Cloud

6/9/2016
11:00 AM
Connect Directly
LinkedIn
RSS
E-Mail vvv
100%
0%

Google Dorking: Exposing The Hidden Threat

Google Dorking sounds harmless, but it can take your company down. Here's what you need to know to avoid being hacked.

Virtually everyone uses Google or other search engines, but what most people don't know is that these search engines can perform advanced queries that are exploited to carry out successful cyberattacks.

For example, earlier this year, a cyberattack by suspected Iranian hackers made headlines when they used a simple technique called Google Dorking to access the computer system that controlled a water dam in New York. Google Dorking is readily available and has been used by hackers for many years to identify vulnerabilities and sensitive information accessible on the Internet.

Since its inception, the capabilities in Google Dorking have been added to other search engines, including Bing, Baidu, and Open Source Network Intelligence Tools (OSNIT) such as Shodan and Maltego.

Google Dorking, however, isn’t as simple as performing a traditional online search. It uses advanced operators in the Google search engine to locate specific information (e.g., version, file name) within search results. The basic syntax for using an advanced operator in Google is Operator_name: keyword

The use of advanced operators in Google is referred to as “Dorking” and the strings themselves are called “Google Dorks.” Dorks can be as basic as just one string, or they can be a more complex combination of multiple advanced operators in a single search string. Each Dork has a special meaning to the Google search engine that enables hackers and others to filter out unwanted results and significantly narrow down search results. For example, Google Dorks can be used to find administrator login pages, user names and passwords, vulnerabilities, sensitive documents, open ports, email lists, bank account details, and more.

Anyone with a computer and Internet access can easily learn about the availability of advanced operators on Wikipedia or via other public sources. Therefore, it’s not surprising that federal authorities say it is increasingly being used by hackers to identify computer vulnerabilities in the United States. The Department of Homeland Security and the FBI in 2014 issued a special security bulletin warning the commercial sector about the risks of Google Dorking.

The underlying threat associated with Google Dorking is that search engines are constantly crawling, indexing, and caching the Internet. While most of this indexed data is meant for public consumption, some is not and is unintentionally made “accessible” by search engines. As a result, a misconfigured intranet, or other confidential information resource, can easily lead to unintended information leakage.

Considering how easy it is for cybercriminals to access sensitive information via public search engines and security tools raises an important question: What can organizations do to minimize the risk of being hacked via Google Dorking?

The first step is to avoid putting sensitive information on the Internet. If unavoidable, assure that the data is password-protected and encrypted. In addition, make sure that websites and pages that contain sensitive information cannot be indexed by search engines. For example, GoogleUSPER provides tools to remove entire sites, individual URLs, cached copies, and directories from Google’s index. Another option is to use the robots.txt file to prevent search engines from indexing individual sites, and place it in the top-level directory of the Web server.

More important, organizations should implement routine Web vulnerability testing as part of standard security practices. In this context, Google Dorking can be a proactive security tool using online repositories like the Google Hacking Database (GHDB), which documents the expanding number of search terms for files containing user names, vulnerable servers, and even files containing passwords. The database provides access to Google Dorks contained in thousands of exploit entries. The direct mapping between Google Dorks and publicly available data allows security professionals to more rapidly determine if a particular web application contains these exploits.

The Google Dorking phenomenon once again underscores how organizations must not only test for vulnerabilities, but also assess whether they can be exploited, and what risks they represent. This is best achieved when vulnerability assessment, penetration test, and a cyber-risk analysis are performed hand in hand.

Related Content:

 

 

Dr. Srinivas Mukkamala is co-founder and CEO of RiskSense and a former advisor to the U.S. Department of Defense and U.S. Intelligence Community. He is an expert on malware analytics, breach exposure management, web application security, and enterprise risk reduction. Dr. ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ruchiroshni
50%
50%
ruchiroshni,
User Rank: Apprentice
10/2/2017 | 12:10:03 AM
Re: Still relevant in 2016
Thanks so much for providing this information, it is really helpful, also i have found one platform to learn more on 

cyber security please visit for more information on https://infosecaddicts.com.
ChristopheV560
50%
50%
ChristopheV560,
User Rank: Author
6/9/2016 | 3:03:54 PM
Still relevant in 2016
This was relevant a decade ago, and continues to be, especially given the recent spat of social engineering related attacks. 
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
Windows 10 Security Questions Prove Easy for Attackers to Exploit
Kelly Sheridan, Staff Editor, Dark Reading,  12/5/2018
Starwood Breach Reaction Focuses on 4-Year Dwell
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I guess this answers the question: who's watching the watchers?
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20050
PUBLISHED: 2018-12-10
Mishandling of an empty string on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via the ONVIF GetStreamUri method and GetVideoEncoderConfigurationOptions method.
CVE-2018-20051
PUBLISHED: 2018-12-10
Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via certain ONVIF methods such as CreateUsers, SetImagingSettings, GetStreamUri, and so on.
CVE-2018-20029
PUBLISHED: 2018-12-10
The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) because uninitialized memory can be read.
CVE-2018-1279
PUBLISHED: 2018-12-10
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on ...
CVE-2018-15800
PUBLISHED: 2018-12-10
Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.