Tuesday, April 12, 2005

Google Hacking for Penetration Testers

Google Hacking for Penetration Testers is a new book on Google Search. Here is the review of the book on slashdot.

Here is my favourite part of the review
"A quick Google search does the trick. Or, suppose you found some new exploit code that only works against a particular version of IIS 5.0. Submit a quick Google query for a helpful list of possible targets. Do you want to harvest user logins, passwords (for example, mySQL passwords in a connect.inc file), credit card numbers, social security numbers or any other potentially damaging tidbit that Web users and administrators accidentally leak onto the Internet? Google Hacking shows you how, with highly refined searches gleaned from the community contributing to the Google Hacking database (GHDB) found on Long's Web site."

Related Book: Google Hacks, 2nd Edition (Hacks)
This is the first book that described the Google Hacks and showed the world new ways of finding what you want.

Update 1 : This site has the 8th chapter excerpts from the book
Google Hacking for Penetration Testers. Must read article

Update 2:
Book Review: Google Hacks (2nd ed.) and Google Hacking for Penetration Testers

"
Google is like an iceberg — a huge entity, of which only a small amount is visible. Millions of casual users find Google quite usable and helpful. Yet there are many who would like to take advantage of the full capabilities of Google. Once harnessed, Google becomes an even more invaluable and indispensable tool.

Like an iceberg, there is a giant mass hidden beyond Google's simple interface. There are now more than 30 books on Google and two of the most beneficial ones are those that detail those hidden powers of Google, namely Google Hacks: Tips & Tools for Smarter Searching and Google Hacking for Penetration Testers. Rather than overlapping, these books are complementary and focus on different uses of Google."

No comments: