Newsletter:

Skip Navigation LinksHome > News > Security > Hackers pounce on Google Code Search

Hackers pounce on Google Code Search

By Clement James
10 October 2006 09:53AM
Tags: hackers | pounce | google | code | search

Tool can unearth a 'treasure trove' of vulnerabilities.

Security watchers from both sides of the fence have been testing Google's Code Search service to determine whether it can be misused.

Experts at Beyond Security's advisory arm, SecuriTeam, have already discovered that the tool can be used to unearth a treasure trove of vulnerabilities in open source software.

"Like most of Google's tools it can easily be abused for hacking," the SecuriTeam researchers wrote in a blog on the site.

Google Code Search has indexed several billions lines of code from archives hosted on the Web, as well as software control repositories from services like SourceForge and Google Code which host open source projects.

Tom Stocky, a product manager with Google, said at the tool's launch: "We will try to make this useful for everyone from computer science students to serious programmers and even hobbyists and code enthusiasts."

It seems that he forgot to mention hackers. The search tool is also proving to be a source of humour for the geek community.

A number of blogs frequented by coders have already posted a litany of amusing search terms which resulted in comic hits, usually amounting to criticism of coders or 'notes to self' that were presumably never meant to be seen.

Some of the less offensive search terms that return hits on the Google Code Search database include 'In Case Some Idiot', 'The Guy Who Wrote This' and 'I am drunk'.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(6677) -  internet
(6423) -  iinet
(6397) -  copyright
(6397) -  afact
(5994) -  servers
(5994) -  mipi
(4846) -  telstra
(4533) -  broadband
(4470) -  nbn
(3005) -  internode
(2531) -  microsoft
(1888) -  network
(1488) -  software
(1469) -  data
(1372) -  google