Home > Enterprise Desktop Tips > > An introduction to Google Hack Honeypots
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


An introduction to Google Hack Honeypots


Brien M. Posey
01.04.2005
Rating: -3.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Although stories in the mainstream media about Google hacking just started last year, Google hacks have been around for almost as long as Google itself. The idea behind a Google hack is that the hacker can use the Google search engine in a way that reveals confidential data by exploiting a poorly written Web application. Fortunately, there is a new type of Web application called a Google Hack Honeypot that allows you to monitor Google hack activity directed at your Web site.

The anatomy of a Google hack

Right now you are probably wondering how Google can possibly be used to hack a Web site. The technique behind a Google hack is frighteningly simple. It's so simple, in fact, that it has long been regarded as an urban legend.

Google hacking resources

Step-by-step guide: Google hacking to test your security
Make sure your Web site is not vulnerable to Google hacking. Let contributor and Microsoft MVP Brien Posey guide you through a Google hack of your Web site.

How to Google hack Windows servers
You should Google your public-facing Windows servers before a bad guy thinks to Google them first. Kevin Beaver offers Google tools and queries to help you find vulnerabilities.

A Google hack is possible because Google offers a number of query tools that searchers use while performing a Google search. Most people don't even know that these query tools exist, but they can be combined with keywords during a Google search.

A classic example of a Google hack is to use the range tool (a double period) to hunt for credit card numbers. Rumor has it that Google now blocks this particular exploit, but the technique can be applied to other types of hacks.

Hackers look at the first four digits on your credit card. Suppose for instance that the numbers are 4052 (this is a random number, not a number off of my credit card). Hackers know that credit card account numbers are typically 16 digits long. They also know that the first four digits in a card's number tell a lot about the type of card. Therefore, there are lots of cards that share the same first four digits. A hacker can then use the range tool to hunt for other credit card numbers that start with 4052. To do so, a hacker would simply enter 4052000000000000..4052999999999999 into the Google search engine. This tells Google to search for Web sites containing any 16-digit number starting with 4052.

Of course there are lots of Web sites that contain 16-digit numbers other than credit card numbers. Keep in mind, though, that the more numbers in this range that Google finds, the higher the page ranking will be. This means that a page full of credit card numbers containing 4052 would likely be toward the very top of the list.

See how easy that was? Right now you may be wondering who in their right mind would publish a page full of credit card numbers on the Internet? The answer is nobody. Poorly constructed Web applications that sell products on the Internet are the problem. The Google spider can index Web sites by indexing pages that use "invisible links." Some poorly constructed Web sites have invisible links to backend data, such as customer lists. A consumer would never see these links, but a search engine does, and therefore indexes the content.

Google Hack Honeypot to the rescue

This is where the Google Hack Honeypot comes in. The idea behind a Google Hack Honeypot is that it places an invisible link onto your Web site. Just like the case with a poorly constructed application, visitors to your site will never see this link, but Google will. However, instead of providing access to backend data, the link directs would-be hackers to a PHP script that logs their activity. Your site's real backend is never exposed through this link.

The best part is that you can get the Google Hack Honeypot for free. It is available and downloadable through GNU public license.

Protecting your Web server against Google hacks

The Google Hack Honeypot will not stop anyone from performing a Google hack against you. All it does is log potentially malicious activity against the honeypot. You can, however, use the log's contents to protect your server.

For example, since the log contains things like the IP address or the domain name from which the hack originated, you could plug this information into your firewall and block Web traffic from those sources. Likewise, Internet Information Server contains filters that you could use in conjunction with the information from your honeypot to block malicious traffic.

Conclusion

In this article, I have explained that Google can be a dangerous hacking tool. You can use a Google Hack Honeypot to detect malicious activity against your Web server and enter information from your honeypot logs into your firewall to block sources of malicious Web traffic. Remember, though, that a Google Hack Honeypot will only detect malicious Web traffic against the honeypot. It does nothing to detect malicious traffic against your Web site or to protect you from such traffic. It is therefore important to make sure your Web site is securely constructed.

Brien M. Posey, MCSE, is a Microsoft Most Valuable Professional for his work with Windows 2000 Server and IIS. He has served as CIO for a nationwide chain of hospitals and was once in charge of IT security for Fort Knox. As a freelance technical writer, he has written for Microsoft, TechTarget, CNET, ZDNet, MSD2D, Relevant Technologies and other technology companies. You can visit his personal Web site at www.brienposey.com.


More information from SearchWindowsSecurity.com

  • Learning Center: Google hacking
  • Tip: How to Google hack Windows servers
  • Security clinic: What to do when you've been hacked


  • Rate this Tip
    To rate tips, you must be a member of SearchEnterpriseDesktop.com.
    Register now to start rating these tips. Log in if you are already a member.


    Submit a Tip




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Intrusion detection, prevention and removal
    Tools for virus removal and detection
    Buffer overflows can be prevented by GS cookies
    Determining the proper Microsoft malware removal tool
    October patches fix four threats
    Cool things about security, nothing about Britney Spears
    Run third-party malware detection tools in Windows
    Malware prevention and detection webcast series
    Rootkit and malware detection and removal guide
    Preventing malware with tools, patches and education
    Removing malware from your Windows system

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

    HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts