Pulp Google Hacking
The Next Generation Search Engine Hacking Arsenal
3 August 2011 – Black Hat 2011 – Las Vegas, NV Presen sented ed b by: Francis Brown Rob Ragan Stach & Liu, LLC www.stachliu.com
Pulp Google Hacking The Next Generation Search Engine Hacking - - PowerPoint PPT Presentation
Pulp Google Hacking The Next Generation Search Engine Hacking Arsenal 3 August 2011 Black Hat 2011 Las Vegas, NV Presen sented ed b by: Francis Brown Rob Ragan Stach & Liu, LLC www.stachliu.com Agenda O V E R V I E W
The Next Generation Search Engine Hacking Arsenal
3 August 2011 – Black Hat 2011 – Las Vegas, NV Presen sented ed b by: Francis Brown Rob Ragan Stach & Liu, LLC www.stachliu.com
2
ucti tion/B /Background und
anced A d Attac acks
ed D Defenses es
uture Di Directi tions O V E R V I E W
3
G E T T I N G U P T O S P E E D
4
S E A R C H I N G P U B L I C S O U R C E S
OSI OSINT – is a form of intelligence collection management that involves finding, selecting, and acquiring information from pu publ blicly av y avai ailab able sources and analyzing it to prod
uce actiona nabl ble intel elligenc ence.
5
S E A R C H E N G I N E A T T A C K S
6
S E A R C H E N G I N E A T T A C K S
class Bing { public static string Search(string query) { return Google.Search(query); } }
7
G O O G L E H A C K I N G D A T A B A S E
vulnerability data (59)
8
Lul LulzSec and Anony nymo mous s believed to use Goog
Hacki cking g as a primary means of identifying vulnerable targets.
Their releases have nothing to do with their goals
find with their "google hacking" queries and then release it.
R E A L W O R L D T H R E A T
9
R E A L W O R L D T H R E A T
22: 22:14 <@k 14 <@kay ayla la> > Sooooo...using the link above and the google hack string. !Host=*.* intext:enc_UserPassword=* ext:pcf Take your pick of VPNs you want access too. Ugghh.. Aaron Barr CEO HBGary Federal Inc. 22: 22:15 15 <@k <@kay ayla> la> download the pcf file 22: 22:16 <@k 16 <@kay ayla> la> then use http://www.unix-ag.uni- kl.de/~massar/bin/cisco-decode?enc= to clear text it 22: 22:16 <@k 16 <@kay ayla> la> = free VPN
10
G O O G L E H A C K I N G R E C A P
Dates Event 2004 Google Hacking Database (GHDB) begins May 2004 Foundstone SiteDigger v1 released Jan 2005 Foundstone SiteDigger v2 released Feb 13, 2005 Google Hack Honeypot first release Feb 20, 2005 Google Hacking v1 released by Johnny Long Jan 10, 2006 MSNPawn v1.0 released by NetSquare Dec 5, 2006 Google stops issuing Google SOAP API keys Mar 2007 Bing disables inurl: link: and linkdomain: Nov 2, 2007 Google Hacking v2 released
11
G O O G L E H A C K I N G R E C A P
Dates Event Mar 2008 cDc Goolag - gui tool released Sept 7, 2009 Google shuts down SOAP Search API Nov 2009 Binging tool released by Blueinfy Dec 1, 2009 FoundStone SiteDigger v 3.0 released 2010 Googlag.org disappears April 21, 2010 Google Hacking Diggity Project initial releases Nov 1, 2010 Google AJAX API slated for retirement Nov 9, 2010 GHDB Reborn Announced – Exploit-db.com July 2011 Bing ceases ‘&format=rss’ support
12
W H A T Y O U S H O U L D K N O W
13
Google Diggity
le JSON/ATO TOM A API
Bing Diggity
S T A C H & L I U T O O L S
14
Google Diggity - New API
JSON ON/ATOM AP API
D I G G I T Y C O R E T O O L S
15
Download Buttons for Google/Bing Diggity
D O W N L O A D B U T T O N
16
SLDB Updates in Progress
project/#SharePoint – GoogleDiggity Dictionary File
A U T O - U P D A T E S
17
D I G G I T Y C O R E T O O L S
18
D I G G I T Y C O R E T O O L S
19
BHDB – Bing Hacking Data Base
rl:, li link nk: and li link nkdomain: directives in March 2007
t:, allin inti titl tle:, allinu inurl:
ilety type: : functionality
Example - Bing vulnerability search:
S T A C H & L I U T O O L S
20
A L L T O P L E V E L D O M A I N S
N E W G O O G L E H A C K I N G T O O L S
21
22
V U L N S I N O P E N S O U R C E C O D E
public code, including popular open source code repositories:
23
A M A Z O N C L O U D S E C R E T K E Y S
N E W G O O G L E H A C K I N G T O O L S
24
25
D I G G I T Y T O O L K I T
26
F O O T P R I N T I N G L A R G E O R G A N I Z A T I O N S
N E W G O O G L E H A C K I N G T O O L S
27
28
D I G G I T Y T O O L K I T
to find off-site links of target applications/domains
to determine if any are malware distribution sites
applications are directly linking to
29
M A L W A R E G O N E W I L D
Malware Distribution Woes – WSJ.com – June2010
customers
30
M A L W A R E G O N E W I L D
Malware Distribution Woes – LizaMoon – April2011
customers
31
M A L W A R E G O N E W I L D
Malware Distribution Woes – willysy.com - August2011
customers
32
D I G G I T Y T O O L K I T
33
D I G G I T Y T O O L K I T
34
D I A G N O S T I C S I N R E S U L T S
N E W G O O G L E H A C K I N G T O O L S
35
36
L O T S O F F I L E S T O D A T A M I N E
37
M O R E D A T A S E A R C H A B L E E V E R Y Y E A R
2004 2007 2011 100,000,000 200,000,000 300,000,000 400,000,000 500,000,000 600,000,000 PDF DOC XLS TXT 10,900,000 2,100,000 969,000 1,720,000 260,000,000 42,000,000 16,100,000 30,100,000 513,000,000 84,500,000 17,300,000 46,400,000
Google Results for Common Docs
2004 2007 2011
38
D I G G I T Y T O O L K I T
N E W G O O G L E H A C K I N G T O O L S
39
40
D I G G I T Y T O O L K I T
for S r SWF WF files on target domains
load ad SWF files to C:\DiggityDownloads\
assemble mble SWF files and an analy alyze for Flash vulnerabilities
N E W G O O G L E H A C K I N G T O O L S
41
42
GoogleScrape Diggity
headers
= value
D I G G I T Y T O O L K I T
N E W G O O G L E H A C K I N G T O O L S
43
44
C H I N A S E A R C H E N G I N E
45
P R O T E C T Y O N E C K
46
G O O G L E H A C K I N G D E F E N S E S
47
“H A C K Y O U R S E L F”
Mul Multi-eng engine r ne results
Real eal-time u me updates es
Conveni enient ent
Hist storical ar archi hived dat d data
Multi-do doma main s n searchi hing Tools e s exist st
48
N E W H O T S I Z Z L E
Stach & Liu now proudly presents:
and B d Bing Hac Hacking A Alerts
Diggity A y Alerts ts F FUNd Ndle Bund undles
lert Clien lient T Tools
49
Google Hacking Alerts
A D V A N C E D D E F E N S E S
50
A D V A N C E D D E F E N S E S
51
Bing Hacking Alerts
ttp://api api.bi bing. g.co com/ m/rss.as aspx px
>900 Bing h g hack ack qu queries via RSS
A D V A N C E D D E F E N S E S
52
L I V E V U L N E R A B I L I T Y F E E D S
World’s Largest Live Vulnerability Repository
~3000 n new h hits pe per day day
A D V A N C E D D E F E N S E T O O L S
53
Diggity Alerts One Feed to Rule Them All
54
A D V A N C E D D E F E N S E S
55
A D V A N C E D D E F E N S E S
56
M O B I L E F R I E N D L Y
A D V A N C E D D E F E N S E T O O L S
57
58
F I N D I N G S C A D A S Y S T E M S
59
S H O D A N R S S F E E D S
60
T H I C K C L I E N T S T O O L S
Google/Bing Hacking Alert Thick Clients
SS feeds a as i inp nput ut
et one o e or mo more e filt filter ers
thick c client nts being released:
A D V A N C E D D E F E N S E T O O L S
61
62
A D V A N C E D D E F E N S E S
A D V A N C E D D E F E N S E T O O L S
63
iDiggity Alerts
64
A D V A N C E D D E F E N S E S
65
A D V A N C E D D E F E N S E S
66
“G O O G L E / B I N G H A C K A L E R T S”
Mul Multi-eng engine r ne results
Real eal-time u me updates es
Conveni enient ent
Hist storical ar archi hived dat d data
Mul Multi-do doma main s n searchi hing Tools e s exist st
67
I S N O W
68
D A T A M I N I N G V U L N S
Diggity Alerts Database
69
3RD P A R T Y I N T E G R A T I O N
New maintainers of the GHDB – 09 Nov 2010
For
mor
e info:
Email: contact@stachliu.com Project: diggity@stachliu.com Stach & Liu, LLC www.stachliu.com
72
Stach ach & & Li Liu G Google gle Hack acking g Diggi ggity Pr Proj
info:
http://www.stachliu.com/index.php/resources/tools/google-hacking-diggity-project/