Cloud

6/9/2016
11:00 AM
Connect Directly
LinkedIn
RSS
E-Mail vvv
100%
0%

Google Dorking: Exposing The Hidden Threat

Google Dorking sounds harmless, but it can take your company down. Here's what you need to know to avoid being hacked.

Virtually everyone uses Google or other search engines, but what most people don't know is that these search engines can perform advanced queries that are exploited to carry out successful cyberattacks.

For example, earlier this year, a cyberattack by suspected Iranian hackers made headlines when they used a simple technique called Google Dorking to access the computer system that controlled a water dam in New York. Google Dorking is readily available and has been used by hackers for many years to identify vulnerabilities and sensitive information accessible on the Internet.

Since its inception, the capabilities in Google Dorking have been added to other search engines, including Bing, Baidu, and Open Source Network Intelligence Tools (OSNIT) such as Shodan and Maltego.

Google Dorking, however, isn’t as simple as performing a traditional online search. It uses advanced operators in the Google search engine to locate specific information (e.g., version, file name) within search results. The basic syntax for using an advanced operator in Google is Operator_name: keyword

The use of advanced operators in Google is referred to as “Dorking” and the strings themselves are called “Google Dorks.” Dorks can be as basic as just one string, or they can be a more complex combination of multiple advanced operators in a single search string. Each Dork has a special meaning to the Google search engine that enables hackers and others to filter out unwanted results and significantly narrow down search results. For example, Google Dorks can be used to find administrator login pages, user names and passwords, vulnerabilities, sensitive documents, open ports, email lists, bank account details, and more.

Anyone with a computer and Internet access can easily learn about the availability of advanced operators on Wikipedia or via other public sources. Therefore, it’s not surprising that federal authorities say it is increasingly being used by hackers to identify computer vulnerabilities in the United States. The Department of Homeland Security and the FBI in 2014 issued a special security bulletin warning the commercial sector about the risks of Google Dorking.

The underlying threat associated with Google Dorking is that search engines are constantly crawling, indexing, and caching the Internet. While most of this indexed data is meant for public consumption, some is not and is unintentionally made “accessible” by search engines. As a result, a misconfigured intranet, or other confidential information resource, can easily lead to unintended information leakage.

Considering how easy it is for cybercriminals to access sensitive information via public search engines and security tools raises an important question: What can organizations do to minimize the risk of being hacked via Google Dorking?

The first step is to avoid putting sensitive information on the Internet. If unavoidable, assure that the data is password-protected and encrypted. In addition, make sure that websites and pages that contain sensitive information cannot be indexed by search engines. For example, GoogleUSPER provides tools to remove entire sites, individual URLs, cached copies, and directories from Google’s index. Another option is to use the robots.txt file to prevent search engines from indexing individual sites, and place it in the top-level directory of the Web server.

More important, organizations should implement routine Web vulnerability testing as part of standard security practices. In this context, Google Dorking can be a proactive security tool using online repositories like the Google Hacking Database (GHDB), which documents the expanding number of search terms for files containing user names, vulnerable servers, and even files containing passwords. The database provides access to Google Dorks contained in thousands of exploit entries. The direct mapping between Google Dorks and publicly available data allows security professionals to more rapidly determine if a particular web application contains these exploits.

The Google Dorking phenomenon once again underscores how organizations must not only test for vulnerabilities, but also assess whether they can be exploited, and what risks they represent. This is best achieved when vulnerability assessment, penetration test, and a cyber-risk analysis are performed hand in hand.

Related Content:

 

 

Dr. Srinivas Mukkamala is co-founder and CEO of RiskSense and a former advisor to the U.S. Department of Defense and U.S. Intelligence Community. He is an expert on malware analytics, breach exposure management, web application security, and enterprise risk reduction. Dr. ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ruchiroshni
50%
50%
ruchiroshni,
User Rank: Apprentice
10/2/2017 | 12:10:03 AM
Re: Still relevant in 2016
Thanks so much for providing this information, it is really helpful, also i have found one platform to learn more on 

cyber security please visit for more information on https://infosecaddicts.com.
ChristopheV560
50%
50%
ChristopheV560,
User Rank: Author
6/9/2016 | 3:03:54 PM
Still relevant in 2016
This was relevant a decade ago, and continues to be, especially given the recent spat of social engineering related attacks. 
Want Your Daughter to Succeed in Cyber? Call Her John
John De Santis, CEO, HyTrust,  5/16/2018
Don't Roll the Dice When Prioritizing Vulnerability Fixes
Ericka Chickowski, Contributing Writer, Dark Reading,  5/15/2018
New Mexico Man Sentenced on DDoS, Gun Charges
Dark Reading Staff 5/18/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Security through obscurity"
Current Issue
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-8010
PUBLISHED: 2018-05-21
This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerabilit...
CVE-2018-8012
PUBLISHED: 2018-05-21
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
CVE-2018-1067
PUBLISHED: 2018-05-21
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is ...
CVE-2018-7268
PUBLISHED: 2018-05-21
MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the file permissions. Confidential information suc...
CVE-2018-11092
PUBLISHED: 2018-05-21
An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an admin/index.php?empty=table (aka Clear Table) action.