Tips To Protect Your Website From Google Hacking

What is Google hacking?


Google hacking is a technique that uses complex Google search and other Google applications to filter specific information from a large number of search queries. It is done to detect websites which are vulnerable to numerous exploits.

If you run a commercial website then you must be aware of these threats online and must take the required preventive measures against these threats. These are the basic and most important things which you must know about security.

Note: This information is being shared with you only to help you secure your website better and protect it against hackers.It is strictly advised not you use this information to cause any damage to anybody's resources. It completely depends on an individual, how he uses a piece of information and the author of this post will not be responsible for anything.

Some queries which can expose vulnerable parts of your website to a hacker

"Microsoft-IIS/5.0 Server at" intitle:"index of"
This query will expose all the open directory link in your website if any.


"BEGIN (DSA|RSA)" ext:key
Displays links to private keys.

filetype:inc intext:mysql_connect
This query will open links to files containing Mysql connectivity information.


filetype:conf slapd.conf
Links to configuration files for open LDAP.

inurl:"wvdial.conf" intext:"password"
Configuration files for WVDial.

ext:pwd inurl:(service|authors|administrators |users) "# -FrontPage-"
Files containing Microsoft FrontPage passwords

intitle:"Index of" pwd.db
Pwd.db files, potentially containing encrypted username and passwords

"Apache/* Server at" intitle:index.of
Query for locating any Apache web server.

inurl:config.php dbuname dbpass
Config file containing db username and db pass.

( filetype:mail | filetype:eml | filetype:mbox | filetype:mbx ) intextassword|subject
Files containing private emails and information in emails.

Tips to protect your website from Google Hacking

  • Upload a bank HTML file on your server in those directories which shows links to server files.
  • Use .htaccess file to secure your confidential files and URL's.( Guide to htaccess intro)
  • Google hacking Honeypot : It is designed to provide reconnaissance against attackers who use search engine as a hacking tool.
     

    About Author

    My PhotoMy name is Shravan Mishra and I'm a part time blogger, living in Delhi, India.

    I like to feature things which can be helpful in blogging, designing, developing or tools to improve the internet surfing experience and more.

    Read more »



    Twitter Updates

    Blog Archive

    Copyright © 2010 Smashapps All rights reserved.