Sinisterly
"Hacking" Google - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.ly/Forum-Website-Server-Hacking)
+--- Thread: "Hacking" Google (/Thread-Hacking-Google)

Pages: 1 2


"Hacking" Google - Little Big Services - 05-12-2013

Hacking Google


Alright well let me start by saying that this isn't really hacking in the sense that most people know it as. This is simply using tools to get information that is publicly available, but not publicly displayed for everyone to clearly see. This guide is straight from the personnel at the NSA. Of course the NSA will not take direct responsibility for it nor will they claim it as their own thoughts, but we all know it's what they want or they wouldn't have used it.

If you can't take the time to PM me for the direct link then you can use the link below. If you want a direct link, send me a PM titled NSA Guide and I will send you a direct link back. Hopefully you will all enjoy this.

http://cur.lv/wskv

Say you’re a cyberspy for the NSA and you want sensitive inside information on companies in South Africa. What do you do?

Search for confidential Excel spreadsheets the company inadvertently posted online by typing “filetype:xls site:za confidential” into Google, the book notes.

Want to find spreadsheets full of passwords in Russia? Type “filetype:xls site:ru login.” Even on websites written in non-English languages the terms “login,” “userid,” and “password” are generally written in English, the authors helpfully point out.

Misconfigured web servers “that list the contents of directories not intended to be on the web often offer a rich load of information to Google hackers,” the authors write, then offer a command to exploit these vulnerabilities — intitle: “index of” site:kr password.

“Nothing I am going to describe to you is illegal, nor does it in any way involve accessing unauthorized data,” the authors assert in their book. Instead it “involves using publicly available search engines to access publicly available information that almost certainly was not intended for public distribution.” You know, sort of like the “hacking” for which Andrew “weev” Aurenheimer was recently sentenced to 3.5 years in prison for obtaining publicly accessible information from AT&T’s website.

Stealing intelligence on the internet that others don’t want you to have might not be illegal, but it does come with other risks, the authors note: “It is critical that you handle all Microsoft file types on the internet with extreme care. Never open a Microsoft file type on the internet. Instead, use one of the techniques described here,” they write in a footnote. The word “here” is hyperlinked, but since the document is a PDF the link is inaccessible. No word about the dangers that Adobe PDFs pose. But the version of the manual the NSA released was last updated in 2007, so let’s hope later versions cover it.

Although the author’s name is redacted in the version released by the NSA, Muckrock’s FOIA indicates it was written by Robyn Winder and Charlie Speight. A note the NSA added to the book before releasing it under FOIA says that the opinions expressed in it are the authors’, and not the agency’s.

Lest you think that none of this is new, that Johnny Long has been talking about this for years at hacker conferences and in his book Google Hacking, you’d be right. In fact, the authors of the NSA book give a shoutout to Johnny, but with the caveat that Johnny’s tips are designed for cracking — breaking into websites and servers. “That is not something I encourage or advocate,” the author writes.

Virus Scan:
Spoiler:
SHA256: b0afc48cd55d6062e60655a1b59a0887ea4608bb7c0d861e0f56a61c053666a4
File name: Untangling_the_Web.pdf
Detection ratio: 0 / 46
Analysis date: 2013-05-12 18:29:12 UTC ( 10 hours ago )
0 2
More details
Analysis
File detail
Additional information
Comments
Votes
Antivirus Result Update
Agnitum 20130512
AhnLab-V3 20130512
AntiVir 20130512
Antiy-AVL 20130512
Avast 20130512
AVG 20130512
BitDefender 20130512
ByteHero 20130510
CAT-QuickHeal 20130510
ClamAV 20130512
Commtouch 20130512
Comodo 20130512
DrWeb 20130512
Emsisoft 20130512
eSafe 20130509
ESET-NOD32 20130512
F-Prot 20130512
F-Secure 20130512
Fortinet 20130512
GData 20130512
Ikarus 20130512
Jiangmin 20130512
K7AntiVirus 20130510
K7GW 20130510
Kaspersky 20130512
Kingsoft 20130506
Malwarebytes 20130512
McAfee 20130512
McAfee-GW-Edition 20130512
Microsoft 20130512
MicroWorld-eScan 20130512
NANO-Antivirus 20130512
Norman 20130512
nProtect 20130512
Panda 20130512
PCTools 20130512
Sophos 20130512
SUPERAntiSpyware 20130512
Symantec 20130512
TheHacker 20130509
TotalDefense 20130512
TrendMicro 20130512
TrendMicro-HouseCall 20130512
VBA32 20130510
VIPRE 20130512
ViRobot 20130512



RE: "Hacking" Google - Little Big Services - 05-13-2013

Sent to all who PM'd me.


RE: "Hacking" Google - Little Big Services - 05-13-2013

Sent to all who PM'd me.


RE: "Hacking" Google - Linuxephus™ - 05-13-2013

(05-13-2013, 05:34 AM)Little Big Services Wrote: Sent to all who PM'd me.

No need to bump the Thread.
The Reader will do that themselves with their findings based upon what's been Inboxed.


RE: "Hacking" Google - Linuxephus™ - 05-13-2013

(05-13-2013, 05:34 AM)Little Big Services Wrote: Sent to all who PM'd me.

No need to bump the Thread.
The Reader will do that themselves with their findings based upon what's been Inboxed.


RE: "Hacking" Google - Deque - 05-13-2013

(05-13-2013, 05:39 AM)Linuxephus™ Wrote:
(05-13-2013, 05:34 AM)Little Big Services Wrote: Sent to all who PM'd me.

No need to bump the Thread.
The Reader will do that themselves with their findings based upon what's been Inboxed.

Do you realize that you are bumping the thread again by replying to it? Biggrin
I usually merge such posts, so it can't be exploited for repeated bumping.
Yes, I know that I have bumped it too.


RE: "Hacking" Google - Deque - 05-13-2013

(05-13-2013, 05:39 AM)Linuxephus™ Wrote:
(05-13-2013, 05:34 AM)Little Big Services Wrote: Sent to all who PM'd me.

No need to bump the Thread.
The Reader will do that themselves with their findings based upon what's been Inboxed.

Do you realize that you are bumping the thread again by replying to it? Biggrin
I usually merge such posts, so it can't be exploited for repeated bumping.
Yes, I know that I have bumped it too.


RE: "Hacking" Google - Linuxephus™ - 05-13-2013

(05-13-2013, 07:50 AM)Deque Wrote: Do you realize that you are bumping the thread again by replying to it? Biggrin
I usually merge such posts, so it can't be exploited for repeated bumping.
Yes, I know that I have bumped it too.

What is this, beat up on the additional Community Manager day?
Let me guess, this is the breaking in period for me, yes?

Yes, I know I too bumped it...but naturally the discipline it took not to make a comment escaped me...as usual.:lol:

I know...I'm still an idiot.:lub:


RE: "Hacking" Google - Linuxephus™ - 05-13-2013

(05-13-2013, 07:50 AM)Deque Wrote: Do you realize that you are bumping the thread again by replying to it? Biggrin
I usually merge such posts, so it can't be exploited for repeated bumping.
Yes, I know that I have bumped it too.

What is this, beat up on the additional Community Manager day?
Let me guess, this is the breaking in period for me, yes?

Yes, I know I too bumped it...but naturally the discipline it took not to make a comment escaped me...as usual.:lol:

I know...I'm still an idiot.:lub:


RE: "Hacking" Google - diana32 - 05-14-2013

All person here have a god or bad way to share his knowledge.I was interest so i send a pm and today i download the book.