Tool Turns Google into Vulnerability Scanner

Thursday, 21 February 2008 21:08 by Selecters

The Cult of the Dead Cow hacking group has released a free tool that turns Google into a point-and-click vulnerability scanner.

Cult of the Dead Cow, or cDc, an old-school hacking crew famous for its anti-censorship stance, has shipped a new tool that turns the Google search engine into an easy-to-use vulnerability scanner.
Taking its cue from Johnny Long's Google Dorks—search queries that reveal sensitive information—cDc's new Goolag Scan pushes the envelope even more, offering a stand-alone Windows GUI-based application to power the searchers.
The open-source program comes with about 1,500 custom Google search queries embedded by default to run searches for vulnerable Web applications, misconfigured Web servers with open backdoors, sensitive user names and passwords, and other documents accidentally exposed on the Internet.
"It's no big secret that the Web is the platform," said Oxblood Ruffin, a spokesperson for the hacker think tank. "This platform pretty much sucks from a security perspective. Goolag Scanner provides one more tool for Web site owners to patch up their online properties.
"We've seen some pretty scary holes through random tests with the scanner in North America, Europe and the Middle East. If I were a government, a large corporation, or anyone with a large Web site, I'd be downloading this beast and aiming it at my site yesterday. The vulnerabilities are that serious," Ruffin said.
The utility ships as a .Net program that can be manually configured to power Google queries for specific servers or for an entire set of domains.
For example, a business can ask Goolag Scan to search for vulnerable servers or "files containing juicy information" on all its Web sites, turning the scanner into a useful auditing tool.

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5
Tags:   , ,
Categories:   Download | General | Google | Security | Software
Actions:   E-mail | Permalink | Comments (1) | Comment RSSRSS comment feed

Related posts

Comments

March 12. 2008 01:24

vulnerability scanner

I think that using google as a vulnerability scanner is brilliant. Google has huge computing power and they are known to allow developers and the community to do very cool stuff with their system. However, I think that if you want to rely on a good vulnerability scanner, you should use a commercial service and not an open source solution. You need a phone number where you can complain - if it is free you can not complain.

vulnerability scanner

Add comment


(Will show your Gravatar icon)  

  Country flag

[b][/b] - [i][/i] - [u][/u]- [quote][/quote]



Live preview

July 23. 2008 09:33