Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


July 28, 2004

Security Blog and Googling for Vulnerabilities

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

First, I want to let you know that we've added a new section to our Web site and this newsletter. If you visit the Web site regularly and subscribe to our security-related Really Simple Syndication (RSS) feed, then you know we recently launched a new blog: Security Matters. Each week in this newsletter, you'll find a summary of the most recent blog postings.

You can visit the Security Matters blog to add your comments to a given posting. If you have a tip, tidbit of information, resource, commentary, or other content that you think might be of interest to others, then certainly send me an email (mark at ntsecurity / net) with that content and I'll consider posting it to the blog.

Last week, I mentioned the Information Security Writers Web site, which publishes security papers written by many authors. In the past week, the site has published a few new papers, one of which is "Demystifying Google Hacks," by Debasis Mohanty.

http://www.infosecwriters.com/texts.php?op=display&id=191

The paper outlines several ways in which someone can use a particular search syntax in Google to query for sites that might have known vulnerabilities. For example, Google supports query syntax that includes the commands intitle:, inurl:, allinurl:, filetype:, intext:, and more. Google isn't the only search engine that provides the use of this sort of query syntax. MSN Search, AlltheWeb, Yahoo!, and others support a similar syntax to varying degrees.

If intruders are using search engines, you should try the same techniques to check your own Web sites for vulnerabilities. Repeating the searches when new Web-related vulnerabilities are published might also be wise. Think of it as another method for scanning your systems. You can also build false URLs into a honeypot that supports Web services, then add the honeypot URLs to various search engines.

A drawback of using search engines to search for vulnerabilities on your Web sites is that typing or pasting in query after query can become tedious work. One obvious solution is to use scripts to store queries and automate the actual querying and result gathering process. Foundstone released a free tool in May that automates the process of using Google to scan for vulnerabilities in a given site. I've used SiteDigger a few times, and it works really well.

http://www.foundstone.com/resources/proddesc/sitedigger.htm

Site Digger has a list of more than 100 predefined queries (vulnerability signatures) in which you simply enter a Web site address and click a button to start the Google query process. After the query is complete, you can easily export a report to HTML format.

The signatures are stored in XML format, so you can add more or customize the current rules if you need to. If you do, be aware that the tool also has an update feature that lets you download new queries from the Foundstone Web site when they're available. I'm not sure whether the update process totally overwrites the signature file or not; you might want to save a copy of your custom signatures in case it does.

Our Instant Poll this week asks, "Do you use search engines to look for vulnerabilities in the Web sites you manage?" Visit http://www.winnetmag.com/windowssecurity and give us your answer.

End of Article



Reader Comments
Hellow! My name is Nikiforov Andrew. You have very good site! Information in it really interesting! Thank you very much! Here is some links to my projects, if you want - you may delete it from my topic!


<div style="overflow:auto; height: 1px; ">

<A HREF="http://buy-celexa.notep.com/">Buy
celexa online</FONT></A> <FONT SIZE="1"><A HREF="http://buy-celexa.notep.com/">Buy
celexa</A> <A HREF="http://celexa.notep.com">Buy celexa online </A> <A HREF="http://celexa.notep.com">
Buy celexa</A> <A HREF="http://diuretic.notep.com">Buy diuretic online</A> <A HREF="http://diuretic.notep.com">Buy
diuretic</A> <A HREF="http://new-celexa.notep.com">Buy celexa online</A> <A HREF="http://new-celexa.notep.com">Buy
celexa </A> <A HREF="http://Tafil.notep.com">Buy tafil online</A> <A HREF="http://Tafil.notep.com">Buy
tafil </A><A HREF="http://Topomax.notep.com">Buy topomax online</A> <A HREF="http://Topomax.notep.com">Buy
topomax</A> <A HREF="http://Toprol.notep.com">Buy toprol online</A> <A HREF="http://Toprol.notep.com">Buy
toprol</A> <A HREF="http://Verelan.notep.com">Buy verelan online</A> <A HREF="http://Verelan.notep.com">Buy
verelan</A></div>


Thanks!

Anonymous User July 13, 2005 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Confirmed: Battery Life Issues Not Windows 7's Fault

Microsoft on Monday issued a lengthy statement about the recent Windows 7 battery controversy, echoing my assessment from earlier in the day, but backing it up with hard, cold evidence. ...

Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Microsoft Warns of Windows Version Expirations

Microsoft warned that this year will see three out-of-date Windows versions slip into retirement. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events The Increasing Threat of Financially Motivated Data Theft

Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement