Using google as a hacking tool

Protecting your Linux box
s7r1k3r
Battalion Quarter Master Havaldaar
Posts: 221
Joined: Wed Aug 07, 2002 3:02 pm
Location: Rawalpindi

A little correction

Post by s7r1k3r »

Assalam-O-Alaekum!

No need to configure the web server or file permissions for this. All we need is a function in php, asp etc. And call this function from each page that should not be indexed by google. This function should check the referer field and either die() if it is google bot or let the script continue.
a10n3 s7r1k3r
lambda
Major General
Posts: 3452
Joined: Tue May 27, 2003 7:04 pm
Location: Lahore
Contact:

Re: A little correction

Post by lambda »

s7r1k3r wrote:This function should check the referer field and either die() if it is google bot or let the script continue.
that would entail converting all your site page content to php or asp or something. not only that, google might cache errors for your site pages.

the meta tag works great, on the other hand.
s7r1k3r
Battalion Quarter Master Havaldaar
Posts: 221
Joined: Wed Aug 07, 2002 3:02 pm
Location: Rawalpindi

YesAssa

Post by s7r1k3r »

Assalam-O-Alaekum!

Well, this was one solution only ;)
a10n3 s7r1k3r
LinuxFreaK
Site Admin
Posts: 5132
Joined: Fri May 02, 2003 10:24 am
Location: Karachi
Contact:

Re: YesAssa

Post by LinuxFreaK »

Dear s7r1k3r,
Salam,
s7r1k3r wrote:Well, this was one solution only ;)
I don't think so this is only the solution :) I think there are softwares through which you can do content filtering like http://pta.gov.pk you will be blocked by the Squid or place a nice switch or firewall on your web server :)
ERROR
The requested URL could not be retrieved

--------------------------------------------------------------------------------

While trying to retrieve the URL: http://pta.gov.pk/

The following error was encountered:

Access Denied.
Access control configuration prevents your request from being allowed at this time. Please contact your service provider if you feel this is incorrect.

Your cache administrator is webmaster.



--------------------------------------------------------------------------------

Generated Fri, 09 Jan 2004 21:36:30 GMT by cbrtest.nacspl.net (squid/2.5.STABLE4)
Best Regards.
Farrukh Ahmed
Aadil
Naik
Posts: 60
Joined: Fri Dec 27, 2002 10:36 pm
Contact:

Post by Aadil »

Right.. well, back on topic. There are certain other techniques and methods of performance one can use to skillfully use Google to your choice.
That includes looking for webadmin pannels using google and or searching for missconfigured servers that allow access to critical directories.
Whatever you do after you find what you're looking for, is another story.
Firstly, a very popular search query is looking for free music. A lot of webservers use a ftproot to store that content. A simple search, inurl:ftprootcould possibly lead to desired results.
There are other drastic searches aswell, such as looking for the /etc/passwd file using Google. If nothing much, it could reveal usernames of people on that b0x.
I forget the name of Exchange server's remote Admin pannel now. Which is also very readily found using the "Index of" search.
Apart from these, there are quite a few Hacks for Google in a freely distributed paper lying around the web.
Luckily, I have a link.
Other books in hard copy, such as, "Hungry Minds, Google for dummies" and "Oreilly's Google Hacks" are one of the best books about Google out there.
Getting skilled with Google is profitable in every aspect.
fahadjalalii
Cadet
Posts: 5
Joined: Sun Sep 19, 2004 2:34 am

Hmmmm

Post by fahadjalalii »

Nice
Post Reply