This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here
by Phil Muncaster
16 Aug 2011
Hackers could be generating more than 80,000 queries a day using botnets as they look to harvest the power of search engines to discover the most vulnerable targets on the web to attack, according to the latest research from Imperva.
The web application security firm revealed in its Hacker Intelligence Initiative report that the attackers use specially crafted search queries known as 'Dorks' or 'Google Dorks' which focus on specific locations or sites to zero in on a potential attack target.
These Dorks are exchanged by hackers on underground forums such as the Google Hacking Database, the firm said.
The search results can then be used by the hackers to identify vulnerabilities and launch attacks to steal or alter data or even compromise company servers.
"The search engines are aware of this abuse of functionality and have implemented various anti-automation techniques, but the figures from the report show that an enormous amount of queries are possible," Imperva chief technology officer Amichai Shulman told V3.
"The hackers are mitigating these anti-automation techniques by distributing their queries over IP addresses and by narrowing the search terms."
Shulman explained that his team has been monitoring Dork activity in two search applications. While the team has not been monitoring "the most prominent" engines, such as Google's, Shulman predicted that this activity will be "fairly common" among all search engines.
Google could not be reached for comment at the time of writing.
Imperva urged search engine companies to look more closely at network traffic, picking out queries which are known to be part of public Dorks databases or that look for known sensitive files.
The security firm added that any IP addresses suspected of being part of a botnet should be blacklisted, and strict anti-automation technology, such as Captcha, should be applied.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
How concerned are you by the rising tide of cyber threats?
BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10
Updating your subscription status
Connect with V3.co.uk
It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model
BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs
Site Support Engineer / Field Service Engineer (Telecoms...
Junior Data Analyst (Excel), to £15K Our client is...
Graduate Software Developer, (C# / .Net) to £18K Our...
Assistant Bid Manager / Bid Writer - Weybridge Key...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree