ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Google hacking expected to boom in 2005

Munir Kotadia ZDNet Australia

Published: 14 Jan 2005 09:25 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts are predicting a massive increase this year in so-called "Google hacking", where malicious Internet users or worms use the search engine to discover resources that are not intended for public consumption.

Last year two high profile worms used Google and other search engines to find potential targets. In August, a MyDoom variant used Google to find email addresses and a few months later the Santy worm found vulnerable bulletin board applications using various search engines. Security experts expect to see a lot more this year and advise enterprises to minimise their exposure to such attacks.

Andrew Collins, security manager in Asia/Pacific for CyberTrust, said that enterprises can avoid many of the potential dangers by ensuring that network resources -- such as Web cams -- are not indexed by search engines.

"We expect to see further automated attacks using Google searches to select potential targets as well as a continuing increase in the discovery of search strings that return unintended information such as error codes, Web-based cameras and restricted/private documents and Web pages. Network enabled physical security systems, such as Web cams and digital video capture systems, should be moved onto private networks that are not addressable from the Internet," said Collins.

Web cams were also highlighted as a potential danger in a recent advisory by Gartner analyst Jay Heiser. According to Heiser, the Web interfaces of network cameras have a default address structure that can easily be found using Google hacking techniques.

"Some of the cameras reached through the search engine are meant to be viewed by the public, but many are not. Keep them up-to-date with patches and use strong passwords. Unpatched cameras have had their configuration or behaviour changed by hackers," said Heiser.

Heiser explained that most search engines look for a file called 'robots.txt', which specifies which areas of a site, if any, can be indexed.

"Using robots.txt and other techniques to prevent indexing is a best practice for non-public systems and the various components supporting public systems. Treat all Internet-facing devices -- even apparently obscure ones such as network cameras -- as relevant to security," said Heiser.

CyberTrust's Collins said that if enterprises think about their security as an entire system rather than the strengths and weaknesses of each individual application and appliance, they will be less vulnerable to attack.

"If an enterprise has invested in a strong security architecture than the threat posed by current Google hacks is minimal," said Collins.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
82 out of 159 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Service Delivery Manager - Customer Development & Food solutions - IT Manager - St. David\'s Park, Teeside , North West

Plans and manages implementation of processes and procedures, tools and techniques for monitoring and managing the performance of automated systems ...

Technical Team leader ITIL Prince II - Oxfordshire

We are currently seeking an established people manager preferably from a technical background to lead and develop the team of senior ...

C/C++ Software Engineer - 60,000 - London - C/C++ Software Engineer

Newly recruiting for a C/C++ software engineer to work within the real time pricing engine team who is responsible for calculation engines. The ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment