tool

Cult of the Dead Cow strikes again

Clement James, vnunet.com 27 Feb 2008
ADVERTISEMENT

Notorious hacker group Cult of the Dead Cow (cDc) has released a web auditing tool which uses Google to find vulnerabilities on sites.

The group claims that the Goolag Scanner enables anyone to audit their own website via Google.

The scanner technology is based on 'Google hacking', a form of vulnerability research developed by a cDc member known as 'Johnny I Hack Stuff'.

Available as a downloadable application, Goolag makes use of 'dorks', or detailed search patterns that show untapped results for sites previously indexed by Google.

Dorks find results that might show information relevant to security issues and/or confidential data, and are not limited to Google's search engine, according to cDc.

However, the Goolag Scanner is focused on usability. It simplifies the use of myriad numbers of dorks to a few mouse clicks, and does not require cryptic command line options or knowledge of 'Google hacking'.

Goolag Scanner comes with its own dorks database, but it is not limited to this, essentially lowering the bar for would be hackers using dorks to scan sites for vulnerabilities.

"It is no big secret that the web is the platform, and this platform pretty much sucks from a security perspective," said cDc spokesman 'Oxblood Ruffin'.

"Goolag Scanner provides one more tool for site owners to patch their online properties. We've seen some pretty scary holes through random tests with the scanner in North America, Europe, and the Middle East.

"If I were a government, a large corporation, or anyone with a large website, I'd be downloading this beast and aiming it at my site yesterday. The vulnerabilities are that serious."

With Goolag, cDc appears to be repeating history by putting easy-to-use hacking tools into the hands of novices.

The group shot to notoriety during the 1990s with the release of the BackOrifice tools which allowed low-level users to hijack and take control of Windows PCs.

See also:

HackingBut brand holders are fighting back  25 Feb 2008
DRamResearchers find way to foil disk encryption  22 Feb 2008
HackerRegional attacks increasing, says McAfee  21 Feb 2008
ZombieThe Mounties always get their man  21 Feb 2008

All Hacking
Tags: Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | Advent Computer Training
Are you stuck in a dead end job? Do you want to take control of your salary, life and career? Advent IT and computer training offers advanced, professional training and helps you find the right ... more >
United Kingdom | University of east anglia
WEB DEVELOPER £22,332 to £27,466 per annum (Grade 6), with agreed progression to £28,290 to £33,780 (Grade 7). Pay award pending from October 2008. We are looking for an experienced Web Developer to join a ... more >
United Kingdom | ESRC
Web/Project Manager - £33,118 to £35,694 + Benefits Cutting-edge research is our business. You'll give us the cutting-edge web technologies to match. The Economic and Social Research Council is the UK's leading research agency for ... more >
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Middle Tier solution Designer - Welwyn Garden CityWho's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at ... more >
More job opportunities