Home > Windows Security Tips > Vulnerability/Authentication tips for Windows > Google your Windows security vulnerabilities
Windows Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

VULNERABILITY/AUTHENTICATION TIPS FOR WINDOWS

Google your Windows security vulnerabilities


Kevin Beaver
04.14.2005
Rating: -3.64- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


The following tip is one of a series on why and how to perform security scans against your public-facing servers using Google. Return to the main series page for the complete list of tips.


If you perform information security assessments -- penetration tests, vulnerability assessments or broader ethical hacking tests -- there's one testing tool you must not be without. Although it may be hard to be "without" a Web site, Google (yes, www.google.com) is one of the hottest tools you can use on a regular basis to test Windows systems for security holes. Given that its functionality and power can even be used against you, it's a good tool to get to know and use on your systems before malicious attackers do it for you.

Aside from all the neat things you can do with Google, one of its greatest qualities is its non-existent price. Google can be considered the poor man's vulnerability assessment tool or the tool for security administrators with little or no IT budget (i.e. most everyone). I'm a big advocate of commercial security tools, which tend to offer more thorough testing features, superior reporting capabilities and other utilities that can make your life easier. However, the adage 'you get what you pay for' doesn't ring true with them. Google provides a hacker's eye view in doing things you never imagined, or were able, to do with any security testing tool (commercial, freeware or open source) – all for free!

Like many external testing tools, Google is great for seeing what you're currently serving up to the world. However, it also crawls, caches, pokes and prods to dig up information you never new existed, much less knew was available for the taking on the Internet. You have several options to perform your security assessment queries. There's the Google home page, the Advanced Search page and you can even write your own custom Web applications using the Google API.

When conducting information security tests on your systems, ideally you want to look at things from a hacker's eye view -- which is where Google excels. Here's just a sampling of information Google can find during your ethical hacking tests:

    1. credit card information, social security numbers and other confidential information embedded in publicly-accessible Web applications and databases
    2. network cameras (webcams)
    3. word processing documents, spreadsheets and presentation files
    4. Outlook Web Access-related files
    5. default (and often insecure) IIS files and custom IIS error messages
    6. supposedly "hidden" Web site login pages
    7. rogue hosts that don't belong on your network
    8. news group postings containing sensitive information

As an example related to that last item, when performing a basic search of Google Groups, I came across support group information posted by a network administrator for a telecom vendor I was considering. The posting divulged details about the vendor's internal network configuration, including network layout, internal IP addresses and host names. He revealed a little too much information, giving me the gut feeling that I shouldn't trust that company with my sensitive corporate information. I found this information with a simple search of the company name and a few keywords – just the beginning of what can be found using advanced Google queries!

In today's world of high-priced vulnerability assessment tools, Google is a breath of fresh air and its security testing queries are unmatched. To stay on top of security vulnerabilities, you not only have to think like a hacker, but you also have to use new and innovative methods for testing. Google allows you to do just that.

In the near future, I'll talk about the types of Windows-centric tests you can perform against your systems along with actual Google queries you can use to help make sure your Windows systems' security is the best it can be.


Click for the next tip in this series, Google tools for automated hacking tests, or go to the main series page.

About the author: Kevin Beaver is an independent information security consultant, author, and speaker with Atlanta-based Principle Logic, LLC, where he specializes in information security assessments for those who take security seriously and incident response for those who don't. He is author of the book Hacking For Dummies and co-author of the upcoming book Hacking Wireless For Dummies, both by Wiley Publishing. Send your ethical hacking questions to Kevin today.


More information from SearchWindowsSecurity.com

  • Webcast: Get hands-on techniques for testing Windows security
  • Topics: Research Windows flaws and vulnerabilities in this section
  • Tip: Report your Windows vulnerabilities to Microsoft


  • Rate this Tip
    To rate tips, you must be a member of SearchWindowsSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Hardening
    ActiveX security improves with Internet Explorer 8's security features
    Web security features of Internet Explorer 8
    How can I use Process Explorer as a Web security tool?
    New Windows security tool protects users from keyloggers: XecureCK
    Cross-site scripting 101: XSS attacks plague Web browsers
    What's hot in Windows security? New Microsoft Office Security Guide
    Data protection on the Web: Windows SSL security and other myths
    What's hot in Windows security: Updating Windows Update; new IE scare
    Web security tactics that harden Windows networks
    What do you know about Microsoft Internet security?

    Product Flaws and Vulnerabilities
    Exploit code targets unpatched PowerPoint flaw
    Debunking the "Blue Pill" Vulnerability Theory
    Anatomy of the Blue Pill attack
    New Microsoft Word zero-day exploit discovered
    MS06-040 review: 'Urgently critical' patch release
    An introduction to Google Hack Honeypots
    Blocking peer-to-peer applications
    Step 1: Blocking peer-to-peer applications
    Step 3: Application-level filters
    Step 4: Software restriction with Group Policy

    IM and E-mail Vulnerabilities
    Stration worm targets Windows machines
    Who is reading my email?
    SearchExchange.com E-mail Security Webcast Series: Locking down Exchange Server
    10 tips in 10 minutes: Phishing exposed
    Office 2003 SP2's antiphishing filter for Outlook
    Freebie antiphishing tool verifies domain information
    Online scams: Top 5 best of the worst
    New Bagle variants on the prowl
    Who, or what, is reading your email?
    Security Bytes: Major spammer offers an allocution
    IM and E-mail Vulnerabilities Research

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts