Google
Hackers claim that Goolag Scanner enables anyone to audit websites via Google

Hackers develop Google-based scanning tool

Cult of the Dead Cow strikes again

Clement James

Notorious hacker group Cult of the Dead Cow (cDc) has released a web auditing tool which uses Google to find vulnerabilities on sites.

The group claims that the Goolag Scanner enables anyone to audit their own website via Google.

Advertisement

The scanner technology is based on 'Google hacking', a form of vulnerability research developed by a cDc member known as 'Johnny I Hack Stuff'.

Available as a downloadable application, Goolag makes use of 'dorks', or detailed search patterns that show untapped results for sites previously indexed by Google.

Dorks find results that might show information relevant to security issues and/or confidential data, and are not limited to Google's search engine, according to cDc.

However, the Goolag Scanner is focused on usability. It simplifies the use of myriad numbers of dorks to a few mouse clicks, and does not require cryptic command line options or knowledge of 'Google hacking'.

We've seen some pretty scary holes through random tests with the scanner in North America, Europe, and the Middle East

'Oxblood Ruffin' Spokesman, Cult of the Dead Cow

Goolag Scanner comes with its own dorks database, but it is not limited to this, essentially lowering the bar for would be hackers using dorks to scan sites for vulnerabilities.

"It is no big secret that the web is the platform, and this platform pretty much sucks from a security perspective," said cDc spokesman 'Oxblood Ruffin'.

"Goolag Scanner provides one more tool for site owners to patch their online properties. We've seen some pretty scary holes through random tests with the scanner in North America, Europe, and the Middle East.

"If I were a government, a large corporation, or anyone with a large website, I'd be downloading this beast and aiming it at my site yesterday. The vulnerabilities are that serious."

With Goolag, cDc appears to be repeating history by putting easy-to-use hacking tools into the hands of novices.

The group shot to notoriety during the 1990s with the release of the BackOrifice tools which allowed low-level users to hijack and take control of Windows PCs.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Hacking

Cyber-squatters reaping rich rewards

But brand holders are fighting back

DRam

DRam crack breaks encryption software

Researchers find way to foil disk encryption

Major Canadian hacker ring cracked

The Mounties always get their man

Malware gets up close and personal

Regional attacks increasing, says McAfee

Related whitepapers

Related jobs

Most watched

Summit video: Intel discusses processors designed for data overload (part one of two)

Intel explains how its Xeon processors can handle data-intensive apps

Summit: Intel discusses processors for data overload (part 2 of 2)

More thoughts on how servers can help manage overload

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

deloitte

Summit interview: Deloitte discusses security implications of the data deluge

We chat to Mike Maddison, UK head of Security, Privacy...

ibm logo

IBM boosts mobile shopping with WebSphere Commerce

Update designed to give mobile users a richer, more personalised...

Summit: Intel discusses processors for data overload (part 2 of 2)

More thoughts on how servers can help manage overload

chrome logo

Google plans a Mac version of Chrome

A Mac-friendly version of the browser is in the pipeline

Primary Navigation