Hackers develop Google-based scanning tool

  • Email a Friend
  • Print Page
Hackers develop Google-based scanning tool
By Clement James
Feb 28, 2008 7:20 AM
Tags: google | hacker | google | cult | of | the | dead | cow | scanning | tool

Notorious hacker group Cult of the Dead Cow (cDc) has released a web auditing tool which uses Google to find vulnerabilities on sites..

The group claims that the Goolag Scanner enables anyone to audit their own website via Google.

The scanner technology is based on 'Google hacking', a form of vulnerability research developed by a cDc member known as 'Johnny I Hack Stuff'.

Available as a downloadable application, Goolag makes use of 'dorks', or detailed search patterns that show untapped results for sites previously indexed by Google.

Dorks find results that might show information relevant to security issues and/or confidential data, and are not limited to Google's search engine, according to cDc.

However, the Goolag Scanner is focused on usability. It simplifies the use of myriad numbers of dorks to a few mouse clicks, and does not require cryptic command line options or knowledge of 'Google hacking'.

Goolag Scanner comes with its own dorks database, but it is not limited to this, essentially lowering the bar for would be hackers using dorks to scan sites for vulnerabilities.

"It is no big secret that the web is the platform, and this platform pretty much sucks from a security perspective," said cDc spokesman 'Oxblood Ruffin'.

"Goolag Scanner provides one more tool for site owners to patch their online properties. We've seen some pretty scary holes through random tests with the scanner in North America, Europe, and the Middle East.

"If I were a government, a large corporation, or anyone with a large website, I'd be downloading this beast and aiming it at my site yesterday. The vulnerabilities are that serious."

With Goolag, cDc appears to be repeating history by putting easy-to-use hacking tools into the hands of novices.

The group shot to notoriety during the 1990s with the release of the BackOrifice tools which allowed low-level users to hijack and take control of Windows PCs.

Copyright © 2009 vnunet.com


 
Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
Top Stories
Conroy opens NBNCo regulation debate
Part two of the regulatory reforms paper.
 
Utilities wise up to smart grids
Power to the people?
 
Sydney Water turned off wrong pipe
Admits error with Macquarie Telecom data centre.
 
Exclusive Data Centre - Sponsored Content by Microsoft

Latest Comments

"I turn bluetooth off on my mobile to save the battery. Looks like now I've got another reason. "
by Slatts Jul 4, 2009 1:09 PM
 
"I'm kind of assuming that the water was used in water cooled condensers for the air-conditioning...."
by Slatts Jul 2, 2009 8:54 PM
 
"Why do we have to listen to Nick Minchin's comments? He is just about irrelevant in his opinions ..."
by ngo Jul 2, 2009 8:35 PM
 
" It's not very surprising that the Chinese junta still wants to impose the 'Green Dam - Youth ..."
by anonymous Jul 2, 2009 3:49 PM
 
"I would suggest for anyone wanting to join in the BOINC projects such as SETI@home, World ..."
by wolfgang8741 Jul 2, 2009 5:37 AM

Polls

What will you do when your iPhone contract comes up for renewal?




   |   View results
Retain my current service provider
  12%
 
Switch to a cheaper plan
  18%
 
Switch to a better network
  17%
 
Switch to whoever offers free tethering
  18%
 
Change handset altogether
  36%
TOTAL VOTES: 193

Vote