Thursday, August 23, 2007

Advanced Google Searching (Google Hacking)

Google is a powerful search engine that hackers often use it to find passwords, and confidential or sensitive documents that companies do not realize are even available to the public. Most computer people use Google, but do not know how to use all of its search parameters. The term "google hacking" is a method used by unscrupulous people to not only uncovers sensitive data, but also to expose web server vulnerabilities. Here I list several Google search parameters and examples.



The syntax "filetype:" instructs Google to search for files on the Internet with specific extensions. For example: filetype:doc site:gov confidential Google will produce all the word documents, from all the gov domains that may contain the word confidential. Another example is, filetype:pdf site:com access-list. You may use any domain type, (com, gov, edu…)

The syntax "cache:" will display the version of the web page that Google has in its cache. For Example: "cache:www.microsoft.com" will display Google's cache of the Microsoft homepage.

The syntax "intext" searches for the words within a specific website and ignores the URLs and page titles. For example: intext:confidential will return only links to those web pages that has the search keyword " confidential " in its webpage.



The syntax "intitle:" instructs Google to search for pages that contain the words behind intitle: For example intitle:index of master.passwd will return pages within Unix or Linux where the master.passwd files are. /etc/passwd "allintitle:" will produce a list of all words in the title. Google will ignore the slashes.

intitle: examples:

intitle:"Index of" .sh_history

intitle:"Index of" .bash_history

intitle:"index of" passwd

intitle:"index of" people.lst

intitle:"index of" pwd.db

intitle:"index of" etc/shadow

intitle:"index of" spwd

intitle:"index of" master.passwd

intitle:"index of" htpasswd

intitle:"index of" members OR accounts

intitle:"index of" user_carts OR user_cart

allintitle: sensitive filetype:doc

allintitle: restricted filetype :mail

allintitle: restricted filetype:doc site:gov

The syntax "inurl:" instructs Google to search for pages that contain specific words or characters included in the URL such as this inurl:windows. The results of this query will produce such pages that have the word "windows" in it. allinurl: will produces the results of URLs with all of the specified words in its query. allinurl:windows/cracks.

inurl: examples:

inurl:admin filetype:txt
inurl:admin filetype:db
inurl:admin filetype:cfg
inurl:mysql filetype:cfg
inurl:passwd filetype:txt
inurl:iisadmin
inurl:auth_user_file.txt
inurl:orders.txt
inurl:"wwwroot/*."
inurl:adpassword.txt
inurl:webeditor.php
inurl:file_upload.php
inurl:gov filetype:xls "restricted"




The syntax "link:" will produce a list of webpages that have a link to a specified webpage. For example: link:www.thenetworkadministrator.com will create a Google list of websites with links to www.thenetworkadministrator.com.

The Google syntax "phonebook" searches for U.S. street addresses and phone number information. For Example: "phonebook:James+FL" will list down all names of person having "James" in their names and located in "Florida (FL)".
The syntax related: lists web pages that are "similar" to a specific web page. For Example: related:www.thenetworkadministrator.com will list web pages that are similar to that of TheNetworkAdministrator's homepage.


The syntax site: instructs Google to search for keywords in a particular site or domain. For example: exchange site:microsoft.com will search for the keywords "exchange" in those web pages in all the links of the domain microsoft.com.



Related Posts:


LimeWire Hackers


Extreme Hacking Videos


Wirless Network Attackers


Hacking Login Windows Screen

Tuesday, August 14, 2007

Hacking Videos

.:: reaL hackinG videoS ::.




Hacking Internet Security Cameras





Extortion Spyware



Related Posts:


LimeWire Hackers


Wirless Network Attackers

Hacking Login Windows Screen

Advanced Google Search Keyword Hacking

Wireless Network Attackers

.:: Wireless Network Attackers ::.

Wireless hacking, or "Wardriving" is when someone from outside your home accesses your wireless network. In most case it is because the victim doesn't have security enabled on their wireless access point. The dangers of having a non-secure wireless access-point are: Spammers can send junk mail from your home, hackers and criminals can hack remote locations that are tracked back to you, your confidential information is exposed to anyone that parks outside your home with a laptop. You may also suffer some liability because attacks were launched from your home by the bad guys. Here is a video of Joe and I as we drove around the local new station, showed them hundreds of open wireless networks in minutes


Listed below are 8 Tips to

Top 8 Tips for Wireless Home Network Security

1) Change Default Administrator Passwords (and Usernames)

Changing the default password is important because everyone that purchases the same Wireless access device, knows your password.

2) Turn on (Compatible) WPA / WEP Encryption


By default, your Wireless device comes without the encryption enables. WPA / WEP are security programs that forced your computer to provide an encrypted password before you are allowed access to the wireless access point.

3) Change the Default SSID

SSID is the network name of your wireless network; most people leave the default name, such as, Linksys or NetGear. By changing the name, intruders have a more difficult time identifying your system and use known vulnerabilities. (And of course, use the unchanged default password.) One mistake people make is naming their home network their family name and or address. When cruising a neighborhood of wireless devices, its always scary to see Smithfamily201Elm.

4) Disable SSID Broadcast

In Wi-Fi networking, the access point or router typically broadcasts the network name (SSID) over the air at regular intervals. This feature was designed for businesses and mobile hotspots where Wi-Fi clients may come and go. In the home, this feature is unnecessary, and it increases the likelihood an unwelcome neighbor or hacker will try to log in to your home network.

5) Assign Static IP Addresses to Devices

Most home networkers gravitate toward using dynamic IP addresses. This means that the IP Address, (the IP Address is needed to participate on a network.) is typically assigned automatically. A dynamic IP address on an unsecure system can also supply a hacker with a IP Address.

6) Enable MAC Address Filtering

Each piece of Wi-Fi gear possesses a unique identifier called the "physical address" or "MAC address." Access points and routers keep track of the MAC addresses of all devices that connect to them. Many such products offer the owner an option to key in the MAC addresses of their home equipment that restricts the network to only allow connections from those devices. Do this, but also know that the feature is not so powerful as it may seem. Hacker software programs can fake MAC addresses easily.

7) Turn Off the Network During Extended Periods of Non-Use

The ultimate in security measures for any wireless network is to shut down, or turn office your wireless access point when you are not using. You are the most vulnerable at work or asleep, and mischief minded people know it.

8) Position the Router or Access Point Safely

Wi-Fi signals normally reach to the exterior of a home. A small amount of "leakage" outdoors is not a problem, but the further this signal reaches, the easier it is for others to detect and exploit. Wi-Fi signals often reach across streets and through neighboring homes. When installing a wireless home network, the position of the access point or router determines it's reach. Try to position these devices near the center of the home rather than near windows to minimize this leakage.



Related Posts:


LimeWire Hackers


Extreme Hacking Videos


Hacking Login Windows Screen

Advanced Google Search Keyword Hacking

LimeWire Hackers

.:: LimeWire Hackers ::.

Limewire may be a convenient tool for downloading shared music and files, but it can also reveal your personal files.

If you know how to search Limewire, you will find thousands, even hundreds of thousands of personal and confidential documents, unknowingly shared on the Internet. Joe showed us tax returns, scanned copies of driver licenses, personal, and sexy pictures, and even banking account information...all for the taking by Internet "bad guys".

Listed below are some security tips to help protect you from having your personal data exposed in the Internet.

Click here to download the Video

Limewire Tip for Safe File Sharing

Limewire is a peer-to-peer file sharing program that lets you search and share file with other people on the Internet. Limewire is free to download and free to use. There are several problems with using a file sharing program like Limewire. Here we will show you how to keep from exposing your computer and your personal files from viruses and identity thieves.

What not to share


When you install Limewire, the program asks you if you want to search you computer for media files to share. This is where the first security problem can arise. Limewire will automatically search your hard drive for any media files then ask you if you want to share the folder those files are stored in. Unfortunately this search almost always asks the user if they want to share the windows system folder. If you were to share your windows system folder you will be sharing all of your computer's primary files to the internet and in worse case sinerios your password files will be exposed to these file sharing programs. The next folder to avoid sharing is My Documents. Let?s see what else gets saved in My Documents. Word documents, Excel spreadsheets, digital photos, your tax documents, scanned documents. Almost every program saves in My Documents by default. Then there are the people who find it easier to share their entire c:\ drive rather than go through the bother of finding the files they wish to share. These make everything on your computer accessible to the internet. So what should you do to share files? The safest way to share files is to create a directory set the directory's permission to read/write only. Then tell Limewire that is the only directory that you wish to share from.

What not to open


Anything, Do not open any files that you download from a file sharing network without scanning the file for viruses first. Viruses can look like any type of file and you are downloading these files from strangers. Virus writers and spammers will flood sharing networks with their malicious files. A favorite technique of virus writer is to name viruses similar to the most popular downloads.

Limewire is not a free iTunes


Downloading copyrighted material can get you into a lot of trouble. So how can you tell what material will not get you into trouble. Limewire will let you know when you are downloading unlicensed content. If it is unlicensed then it can get you into trouble. A good rule of thumb is if you have seen it in the movie theater or the music store then you probably could get in trouble for downloading.

Visit Joe's website at www.CRCIT.net for more Tips.

http://www.crcit.net/limewire.html



Related Posts:


Extreme Hacking Videos

Wirless Network Attackers


Hacking Login Windows Screen

Advanced Google Search Keyword Hacking