Google Hacking
Google is one of several very large companies in the Internet business. In addition to being one of several companies in the world's largest Internet this, Google also appeared to be one of several websites that can be said to have a record number of visitors the most, how not? Everything in connection with the Internet now semuannya be searchable through Google, from data on the general issues, news, to the technical information.Speaking in connection with the sub-title of this article, which says "Taking Advantage of Technology," in this article I will discuss about a little hacking techniques that use services provided from Google itself.
As we know, that with the advancement of technology and the development of the Internet industry, also many other things that occurred in connection with the security system. Advancement of a type of technology, of techniques will be balanced with "downloading smashed" rather than the system itself. This we can see in the case of google.com has been known that besides useful as a search engine with the most powerful database that reaches billions in number, google it can not cover up the fact that many hackers who use google.com as a means of conducting follow "fad "On the internet, because other than the data can search data such as MP3, Film, articles, and other sebagainyam google also has the ability to be able to find data that can be classified as confidential data.
With little ability to use unique and, of course, by using google.com search for a means of the data, people can find out more sensitive data on the Internet. Data is data with the data is sensitive data that can be classified as personal data, such as credit card numbers and passwords.
Using Google certainly is not a strange thing again for those who frequently use the Internet. Furthermore, considering the use of the website google.com itself a very user-friendly, the author feels no need to explain more about the method by using google search. In this article we will discuss more towards the basic search methods and the introduction of the use of string on google.com and the example example of the search that help make Google hacking in the future.
Basic search techniques
* Use string (+) is used to search force against a similar letter. While (-) are used to downloading does not include a word in the search.
* To find a specific word order with the very right, then you need to use string ( "")
* The point (.) Method is used to search the text of the characters.
* Signature stars symbolizing all the letters.
* Syntax site: used to order Google to conduct searches in certain sites only. The address of the site can be entered after the colon. (e.g site: www.th0r.name)
* Syntax filetype: used to order Google to search on the file type in a pitch-specification. The type of file that you want to search can be positioned after the colon.
* Link syntax: used to order Google to search only in certain hyperlinks.
* Cache syntax: used to order Google to display the version of a webpage on google open. Information about the address of the website can be added at the end of the colon.
* Syntax intitle: in this case are only google search for information based on the title documents of a particular document, in accordance with our typing at the end of syntax after the colon.
* Syntax inurl: Google will search the data in a specific URL syntax is given after the colon.
Know more about the syntax for the Google Hacking
After know the basic method of using google.com search, we will now switch to the syntax that can be more specific and more complications than the syntax that has been given above. Let us now note the syntax below:
intitle: "Index of" modified Passwords
allinurl: auth_user_file.txt
"access denied for user" "using password"
"A syntax error has occurred" filetype: ihtml
allinurl: admin mdb
"ORA-00921: Unexpected end of SQL command"
inurlasslist.txt
"Index of / backup"
"Chatologica MetaSearch" "stack tracking:
Examples given above example is an example of bias, saying the syntax used to search for a password or admin page, and can also be used to find the page that can not be opened by the user. Combinations of different combinations can be used to search the other and only need to be modified in accordance with the needs and target you.
Amex Numbers: 300000000000000 .. 399999999999999
MC Numbers: 5178000000000000 .. 5178999999999999
4356999999999999 visa 4356000000000000 ..
While the above syntax is used to search for a credit card number of people using google.com
Syntax Surgery
After viewing some of the more Sell syntax above, let's discuss some of the syntax syntax is below.
"parent directory" / appz /-xxx-html-htm-php-shtml-opendivx-md5-md5sums
"parent directory" DVDRip-xxx-html-htm-php-shtml-opendivx-md5-md5sums
"parent directory" Xvid-xxx-html-htm-php-shtml-opendivx-md5-md5sums
"parent directory" Gamez-xxx-html-htm-php-shtml-opendivx-md5-md5sums
"parent directory" MP3-xxx-html-htm-php-shtml-opendivx-md5-md5sums
"parent directory" Name of Singer or album-xxx-html-htm-php-shtml-opendivx-md5-md5sums
As you can see from the overall syntax. The part that always be replaced only after the word "Parent Directory". Why? After we learned at the beginning of this article was that the syntax ( "") is used to search for the exact sentence, and (-) is used for downloading not to include a word search in the entire sentence. So in the syntax of this we can also artikan roughly as follows:
* "Parent Directory" Searchers are conducting a search for the word Parent Directory, and certainly not in a concentrated (Parent and own their own Directory)
* Searchers want to put what he was looking for. (Example: / appz / is the application. And MP3, meaning he find things on the MP3)
* Xxx- Searchers do not want the content xxx in the search.
* Html- Searchers do not want the html content in the search.
* Htm- Searchers do not want the content htm in the search.
* Php- Searchers do not want the content php in the search.
* And others.
List syntax, and the combination
After discussing the methods of search, the syntax is quite distinct meaning complications to the syntax, in the previous section. In this section we will discuss about the combination of syntax and how to function, and how to read the meaning of the syntax.
Inurl: Microsoft filetype: iso
You will find on every element of the URL for Microsoft said all the files that bertipe iso. You can change the URL and any filetype to be tailored to your needs.
"#, FrontPage," inurl: service.pwd
By using this syntax, you tell Google to find the password for your frontpage.
"Http:// *: * @ www"
Syntax be used to search online password on your url. In case you find a user password and any writings, in a particular domain name. (Enter the domain name without. Com. Net /. Org) - (Example: "http:// *: * @ www" neotek)
Another way to use this syntax in a form that is the way berkesebalikan write syntax like this:
"Http://th0r:th0r @ www" in case you find the username and password th0r on the website that will address your input at the rear.
"Sets the mode + k"
Anyway, the IRC? It's true. There are also a lot of room in the IRC using the key to join into the room and, using this syntax, you can find some of the key conversations recorded in the log channel / the room.
Allinrul: Admin mdb
You will find many web pages in conjunction with the system administrator page.
Intitle: "Index of" config.php
With the above syntax, you will be given batch of data on the website which has a website file config.php
Even Google can also be used as a place to find warez serial code. Say you need Windows XP Pro serial number. You only need to open http://www.google.com and syntax to use them as follows:
"Windows XP Professional" 94FBR
That we can also search words artikan as Windows XP Professional without the eggs. Meanwhile 94FBR itself is a code that often entered into the part of the registration code that is in most Microsoft software. By because of this, the use of the code 94FBR may be enough to help in the search serial code. However, everything still can be modified in accordance with the wishes and needs you.
If the story short, my time is about Google Hacking. Please note that the level of success in how to use Google hacking is 100% depending on the ideas and your own creativity in combining the syntax and adjust the data you know about a specific target. But I need to explain here, that Google hacking techniques is one of the egregious enough when you can use it very well. It starters supported by the fact that most security experts in the world has the Google Hacking place as one of the techniques that parallel and equal berbahayanya with SQL Injection, Cross-site Scripting and Remote Command Execution.
Credit and Special Thanks To: Johnny Long With His Book named as "Google Hacking"
I also do not forget to thank Epel (Thanks yoo = P), Ignes (nemenin chat is the time I created this article), Cindy (who also have a chat to the article nemenin year) but also JEFFRY and Nico. And some friends of my friends the other.
Finally, I just want to say. Developing technology for the exploitation of the functions and benefits. If in-exploitation of natural wealth is wrong, to exploitation funsi technology is a good thing can be said. By because of that, keep seeking the benefits of the use of the system itself.
Indonesian

0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home