• No results found

Hacker Halted 2011 Pulp Google Hacking 27Oct2011 pdf

N/A
N/A
Protected

Academic year: 2020

Share "Hacker Halted 2011 Pulp Google Hacking 27Oct2011 pdf"

Copied!
74
0
0

Loading.... (view fulltext now)

Full text

(1)

Pulp Google Hacking

The Next Generation Search Engine Hacking Arsenal

27 October 2011 – Hacker Halted 2011 – Miami, FL

(2)

Agenda

2

• Introduction/Background • Advanced Attacks

• Google/Bing Hacking - Core Tools

• NEW Diggity Attack Tools

• Advanced Defenses

• Google/Bing Hacking Alert RSS Feeds

• NEW Diggity Alert Feeds and Updates

• NEW Diggity Alert RSS Feed Client Tools

• Future Directions

(3)

Introduction/

Background

3

(4)

Open Source Intelligence

4

S E A R C H I N G P U B L I C S O U R C E S

OSINT – is a form of intelligence

collection management that involves

finding, selecting, and acquiring

information from

publicly available

(5)

Google/Bing Hacking

5

(6)

Google/Bing Hacking

6

S E A R C H E N G I N E A T T A C K S

Bing's source leaked!

class Bing {

public static string Search(string

query)

{

return Google.Search(query);

}

(7)

Attack Targets

7

• Advisories and Vulnerabilities (215)

• Error Messages (58)

• Files containing juicy info (230)

• Files containing passwords (135)

• Files containing usernames (15)

• Footholds (21)

• Pages containing login portals (232)

G O O G L E H A C K I N G D A T A B A S E

• Pages containing network or

vulnerability data (59)

• Sensitive Directories (61)

• Sensitive Online Shopping Info (9)

• Various Online Devices (201)

• Vulnerable Files (57)

• Vulnerable Servers (48)

(8)

Google Hacking = Lulz

8

LulzSec and Anonymous believed to use

Google Hacking as a primary means of

identifying vulnerable targets.

Their releases have nothing to do with their goals or their lulz. It's purely based on whatever they find with their "google hacking" queries and then release it.

-- A-Team, 28 June 2011

(9)

Google Hacking = Lulz

9

R E A L W O R L D T H R E A T

22:14 <@kayla> Sooooo...using the link above and the google hack string.

!Host=*.* intext:enc_UserPassword=* ext:pcf Take your pick of VPNs you want access too. Ugghh.. Aaron Barr CEO HBGary Federal Inc.

22:15 <@kayla> download the pcf file

(10)

Quick History

10

G O O G L E H A C K I N G R E C A P

Dates Event

2004 Google Hacking Database (GHDB) begins May 2004 Foundstone SiteDigger v1 released

Jan 2005 Foundstone SiteDigger v2 released Feb 13, 2005 Google Hack Honeypot first release

Feb 20, 2005 Google Hacking v1 released by Johnny Long Jan 10, 2006 MSNPawn v1.0 released by NetSquare

(11)

Quick History…cont.

11

G O O G L E H A C K I N G R E C A P

Dates Event

Mar 2008 cDc Goolag - gui tool released

Sept 7, 2009 Google shuts down SOAP Search API Nov 2009 Binging tool released by Blueinfy Dec 1, 2009 FoundStone SiteDigger v 3.0 released 2010 Googlag.org disappears

April 21, 2010 Google Hacking Diggity Project initial releases

Nov 1, 2010 Google AJAX API slated for retirement

(12)

Advanced Attacks

12

(13)

Diggity Core Tools

13

Google Diggity

• Uses Google JSON/ATOM API

• Not blocked by Google bot detection

• Does not violate Terms of Service

• Required to use

Bing Diggity

• Uses Bing 2.0 SOAP API

• Company/Webapp Profiling

• Enumerate: URLs, IP-to-virtual hosts, etc.

• Bing Hacking Database (BHDB)

• Vulnerability search queries in Bing format

(14)

New Features

14

Google Diggity - New API

• Updated to use Google JSON/ATOM API • Due to deprecated Google AJAX API

Misc. Feature Uprades

• Auto-update for dictionaries • Output export formats

• Now also XLS and HTML • Help File – chm file added

(15)

New Features

15

Download Buttons for Google/Bing Diggity

• Download actual files from Google/Bing search results • Downloads to default: C:\DiggityDownloads\

• Used by other tools for file download/analysis: • FlashDiggity, DLP Diggity, MalwareDiggity,…

(16)

New Features

16

SLDB Updates in Progress

• Example: SharePoint Google Dictionary

http://www.stachliu.com/resources/tools/sharepoint-hacking-diggity-project/#SharePoint – GoogleDiggity Dictionary File

(17)

Dictionary Updates

17

3RD P A R T Y I N T E G R A T I O N

New maintainers of the GHDB – 09 Nov 2010

(18)

Google Diggity

18

(19)

Bing Diggity

19

(20)

Bing Hacking Database

20 BHDB – Bing Hacking Data Base

• First ever Bing hacking database

• Bing hacking limitations

• Disabled inurl:, link: and linkdomain: directives in March 2007

• No support for ext:, allintitle:, allinurl: • Limited filetype: functionality

• Only 12 extensions supported

Example - Bing vulnerability search: • GHDB query

• "allintitle:Netscape FastTrack Server Home Page"

• BHDB version

• intitle:”Netscape FastTrack Server Home Page"

(21)

Hacking CSE’s

21

(22)

N E W G O O G L E H A C K I N G T O O L S

(23)

Google Code Search

23

V U L N S I N O P E N S O U R C E C O D E

• Regex search for vulnerabilities in indexed

public code, including popular open source code repositories:

(24)

CodeSearch Diggity

24

(25)

Cloud Security

25

N O P R O M I S E S . . .N O N E

(26)

N E W G O O G L E H A C K I N G T O O L S

(27)

Bing LinkFromDomain

27

(28)

Bing LinkFromDomain

28

(29)

N E W G O O G L E H A C K I N G T O O L S

(30)

MalwareDiggity

30

D I G G I T Y T O O L K I T

1. Leverages Bing’s linkfromdomain: search directive

to find off-site links of target applications/domains

2. Runs off-site links against Google’s Safe Browsing API

to determine if any are malware distribution sites

(31)

Mass Injection Attacks

31

M A L W A R E G O N E W I L D

Malware Distribution Woes – WSJ.com – June2010

(32)

Mass Injection Attacks

32

M A L W A R E G O N E W I L D

Malware Distribution Woes – LizaMoon – April2011

(33)

Mass Injection Attacks

33

M A L W A R E G O N E W I L D

(34)

Mass Injection Attacks

34

M A L W A R E G O N E W I L D

Malware Distribution Woes – mysql.com - Sept2011

(35)

Malware Diggity

35

(36)

Malware Diggity

36

(37)

Malware Diggity

37

(38)

N E W G O O G L E H A C K I N G T O O L S

(39)

DLP Diggity

39

(40)

DLP Diggity

40

M O R E D A T A S E A R C H A B L E E V E R Y Y E A R

2004 2007 2011 0 100,000,000 200,000,000 300,000,000 400,000,000 500,000,000 600,000,000 PDF DOC XLS TXT 10,900,000 2,100,000 969,000 1,720,000 260,000,000 42,000,000

16,100,000 30,100,000 513,000,000

84,500,000

17,300,000 46,400,000

Google Results for Common Docs

(41)

DLP Diggity

41

(42)

N E W G O O G L E H A C K I N G T O O L S

(43)

Flash Diggity

43

D I G G I T Y T O O L K I T

• Google for SWF files on target domains

• Example search: filetype:swf site:example.com

• Download SWF files to C:\DiggityDownloads\

(44)

DEMO

N E W G O O G L E H A C K I N G T O O L S

(45)

GoogleScrape Diggity

45

GoogleScrape Diggity

• Uses Google mobile interface

• Light-weight, no advertisements

• Violates Terms of Service

• Bot detection avoidance • Distributed via proxies

• Spoofs User-agent and Referer headers

• Random &userip= value • Across Google servers

(46)

N E W G O O G L E H A C K I N G T O O L S

(47)

BaiduDiggity

47

C H I N A S E A R C H E N G I N E

(48)

Advanced Defenses

48

(49)

• “Google Hack yourself” organization

• Employ tools and techniques used by hackers

• Remove info leaks from Google cache

• Using Google Webmaster Tools

• Regularly update your robots.txt.

• Or robots meta tags for individual page exclusion

• Data Loss Prevention/Extrusion Prevention Systems

• Free Tools: OpenDLP, Senf

• Policy and Legal Restrictions

Traditional Defenses

49

(50)

Existing Defenses

50

“H A C K Y O U R S E L F”

Multi-engine results

Real-time updates

Convenient

Historical archived data

Multi-domain searching

(51)

Advanced Defenses

51

N E W H O T S I Z Z L E

Stach & Liu now proudly presents:

• Google and Bing Hacking Alerts

• SharePoint Hacking Alerts – 118 dorks • SHODAN Hacking Alerts – 26 dorks

• Diggity Alerts FUNdle Bundles

• Consolidated alerts into 1 RSS feed

• Alert Client Tools

(52)

Google Hacking Alerts

52

Google Hacking Alerts

• All hacking database queries using

• Real-time vuln updates to >2400 hack queries via RSS

• Organized and available via importable file

(53)

Google Hacking Alerts

53

(54)

Bing Hacking Alerts

54

Bing Hacking Alerts

• Bing searches with regexs from BHDB

• Leverages http://api.bing.com/rss.aspx

• Real-time vuln updates to >900 Bing hack queries via RSS

(55)

Bing/Google Alerts

55

L I V E V U L N E R A B I L I T Y F E E D S

World’s Largest Live Vulnerability Repository

(56)

A D V A N C E D D E F E N S E T O O L S

56

Diggity Alert Fundle Bundle

Diggity Alerts

(57)

FUNdle Bundle

57

(58)

FUNdle Bundle

58

(59)

FUNdle Bundle

59

(60)

A D V A N C E D D E F E N S E T O O L S

60

(61)

SHODAN Alerts

61

(62)

SHODAN Alerts

62

(63)

Bing/Google Alerts

63

T H I C K C L I E N T S T O O L S

Google/Bing Hacking Alert Thick Clients

• Google/Bing Alerts RSS feeds as input • Allow user to set one or more filters

• e.g. “yourcompany.com” in the URL

• Several thick clients being released:

• Windows Systray App

• Droid app (coming soon)

(64)

A D V A N C E D D E F E N S E T O O L S

64

(65)

Alerts Diggity

65

(66)

A D V A N C E D D E F E N S E T O O L S

66

iDiggity Alerts

(67)

iDiggity Alerts

67

(68)

iDiggity Alerts

68

(69)

New Defenses

69

“G O O G L E / B I N G H A C K A L E R T S”

Multi-engine results

Real-time updates

Convenient

Historical archived data

Multi-domain searching

(70)

Future Direction

70

(71)

Diggity Alert DB

71

(72)

Special Thanks

Oscar “The Bull” Salazar

Brad “BeSickWittIt” Sickles

Nick “King Luscious” Harbin

Prajakta “The Flasher” Jagdale

Ruihai “Ninja” Fang

(73)

Questions?

Ask us something

We’ll try to answer it.

For more info:

Email: contact@stachliu.com Project: diggity@stachliu.com Stach & Liu, LLC

(74)

Thank You

74

Stach & Liu Google Hacking Diggity Project info:

References

Related documents

Curtius’s brochure also contains an interesting account of the events of 12 July 1789, one which reveals the unique mix of the canny and the ‘uncanny’ in his art, and which sheds

Nurses clustered around four main perspectives on the barriers to research use: (1) Problems in interpreting and using research products, which were seen as too complex, academic

Since the PE only tells us about what is happening in optimal conditions, Wright normally describes our optimal judgement of whether P as at best partially determining the

(b) Mean base out (BO) prism fusion range measurements to break point of participants grouped according to their response to vergence facility testing.. Error bars at 95%

(2 more authors) (2002) Contact Transitions Tracking During Force-Controlled Compliant Motion Using an Interacting Multiple Model Estimator.. Information

Further progress has been achieved in [7, 8] where the symbolic representation of the ring of differential polynomials enables to reduce the problem of classification of

Results from a coupled deployment of pore-water gel probes in Loch Duich, Scotland, provide direct evidence for rapid recycling within the iron reduction (FeR) and sulphate

Why don't the atomic facts make it the case that I and other conscious human beings exist.. How could they fail to do so, given that human beings are made up entirely