Book description
Google is the most popular search engine ever created, but Google’s search capabilities are so powerful, they sometimes discover content that no one ever intended to be publicly available on the Web, including social security numbers, credit card numbers, trade secrets, and federally classified documents. Google Hacking for Penetration Testers, Third Edition, shows you how security professionals and system administratord manipulate Google to find this sensitive information and "self-police" their own organizations.
You will learn how Google Maps and Google Earth provide pinpoint military accuracy, see how bad guys can manipulate Google to create super worms, and see how they can "mash up" Google with Facebook, LinkedIn, and more for passive reconnaissance.
This third edition includes completely updated content throughout and all new hacks such as Google scripting and using Google hacking with other search engines and APIs. Noted author Johnny Long, founder of Hackers for Charity, gives you all the tools you need to conduct the ultimate open source reconnaissance and penetration testing.
- Third edition of the seminal work on Google hacking
- Google hacking continues to be a critical phase of reconnaissance in penetration testing and Open Source Intelligence (OSINT)
- Features cool new hacks such as finding reports generated by security scanners and back-up files, finding sensitive info in WordPress and SSH configuration, and all new chapters on scripting Google hacks for better searches as well as using Google hacking with other search engines and APIs
Table of contents
- Cover
- Title page
- Table of Contents
- Copyright
- Chapter 1: Google Search Basics
-
Chapter 2: Advanced Operators
- Abstract
- Introduction
- Operator syntax
- Troubleshooting your syntax
- Introducing Google’s advanced operators
- “Intitle” and “allintitle”: search within the title of a page
- Allintext: locate a string within the text of a page
- Inurl and allinurl: finding text in a URL
- Site: narrow search to specific sites
- Filetype: search for files of a specific type
- Link: search for links to a page
- Inanchor: locate text within link text
- Cache: show the cached version of a page
- Numrange: search for a number
- Daterange: search for pages published within a certain date range
- Info: show Google’s summary information
- Related: show related sites
- Stocks: search for stock information
- Define: show the definition of a term
- Colliding operators and bad search-fu
- Summary
- Fast track solutions
- Links to sites
- Chapter 3: Google Hacking Basics
- Chapter 4: Document Grinding and Database Digging
-
Chapter 5: Google’s Part in an Information Collection Framework
- Abstract
- Introduction
- The principles of automating searches
- The original search term
- Expanding search terms
- Using “special” operators
- Getting the data from the source
- Scraping it yourself: requesting and receiving responses
- Scraping it yourself: the butcher shop
- Using other search engines
- Parsing the data
- Domains and subdomains
- Telephone numbers
- Postprocessing
- Collecting search terms
- Summary
- Chapter 6: Locating Exploits and Finding Targets
-
Chapter 7: Ten Simple Security Searches That Work
- Abstract
- Introduction
- site
- intitle:index.of
- error | warning
- login | logon
- username | userid | employee.ID \ “your username is”
- password | passcode | “your password is”
- admin | administrator
- –ext:html –ext:htm –ext:shtml –ext:asp –ext:php
- inurl:temp | inurl:tmp | inurl:backup | inurl.bak
- intranet | help.desk
- Summary
- Chapter 8: Tracking Down Web Servers, Login Portals, and Network Hardware
- Chapter 9: Usernames, Passwords, and Secret Stuff, Oh My!
- Chapter 10: Hacking Google Services
- Chapter 11: Hacking Google Showcase
- Chapter 12: Protecting Yourself from Google Hackers
- Subject Index
Product information
- Title: Google Hacking for Penetration Testers, 3rd Edition
- Author(s):
- Release date: November 2015
- Publisher(s): Syngress
- ISBN: 9780128029824
You might also like
book
Google Hacking for Penetration Testers
This book helps people find sensitive information on the Web. Google is one of the 5 …
book
Hack I.T.: Security Through Penetration Testing
"This book covers not just the glamorous aspects such as the intrusion act itself, but all …
book
Web Hacking: Attacks and Defense
"Both novice and seasoned readers will come away with an increased understanding of how Web hacking …
book
Penetration Testing and Network Defense
The practical guide to simulating, detecting, and responding to network attacks Create step-by-step testing plans Learn …