Home › News › Industry News
Hackers turn Google into vulnerability scanner
Infamous hacking group the Cult of the Dead Cow (cDc), probably best known for their release of Back Orifice ten years ago, today released a tool that utilizes known server exploits as search terms in Google to scan websites for vulnerabilities and private data.
The new tool, dubbed Goolag Scan, presents the results as a list of links containing information regarding the nature of each vulnerability and exploit. It’s just as provoking as any of the other tools the group has released, making it easy for unskilled users to track down sensitive information on specific websites. Though according to the cDc, their intention is to provide an easy and legitimate tool for security professionals to test their own websites for vulnerabilities.
Indeed Goolag Scan does give IT administrators a handier way to look for flaws and leaks that could be exposed via Google searches. Of course, by performing large-scale automated searches, there’s always the risk of getting your IP address blocked by Google.
The new tool, dubbed Goolag Scan, presents the results as a list of links containing information regarding the nature of each vulnerability and exploit. It’s just as provoking as any of the other tools the group has released, making it easy for unskilled users to track down sensitive information on specific websites. Though according to the cDc, their intention is to provide an easy and legitimate tool for security professionals to test their own websites for vulnerabilities.
Indeed Goolag Scan does give IT administrators a handier way to look for flaws and leaks that could be exposed via Google searches. Of course, by performing large-scale automated searches, there’s always the risk of getting your IP address blocked by Google.
User Comments (2)
Post a comment|
phantasm66 on February 23, 2008 5:28 AM |
I just downloaded it and gave it a go, looks very powerful but you quickly get locked out doing so many queries so quickly. |
|
yairba on March 11, 2008 5:16 AM |
I checked this tool and I think it is great. I think that having this tool for small personal sites is great but it can't replace a real vulnerability scanner for this simple reason that most organizations that need real security can not trust an open source software developed by hackers. If you are running a business and need to your site scanned daily, you can't trust hackers to wake up in the morning and update their database for Vulnerabilities... |
Most Popular
| Trending | Featured |
-
1Windows Phone 8 'Apollo' based on the desktop OS' kernel, brings NFC, native Skype, more
-
2AMD will focus less on desktop CPUs, more on mobile APUs
-
3Bethesda releases Skyrim 1.4 patch, mod kit previewed
-
4You might be a terrorist if you have two cell phones, use Web proxies
-
5French courts fines Google for offering free mapping services
