Category: Certification/Security+/General Security Concepts/Vulnerability

  • Google Hacking Part 1

    I love Google.  It is changing the entire Internet for
    the better.  The only problem is that their search engine is TOO
    effective. 

    If  webmasters, security professionals and even home computer
    users aren't careful in securing their websites they could end up
    posting more information than they bargained for. 

    Here is an examples [ copy and paste the code in your browser ]:

    http://www.google.ca/search?q=inurl:password+intitle:index-of&num=100&hl=en&lr=&output=search
    Results 1 – 100 of about 4,030 for inurl:password intitle:index-of

    If you look through the websites you will actually see usernames and passwords.

    There are many groups on the Internet that find web site vulerabilites as a
    hobby. 
    They are called Google Dorks:
    www.ihackgoogle.com
    http://jn0x00.com
    http://linuxweblog.com/node/147

    With google hacking ALL roads lead to Johnny Long – iHackgoogle.com

    Google Hacking Documents:
    Hacking Primer
    Google Honey Pot
    Google Hacking

    Another cool  site I  found among Mr. Longs  Links:
    Google Cooking
    http://www.researchbuzz.org/cookin_with_google.shtml

  • Remove the HWCLOCK.EXE/W32.Hwbot-A Trojan

    I got the HWCLOCK.EXE when I was testing my new Internet connection.  I noticed it when my Internet DSL connection started feeling like a  56K dialup. 

    I removed it by going into Showing all files, going into Safe Mode and deleting the HWCLOCK.exe/W32.Hwbot-A Trojan.

    This is a trojan that can actually steal your passwords and other personal data.  On my system is was attacking other system.

    I've got more detail instructions on how to remove the HWCLOCK.exe at http://elamb.blogharbor.com/hacked/hwclock.htm

    If you found this post or others useful, feel free to donate to

    elamb – Home Computer Security.  No amount is too low (or high).